Commit fc3796c
committed
test(api): cover Alchemy::Node guest and member ability rules
The nodes#index authorization fix is exercised through accessible_by,
which builds its query from the ability's SQL scope and never runs the
per-instance can? block. That left the guest and member Node rule
blocks in Permissions uncovered. Add ability specs that check can?
directly for both roles, asserting guests are denied nodes linking to
restricted or unpublished pages while members may still see restricted
ones.1 parent 02c46b7 commit fc3796c
1 file changed
Lines changed: 18 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
20 | 24 | | |
21 | 25 | | |
22 | 26 | | |
| |||
44 | 48 | | |
45 | 49 | | |
46 | 50 | | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
47 | 58 | | |
48 | 59 | | |
49 | 60 | | |
| |||
72 | 83 | | |
73 | 84 | | |
74 | 85 | | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
75 | 93 | | |
76 | 94 | | |
77 | 95 | | |
| |||
0 commit comments