You cannot select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
2762 lines
78 KiB
JavaScript
2762 lines
78 KiB
JavaScript
8 years ago
|
'use strict';
|
||
|
|
||
4 years ago
|
const async = require('async');
|
||
|
const assert = require('assert');
|
||
|
const nconf = require('nconf');
|
||
|
const request = require('request');
|
||
4 years ago
|
const requestAsync = require('request-promise-native');
|
||
4 years ago
|
const fs = require('fs');
|
||
|
const path = require('path');
|
||
2 years ago
|
const util = require('util');
|
||
|
|
||
4 years ago
|
const db = require('./mocks/databasemock');
|
||
2 years ago
|
const api = require('../src/api');
|
||
4 years ago
|
const categories = require('../src/categories');
|
||
|
const topics = require('../src/topics');
|
||
|
const posts = require('../src/posts');
|
||
|
const user = require('../src/user');
|
||
|
const groups = require('../src/groups');
|
||
|
const meta = require('../src/meta');
|
||
|
const translator = require('../src/translator');
|
||
|
const privileges = require('../src/privileges');
|
||
|
const plugins = require('../src/plugins');
|
||
|
const utils = require('../src/utils');
|
||
|
const helpers = require('./helpers');
|
||
8 years ago
|
|
||
2 years ago
|
const sleep = util.promisify(setTimeout);
|
||
|
|
||
4 years ago
|
describe('Controllers', () => {
|
||
4 years ago
|
let tid;
|
||
|
let cid;
|
||
|
let pid;
|
||
|
let fooUid;
|
||
3 years ago
|
let adminUid;
|
||
4 years ago
|
let category;
|
||
8 years ago
|
|
||
3 years ago
|
before(async () => {
|
||
|
category = await categories.create({
|
||
|
name: 'Test Category',
|
||
|
description: 'Test category created by testing script',
|
||
8 years ago
|
});
|
||
3 years ago
|
cid = category.cid;
|
||
|
|
||
|
fooUid = await user.create({ username: 'foo', password: 'barbar', gdpr_consent: true });
|
||
|
await user.setUserField(fooUid, 'email', '[email protected]');
|
||
|
await user.email.confirmByUid(fooUid);
|
||
|
|
||
|
adminUid = await user.create({ username: 'admin', password: 'barbar', gdpr_consent: true });
|
||
|
await groups.join('administrators', adminUid);
|
||
|
|
||
|
const navigation = require('../src/navigation/admin');
|
||
|
const data = require('../install/data/navigation.json');
|
||
|
|
||
|
await navigation.save(data);
|
||
|
|
||
|
const result = await topics.post({ uid: fooUid, title: 'test topic title', content: 'test topic content', cid: cid });
|
||
|
tid = result.topicData.tid;
|
||
|
pid = result.postData.pid;
|
||
8 years ago
|
});
|
||
|
|
||
4 years ago
|
it('should load /config with csrf_token', (done) => {
|
||
6 years ago
|
request({
|
||
4 years ago
|
url: `${nconf.get('url')}/api/config`,
|
||
6 years ago
|
json: true,
|
||
4 years ago
|
}, (err, response, body) => {
|
||
6 years ago
|
assert.ifError(err);
|
||
|
assert.equal(response.statusCode, 200);
|
||
|
assert(body.csrf_token);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load /config with no csrf_token as spider', (done) => {
|
||
6 years ago
|
request({
|
||
4 years ago
|
url: `${nconf.get('url')}/api/config`,
|
||
6 years ago
|
json: true,
|
||
|
headers: {
|
||
|
'user-agent': 'yandex',
|
||
|
},
|
||
4 years ago
|
}, (err, response, body) => {
|
||
6 years ago
|
assert.ifError(err);
|
||
|
assert.equal(response.statusCode, 200);
|
||
|
assert.strictEqual(body.csrf_token, false);
|
||
|
assert.strictEqual(body.uid, -1);
|
||
|
assert.strictEqual(body.loggedIn, false);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
describe('homepage', () => {
|
||
7 years ago
|
function hookMethod(hookData) {
|
||
|
assert(hookData.req);
|
||
|
assert(hookData.res);
|
||
|
assert(hookData.next);
|
||
8 years ago
|
|
||
4 years ago
|
hookData.res.render('mycustompage', {
|
||
7 years ago
|
works: true,
|
||
|
});
|
||
|
}
|
||
4 years ago
|
const message = utils.generateUUID();
|
||
|
const name = 'mycustompage.tpl';
|
||
|
const tplPath = path.join(nconf.get('views_dir'), name);
|
||
8 years ago
|
|
||
6 years ago
|
before(async () => {
|
||
4 years ago
|
plugins.hooks.register('myTestPlugin', {
|
||
4 years ago
|
hook: 'action:homepage.get:mycustompage',
|
||
7 years ago
|
method: hookMethod,
|
||
|
});
|
||
7 years ago
|
|
||
7 years ago
|
fs.writeFileSync(tplPath, message);
|
||
6 years ago
|
await meta.templates.compileTemplate(name, message);
|
||
7 years ago
|
});
|
||
|
|
||
4 years ago
|
it('should load default', (done) => {
|
||
|
request(nconf.get('url'), (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
8 years ago
|
});
|
||
7 years ago
|
|
||
4 years ago
|
it('should load unread', (done) => {
|
||
|
meta.configs.set('homePageRoute', 'unread', (err) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
7 years ago
|
|
||
4 years ago
|
request(nconf.get('url'), (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
7 years ago
|
});
|
||
8 years ago
|
});
|
||
|
|
||
4 years ago
|
it('should load recent', (done) => {
|
||
|
meta.configs.set('homePageRoute', 'recent', (err) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
7 years ago
|
|
||
4 years ago
|
request(nconf.get('url'), (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
7 years ago
|
});
|
||
8 years ago
|
});
|
||
7 years ago
|
|
||
4 years ago
|
it('should load top', (done) => {
|
||
|
meta.configs.set('homePageRoute', 'top', (err) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
|
||
4 years ago
|
request(nconf.get('url'), (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load popular', (done) => {
|
||
|
meta.configs.set('homePageRoute', 'popular', (err) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
7 years ago
|
|
||
4 years ago
|
request(nconf.get('url'), (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
7 years ago
|
});
|
||
8 years ago
|
});
|
||
|
|
||
4 years ago
|
it('should load category', (done) => {
|
||
|
meta.configs.set('homePageRoute', 'category/1/test-category', (err) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
7 years ago
|
|
||
4 years ago
|
request(nconf.get('url'), (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
});
|
||
7 years ago
|
|
||
4 years ago
|
it('should not load breadcrumbs on home page route', (done) => {
|
||
|
request(`${nconf.get('url')}/api`, { json: true }, (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
7 years ago
|
assert(!body.breadcrumbs);
|
||
7 years ago
|
done();
|
||
|
});
|
||
7 years ago
|
});
|
||
|
|
||
4 years ago
|
it('should redirect to custom', (done) => {
|
||
|
meta.configs.set('homePageRoute', 'groups', (err) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
|
||
4 years ago
|
request(nconf.get('url'), (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
});
|
||
7 years ago
|
|
||
4 years ago
|
it('should 404 if custom does not exist', (done) => {
|
||
|
meta.configs.set('homePageRoute', 'this-route-does-not-exist', (err) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
7 years ago
|
|
||
4 years ago
|
request(nconf.get('url'), (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 404);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
7 years ago
|
});
|
||
7 years ago
|
});
|
||
|
|
||
4 years ago
|
it('api should work with hook', (done) => {
|
||
|
meta.configs.set('homePageRoute', 'mycustompage', (err) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
|
||
4 years ago
|
request(`${nconf.get('url')}/api`, { json: true }, (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert.equal(body.works, true);
|
||
4 years ago
|
assert.equal(body.template.mycustompage, true);
|
||
7 years ago
|
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
7 years ago
|
});
|
||
7 years ago
|
|
||
4 years ago
|
it('should render with hook', (done) => {
|
||
|
meta.configs.set('homePageRoute', 'mycustompage', (err) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
7 years ago
|
|
||
4 years ago
|
request(nconf.get('url'), (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert.ok(body);
|
||
|
assert.ok(body.indexOf('<main id="panel"'));
|
||
6 years ago
|
assert.ok(body.includes(message));
|
||
7 years ago
|
|
||
|
done();
|
||
|
});
|
||
7 years ago
|
});
|
||
7 years ago
|
});
|
||
7 years ago
|
|
||
4 years ago
|
after(() => {
|
||
4 years ago
|
plugins.hooks.unregister('myTestPlugin', 'action:homepage.get:custom', hookMethod);
|
||
7 years ago
|
fs.unlinkSync(tplPath);
|
||
|
fs.unlinkSync(tplPath.replace(/\.tpl$/, '.js'));
|
||
|
});
|
||
7 years ago
|
});
|
||
|
|
||
4 years ago
|
it('should load /reset without code', (done) => {
|
||
|
request(`${nconf.get('url')}/reset`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load /reset with invalid code', (done) => {
|
||
|
request(`${nconf.get('url')}/reset/123123`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load /login', (done) => {
|
||
|
request(`${nconf.get('url')}/login`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load /register', (done) => {
|
||
|
request(`${nconf.get('url')}/register`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load /register/complete', (done) => {
|
||
4 years ago
|
const data = {
|
||
8 years ago
|
username: 'interstitial',
|
||
|
password: '123456',
|
||
8 years ago
|
'password-confirm': '123456',
|
||
8 years ago
|
email: '[email protected]',
|
||
|
};
|
||
|
|
||
4 years ago
|
const jar = request.jar();
|
||
8 years ago
|
request({
|
||
4 years ago
|
url: `${nconf.get('url')}/api/config`,
|
||
8 years ago
|
json: true,
|
||
|
jar: jar,
|
||
4 years ago
|
}, (err, response, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
|
||
4 years ago
|
request.post(`${nconf.get('url')}/register`, {
|
||
8 years ago
|
form: data,
|
||
|
json: true,
|
||
|
jar: jar,
|
||
|
headers: {
|
||
|
'x-csrf-token': body.csrf_token,
|
||
|
},
|
||
4 years ago
|
}, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
4 years ago
|
assert.strictEqual(body.next, `${nconf.get('relative_path')}/register/complete`);
|
||
|
request(`${nconf.get('url')}/api/register/complete`, {
|
||
8 years ago
|
jar: jar,
|
||
|
json: true,
|
||
4 years ago
|
}, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body.sections);
|
||
|
assert(body.errors);
|
||
|
assert(body.title);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
});
|
||
|
});
|
||
|
|
||
2 years ago
|
describe('registration interstitials', () => {
|
||
2 years ago
|
describe('email update', () => {
|
||
2 years ago
|
let jar;
|
||
|
let token;
|
||
2 years ago
|
const dummyEmailerHook = async (data) => {};
|
||
2 years ago
|
|
||
|
before(async () => {
|
||
2 years ago
|
// Attach an emailer hook so related requests do not error
|
||
|
plugins.hooks.register('emailer-test', {
|
||
|
hook: 'filter:email.send',
|
||
|
method: dummyEmailerHook,
|
||
|
});
|
||
|
|
||
2 years ago
|
jar = await helpers.registerUser({
|
||
|
username: utils.generateUUID().slice(0, 10),
|
||
|
password: utils.generateUUID(),
|
||
|
});
|
||
|
token = await helpers.getCsrfToken(jar);
|
||
3 years ago
|
|
||
2 years ago
|
meta.config.requireEmailAddress = 1;
|
||
3 years ago
|
});
|
||
|
|
||
2 years ago
|
after(() => {
|
||
|
meta.config.requireEmailAddress = 0;
|
||
2 years ago
|
plugins.hooks.unregister('emailer-test', 'filter:email.send');
|
||
3 years ago
|
});
|
||
|
|
||
2 years ago
|
it('email interstitial should still apply if empty email entered and requireEmailAddress is enabled', async () => {
|
||
|
let res = await requestAsync(`${nconf.get('url')}/register/complete`, {
|
||
|
method: 'post',
|
||
|
jar,
|
||
|
json: true,
|
||
|
followRedirect: false,
|
||
|
simple: false,
|
||
|
resolveWithFullResponse: true,
|
||
|
headers: {
|
||
|
'x-csrf-token': token,
|
||
|
},
|
||
|
form: {
|
||
|
email: '',
|
||
|
},
|
||
|
});
|
||
3 years ago
|
|
||
2 years ago
|
assert.strictEqual(res.headers.location, `${nconf.get('relative_path')}/register/complete`);
|
||
3 years ago
|
|
||
2 years ago
|
res = await requestAsync(`${nconf.get('url')}/api/register/complete`, {
|
||
|
jar,
|
||
|
json: true,
|
||
|
resolveWithFullResponse: true,
|
||
|
});
|
||
|
assert.strictEqual(res.statusCode, 200);
|
||
|
assert(res.body.errors.length);
|
||
|
assert(res.body.errors.includes('[[error:invalid-email]]'));
|
||
3 years ago
|
});
|
||
|
|
||
2 years ago
|
it('gdpr interstitial should still apply if email requirement is disabled', async () => {
|
||
|
meta.config.requireEmailAddress = 0;
|
||
3 years ago
|
|
||
2 years ago
|
const res = await requestAsync(`${nconf.get('url')}/api/register/complete`, {
|
||
|
jar,
|
||
|
json: true,
|
||
|
resolveWithFullResponse: true,
|
||
|
});
|
||
|
|
||
|
assert(!res.body.errors.includes('[[error:invalid-email]]'));
|
||
|
assert(!res.body.errors.includes('[[error:gdpr_consent_denied]]'));
|
||
2 years ago
|
|
||
|
meta.config.requireEmailAddress = 1;
|
||
3 years ago
|
});
|
||
|
|
||
2 years ago
|
it('should error if userData is falsy', async () => {
|
||
|
try {
|
||
|
await user.interstitials.email({ userData: null });
|
||
|
assert(false);
|
||
|
} catch (err) {
|
||
|
assert.strictEqual(err.message, '[[error:invalid-data]]');
|
||
|
}
|
||
|
});
|
||
3 years ago
|
|
||
2 years ago
|
it('should throw error if email is not valid', async () => {
|
||
|
const uid = await user.create({ username: 'interstiuser1' });
|
||
2 years ago
|
const result = await user.interstitials.email({
|
||
|
userData: { uid: uid, updateEmail: true },
|
||
|
req: { uid: uid },
|
||
|
interstitials: [],
|
||
|
});
|
||
|
assert.strictEqual(result.interstitials[0].template, 'partials/email_update');
|
||
2 years ago
|
await assert.rejects(result.interstitials[0].callback({ uid }, {
|
||
2 years ago
|
email: 'invalidEmail',
|
||
|
}), { message: '[[error:invalid-email]]' });
|
||
|
});
|
||
|
|
||
|
it('should reject an email that comprises only whitespace', async () => {
|
||
|
const uid = await user.create({ username: utils.generateUUID().slice(0, 10) });
|
||
|
const result = await user.interstitials.email({
|
||
|
userData: { uid: uid, updateEmail: true },
|
||
|
req: { uid: uid },
|
||
|
interstitials: [],
|
||
|
});
|
||
|
assert.strictEqual(result.interstitials[0].template, 'partials/email_update');
|
||
2 years ago
|
await assert.rejects(result.interstitials[0].callback({ uid }, {
|
||
2 years ago
|
email: ' ',
|
||
|
}), { message: '[[error:invalid-email]]' });
|
||
2 years ago
|
});
|
||
3 years ago
|
|
||
2 years ago
|
it('should set req.session.emailChanged to 1', async () => {
|
||
|
const uid = await user.create({ username: 'interstiuser2' });
|
||
3 years ago
|
const result = await user.interstitials.email({
|
||
|
userData: { uid: uid, updateEmail: true },
|
||
2 years ago
|
req: { uid: uid, session: {} },
|
||
3 years ago
|
interstitials: [],
|
||
|
});
|
||
2 years ago
|
|
||
3 years ago
|
await result.interstitials[0].callback({ uid: uid }, {
|
||
2 years ago
|
email: '[email protected]',
|
||
3 years ago
|
});
|
||
2 years ago
|
assert.strictEqual(result.req.session.emailChanged, 1);
|
||
3 years ago
|
});
|
||
|
|
||
2 years ago
|
it('should throw error if user tries to edit other users email', async () => {
|
||
|
const uid = await user.create({ username: 'interstiuser4' });
|
||
|
try {
|
||
|
const result = await user.interstitials.email({
|
||
|
userData: { uid: uid, updateEmail: true },
|
||
|
req: { uid: 1000 },
|
||
|
interstitials: [],
|
||
|
});
|
||
|
|
||
|
await result.interstitials[0].callback({ uid: uid }, {
|
||
|
email: '[email protected]',
|
||
|
});
|
||
|
assert(false);
|
||
|
} catch (err) {
|
||
|
assert.strictEqual(err.message, '[[error:no-privileges]]');
|
||
|
}
|
||
3 years ago
|
});
|
||
|
|
||
2 years ago
|
it('should remove current email (only allowed if email not required)', async () => {
|
||
2 years ago
|
meta.config.requireEmailAddress = 0;
|
||
2 years ago
|
|
||
2 years ago
|
const uid = await user.create({ username: 'interstiuser5' });
|
||
|
await user.setUserField(uid, 'email', '[email protected]');
|
||
|
await user.email.confirmByUid(uid);
|
||
|
|
||
3 years ago
|
const result = await user.interstitials.email({
|
||
|
userData: { uid: uid, updateEmail: true },
|
||
2 years ago
|
req: { uid: uid, session: { id: 0 } },
|
||
3 years ago
|
interstitials: [],
|
||
|
});
|
||
|
|
||
|
await result.interstitials[0].callback({ uid: uid }, {
|
||
2 years ago
|
email: '',
|
||
3 years ago
|
});
|
||
2 years ago
|
const userData = await user.getUserData(uid);
|
||
|
assert.strictEqual(userData.email, '');
|
||
|
assert.strictEqual(userData['email:confirmed'], 0);
|
||
2 years ago
|
|
||
|
meta.config.requireEmailAddress = 1;
|
||
2 years ago
|
});
|
||
2 years ago
|
|
||
|
it('should require a password (if one is set) for email change', async () => {
|
||
|
try {
|
||
|
const [username, password] = [utils.generateUUID().slice(0, 10), utils.generateUUID()];
|
||
|
const uid = await user.create({ username, password });
|
||
|
await user.setUserField(uid, 'email', `${username}@nodebb.org`);
|
||
|
await user.email.confirmByUid(uid);
|
||
|
|
||
|
const result = await user.interstitials.email({
|
||
|
userData: { uid: uid, updateEmail: true },
|
||
|
req: { uid: uid, session: { id: 0 } },
|
||
|
interstitials: [],
|
||
|
});
|
||
|
|
||
|
await result.interstitials[0].callback({ uid: uid }, {
|
||
|
email: `${username}@nodebb.com`,
|
||
|
});
|
||
|
} catch (err) {
|
||
|
assert.strictEqual(err.message, '[[error:invalid-password]]');
|
||
|
}
|
||
|
});
|
||
|
|
||
|
it('should require a password (if one is set) for email clearing', async () => {
|
||
2 years ago
|
meta.config.requireEmailAddress = 0;
|
||
|
|
||
2 years ago
|
try {
|
||
|
const [username, password] = [utils.generateUUID().slice(0, 10), utils.generateUUID()];
|
||
|
const uid = await user.create({ username, password });
|
||
|
await user.setUserField(uid, 'email', `${username}@nodebb.org`);
|
||
|
await user.email.confirmByUid(uid);
|
||
|
|
||
|
const result = await user.interstitials.email({
|
||
|
userData: { uid: uid, updateEmail: true },
|
||
|
req: { uid: uid, session: { id: 0 } },
|
||
|
interstitials: [],
|
||
|
});
|
||
|
|
||
|
await result.interstitials[0].callback({ uid: uid }, {
|
||
|
email: '',
|
||
|
});
|
||
|
} catch (err) {
|
||
|
assert.strictEqual(err.message, '[[error:invalid-password]]');
|
||
|
}
|
||
2 years ago
|
|
||
|
meta.config.requireEmailAddress = 1;
|
||
2 years ago
|
});
|
||
|
|
||
|
it('should successfully issue validation request if the correct password is passed in', async () => {
|
||
|
const [username, password] = [utils.generateUUID().slice(0, 10), utils.generateUUID()];
|
||
|
const uid = await user.create({ username, password });
|
||
|
await user.setUserField(uid, 'email', `${username}@nodebb.org`);
|
||
|
await user.email.confirmByUid(uid);
|
||
|
|
||
|
const result = await user.interstitials.email({
|
||
|
userData: { uid: uid, updateEmail: true },
|
||
|
req: { uid: uid, session: { id: 0 } },
|
||
|
interstitials: [],
|
||
|
});
|
||
|
|
||
|
await result.interstitials[0].callback({ uid }, {
|
||
|
email: `${username}@nodebb.com`,
|
||
|
password,
|
||
|
});
|
||
|
|
||
|
const pending = await user.email.isValidationPending(uid, `${username}@nodebb.com`);
|
||
|
assert.strictEqual(pending, true);
|
||
|
await user.setUserField(uid, 'email', `${username}@nodebb.com`);
|
||
|
await user.email.confirmByUid(uid);
|
||
|
const userData = await user.getUserData(uid);
|
||
|
assert.strictEqual(userData.email, `${username}@nodebb.com`);
|
||
|
assert.strictEqual(userData['email:confirmed'], 1);
|
||
|
});
|
||
2 years ago
|
|
||
|
describe('blocking access for unconfirmed emails', () => {
|
||
|
let jar;
|
||
|
let token;
|
||
|
|
||
|
before(async () => {
|
||
|
jar = await helpers.registerUser({
|
||
|
username: utils.generateUUID().slice(0, 10),
|
||
|
password: utils.generateUUID(),
|
||
|
});
|
||
|
token = await helpers.getCsrfToken(jar);
|
||
|
});
|
||
|
|
||
|
it('should not apply if requireEmailAddress is not enabled', async () => {
|
||
|
meta.config.requireEmailAddress = 0;
|
||
|
|
||
|
const res = await requestAsync(`${nconf.get('url')}/register/complete`, {
|
||
|
method: 'post',
|
||
|
jar,
|
||
|
json: true,
|
||
|
followRedirect: false,
|
||
|
simple: false,
|
||
|
resolveWithFullResponse: true,
|
||
|
headers: {
|
||
|
'x-csrf-token': token,
|
||
|
},
|
||
|
form: {
|
||
|
email: `${utils.generateUUID().slice(0, 10)}@example.org`,
|
||
|
gdpr_agree_data: 'on',
|
||
|
gdpr_agree_email: 'on',
|
||
|
},
|
||
|
});
|
||
|
|
||
|
assert.strictEqual(res.headers.location, `${nconf.get('relative_path')}/`);
|
||
|
meta.config.requireEmailAddress = 1;
|
||
|
});
|
||
|
|
||
|
it('should continue to redirect back to interstitial after an email is entered, as it is not confirmed', async () => {
|
||
|
const res = await requestAsync(`${nconf.get('url')}/recent`, {
|
||
|
jar,
|
||
|
json: true,
|
||
|
resolveWithFullResponse: true,
|
||
|
followRedirect: false,
|
||
|
simple: false,
|
||
|
});
|
||
|
|
||
|
assert.strictEqual(res.statusCode, 307);
|
||
2 years ago
|
assert.strictEqual(res.headers.location, `${nconf.get('relative_path')}/register/complete`);
|
||
2 years ago
|
});
|
||
|
});
|
||
3 years ago
|
});
|
||
|
|
||
2 years ago
|
describe('gdpr', () => {
|
||
|
let jar;
|
||
|
let token;
|
||
3 years ago
|
|
||
2 years ago
|
before(async () => {
|
||
|
jar = await helpers.registerUser({
|
||
2 years ago
|
username: utils.generateUUID().slice(0, 10),
|
||
2 years ago
|
password: utils.generateUUID(),
|
||
|
});
|
||
|
token = await helpers.getCsrfToken(jar);
|
||
3 years ago
|
});
|
||
|
|
||
2 years ago
|
it('registration should succeed once gdpr prompts are agreed to', async () => {
|
||
|
const res = await requestAsync(`${nconf.get('url')}/register/complete`, {
|
||
|
method: 'post',
|
||
|
jar,
|
||
|
json: true,
|
||
|
followRedirect: false,
|
||
|
simple: false,
|
||
|
resolveWithFullResponse: true,
|
||
|
headers: {
|
||
|
'x-csrf-token': token,
|
||
|
},
|
||
|
form: {
|
||
|
gdpr_agree_data: 'on',
|
||
|
gdpr_agree_email: 'on',
|
||
|
},
|
||
|
});
|
||
|
|
||
|
assert.strictEqual(res.statusCode, 302);
|
||
|
assert.strictEqual(res.headers.location, `${nconf.get('relative_path')}/`);
|
||
3 years ago
|
});
|
||
|
});
|
||
2 years ago
|
|
||
|
describe('abort behaviour', () => {
|
||
|
let jar;
|
||
|
let token;
|
||
|
|
||
|
beforeEach(async () => {
|
||
|
jar = await helpers.registerUser({
|
||
|
username: utils.generateUUID().slice(0, 10),
|
||
|
password: utils.generateUUID(),
|
||
|
});
|
||
|
token = await helpers.getCsrfToken(jar);
|
||
|
});
|
||
|
|
||
|
it('should terminate the session and send user back to index if interstitials remain', async () => {
|
||
|
const res = await requestAsync(`${nconf.get('url')}/register/abort`, {
|
||
|
method: 'post',
|
||
|
jar,
|
||
|
json: true,
|
||
|
followRedirect: false,
|
||
|
simple: false,
|
||
|
resolveWithFullResponse: true,
|
||
|
headers: {
|
||
|
'x-csrf-token': token,
|
||
|
},
|
||
|
});
|
||
|
|
||
|
assert.strictEqual(res.statusCode, 302);
|
||
|
assert.strictEqual(res.headers['set-cookie'][0], `express.sid=; Path=${nconf.get('relative_path') || '/'}; Expires=Thu, 01 Jan 1970 00:00:00 GMT; SameSite=Lax`);
|
||
|
assert.strictEqual(res.headers.location, `${nconf.get('relative_path')}/`);
|
||
|
});
|
||
|
|
||
|
it('should preserve the session and send user back to user profile if no interstitials remain (e.g. GDPR OK + email change cancellation)', async () => {
|
||
|
// Submit GDPR consent
|
||
|
await requestAsync(`${nconf.get('url')}/register/complete`, {
|
||
|
method: 'post',
|
||
|
jar,
|
||
|
json: true,
|
||
|
followRedirect: false,
|
||
|
simple: false,
|
||
|
resolveWithFullResponse: true,
|
||
|
headers: {
|
||
|
'x-csrf-token': token,
|
||
|
},
|
||
|
form: {
|
||
|
gdpr_agree_data: 'on',
|
||
|
gdpr_agree_email: 'on',
|
||
|
},
|
||
|
});
|
||
|
|
||
|
// Start email change flow
|
||
|
await requestAsync(`${nconf.get('url')}/me/edit/email`, { jar });
|
||
|
|
||
|
const res = await requestAsync(`${nconf.get('url')}/register/abort`, {
|
||
|
method: 'post',
|
||
|
jar,
|
||
|
json: true,
|
||
|
followRedirect: false,
|
||
|
simple: false,
|
||
|
resolveWithFullResponse: true,
|
||
|
headers: {
|
||
|
'x-csrf-token': token,
|
||
|
},
|
||
|
});
|
||
|
|
||
|
assert.strictEqual(res.statusCode, 302);
|
||
|
assert(res.headers.location.match(/\/uid\/\d+$/));
|
||
|
});
|
||
|
});
|
||
3 years ago
|
});
|
||
|
|
||
4 years ago
|
it('should load /robots.txt', (done) => {
|
||
|
request(`${nconf.get('url')}/robots.txt`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load /manifest.webmanifest', (done) => {
|
||
|
request(`${nconf.get('url')}/manifest.webmanifest`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load /outgoing?url=<url>', (done) => {
|
||
|
request(`${nconf.get('url')}/outgoing?url=http://youtube.com`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should 404 on /outgoing with no url', (done) => {
|
||
|
request(`${nconf.get('url')}/outgoing`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 404);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should 404 on /outgoing with javascript: protocol', (done) => {
|
||
|
request(`${nconf.get('url')}/outgoing?url=javascript:alert(1);`, (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 404);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should 404 on /outgoing with invalid url', (done) => {
|
||
|
request(`${nconf.get('url')}/outgoing?url=derp`, (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 404);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load /tos', (done) => {
|
||
8 years ago
|
meta.config.termsOfUse = 'please accept our tos';
|
||
4 years ago
|
request(`${nconf.get('url')}/tos`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
|
|
||
4 years ago
|
it('should load 404 if meta.config.termsOfUse is empty', (done) => {
|
||
8 years ago
|
meta.config.termsOfUse = '';
|
||
4 years ago
|
request(`${nconf.get('url')}/tos`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 404);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load /sping', (done) => {
|
||
|
request(`${nconf.get('url')}/sping`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert.equal(body, 'healthy');
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load /ping', (done) => {
|
||
|
request(`${nconf.get('url')}/ping`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert.equal(body, '200');
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should handle 404', (done) => {
|
||
|
request(`${nconf.get('url')}/arouteinthevoid`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 404);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load topic rss feed', (done) => {
|
||
|
request(`${nconf.get('url')}/topic/${tid}.rss`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load category rss feed', (done) => {
|
||
|
request(`${nconf.get('url')}/category/${cid}.rss`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
7 years ago
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load topics rss feed', (done) => {
|
||
|
request(`${nconf.get('url')}/topics.rss`, (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
8 years ago
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load recent rss feed', (done) => {
|
||
|
request(`${nconf.get('url')}/recent.rss`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load top rss feed', (done) => {
|
||
|
request(`${nconf.get('url')}/top.rss`, (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load popular rss feed', (done) => {
|
||
|
request(`${nconf.get('url')}/popular.rss`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load popular rss feed with term', (done) => {
|
||
|
request(`${nconf.get('url')}/popular/day.rss`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load recent posts rss feed', (done) => {
|
||
|
request(`${nconf.get('url')}/recentposts.rss`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load category recent posts rss feed', (done) => {
|
||
|
request(`${nconf.get('url')}/category/${cid}/recentposts.rss`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load user topics rss feed', (done) => {
|
||
|
request(`${nconf.get('url')}/user/foo/topics.rss`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
8 years ago
|
|
||
4 years ago
|
it('should load tag rss feed', (done) => {
|
||
|
request(`${nconf.get('url')}/tags/nodebb.rss`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load client.css', (done) => {
|
||
|
request(`${nconf.get('url')}/assets/client.css`, (err, res, body) => {
|
||
6 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load admin.css', (done) => {
|
||
|
request(`${nconf.get('url')}/assets/admin.css`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load sitemap.xml', (done) => {
|
||
|
request(`${nconf.get('url')}/sitemap.xml`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load sitemap/pages.xml', (done) => {
|
||
|
request(`${nconf.get('url')}/sitemap/pages.xml`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load sitemap/categories.xml', (done) => {
|
||
|
request(`${nconf.get('url')}/sitemap/categories.xml`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load sitemap/topics/1.xml', (done) => {
|
||
|
request(`${nconf.get('url')}/sitemap/topics.1.xml`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load robots.txt', (done) => {
|
||
|
request(`${nconf.get('url')}/robots.txt`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load theme screenshot', (done) => {
|
||
|
request(`${nconf.get('url')}/css/previews/nodebb-theme-persona`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load users page', (done) => {
|
||
|
request(`${nconf.get('url')}/users`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load users page', (done) => {
|
||
|
request(`${nconf.get('url')}/users?section=online`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should error if guests do not have search privilege', (done) => {
|
||
|
request(`${nconf.get('url')}/api/users?query=bar§ion=sort-posts`, { json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
7 years ago
|
assert.equal(res.statusCode, 500);
|
||
8 years ago
|
assert(body);
|
||
7 years ago
|
assert.equal(body.error, '[[error:no-privileges]]');
|
||
8 years ago
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load users search page', (done) => {
|
||
|
privileges.global.give(['groups:search:users'], 'guests', (err) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
4 years ago
|
request(`${nconf.get('url')}/users?query=bar§ion=sort-posts`, (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
5 years ago
|
privileges.global.rescind(['groups:search:users'], 'guests', done);
|
||
7 years ago
|
});
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load groups page', (done) => {
|
||
|
request(`${nconf.get('url')}/groups`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load group details page', (done) => {
|
||
8 years ago
|
groups.create({
|
||
|
name: 'group-details',
|
||
|
description: 'Foobar!',
|
||
8 years ago
|
hidden: 0,
|
||
4 years ago
|
}, (err) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
4 years ago
|
groups.join('group-details', fooUid, (err) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
8 years ago
|
topics.post({
|
||
|
uid: fooUid,
|
||
|
title: 'topic title',
|
||
|
content: 'test topic content',
|
||
|
cid: cid,
|
||
4 years ago
|
}, (err) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
4 years ago
|
request(`${nconf.get('url')}/api/groups/group-details`, { json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
assert.equal(body.posts[0].content, 'test topic content');
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
8 years ago
|
});
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load group members page', (done) => {
|
||
|
request(`${nconf.get('url')}/groups/group-details/members`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should 404 when trying to load group members of hidden group', (done) => {
|
||
4 years ago
|
const groups = require('../src/groups');
|
||
8 years ago
|
groups.create({
|
||
|
name: 'hidden-group',
|
||
|
description: 'Foobar!',
|
||
8 years ago
|
hidden: 1,
|
||
4 years ago
|
}, (err) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
4 years ago
|
request(`${nconf.get('url')}/groups/hidden-group/members`, (err, res) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 404);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should get recent posts', (done) => {
|
||
|
request(`${nconf.get('url')}/api/recent/posts/month`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should get post data', (done) => {
|
||
|
request(`${nconf.get('url')}/api/v3/posts/${pid}`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should get topic data', (done) => {
|
||
|
request(`${nconf.get('url')}/api/v3/topics/${tid}`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should get category data', (done) => {
|
||
|
request(`${nconf.get('url')}/api/v3/categories/${cid}`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
8 years ago
|
|
||
4 years ago
|
describe('revoke session', () => {
|
||
4 years ago
|
let uid;
|
||
|
let jar;
|
||
|
let csrf_token;
|
||
8 years ago
|
|
||
3 years ago
|
before(async () => {
|
||
|
uid = await user.create({ username: 'revokeme', password: 'barbar' });
|
||
|
const login = await helpers.loginUser('revokeme', 'barbar');
|
||
|
jar = login.jar;
|
||
|
csrf_token = login.csrf_token;
|
||
8 years ago
|
});
|
||
|
|
||
4 years ago
|
it('should fail to revoke session with missing uuid', (done) => {
|
||
4 years ago
|
request.del(`${nconf.get('url')}/api/user/revokeme/session`, {
|
||
8 years ago
|
jar: jar,
|
||
|
headers: {
|
||
8 years ago
|
'x-csrf-token': csrf_token,
|
||
|
},
|
||
4 years ago
|
}, (err, res) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 404);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should fail if user doesn\'t exist', (done) => {
|
||
4 years ago
|
request.del(`${nconf.get('url')}/api/v3/users/doesnotexist/sessions/1112233`, {
|
||
8 years ago
|
jar: jar,
|
||
|
headers: {
|
||
8 years ago
|
'x-csrf-token': csrf_token,
|
||
|
},
|
||
4 years ago
|
}, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
4 years ago
|
assert.strictEqual(res.statusCode, 404);
|
||
|
const parsedResponse = JSON.parse(body);
|
||
|
assert.deepStrictEqual(parsedResponse.response, {});
|
||
|
assert.deepStrictEqual(parsedResponse.status, {
|
||
|
code: 'not-found',
|
||
4 years ago
|
message: 'User does not exist',
|
||
6 years ago
|
});
|
||
8 years ago
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should revoke user session', (done) => {
|
||
|
db.getSortedSetRange(`uid:${uid}:sessions`, 0, -1, (err, sids) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
4 years ago
|
const sid = sids[0];
|
||
8 years ago
|
|
||
4 years ago
|
db.sessionStore.get(sid, (err, sessionObj) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
4 years ago
|
request.del(`${nconf.get('url')}/api/v3/users/${uid}/sessions/${sessionObj.meta.uuid}`, {
|
||
8 years ago
|
jar: jar,
|
||
|
headers: {
|
||
8 years ago
|
'x-csrf-token': csrf_token,
|
||
|
},
|
||
4 years ago
|
}, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
4 years ago
|
assert.strictEqual(res.statusCode, 200);
|
||
|
assert.deepStrictEqual(JSON.parse(body), {
|
||
|
status: {
|
||
|
code: 'ok',
|
||
|
message: 'OK',
|
||
|
},
|
||
|
response: {},
|
||
|
});
|
||
8 years ago
|
done();
|
||
|
});
|
||
|
});
|
||
|
});
|
||
|
});
|
||
8 years ago
|
});
|
||
|
|
||
4 years ago
|
describe('widgets', () => {
|
||
4 years ago
|
const widgets = require('../src/widgets');
|
||
8 years ago
|
|
||
4 years ago
|
before((done) => {
|
||
8 years ago
|
async.waterfall([
|
||
|
function (next) {
|
||
|
widgets.reset(next);
|
||
|
},
|
||
|
function (next) {
|
||
4 years ago
|
const data = {
|
||
8 years ago
|
template: 'categories.tpl',
|
||
|
location: 'sidebar',
|
||
|
widgets: [
|
||
|
{
|
||
|
widget: 'html',
|
||
6 years ago
|
data: {
|
||
|
html: 'test',
|
||
|
title: '',
|
||
|
container: '',
|
||
|
},
|
||
8 years ago
|
},
|
||
|
],
|
||
8 years ago
|
};
|
||
|
|
||
|
widgets.setArea(data, next);
|
||
8 years ago
|
},
|
||
8 years ago
|
], done);
|
||
|
});
|
||
8 years ago
|
|
||
4 years ago
|
it('should return {} if there are no widgets', (done) => {
|
||
|
request(`${nconf.get('url')}/api/category/${cid}`, { json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
8 years ago
|
assert(body.widgets);
|
||
7 years ago
|
assert.equal(Object.keys(body.widgets).length, 0);
|
||
8 years ago
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should render templates', (done) => {
|
||
4 years ago
|
const url = `${nconf.get('url')}/api/categories`;
|
||
4 years ago
|
request(url, { json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
8 years ago
|
assert(body.widgets);
|
||
|
assert(body.widgets.sidebar);
|
||
6 years ago
|
assert.equal(body.widgets.sidebar[0].html, 'test');
|
||
8 years ago
|
done();
|
||
|
});
|
||
|
});
|
||
7 years ago
|
|
||
4 years ago
|
it('should reset templates', (done) => {
|
||
|
widgets.resetTemplates(['categories', 'category'], (err) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
4 years ago
|
request(`${nconf.get('url')}/api/categories`, { json: true }, (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body.widgets);
|
||
|
assert.equal(Object.keys(body.widgets).length, 0);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
});
|
||
8 years ago
|
});
|
||
|
|
||
4 years ago
|
describe('tags', () => {
|
||
4 years ago
|
let tid;
|
||
4 years ago
|
before((done) => {
|
||
8 years ago
|
topics.post({
|
||
|
uid: fooUid,
|
||
|
title: 'topic title',
|
||
|
content: 'test topic content',
|
||
|
cid: cid,
|
||
8 years ago
|
tags: ['nodebb', 'bug', 'test'],
|
||
4 years ago
|
}, (err, result) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
tid = result.topicData.tid;
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should render tags page', (done) => {
|
||
|
request(`${nconf.get('url')}/api/tags`, { json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
assert(Array.isArray(body.tags));
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should render tag page with no topics', (done) => {
|
||
|
request(`${nconf.get('url')}/api/tags/notag`, { json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
assert(Array.isArray(body.topics));
|
||
|
assert.equal(body.topics.length, 0);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should render tag page with 1 topic', (done) => {
|
||
|
request(`${nconf.get('url')}/api/tags/nodebb`, { json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
assert(Array.isArray(body.topics));
|
||
|
assert.equal(body.topics.length, 1);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
});
|
||
|
|
||
8 years ago
|
|
||
4 years ago
|
describe('maintenance mode', () => {
|
||
|
before((done) => {
|
||
8 years ago
|
meta.config.maintenanceMode = 1;
|
||
|
done();
|
||
|
});
|
||
4 years ago
|
after((done) => {
|
||
8 years ago
|
meta.config.maintenanceMode = 0;
|
||
|
done();
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should return 503 in maintenance mode', (done) => {
|
||
|
request(`${nconf.get('url')}/recent`, { json: true }, (err, res) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 503);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should return 503 in maintenance mode', (done) => {
|
||
|
request(`${nconf.get('url')}/api/recent`, { json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 503);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should return 200 in maintenance mode', (done) => {
|
||
|
request(`${nconf.get('url')}/api/login`, { json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
2 years ago
|
|
||
|
it('should return 200 if guests are allowed', (done) => {
|
||
|
const oldValue = meta.config.groupsExemptFromMaintenanceMode;
|
||
|
meta.config.groupsExemptFromMaintenanceMode.push('guests');
|
||
|
request(`${nconf.get('url')}/api/recent`, { json: true }, (err, res, body) => {
|
||
|
assert.ifError(err);
|
||
|
assert.strictEqual(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
meta.config.groupsExemptFromMaintenanceMode = oldValue;
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
8 years ago
|
});
|
||
|
|
||
4 years ago
|
describe('account pages', () => {
|
||
4 years ago
|
let jar;
|
||
2 years ago
|
let csrf_token;
|
||
|
|
||
3 years ago
|
before(async () => {
|
||
2 years ago
|
({ jar, csrf_token } = await helpers.loginUser('foo', 'barbar'));
|
||
8 years ago
|
});
|
||
|
|
||
4 years ago
|
it('should redirect to account page with logged in user', (done) => {
|
||
|
request(`${nconf.get('url')}/api/login`, { jar: jar, json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
8 years ago
|
assert.equal(res.statusCode, 200);
|
||
|
assert.equal(res.headers['x-redirect'], '/user/foo');
|
||
8 years ago
|
assert.equal(body, '/user/foo');
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should 404 if uid is not a number', (done) => {
|
||
|
request(`${nconf.get('url')}/api/uid/test`, { json: true }, (err, res) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 404);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should redirect to userslug', (done) => {
|
||
|
request(`${nconf.get('url')}/api/uid/${fooUid}`, { json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
8 years ago
|
assert.equal(res.statusCode, 200);
|
||
|
assert.equal(res.headers['x-redirect'], '/user/foo');
|
||
8 years ago
|
assert.equal(body, '/user/foo');
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should redirect to userslug and keep query params', (done) => {
|
||
|
request(`${nconf.get('url')}/api/uid/${fooUid}/topics?foo=bar`, { json: true }, (err, res, body) => {
|
||
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert.equal(res.headers['x-redirect'], '/user/foo/topics?foo=bar');
|
||
|
assert.equal(body, '/user/foo/topics?foo=bar');
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should 404 if user does not exist', (done) => {
|
||
|
request(`${nconf.get('url')}/api/uid/123123`, { json: true }, (err, res) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 404);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
describe('/me/*', () => {
|
||
|
it('should redirect to user profile', (done) => {
|
||
|
request(`${nconf.get('url')}/me`, { jar: jar, json: true }, (err, res, body) => {
|
||
5 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
4 years ago
|
assert(body.includes('"template":{"name":"account/profile","account/profile":true}'));
|
||
5 years ago
|
assert(body.includes('"username":"foo"'));
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
4 years ago
|
it('api should redirect to /user/[userslug]/bookmarks', (done) => {
|
||
|
request(`${nconf.get('url')}/api/me/bookmarks`, { jar: jar, json: true }, (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert.equal(res.headers['x-redirect'], '/user/foo/bookmarks');
|
||
|
assert.equal(body, '/user/foo/bookmarks');
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
4 years ago
|
it('api should redirect to /user/[userslug]/edit/username', (done) => {
|
||
|
request(`${nconf.get('url')}/api/me/edit/username`, { jar: jar, json: true }, (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert.equal(res.headers['x-redirect'], '/user/foo/edit/username');
|
||
|
assert.equal(body, '/user/foo/edit/username');
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
4 years ago
|
it('should redirect to login if user is not logged in', (done) => {
|
||
|
request(`${nconf.get('url')}/me/bookmarks`, { json: true }, (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
7 years ago
|
assert.equal(res.statusCode, 200);
|
||
3 years ago
|
assert(body.includes('Login to your account'), body.slice(0, 500));
|
||
7 years ago
|
done();
|
||
|
});
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should 401 if user is not logged in', (done) => {
|
||
|
request(`${nconf.get('url')}/api/admin`, { json: true }, (err, res) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 401);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should 403 if user is not admin', (done) => {
|
||
|
request(`${nconf.get('url')}/api/admin`, { jar: jar, json: true }, (err, res) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 403);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load /user/foo/posts', (done) => {
|
||
|
request(`${nconf.get('url')}/api/user/foo/posts`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should 401 if not logged in', (done) => {
|
||
|
request(`${nconf.get('url')}/api/user/foo/bookmarks`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 401);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load /user/foo/bookmarks', (done) => {
|
||
|
request(`${nconf.get('url')}/api/user/foo/bookmarks`, { jar: jar }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load /user/foo/upvoted', (done) => {
|
||
|
request(`${nconf.get('url')}/api/user/foo/upvoted`, { jar: jar }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load /user/foo/downvoted', (done) => {
|
||
|
request(`${nconf.get('url')}/api/user/foo/downvoted`, { jar: jar }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load /user/foo/best', (done) => {
|
||
|
request(`${nconf.get('url')}/api/user/foo/best`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
3 years ago
|
it('should load /user/foo/controversial', (done) => {
|
||
|
request(`${nconf.get('url')}/api/user/foo/controversial`, (err, res, body) => {
|
||
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load /user/foo/watched', (done) => {
|
||
|
request(`${nconf.get('url')}/api/user/foo/watched`, { jar: jar }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load /user/foo/ignored', (done) => {
|
||
|
request(`${nconf.get('url')}/api/user/foo/ignored`, { jar: jar }, (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load /user/foo/topics', (done) => {
|
||
|
request(`${nconf.get('url')}/api/user/foo/topics`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
8 years ago
|
|
||
4 years ago
|
it('should load /user/foo/blocks', (done) => {
|
||
|
request(`${nconf.get('url')}/api/user/foo/blocks`, { jar: jar }, (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load /user/foo/consent', (done) => {
|
||
|
request(`${nconf.get('url')}/api/user/foo/consent`, { jar: jar }, (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load /user/foo/sessions', (done) => {
|
||
|
request(`${nconf.get('url')}/api/user/foo/sessions`, { jar: jar }, (err, res, body) => {
|
||
6 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load /user/foo/categories', (done) => {
|
||
|
request(`${nconf.get('url')}/api/user/foo/categories`, { jar: jar }, (err, res, body) => {
|
||
6 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load /user/foo/uploads', (done) => {
|
||
|
request(`${nconf.get('url')}/api/user/foo/uploads`, { jar: jar }, (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
2 years ago
|
describe('user data export routes', () => {
|
||
|
before(async () => {
|
||
|
const types = ['profile', 'uploads', 'posts'];
|
||
|
await Promise.all(types.map(async (type) => {
|
||
|
await api.users.generateExport({ uid: fooUid, ip: '127.0.0.1' }, { uid: fooUid, type });
|
||
|
}));
|
||
2 years ago
|
await sleep(10000);
|
||
7 years ago
|
});
|
||
|
|
||
2 years ago
|
it('should export users posts', (done) => {
|
||
|
request(`${nconf.get('url')}/api/v3/users/${fooUid}/exports/posts`, { jar: jar }, (err, res, body) => {
|
||
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
7 years ago
|
});
|
||
|
|
||
2 years ago
|
it('should export users uploads', (done) => {
|
||
|
request(`${nconf.get('url')}/api/v3/users/${fooUid}/exports/uploads`, { jar: jar }, (err, res, body) => {
|
||
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
|
it('should export users profile', (done) => {
|
||
|
request(`${nconf.get('url')}/api/v3/users/${fooUid}/exports/profile`, { jar: jar }, (err, res, body) => {
|
||
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
7 years ago
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load notifications page', (done) => {
|
||
4 years ago
|
const notifications = require('../src/notifications');
|
||
|
const notifData = {
|
||
8 years ago
|
bodyShort: '[[notifications:user_posted_to, test1, test2]]',
|
||
|
bodyLong: 'some post content',
|
||
|
pid: 1,
|
||
4 years ago
|
path: `/post/${1}`,
|
||
|
nid: `new_post:tid:${1}:pid:${1}:uid:${fooUid}`,
|
||
8 years ago
|
tid: 1,
|
||
|
from: fooUid,
|
||
4 years ago
|
mergeId: `notifications:user_posted_to|${1}`,
|
||
8 years ago
|
topicTitle: 'topic title',
|
||
8 years ago
|
};
|
||
|
async.waterfall([
|
||
|
function (next) {
|
||
|
notifications.create(notifData, next);
|
||
|
},
|
||
|
function (notification, next) {
|
||
|
notifications.push(notification, fooUid, next);
|
||
|
},
|
||
|
function (next) {
|
||
|
setTimeout(next, 2500);
|
||
|
},
|
||
|
function (next) {
|
||
4 years ago
|
request(`${nconf.get('url')}/api/notifications`, { jar: jar, json: true }, next);
|
||
8 years ago
|
},
|
||
|
function (res, body, next) {
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
4 years ago
|
const notif = body.notifications[0];
|
||
2 years ago
|
assert.equal(notif.bodyShort, '<strong>test1</strong> has posted a reply to: <strong>test2</strong>');
|
||
8 years ago
|
assert.equal(notif.bodyLong, notifData.bodyLong);
|
||
|
assert.equal(notif.pid, notifData.pid);
|
||
5 years ago
|
assert.equal(notif.path, nconf.get('relative_path') + notifData.path);
|
||
8 years ago
|
assert.equal(notif.nid, notifData.nid);
|
||
|
next();
|
||
8 years ago
|
},
|
||
8 years ago
|
], done);
|
||
|
});
|
||
8 years ago
|
|
||
4 years ago
|
it('should 404 if user does not exist', (done) => {
|
||
|
request(`${nconf.get('url')}/api/user/email/doesnotexist`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 404);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load user by uid', (done) => {
|
||
|
request(`${nconf.get('url')}/api/user/uid/${fooUid}`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load user by username', (done) => {
|
||
|
request(`${nconf.get('url')}/api/user/username/foo`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should NOT load user by email (by default)', async () => {
|
||
|
const res = await requestAsync(`${nconf.get('url')}/api/user/email/[email protected]`, {
|
||
|
resolveWithFullResponse: true,
|
||
|
simple: false,
|
||
|
});
|
||
|
|
||
|
assert.strictEqual(res.statusCode, 404);
|
||
|
});
|
||
|
|
||
|
it('should load user by email if user has elected to show their email', async () => {
|
||
|
await user.setSetting(fooUid, 'showemail', 1);
|
||
|
const res = await requestAsync(`${nconf.get('url')}/api/user/email/[email protected]`, {
|
||
|
resolveWithFullResponse: true,
|
||
8 years ago
|
});
|
||
4 years ago
|
assert.strictEqual(res.statusCode, 200);
|
||
|
assert(res.body);
|
||
|
await user.setSetting(fooUid, 'showemail', 0);
|
||
8 years ago
|
});
|
||
8 years ago
|
|
||
4 years ago
|
it('should return 401 if user does not have view:users privilege', (done) => {
|
||
|
privileges.global.rescind(['groups:view:users'], 'guests', (err) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
4 years ago
|
request(`${nconf.get('url')}/api/user/foo`, { json: true }, (err, res, body) => {
|
||
6 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 401);
|
||
4 years ago
|
assert.deepEqual(body, {
|
||
|
response: {},
|
||
|
status: {
|
||
|
code: 'not-authorised',
|
||
|
message: 'A valid login session was not found. Please log in and try again.',
|
||
|
},
|
||
|
});
|
||
5 years ago
|
privileges.global.give(['groups:view:users'], 'guests', done);
|
||
6 years ago
|
});
|
||
8 years ago
|
});
|
||
|
});
|
||
|
|
||
2 years ago
|
it('should return false if user can not edit user', async () => {
|
||
|
await user.create({ username: 'regularJoe', password: 'barbar' });
|
||
|
const { jar } = await helpers.loginUser('regularJoe', 'barbar');
|
||
|
let { statusCode } = await requestAsync(`${nconf.get('url')}/api/user/foo/info`, { jar: jar, json: true, simple: false, resolveWithFullResponse: true });
|
||
|
assert.equal(statusCode, 403);
|
||
|
({ statusCode } = await requestAsync(`${nconf.get('url')}/api/user/foo/edit`, { jar: jar, json: true, simple: false, resolveWithFullResponse: true }));
|
||
|
assert.equal(statusCode, 403);
|
||
8 years ago
|
});
|
||
8 years ago
|
|
||
4 years ago
|
it('should load correct user', (done) => {
|
||
|
request(`${nconf.get('url')}/api/user/FOO`, { jar: jar, json: true }, (err, res) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should redirect', (done) => {
|
||
|
request(`${nconf.get('url')}/user/FOO`, { jar: jar }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should 404 if user does not exist', (done) => {
|
||
|
request(`${nconf.get('url')}/api/user/doesnotexist`, { jar: jar }, (err, res) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 404);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
5 years ago
|
it('should not increase profile view if you visit your own profile', (done) => {
|
||
4 years ago
|
request(`${nconf.get('url')}/api/user/foo`, { jar: jar }, (err, res) => {
|
||
5 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
4 years ago
|
setTimeout(() => {
|
||
|
user.getUserField(fooUid, 'profileviews', (err, viewcount) => {
|
||
5 years ago
|
assert.ifError(err);
|
||
|
assert(viewcount === 0);
|
||
|
done();
|
||
|
});
|
||
|
}, 500);
|
||
|
});
|
||
|
});
|
||
|
|
||
|
it('should not increase profile view if a guest visits a profile', (done) => {
|
||
4 years ago
|
request(`${nconf.get('url')}/api/user/foo`, {}, (err, res) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
4 years ago
|
setTimeout(() => {
|
||
|
user.getUserField(fooUid, 'profileviews', (err, viewcount) => {
|
||
6 years ago
|
assert.ifError(err);
|
||
5 years ago
|
assert(viewcount === 0);
|
||
6 years ago
|
done();
|
||
|
});
|
||
|
}, 500);
|
||
8 years ago
|
});
|
||
|
});
|
||
|
|
||
2 years ago
|
it('should increase profile view', async () => {
|
||
|
const { jar } = await helpers.loginUser('regularJoe', 'barbar');
|
||
|
const { statusCode } = await requestAsync(`${nconf.get('url')}/api/user/foo`, {
|
||
|
jar: jar,
|
||
|
simple: false,
|
||
|
resolveWithFullResponse: true,
|
||
5 years ago
|
});
|
||
2 years ago
|
assert.equal(statusCode, 200);
|
||
|
|
||
|
await sleep(500);
|
||
|
const viewcount = await user.getUserField(fooUid, 'profileviews');
|
||
|
assert(viewcount > 0);
|
||
5 years ago
|
});
|
||
|
|
||
4 years ago
|
it('should parse about me', (done) => {
|
||
|
user.setUserFields(fooUid, { picture: '/path/to/picture', aboutme: 'hi i am a bot' }, (err) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
4 years ago
|
request(`${nconf.get('url')}/api/user/foo`, { json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert.equal(body.aboutme, 'hi i am a bot');
|
||
|
assert.equal(body.picture, '/path/to/picture');
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should not return reputation if reputation is disabled', (done) => {
|
||
8 years ago
|
meta.config['reputation:disabled'] = 1;
|
||
4 years ago
|
request(`${nconf.get('url')}/api/user/foo`, { json: true }, (err, res, body) => {
|
||
8 years ago
|
meta.config['reputation:disabled'] = 0;
|
||
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(!body.hasOwnProperty('reputation'));
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should only return posts that are not deleted', (done) => {
|
||
4 years ago
|
let topicData;
|
||
|
let pidToDelete;
|
||
8 years ago
|
async.waterfall([
|
||
|
function (next) {
|
||
|
topics.post({ uid: fooUid, title: 'visible', content: 'some content', cid: cid }, next);
|
||
|
},
|
||
|
function (data, next) {
|
||
|
topicData = data.topicData;
|
||
|
topics.reply({ uid: fooUid, content: '1st reply', tid: topicData.tid }, next);
|
||
|
},
|
||
|
function (postData, next) {
|
||
|
pidToDelete = postData.pid;
|
||
|
topics.reply({ uid: fooUid, content: '2nd reply', tid: topicData.tid }, next);
|
||
|
},
|
||
|
function (postData, next) {
|
||
|
posts.delete(pidToDelete, fooUid, next);
|
||
|
},
|
||
|
function (next) {
|
||
4 years ago
|
request(`${nconf.get('url')}/api/user/foo`, { json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
4 years ago
|
const contents = body.posts.map(p => p.content);
|
||
6 years ago
|
assert(!contents.includes('1st reply'));
|
||
8 years ago
|
done();
|
||
|
});
|
||
|
},
|
||
|
], done);
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should return selected group title', (done) => {
|
||
8 years ago
|
groups.create({
|
||
|
name: 'selectedGroup',
|
||
4 years ago
|
}, (err) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
4 years ago
|
user.create({ username: 'groupie' }, (err, uid) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
4 years ago
|
groups.join('selectedGroup', uid, (err) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
4 years ago
|
request(`${nconf.get('url')}/api/user/groupie`, { json: true }, (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(Array.isArray(body.selectedGroup));
|
||
|
assert.equal(body.selectedGroup[0].name, 'selectedGroup');
|
||
|
done();
|
||
|
});
|
||
8 years ago
|
});
|
||
|
});
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should 404 if user does not exist', (done) => {
|
||
|
groups.join('administrators', fooUid, (err) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
4 years ago
|
request(`${nconf.get('url')}/api/user/doesnotexist/edit`, { jar: jar, json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 404);
|
||
|
groups.leave('administrators', fooUid, done);
|
||
|
});
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should render edit/password', (done) => {
|
||
|
request(`${nconf.get('url')}/api/user/foo/edit/password`, { jar: jar, json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should render edit/email', async () => {
|
||
|
const res = await requestAsync(`${nconf.get('url')}/api/user/foo/edit/email`, {
|
||
|
jar,
|
||
|
json: true,
|
||
|
resolveWithFullResponse: true,
|
||
|
});
|
||
|
|
||
|
assert.strictEqual(res.statusCode, 200);
|
||
|
assert.strictEqual(res.body, '/register/complete');
|
||
|
|
||
|
await requestAsync({
|
||
2 years ago
|
uri: `${nconf.get('url')}/register/abort`,
|
||
4 years ago
|
method: 'post',
|
||
|
jar,
|
||
|
simple: false,
|
||
2 years ago
|
headers: {
|
||
|
'x-csrf-token': csrf_token,
|
||
|
},
|
||
8 years ago
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should render edit/username', (done) => {
|
||
|
request(`${nconf.get('url')}/api/user/foo/edit/username`, { jar: jar, json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
8 years ago
|
});
|
||
|
|
||
4 years ago
|
describe('account follow page', () => {
|
||
4 years ago
|
const socketUser = require('../src/socket.io/user');
|
||
3 years ago
|
const apiUser = require('../src/api/users');
|
||
4 years ago
|
let uid;
|
||
3 years ago
|
before(async () => {
|
||
|
uid = await user.create({ username: 'follower' });
|
||
|
await apiUser.follow({ uid: uid }, { uid: fooUid });
|
||
|
const isFollowing = await socketUser.isFollowing({ uid: uid }, { uid: fooUid });
|
||
|
assert(isFollowing);
|
||
8 years ago
|
});
|
||
|
|
||
4 years ago
|
it('should get followers page', (done) => {
|
||
|
request(`${nconf.get('url')}/api/user/foo/followers`, { json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert.equal(body.users[0].username, 'follower');
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should get following page', (done) => {
|
||
|
request(`${nconf.get('url')}/api/user/follower/following`, { json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert.equal(body.users[0].username, 'foo');
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
8 years ago
|
|
||
3 years ago
|
it('should return empty after unfollow', async () => {
|
||
|
await apiUser.unfollow({ uid: uid }, { uid: fooUid });
|
||
|
const { res, body } = await helpers.request('get', `/api/user/foo/followers`, { json: true });
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert.equal(body.users.length, 0);
|
||
8 years ago
|
});
|
||
8 years ago
|
});
|
||
|
|
||
4 years ago
|
describe('post redirect', () => {
|
||
4 years ago
|
let jar;
|
||
3 years ago
|
before(async () => {
|
||
|
({ jar } = await helpers.loginUser('foo', 'barbar'));
|
||
8 years ago
|
});
|
||
|
|
||
4 years ago
|
it('should 404 for invalid pid', (done) => {
|
||
|
request(`${nconf.get('url')}/api/post/fail`, (err, res) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 404);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should 403 if user does not have read privilege', (done) => {
|
||
|
privileges.categories.rescind(['groups:topics:read'], category.cid, 'registered-users', (err) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
4 years ago
|
request(`${nconf.get('url')}/api/post/${pid}`, { jar: jar }, (err, res) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 403);
|
||
5 years ago
|
privileges.categories.give(['groups:topics:read'], category.cid, 'registered-users', done);
|
||
8 years ago
|
});
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should return correct post path', (done) => {
|
||
|
request(`${nconf.get('url')}/api/post/${pid}`, { json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
8 years ago
|
assert.equal(res.statusCode, 200);
|
||
1 year ago
|
assert.equal(res.headers['x-redirect'], '/topic/1/test-topic-title');
|
||
|
assert.equal(body, '/topic/1/test-topic-title');
|
||
8 years ago
|
done();
|
||
|
});
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
describe('cookie consent', () => {
|
||
|
it('should return relevant data in configs API route', (done) => {
|
||
|
request(`${nconf.get('url')}/api/config`, (err, res, body) => {
|
||
4 years ago
|
let parsed;
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
|
||
|
try {
|
||
|
parsed = JSON.parse(body);
|
||
|
} catch (e) {
|
||
|
assert.ifError(e);
|
||
|
}
|
||
|
|
||
|
assert.ok(parsed.cookies);
|
||
8 years ago
|
assert.equal(translator.escape('[[global:cookies.message]]'), parsed.cookies.message);
|
||
|
assert.equal(translator.escape('[[global:cookies.accept]]'), parsed.cookies.dismiss);
|
||
|
assert.equal(translator.escape('[[global:cookies.learn_more]]'), parsed.cookies.link);
|
||
8 years ago
|
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('response should be parseable when entries have apostrophes', (done) => {
|
||
|
meta.configs.set('cookieConsentMessage', 'Julian\'s Message', (err) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
|
||
4 years ago
|
request(`${nconf.get('url')}/api/config`, (err, res, body) => {
|
||
4 years ago
|
let parsed;
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
|
||
|
try {
|
||
|
parsed = JSON.parse(body);
|
||
|
} catch (e) {
|
||
|
assert.ifError(e);
|
||
|
}
|
||
|
|
||
|
assert.equal('Julian's Message', parsed.cookies.message);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should return osd data', (done) => {
|
||
|
request(`${nconf.get('url')}/osd.xml`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
6 years ago
|
assert.equal(res.statusCode, 200);
|
||
8 years ago
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
describe('handle errors', () => {
|
||
4 years ago
|
const plugins = require('../src/plugins');
|
||
4 years ago
|
after((done) => {
|
||
8 years ago
|
plugins.loadedHooks['filter:router.page'] = undefined;
|
||
|
done();
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should handle topic malformed uri', (done) => {
|
||
|
request(`${nconf.get('url')}/topic/1/a%AFc`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
6 years ago
|
assert.equal(res.statusCode, 200);
|
||
8 years ago
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should handle category malformed uri', (done) => {
|
||
|
request(`${nconf.get('url')}/category/1/a%AFc`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
6 years ago
|
assert.equal(res.statusCode, 200);
|
||
8 years ago
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should handle malformed uri ', (done) => {
|
||
|
request(`${nconf.get('url')}/user/a%AFc`, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert(body);
|
||
|
assert.equal(res.statusCode, 400);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should handle malformed uri in api', (done) => {
|
||
|
request(`${nconf.get('url')}/api/user/a%AFc`, { json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 400);
|
||
|
assert.equal(body.error, '[[global:400.title]]');
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should handle CSRF error', (done) => {
|
||
8 years ago
|
plugins.loadedHooks['filter:router.page'] = plugins.loadedHooks['filter:router.page'] || [];
|
||
|
plugins.loadedHooks['filter:router.page'].push({
|
||
|
method: function (req, res, next) {
|
||
4 years ago
|
const err = new Error('csrf-error');
|
||
8 years ago
|
err.code = 'EBADCSRFTOKEN';
|
||
|
next(err);
|
||
|
},
|
||
|
});
|
||
|
|
||
4 years ago
|
request(`${nconf.get('url')}/users`, {}, (err, res) => {
|
||
8 years ago
|
plugins.loadedHooks['filter:router.page'] = [];
|
||
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 403);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should handle black-list error', (done) => {
|
||
8 years ago
|
plugins.loadedHooks['filter:router.page'] = plugins.loadedHooks['filter:router.page'] || [];
|
||
|
plugins.loadedHooks['filter:router.page'].push({
|
||
|
method: function (req, res, next) {
|
||
4 years ago
|
const err = new Error('blacklist error message');
|
||
8 years ago
|
err.code = 'blacklisted-ip';
|
||
|
next(err);
|
||
|
},
|
||
|
});
|
||
|
|
||
4 years ago
|
request(`${nconf.get('url')}/users`, {}, (err, res, body) => {
|
||
8 years ago
|
plugins.loadedHooks['filter:router.page'] = [];
|
||
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 403);
|
||
|
assert.equal(body, 'blacklist error message');
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should handle page redirect through error', (done) => {
|
||
8 years ago
|
plugins.loadedHooks['filter:router.page'] = plugins.loadedHooks['filter:router.page'] || [];
|
||
|
plugins.loadedHooks['filter:router.page'].push({
|
||
|
method: function (req, res, next) {
|
||
4 years ago
|
const err = new Error('redirect');
|
||
8 years ago
|
err.status = 302;
|
||
|
err.path = '/popular';
|
||
|
plugins.loadedHooks['filter:router.page'] = [];
|
||
|
next(err);
|
||
|
},
|
||
|
});
|
||
|
|
||
4 years ago
|
request(`${nconf.get('url')}/users`, {}, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should handle api page redirect through error', (done) => {
|
||
8 years ago
|
plugins.loadedHooks['filter:router.page'] = plugins.loadedHooks['filter:router.page'] || [];
|
||
|
plugins.loadedHooks['filter:router.page'].push({
|
||
|
method: function (req, res, next) {
|
||
4 years ago
|
const err = new Error('redirect');
|
||
8 years ago
|
err.status = 308;
|
||
|
err.path = '/api/popular';
|
||
|
plugins.loadedHooks['filter:router.page'] = [];
|
||
|
next(err);
|
||
|
},
|
||
|
});
|
||
|
|
||
4 years ago
|
request(`${nconf.get('url')}/api/users`, { json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
8 years ago
|
assert.equal(res.statusCode, 200);
|
||
|
assert.equal(res.headers['x-redirect'], '/api/popular');
|
||
8 years ago
|
assert(body, '/api/popular');
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should handle error page', (done) => {
|
||
8 years ago
|
plugins.loadedHooks['filter:router.page'] = plugins.loadedHooks['filter:router.page'] || [];
|
||
|
plugins.loadedHooks['filter:router.page'].push({
|
||
|
method: function (req, res, next) {
|
||
4 years ago
|
const err = new Error('regular error');
|
||
8 years ago
|
next(err);
|
||
|
},
|
||
|
});
|
||
|
|
||
4 years ago
|
request(`${nconf.get('url')}/users`, (err, res, body) => {
|
||
8 years ago
|
plugins.loadedHooks['filter:router.page'] = [];
|
||
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 500);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
describe('category', () => {
|
||
4 years ago
|
let jar;
|
||
3 years ago
|
before(async () => {
|
||
|
({ jar } = await helpers.loginUser('foo', 'barbar'));
|
||
8 years ago
|
});
|
||
|
|
||
4 years ago
|
it('should return 404 if cid is not a number', (done) => {
|
||
|
request(`${nconf.get('url')}/api/category/fail`, (err, res) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 404);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should return 404 if topic index is not a number', (done) => {
|
||
|
request(`${nconf.get('url')}/api/category/${category.slug}/invalidtopicindex`, (err, res) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 404);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should 404 if category does not exist', (done) => {
|
||
|
request(`${nconf.get('url')}/api/category/123123`, (err, res) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 404);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should 404 if category is disabled', (done) => {
|
||
|
categories.create({ name: 'disabled' }, (err, category) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
4 years ago
|
categories.setCategoryField(category.cid, 'disabled', 1, (err) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
4 years ago
|
request(`${nconf.get('url')}/api/category/${category.slug}`, (err, res) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 404);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should return 401 if not allowed to read', (done) => {
|
||
|
categories.create({ name: 'hidden' }, (err, category) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
4 years ago
|
privileges.categories.rescind(['groups:read'], category.cid, 'guests', (err) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
4 years ago
|
request(`${nconf.get('url')}/api/category/${category.slug}`, (err, res) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 401);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should redirect if topic index is negative', (done) => {
|
||
|
request(`${nconf.get('url')}/api/category/${category.slug}/-10`, (err, res) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
8 years ago
|
assert.equal(res.statusCode, 200);
|
||
|
assert.ok(res.headers['x-redirect']);
|
||
8 years ago
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should 404 if page is not found', (done) => {
|
||
|
user.setSetting(fooUid, 'usePagination', 1, (err) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
4 years ago
|
request(`${nconf.get('url')}/api/category/${category.slug}?page=100`, { jar: jar, json: true }, (err, res) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 404);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load page 1 if req.query.page is not sent', (done) => {
|
||
|
request(`${nconf.get('url')}/api/category/${category.slug}`, { jar: jar, json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert.equal(body.pagination.currentPage, 1);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should sort topics by most posts', (done) => {
|
||
8 years ago
|
async.waterfall([
|
||
|
function (next) {
|
||
|
categories.create({ name: 'most-posts-category' }, next);
|
||
|
},
|
||
|
function (category, next) {
|
||
|
async.waterfall([
|
||
|
function (next) {
|
||
|
topics.post({ uid: fooUid, cid: category.cid, title: 'topic 1', content: 'topic 1 OP' }, next);
|
||
|
},
|
||
|
function (data, next) {
|
||
|
topics.post({ uid: fooUid, cid: category.cid, title: 'topic 2', content: 'topic 2 OP' }, next);
|
||
|
},
|
||
|
function (data, next) {
|
||
|
topics.reply({ uid: fooUid, content: 'topic 2 reply', tid: data.topicData.tid }, next);
|
||
|
},
|
||
|
function (postData, next) {
|
||
4 years ago
|
request(`${nconf.get('url')}/api/category/${category.slug}?sort=most_posts`, { jar: jar, json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert.equal(body.topics[0].title, 'topic 2');
|
||
|
assert.equal(body.topics[0].postcount, 2);
|
||
|
assert.equal(body.topics[1].postcount, 1);
|
||
|
next();
|
||
|
});
|
||
|
},
|
||
4 years ago
|
], (err) => {
|
||
8 years ago
|
next(err);
|
||
|
});
|
||
|
},
|
||
|
], done);
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load a specific users topics from a category with tags', (done) => {
|
||
8 years ago
|
async.waterfall([
|
||
|
function (next) {
|
||
|
categories.create({ name: 'filtered-category' }, next);
|
||
|
},
|
||
|
function (category, next) {
|
||
|
async.waterfall([
|
||
|
function (next) {
|
||
|
topics.post({ uid: fooUid, cid: category.cid, title: 'topic 1', content: 'topic 1 OP', tags: ['java', 'cpp'] }, next);
|
||
|
},
|
||
|
function (data, next) {
|
||
|
topics.post({ uid: fooUid, cid: category.cid, title: 'topic 2', content: 'topic 2 OP', tags: ['node', 'javascript'] }, next);
|
||
|
},
|
||
|
function (data, next) {
|
||
|
topics.post({ uid: fooUid, cid: category.cid, title: 'topic 3', content: 'topic 3 OP', tags: ['java', 'cpp', 'best'] }, next);
|
||
|
},
|
||
|
function (data, next) {
|
||
4 years ago
|
request(`${nconf.get('url')}/api/category/${category.slug}?tag=node&author=foo`, { jar: jar, json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert.equal(body.topics[0].title, 'topic 2');
|
||
|
next();
|
||
|
});
|
||
|
},
|
||
|
function (next) {
|
||
4 years ago
|
request(`${nconf.get('url')}/api/category/${category.slug}?tag[]=java&tag[]=cpp`, { jar: jar, json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert.equal(body.topics[0].title, 'topic 3');
|
||
|
assert.equal(body.topics[1].title, 'topic 1');
|
||
|
next();
|
||
|
});
|
||
|
},
|
||
4 years ago
|
], (err) => {
|
||
8 years ago
|
next(err);
|
||
|
});
|
||
|
},
|
||
|
], done);
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should redirect if category is a link', (done) => {
|
||
4 years ago
|
let cid;
|
||
|
let category;
|
||
8 years ago
|
async.waterfall([
|
||
|
function (next) {
|
||
|
categories.create({ name: 'redirect', link: 'https://nodebb.org' }, next);
|
||
|
},
|
||
4 years ago
|
function (_category, next) {
|
||
|
category = _category;
|
||
|
cid = category.cid;
|
||
4 years ago
|
request(`${nconf.get('url')}/api/category/${category.slug}`, { jar: jar, json: true }, (err, res, body) => {
|
||
4 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert.equal(res.headers['x-redirect'], 'https://nodebb.org');
|
||
|
assert.equal(body, 'https://nodebb.org');
|
||
|
next();
|
||
|
});
|
||
|
},
|
||
|
function (next) {
|
||
|
categories.setCategoryField(cid, 'link', '/recent', next);
|
||
|
},
|
||
|
function (next) {
|
||
4 years ago
|
request(`${nconf.get('url')}/api/category/${category.slug}`, { jar: jar, json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
8 years ago
|
assert.equal(res.statusCode, 200);
|
||
4 years ago
|
assert.equal(res.headers['x-redirect'], '/recent');
|
||
|
assert.equal(body, '/recent');
|
||
8 years ago
|
next();
|
||
|
});
|
||
|
},
|
||
|
], done);
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should get recent topic replies from children categories', (done) => {
|
||
4 years ago
|
let parentCategory;
|
||
|
let childCategory1;
|
||
|
let childCategory2;
|
||
8 years ago
|
|
||
|
async.waterfall([
|
||
|
function (next) {
|
||
|
categories.create({ name: 'parent category', backgroundImage: 'path/to/some/image' }, next);
|
||
|
},
|
||
|
function (category, next) {
|
||
|
parentCategory = category;
|
||
|
async.waterfall([
|
||
|
function (next) {
|
||
|
categories.create({ name: 'child category 1', parentCid: category.cid }, next);
|
||
|
},
|
||
|
function (category, next) {
|
||
|
childCategory1 = category;
|
||
|
categories.create({ name: 'child category 2', parentCid: parentCategory.cid }, next);
|
||
|
},
|
||
|
function (category, next) {
|
||
|
childCategory2 = category;
|
||
|
topics.post({ uid: fooUid, cid: childCategory2.cid, title: 'topic 1', content: 'topic 1 OP' }, next);
|
||
|
},
|
||
|
function (data, next) {
|
||
4 years ago
|
request(`${nconf.get('url')}/api/category/${parentCategory.slug}`, { jar: jar, json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
4 years ago
|
assert.equal(body.children[0].posts[0].content, 'topic 1 OP');
|
||
8 years ago
|
next();
|
||
|
});
|
||
|
},
|
||
4 years ago
|
], (err) => {
|
||
8 years ago
|
next(err);
|
||
|
});
|
||
|
},
|
||
|
], done);
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should create 2 pages of topics', (done) => {
|
||
8 years ago
|
async.waterfall([
|
||
|
function (next) {
|
||
|
categories.create({ name: 'category with 2 pages' }, next);
|
||
|
},
|
||
|
function (category, next) {
|
||
4 years ago
|
const titles = [];
|
||
|
for (let i = 0; i < 30; i++) {
|
||
4 years ago
|
titles.push(`topic title ${i}`);
|
||
8 years ago
|
}
|
||
|
|
||
|
async.waterfall([
|
||
|
function (next) {
|
||
4 years ago
|
async.eachSeries(titles, (title, next) => {
|
||
8 years ago
|
topics.post({ uid: fooUid, cid: category.cid, title: title, content: 'does not really matter' }, next);
|
||
|
}, next);
|
||
|
},
|
||
|
function (next) {
|
||
|
user.getSettings(fooUid, next);
|
||
|
},
|
||
|
function (settings, next) {
|
||
4 years ago
|
request(`${nconf.get('url')}/api/category/${category.slug}`, { jar: jar, json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert.equal(body.topics.length, settings.topicsPerPage);
|
||
|
assert.equal(body.pagination.pageCount, 2);
|
||
|
next();
|
||
|
});
|
||
|
},
|
||
4 years ago
|
], (err) => {
|
||
8 years ago
|
next(err);
|
||
|
});
|
||
|
},
|
||
|
], done);
|
||
|
});
|
||
3 years ago
|
|
||
|
it('should load categories', async () => {
|
||
|
const helpers = require('../src/controllers/helpers');
|
||
|
const data = await helpers.getCategories('cid:0:children', 1, 'topics:read', 0);
|
||
|
assert(data.categories.length > 0);
|
||
|
assert.strictEqual(data.selectedCategory, null);
|
||
|
assert.deepStrictEqual(data.selectedCids, []);
|
||
|
});
|
||
|
|
||
|
it('should load categories by states', async () => {
|
||
|
const helpers = require('../src/controllers/helpers');
|
||
|
const data = await helpers.getCategoriesByStates(1, 1, Object.values(categories.watchStates), 'topics:read');
|
||
|
assert.deepStrictEqual(data.selectedCategory.cid, 1);
|
||
|
assert.deepStrictEqual(data.selectedCids, [1]);
|
||
|
});
|
||
|
|
||
|
it('should load categories by states', async () => {
|
||
|
const helpers = require('../src/controllers/helpers');
|
||
|
const data = await helpers.getCategoriesByStates(1, 0, [categories.watchStates.ignoring], 'topics:read');
|
||
|
assert(data.categories.length === 0);
|
||
|
assert.deepStrictEqual(data.selectedCategory, null);
|
||
|
assert.deepStrictEqual(data.selectedCids, []);
|
||
|
});
|
||
8 years ago
|
});
|
||
|
|
||
4 years ago
|
describe('unread', () => {
|
||
4 years ago
|
let jar;
|
||
3 years ago
|
before(async () => {
|
||
|
({ jar } = await helpers.loginUser('foo', 'barbar'));
|
||
8 years ago
|
});
|
||
|
|
||
4 years ago
|
it('should load unread page', (done) => {
|
||
|
request(`${nconf.get('url')}/api/unread`, { jar: jar }, (err, res) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should 404 if filter is invalid', (done) => {
|
||
|
request(`${nconf.get('url')}/api/unread/doesnotexist`, { jar: jar }, (err, res) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 404);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should return total unread count', (done) => {
|
||
|
request(`${nconf.get('url')}/api/unread/total?filter=new`, { jar: jar }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert.equal(body, 0);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should redirect if page is out of bounds', (done) => {
|
||
|
request(`${nconf.get('url')}/api/unread?page=-1`, { jar: jar, json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
8 years ago
|
assert.equal(res.statusCode, 200);
|
||
|
assert.equal(res.headers['x-redirect'], '/unread?page=1');
|
||
|
assert.equal(body, '/unread?page=1');
|
||
8 years ago
|
done();
|
||
|
});
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
describe('admin middlewares', () => {
|
||
|
it('should redirect to login', (done) => {
|
||
|
request(`${nconf.get('url')}//api/admin/advanced/database`, { json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
8 years ago
|
assert.equal(res.statusCode, 401);
|
||
8 years ago
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should redirect to login', (done) => {
|
||
|
request(`${nconf.get('url')}//admin/advanced/database`, { json: true }, (err, res, body) => {
|
||
8 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
6 years ago
|
assert(body.includes('Login to your account'));
|
||
8 years ago
|
done();
|
||
|
});
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
describe('composer', () => {
|
||
4 years ago
|
let csrf_token;
|
||
|
let jar;
|
||
7 years ago
|
|
||
3 years ago
|
before(async () => {
|
||
|
const login = await helpers.loginUser('foo', 'barbar');
|
||
|
jar = login.jar;
|
||
|
csrf_token = login.csrf_token;
|
||
7 years ago
|
});
|
||
|
|
||
4 years ago
|
it('should load the composer route', (done) => {
|
||
3 years ago
|
request(`${nconf.get('url')}/api/compose?cid=1`, { json: true }, (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body.title);
|
||
|
assert(body.template);
|
||
4 years ago
|
assert.equal(body.url, `${nconf.get('relative_path')}/compose`);
|
||
7 years ago
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should load the composer route if disabled by plugin', (done) => {
|
||
7 years ago
|
function hookMethod(hookData, callback) {
|
||
|
hookData.templateData.disabled = true;
|
||
|
callback(null, hookData);
|
||
|
}
|
||
|
|
||
4 years ago
|
plugins.hooks.register('myTestPlugin', {
|
||
7 years ago
|
hook: 'filter:composer.build',
|
||
|
method: hookMethod,
|
||
|
});
|
||
|
|
||
3 years ago
|
request(`${nconf.get('url')}/api/compose?cid=1`, { json: true }, (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body.title);
|
||
|
assert.strictEqual(body.template.name, '');
|
||
4 years ago
|
assert.strictEqual(body.url, `${nconf.get('relative_path')}/compose`);
|
||
7 years ago
|
|
||
4 years ago
|
plugins.hooks.unregister('myTestPlugin', 'filter:composer.build', hookMethod);
|
||
7 years ago
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should error with invalid data', (done) => {
|
||
4 years ago
|
request.post(`${nconf.get('url')}/compose`, {
|
||
7 years ago
|
form: {
|
||
|
content: 'a new reply',
|
||
|
},
|
||
|
jar: jar,
|
||
|
headers: {
|
||
|
'x-csrf-token': csrf_token,
|
||
|
},
|
||
4 years ago
|
}, (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 400);
|
||
4 years ago
|
request.post(`${nconf.get('url')}/compose`, {
|
||
7 years ago
|
form: {
|
||
|
tid: tid,
|
||
|
},
|
||
|
jar: jar,
|
||
|
headers: {
|
||
|
'x-csrf-token': csrf_token,
|
||
|
},
|
||
4 years ago
|
}, (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 400);
|
||
|
done();
|
||
|
});
|
||
7 years ago
|
});
|
||
|
});
|
||
|
|
||
4 years ago
|
it('should create a new topic and reply by composer route', (done) => {
|
||
4 years ago
|
const data = {
|
||
7 years ago
|
cid: cid,
|
||
|
title: 'no js is good',
|
||
|
content: 'a topic with noscript',
|
||
|
};
|
||
4 years ago
|
request.post(`${nconf.get('url')}/compose`, {
|
||
7 years ago
|
form: data,
|
||
|
jar: jar,
|
||
|
headers: {
|
||
|
'x-csrf-token': csrf_token,
|
||
|
},
|
||
4 years ago
|
}, (err, res) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 302);
|
||
4 years ago
|
request.post(`${nconf.get('url')}/compose`, {
|
||
7 years ago
|
form: {
|
||
|
tid: tid,
|
||
|
content: 'a new reply',
|
||
|
},
|
||
|
jar: jar,
|
||
|
headers: {
|
||
|
'x-csrf-token': csrf_token,
|
||
|
},
|
||
4 years ago
|
}, (err, res, body) => {
|
||
7 years ago
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 302);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
});
|
||
2 years ago
|
|
||
|
it('should create a new topic and reply by composer route as a guest', async () => {
|
||
|
const jar = request.jar();
|
||
|
const csrf_token = await helpers.getCsrfToken(jar);
|
||
|
const data = {
|
||
|
cid: cid,
|
||
|
title: 'no js is good',
|
||
|
content: 'a topic with noscript',
|
||
|
handle: 'guest1',
|
||
|
};
|
||
|
|
||
|
await privileges.categories.give(['groups:topics:create', 'groups:topics:reply'], cid, 'guests');
|
||
|
|
||
|
const result = await helpers.request('post', `/compose`, {
|
||
|
form: data,
|
||
|
jar,
|
||
|
headers: {
|
||
|
'x-csrf-token': csrf_token,
|
||
|
},
|
||
|
});
|
||
|
assert.strictEqual(result.res.statusCode, 302);
|
||
|
|
||
|
const replyResult = await helpers.request('post', `/compose`, {
|
||
|
form: {
|
||
|
tid: tid,
|
||
|
content: 'a new reply',
|
||
|
handle: 'guest2',
|
||
|
},
|
||
|
jar,
|
||
|
headers: {
|
||
|
'x-csrf-token': csrf_token,
|
||
|
},
|
||
|
});
|
||
|
assert.equal(replyResult.res.statusCode, 302);
|
||
|
await privileges.categories.rescind(['groups:topics:post', 'groups:topics:reply'], cid, 'guests');
|
||
|
});
|
||
7 years ago
|
});
|
||
|
|
||
3 years ago
|
describe('test routes', () => {
|
||
|
if (process.env.NODE_ENV === 'development') {
|
||
|
it('should load debug route', (done) => {
|
||
|
request(`${nconf.get('url')}/debug/test`, {}, (err, res, body) => {
|
||
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 404);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
|
it('should load redoc read route', (done) => {
|
||
|
request(`${nconf.get('url')}/debug/spec/read`, {}, (err, res, body) => {
|
||
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
|
it('should load redoc write route', (done) => {
|
||
|
request(`${nconf.get('url')}/debug/spec/write`, {}, (err, res, body) => {
|
||
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 200);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
|
||
|
it('should load 404 for invalid type', (done) => {
|
||
|
request(`${nconf.get('url')}/debug/spec/doesnotexist`, {}, (err, res, body) => {
|
||
|
assert.ifError(err);
|
||
|
assert.equal(res.statusCode, 404);
|
||
|
assert(body);
|
||
|
done();
|
||
|
});
|
||
|
});
|
||
|
}
|
||
|
});
|
||
|
|
||
4 years ago
|
after((done) => {
|
||
4 years ago
|
const analytics = require('../src/analytics');
|
||
8 years ago
|
analytics.writeData(done);
|
||
8 years ago
|
});
|
||
|
});
|