2020-02-21 10:09:05 -05:00
|
|
|
# frozen_string_literal: true
|
|
|
|
|
|
|
|
require 'spec_helper'
|
|
|
|
|
2020-06-24 02:09:01 -04:00
|
|
|
RSpec.describe 'Sessions' do
|
2020-02-21 10:09:05 -05:00
|
|
|
context 'authentication', :allow_forgery_protection do
|
|
|
|
let(:user) { create(:user) }
|
|
|
|
|
|
|
|
it 'logout does not require a csrf token' do
|
|
|
|
login_as(user)
|
|
|
|
|
|
|
|
post(destroy_user_session_path, headers: { 'X-CSRF-Token' => 'invalid' })
|
|
|
|
|
|
|
|
expect(response).to redirect_to(new_user_session_path)
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|