diff options
author | Alex Gleason <alex@alexgleason.me> | 2020-09-11 14:00:34 -0500 |
---|---|---|
committer | Alex Gleason <alex@alexgleason.me> | 2020-09-11 14:11:07 -0500 |
commit | dfb831ca39db3098d6d585448a6ff8e938e51e8c (patch) | |
tree | f459ef9da6c865a39ef00627cd8b05f4b28b83fd /test/web/admin_api/controllers/admin_api_controller_test.exs | |
parent | e229536e5cca65d811f85d25c86bf3c92b3d8c45 (diff) | |
download | pleroma-dfb831ca39db3098d6d585448a6ff8e938e51e8c.tar.gz pleroma-dfb831ca39db3098d6d585448a6ff8e938e51e8c.zip |
Chat moderation: add tests for unauthorized access
Diffstat (limited to 'test/web/admin_api/controllers/admin_api_controller_test.exs')
-rw-r--r-- | test/web/admin_api/controllers/admin_api_controller_test.exs | 29 |
1 files changed, 29 insertions, 0 deletions
diff --git a/test/web/admin_api/controllers/admin_api_controller_test.exs b/test/web/admin_api/controllers/admin_api_controller_test.exs index cf5637246..dbeeb7f3d 100644 --- a/test/web/admin_api/controllers/admin_api_controller_test.exs +++ b/test/web/admin_api/controllers/admin_api_controller_test.exs @@ -1528,6 +1528,35 @@ defmodule Pleroma.Web.AdminAPI.AdminAPIControllerTest do end end + describe "GET /api/pleroma/admin/users/:nickname/chats unauthorized" do + setup do + user = insert(:user) + insert(:chat, user: user) + %{conn: conn} = oauth_access(["read:chats"]) + %{conn: conn, user: user} + end + + test "returns 403", %{conn: conn, user: user} do + conn + |> get("/api/pleroma/admin/users/#{user.nickname}/chats") + |> json_response(403) + end + end + + describe "GET /api/pleroma/admin/users/:nickname/chats unauthenticated" do + setup do + user = insert(:user) + insert(:chat, user: user) + %{conn: build_conn(), user: user} + end + + test "returns 403", %{conn: conn, user: user} do + conn + |> get("/api/pleroma/admin/users/#{user.nickname}/chats") + |> json_response(403) + end + end + describe "GET /api/pleroma/admin/moderation_log" do setup do moderator = insert(:user, is_moderator: true) |