2013-09-17 16:37:36 -04:00
|
|
|
require 'spec_helper'
|
|
|
|
|
|
|
|
describe ApplicationController do
|
|
|
|
describe '#check_password_expiration' do
|
|
|
|
let(:user) { create(:user) }
|
|
|
|
let(:controller) { ApplicationController.new }
|
|
|
|
|
|
|
|
it 'should redirect if the user is over their password expiry' do
|
|
|
|
user.password_expires_at = Time.new(2002)
|
2015-02-12 13:17:35 -05:00
|
|
|
expect(user.ldap_user?).to be_falsey
|
|
|
|
allow(controller).to receive(:current_user).and_return(user)
|
|
|
|
expect(controller).to receive(:redirect_to)
|
|
|
|
expect(controller).to receive(:new_profile_password_path)
|
2013-09-17 16:37:36 -04:00
|
|
|
controller.send(:check_password_expiration)
|
|
|
|
end
|
|
|
|
|
|
|
|
it 'should not redirect if the user is under their password expiry' do
|
|
|
|
user.password_expires_at = Time.now + 20010101
|
2015-02-12 13:17:35 -05:00
|
|
|
expect(user.ldap_user?).to be_falsey
|
|
|
|
allow(controller).to receive(:current_user).and_return(user)
|
|
|
|
expect(controller).not_to receive(:redirect_to)
|
2013-09-17 16:37:36 -04:00
|
|
|
controller.send(:check_password_expiration)
|
|
|
|
end
|
|
|
|
|
|
|
|
it 'should not redirect if the user is over their password expiry but they are an ldap user' do
|
|
|
|
user.password_expires_at = Time.new(2002)
|
2015-02-12 13:17:35 -05:00
|
|
|
allow(user).to receive(:ldap_user?).and_return(true)
|
|
|
|
allow(controller).to receive(:current_user).and_return(user)
|
|
|
|
expect(controller).not_to receive(:redirect_to)
|
2013-09-17 16:37:36 -04:00
|
|
|
controller.send(:check_password_expiration)
|
|
|
|
end
|
|
|
|
end
|
2016-04-19 06:52:15 -04:00
|
|
|
|
2016-06-01 04:34:38 -04:00
|
|
|
describe "#authenticate_user_from_token!" do
|
|
|
|
describe "authenticating a user from a private token" do
|
|
|
|
controller(ApplicationController) do
|
|
|
|
def index
|
|
|
|
render text: "authenticated"
|
|
|
|
end
|
2016-04-19 06:52:15 -04:00
|
|
|
end
|
|
|
|
|
2016-06-01 04:34:38 -04:00
|
|
|
let(:user) { create(:user) }
|
2016-04-19 06:52:15 -04:00
|
|
|
|
2016-06-02 23:30:39 -04:00
|
|
|
context "when the 'private_token' param is populated with the private token" do
|
|
|
|
it "logs the user in" do
|
|
|
|
get :index, private_token: user.private_token
|
2016-06-27 14:10:42 -04:00
|
|
|
expect(response).to have_http_status(200)
|
2016-06-02 23:30:39 -04:00
|
|
|
expect(response.body).to eq("authenticated")
|
|
|
|
end
|
2016-06-01 04:34:38 -04:00
|
|
|
end
|
2016-04-19 06:52:15 -04:00
|
|
|
|
2016-06-02 23:30:39 -04:00
|
|
|
context "when the 'PRIVATE-TOKEN' header is populated with the private token" do
|
|
|
|
it "logs the user in" do
|
|
|
|
@request.headers['PRIVATE-TOKEN'] = user.private_token
|
|
|
|
get :index
|
2016-06-27 14:10:42 -04:00
|
|
|
expect(response).to have_http_status(200)
|
2016-06-02 23:30:39 -04:00
|
|
|
expect(response.body).to eq("authenticated")
|
|
|
|
end
|
2016-06-01 04:34:38 -04:00
|
|
|
end
|
2016-04-19 06:52:15 -04:00
|
|
|
|
2016-06-01 04:34:38 -04:00
|
|
|
it "doesn't log the user in otherwise" do
|
|
|
|
@request.headers['PRIVATE-TOKEN'] = "token"
|
|
|
|
get :index, private_token: "token", authenticity_token: "token"
|
2016-06-03 00:40:58 -04:00
|
|
|
expect(response.status).not_to eq(200)
|
|
|
|
expect(response.body).not_to eq("authenticated")
|
2016-06-01 04:34:38 -04:00
|
|
|
end
|
2016-04-19 06:52:15 -04:00
|
|
|
end
|
|
|
|
|
2016-06-01 04:34:38 -04:00
|
|
|
describe "authenticating a user from a personal access token" do
|
|
|
|
controller(ApplicationController) do
|
|
|
|
def index
|
|
|
|
render text: 'authenticated'
|
|
|
|
end
|
2016-04-19 06:52:15 -04:00
|
|
|
end
|
|
|
|
|
2016-06-01 04:34:38 -04:00
|
|
|
let(:user) { create(:user) }
|
|
|
|
let(:personal_access_token) { create(:personal_access_token, user: user) }
|
2016-04-19 06:52:15 -04:00
|
|
|
|
2016-06-02 23:30:39 -04:00
|
|
|
context "when the 'personal_access_token' param is populated with the personal access token" do
|
|
|
|
it "logs the user in" do
|
|
|
|
get :index, private_token: personal_access_token.token
|
2016-06-27 14:10:42 -04:00
|
|
|
expect(response).to have_http_status(200)
|
2016-06-02 23:30:39 -04:00
|
|
|
expect(response.body).to eq('authenticated')
|
|
|
|
end
|
2016-06-01 04:34:38 -04:00
|
|
|
end
|
2016-04-19 06:52:15 -04:00
|
|
|
|
2016-06-02 23:30:39 -04:00
|
|
|
context "when the 'PERSONAL_ACCESS_TOKEN' header is populated with the personal access token" do
|
|
|
|
it "logs the user in" do
|
|
|
|
@request.headers["PRIVATE-TOKEN"] = personal_access_token.token
|
|
|
|
get :index
|
2016-06-27 14:10:42 -04:00
|
|
|
expect(response).to have_http_status(200)
|
2016-06-02 23:30:39 -04:00
|
|
|
expect(response.body).to eq('authenticated')
|
|
|
|
end
|
2016-06-01 04:34:38 -04:00
|
|
|
end
|
2016-04-19 06:52:15 -04:00
|
|
|
|
2016-06-01 04:34:38 -04:00
|
|
|
it "doesn't log the user in otherwise" do
|
|
|
|
get :index, private_token: "token"
|
2016-06-03 00:40:58 -04:00
|
|
|
expect(response.status).not_to eq(200)
|
|
|
|
expect(response.body).not_to eq('authenticated')
|
2016-06-01 04:34:38 -04:00
|
|
|
end
|
2016-04-19 06:52:15 -04:00
|
|
|
end
|
|
|
|
end
|
2014-06-21 05:18:57 -04:00
|
|
|
end
|