1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414 |
- import json
- from datetime import timedelta
- from django.urls import reverse
- from django.utils import timezone
- from misago.acl.testutils import override_acl
- from misago.categories.models import Category
- from misago.threads import testutils
- from misago.threads.models import Thread, Post
- from misago.users.testutils import AuthenticatedUserTestCase
- class ThreadPostPatchApiTestCase(AuthenticatedUserTestCase):
- def setUp(self):
- super().setUp()
- self.category = Category.objects.get(slug='first-category')
- self.thread = testutils.post_thread(category=self.category)
- self.post = testutils.reply_thread(self.thread, poster=self.user)
- self.api_link = reverse(
- 'misago:api:thread-post-detail',
- kwargs={
- 'thread_pk': self.thread.pk,
- 'pk': self.post.pk,
- }
- )
- def patch(self, api_link, ops):
- return self.client.patch(api_link, json.dumps(ops), content_type="application/json")
- def refresh_post(self):
- self.post = self.thread.post_set.get(pk=self.post.pk)
- def refresh_thread(self):
- self.thread = Thread.objects.get(pk=self.thread.pk)
- def override_acl(self, extra_acl=None):
- new_acl = self.user.acl_cache
- new_acl['categories'][self.category.pk].update({
- 'can_see': 1,
- 'can_browse': 1,
- 'can_start_threads': 0,
- 'can_reply_threads': 0,
- 'can_edit_posts': 1,
- })
- if extra_acl:
- new_acl['categories'][self.category.pk].update(extra_acl)
- override_acl(self.user, new_acl)
- class PostAddAclApiTests(ThreadPostPatchApiTestCase):
- def test_add_acl_true(self):
- """api adds current event's acl to response"""
- response = self.patch(self.api_link, [
- {
- 'op': 'add',
- 'path': 'acl',
- 'value': True,
- },
- ])
- self.assertEqual(response.status_code, 200)
- response_json = response.json()
- self.assertTrue(response_json['acl'])
- def test_add_acl_false(self):
- """if value is false, api won't add acl to the response, but will set empty key"""
- response = self.patch(self.api_link, [
- {
- 'op': 'add',
- 'path': 'acl',
- 'value': False,
- },
- ])
- self.assertEqual(response.status_code, 200)
- response_json = response.json()
- self.assertIsNone(response_json['acl'])
- class PostProtectApiTests(ThreadPostPatchApiTestCase):
- def test_protect_post(self):
- """api makes it possible to protect post"""
- self.override_acl({'can_protect_posts': 1})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-protected',
- 'value': True,
- },
- ]
- )
- self.assertEqual(response.status_code, 200)
- reponse_json = response.json()
- self.assertTrue(reponse_json['is_protected'])
- self.refresh_post()
- self.assertTrue(self.post.is_protected)
- def test_unprotect_post(self):
- """api makes it possible to unprotect protected post"""
- self.post.is_protected = True
- self.post.save()
- self.override_acl({'can_protect_posts': 1})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-protected',
- 'value': False,
- },
- ]
- )
- self.assertEqual(response.status_code, 200)
- reponse_json = response.json()
- self.assertFalse(reponse_json['is_protected'])
- self.refresh_post()
- self.assertFalse(self.post.is_protected)
- def test_protect_best_answer(self):
- """api makes it possible to protect post"""
- self.thread.set_best_answer(self.user, self.post)
- self.thread.save()
- self.assertFalse(self.thread.best_answer_is_protected)
-
- self.override_acl({'can_protect_posts': 1})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-protected',
- 'value': True,
- },
- ]
- )
- self.assertEqual(response.status_code, 200)
- reponse_json = response.json()
- self.assertTrue(reponse_json['is_protected'])
- self.refresh_post()
- self.assertTrue(self.post.is_protected)
- self.refresh_thread()
- self.assertTrue(self.thread.best_answer_is_protected)
- def test_unprotect_best_answer(self):
- """api makes it possible to unprotect protected post"""
- self.post.is_protected = True
- self.post.save()
- self.thread.set_best_answer(self.user, self.post)
- self.thread.save()
- self.assertTrue(self.thread.best_answer_is_protected)
- self.override_acl({'can_protect_posts': 1})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-protected',
- 'value': False,
- },
- ]
- )
- self.assertEqual(response.status_code, 200)
- reponse_json = response.json()
- self.assertFalse(reponse_json['is_protected'])
- self.refresh_post()
- self.assertFalse(self.post.is_protected)
- self.refresh_thread()
- self.assertFalse(self.thread.best_answer_is_protected)
- def test_protect_post_no_permission(self):
- """api validates permission to protect post"""
- self.override_acl({'can_protect_posts': 0})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-protected',
- 'value': True,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(response_json['detail'][0], "You can't protect posts in this category.")
- self.refresh_post()
- self.assertFalse(self.post.is_protected)
- def test_unprotect_post_no_permission(self):
- """api validates permission to unprotect post"""
- self.post.is_protected = True
- self.post.save()
- self.override_acl({'can_protect_posts': 0})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-protected',
- 'value': False,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(response_json['detail'][0], "You can't protect posts in this category.")
- self.refresh_post()
- self.assertTrue(self.post.is_protected)
- def test_protect_post_not_editable(self):
- """api validates if we can edit post we want to protect"""
- self.override_acl({'can_edit_posts': 0, 'can_protect_posts': 1})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-protected',
- 'value': True,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(response_json['detail'][0], "You can't protect posts you can't edit.")
- self.refresh_post()
- self.assertFalse(self.post.is_protected)
- def test_unprotect_post_not_editable(self):
- """api validates if we can edit post we want to protect"""
- self.post.is_protected = True
- self.post.save()
- self.override_acl({'can_edit_posts': 0, 'can_protect_posts': 1})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-protected',
- 'value': False,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(response_json['detail'][0], "You can't protect posts you can't edit.")
- self.refresh_post()
- self.assertTrue(self.post.is_protected)
- class PostApproveApiTests(ThreadPostPatchApiTestCase):
- def test_approve_post(self):
- """api makes it possible to approve post"""
- self.post.is_unapproved = True
- self.post.save()
- self.override_acl({'can_approve_content': 1})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-unapproved',
- 'value': False,
- },
- ]
- )
- self.assertEqual(response.status_code, 200)
- reponse_json = response.json()
- self.assertFalse(reponse_json['is_unapproved'])
- self.refresh_post()
- self.assertFalse(self.post.is_unapproved)
- def test_unapprove_post(self):
- """unapproving posts is not supported by api"""
- self.override_acl({'can_approve_content': 1})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-unapproved',
- 'value': True,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(response_json['detail'][0], "Content approval can't be reversed.")
- self.refresh_post()
- self.assertFalse(self.post.is_unapproved)
- def test_approve_post_no_permission(self):
- """api validates approval permission"""
- self.post.is_unapproved = True
- self.post.save()
- self.override_acl({'can_approve_content': 0})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-unapproved',
- 'value': False,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(response_json['detail'][0], "You can't approve posts in this category.")
- self.refresh_post()
- self.assertTrue(self.post.is_unapproved)
- def test_approve_post_closed_thread_no_permission(self):
- """api validates approval permission in closed threads"""
- self.post.is_unapproved = True
- self.post.save()
- self.thread.is_closed = True
- self.thread.save()
- self.override_acl({
- 'can_approve_content': 1,
- 'can_close_threads': 0,
- })
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-unapproved',
- 'value': False,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(
- response_json['detail'][0],
- "This thread is closed. You can't approve posts in it.",
- )
- self.refresh_post()
- self.assertTrue(self.post.is_unapproved)
- def test_approve_post_closed_category_no_permission(self):
- """api validates approval permission in closed categories"""
- self.post.is_unapproved = True
- self.post.save()
- self.category.is_closed = True
- self.category.save()
- self.override_acl({
- 'can_approve_content': 1,
- 'can_close_threads': 0,
- })
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-unapproved',
- 'value': False,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(
- response_json['detail'][0],
- "This category is closed. You can't approve posts in it.",
- )
- self.refresh_post()
- self.assertTrue(self.post.is_unapproved)
- def test_approve_first_post(self):
- """api approve first post fails"""
- self.post.is_unapproved = True
- self.post.save()
- self.thread.set_first_post(self.post)
- self.thread.save()
- self.override_acl({'can_approve_content': 1})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-unapproved',
- 'value': False,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(response_json['detail'][0], "You can't approve thread's first post.")
- self.refresh_post()
- self.assertTrue(self.post.is_unapproved)
- def test_approve_hidden_post(self):
- """api approve hidden post fails"""
- self.post.is_unapproved = True
- self.post.is_hidden = True
- self.post.save()
- self.override_acl({'can_approve_content': 1})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-unapproved',
- 'value': False,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(
- response_json['detail'][0], "You can't approve posts the content you can't see."
- )
- self.refresh_post()
- self.assertTrue(self.post.is_unapproved)
- class PostHideApiTests(ThreadPostPatchApiTestCase):
- def test_hide_post(self):
- """api makes it possible to hide post"""
- self.override_acl({'can_hide_posts': 1})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-hidden',
- 'value': True,
- },
- ]
- )
- self.assertEqual(response.status_code, 200)
- reponse_json = response.json()
- self.assertTrue(reponse_json['is_hidden'])
- self.refresh_post()
- self.assertTrue(self.post.is_hidden)
- def test_hide_own_post(self):
- """api makes it possible to hide owned post"""
- self.override_acl({'can_hide_own_posts': 1})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-hidden',
- 'value': True,
- },
- ]
- )
- self.assertEqual(response.status_code, 200)
- reponse_json = response.json()
- self.assertTrue(reponse_json['is_hidden'])
- self.refresh_post()
- self.assertTrue(self.post.is_hidden)
- def test_hide_post_no_permission(self):
- """api hide post with no permission fails"""
- self.override_acl({'can_hide_posts': 0})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-hidden',
- 'value': True,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(response_json['detail'][0], "You can't hide posts in this category.")
- self.refresh_post()
- self.assertFalse(self.post.is_hidden)
- def test_hide_own_protected_post(self):
- """api validates if we are trying to hide protected post"""
- self.post.is_protected = True
- self.post.save()
- self.override_acl({'can_protect_posts': 0, 'can_hide_own_posts': 1})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-hidden',
- 'value': True,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(response_json['detail'][0], "This post is protected. You can't hide it.")
- self.refresh_post()
- self.assertFalse(self.post.is_hidden)
- def test_hide_other_user_post(self):
- """api validates post ownership when hiding"""
- self.post.poster = None
- self.post.save()
- self.override_acl({'can_hide_own_posts': 1})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-hidden',
- 'value': True,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(
- response_json['detail'][0], "You can't hide other users posts in this category."
- )
- self.refresh_post()
- self.assertFalse(self.post.is_hidden)
- def test_hide_own_post_after_edit_time(self):
- """api validates if we are trying to hide post after edit time"""
- self.post.posted_on = timezone.now() - timedelta(minutes=10)
- self.post.save()
- self.override_acl({'post_edit_time': 1, 'can_hide_own_posts': 1})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-hidden',
- 'value': True,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(
- response_json['detail'][0], "You can't hide posts that are older than 1 minute."
- )
- self.refresh_post()
- self.assertFalse(self.post.is_hidden)
- def test_hide_post_in_closed_thread(self):
- """api validates if we are trying to hide post in closed thread"""
- self.thread.is_closed = True
- self.thread.save()
- self.override_acl({'can_hide_own_posts': 1})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-hidden',
- 'value': True,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(
- response_json['detail'][0], "This thread is closed. You can't hide posts in it."
- )
- self.refresh_post()
- self.assertFalse(self.post.is_hidden)
- def test_hide_post_in_closed_category(self):
- """api validates if we are trying to hide post in closed category"""
- self.category.is_closed = True
- self.category.save()
- self.override_acl({'can_hide_own_posts': 1})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-hidden',
- 'value': True,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(
- response_json['detail'][0], "This category is closed. You can't hide posts in it."
- )
- self.refresh_post()
- self.assertFalse(self.post.is_hidden)
- def test_hide_first_post(self):
- """api hide first post fails"""
- self.thread.set_first_post(self.post)
- self.thread.save()
- self.override_acl({'can_hide_posts': 1})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-hidden',
- 'value': True,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(response_json['detail'][0], "You can't hide thread's first post.")
- def test_hide_best_answer(self):
- """api hide first post fails"""
- self.thread.set_best_answer(self.user, self.post)
- self.thread.save()
- self.override_acl({'can_hide_posts': 2})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-hidden',
- 'value': True,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- self.assertEqual(response.json(), {
- 'id': self.post.id,
- 'detail': ["You can't hide this post because its marked as best answer."],
- })
- class PostUnhideApiTests(ThreadPostPatchApiTestCase):
- def test_show_post(self):
- """api makes it possible to unhide post"""
- self.post.is_hidden = True
- self.post.save()
- self.refresh_post()
- self.assertTrue(self.post.is_hidden)
- self.override_acl({'can_hide_posts': 1})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-hidden',
- 'value': False,
- },
- ]
- )
- self.assertEqual(response.status_code, 200)
- reponse_json = response.json()
- self.assertFalse(reponse_json['is_hidden'])
- self.refresh_post()
- self.assertFalse(self.post.is_hidden)
- def test_show_own_post(self):
- """api makes it possible to unhide owned post"""
- self.post.is_hidden = True
- self.post.save()
- self.refresh_post()
- self.assertTrue(self.post.is_hidden)
- self.override_acl({'can_hide_own_posts': 1})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-hidden',
- 'value': False,
- },
- ]
- )
- self.assertEqual(response.status_code, 200)
- reponse_json = response.json()
- self.assertFalse(reponse_json['is_hidden'])
- self.refresh_post()
- self.assertFalse(self.post.is_hidden)
- def test_show_post_no_permission(self):
- """api unhide post with no permission fails"""
- self.post.is_hidden = True
- self.post.save()
- self.refresh_post()
- self.assertTrue(self.post.is_hidden)
- self.override_acl({'can_hide_posts': 0})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-hidden',
- 'value': False,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(response_json['detail'][0], "You can't reveal posts in this category.")
- self.refresh_post()
- self.assertTrue(self.post.is_hidden)
- def test_show_own_protected_post(self):
- """api validates if we are trying to reveal protected post"""
- self.post.is_hidden = True
- self.post.save()
- self.override_acl({'can_protect_posts': 0, 'can_hide_own_posts': 1})
- self.post.is_protected = True
- self.post.save()
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-hidden',
- 'value': False,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(
- response_json['detail'][0], "This post is protected. You can't reveal it."
- )
- self.refresh_post()
- self.assertTrue(self.post.is_hidden)
- def test_show_other_user_post(self):
- """api validates post ownership when revealing"""
- self.post.is_hidden = True
- self.post.poster = None
- self.post.save()
- self.override_acl({'can_hide_own_posts': 1})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-hidden',
- 'value': False,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(
- response_json['detail'][0], "You can't reveal other users posts in this category."
- )
- self.refresh_post()
- self.assertTrue(self.post.is_hidden)
- def test_show_own_post_after_edit_time(self):
- """api validates if we are trying to reveal post after edit time"""
- self.post.is_hidden = True
- self.post.posted_on = timezone.now() - timedelta(minutes=10)
- self.post.save()
- self.override_acl({'post_edit_time': 1, 'can_hide_own_posts': 1})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-hidden',
- 'value': False,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(
- response_json['detail'][0], "You can't reveal posts that are older than 1 minute."
- )
- self.refresh_post()
- self.assertTrue(self.post.is_hidden)
- def test_show_post_in_closed_thread(self):
- """api validates if we are trying to reveal post in closed thread"""
- self.thread.is_closed = True
- self.thread.save()
- self.post.is_hidden = True
- self.post.save()
- self.override_acl({'can_hide_own_posts': 1})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-hidden',
- 'value': False,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(
- response_json['detail'][0], "This thread is closed. You can't reveal posts in it."
- )
- self.refresh_post()
- self.assertTrue(self.post.is_hidden)
- def test_show_post_in_closed_category(self):
- """api validates if we are trying to reveal post in closed category"""
- self.category.is_closed = True
- self.category.save()
- self.post.is_hidden = True
- self.post.save()
- self.override_acl({'can_hide_own_posts': 1})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-hidden',
- 'value': False,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(
- response_json['detail'][0], "This category is closed. You can't reveal posts in it."
- )
- self.refresh_post()
- self.assertTrue(self.post.is_hidden)
- def test_show_first_post(self):
- """api unhide first post fails"""
- self.thread.set_first_post(self.post)
- self.thread.save()
- self.override_acl({'can_hide_posts': 1})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-hidden',
- 'value': False,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(response_json['detail'][0], "You can't reveal thread's first post.")
- class PostLikeApiTests(ThreadPostPatchApiTestCase):
- def test_like_no_see_permission(self):
- """api validates user's permission to see posts likes"""
- self.override_acl({'can_see_posts_likes': 0})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-liked',
- 'value': True,
- },
- ]
- )
- self.assertContains(response, "You can't like posts in this category.", status_code=400)
- def test_like_no_like_permission(self):
- """api validates user's permission to see posts likes"""
- self.override_acl({'can_like_posts': False})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-liked',
- 'value': True,
- },
- ]
- )
- self.assertContains(response, "You can't like posts in this category.", status_code=400)
- def test_like_post(self):
- """api adds user like to post"""
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-liked',
- 'value': True,
- },
- ]
- )
- self.assertEqual(response.status_code, 200)
- response_json = response.json()
- self.assertEqual(response_json['likes'], 1)
- self.assertEqual(response_json['is_liked'], True)
- self.assertEqual(
- response_json['last_likes'], [
- {
- 'id': self.user.id,
- 'username': self.user.username,
- },
- ]
- )
- post = Post.objects.get(pk=self.post.pk)
- self.assertEqual(post.likes, response_json['likes'])
- self.assertEqual(post.last_likes, response_json['last_likes'])
- def test_like_liked_post(self):
- """api adds user like to post"""
- testutils.like_post(self.post, username='Myo')
- testutils.like_post(self.post, username='Mugi')
- testutils.like_post(self.post, username='Bob')
- testutils.like_post(self.post, username='Miku')
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-liked',
- 'value': True,
- },
- ]
- )
- self.assertEqual(response.status_code, 200)
- response_json = response.json()
- self.assertEqual(response_json['likes'], 5)
- self.assertEqual(response_json['is_liked'], True)
- self.assertEqual(
- response_json['last_likes'], [
- {
- 'id': self.user.id,
- 'username': self.user.username
- },
- {
- 'id': None,
- 'username': 'Miku',
- },
- {
- 'id': None,
- 'username': 'Bob',
- },
- {
- 'id': None,
- 'username': 'Mugi',
- },
- ]
- )
- post = Post.objects.get(pk=self.post.pk)
- self.assertEqual(post.likes, response_json['likes'])
- self.assertEqual(post.last_likes, response_json['last_likes'])
- def test_unlike_post(self):
- """api removes user like from post"""
- testutils.like_post(self.post, self.user)
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-liked',
- 'value': False,
- },
- ]
- )
- self.assertEqual(response.status_code, 200)
- response_json = response.json()
- self.assertEqual(response_json['likes'], 0)
- self.assertEqual(response_json['is_liked'], False)
- self.assertEqual(response_json['last_likes'], [])
- post = Post.objects.get(pk=self.post.pk)
- self.assertEqual(post.likes, response_json['likes'])
- self.assertEqual(post.last_likes, response_json['last_likes'])
- def test_like_post_no_change(self):
- """api does no state change if we are linking liked post"""
- testutils.like_post(self.post, self.user)
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-liked',
- 'value': True,
- },
- ]
- )
- self.assertEqual(response.status_code, 200)
- response_json = response.json()
- self.assertEqual(response_json['likes'], 1)
- self.assertEqual(response_json['is_liked'], True)
- self.assertEqual(
- response_json['last_likes'], [
- {
- 'id': self.user.id,
- 'username': self.user.username,
- },
- ]
- )
- post = Post.objects.get(pk=self.post.pk)
- self.assertEqual(post.likes, response_json['likes'])
- self.assertEqual(post.last_likes, response_json['last_likes'])
- def test_unlike_post_no_change(self):
- """api does no state change if we are unlinking unliked post"""
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-liked',
- 'value': False,
- },
- ]
- )
- self.assertEqual(response.status_code, 200)
- response_json = response.json()
- self.assertEqual(response_json['likes'], 0)
- self.assertEqual(response_json['is_liked'], False)
- self.assertEqual(response_json['last_likes'], [])
- class ThreadEventPatchApiTestCase(ThreadPostPatchApiTestCase):
- def setUp(self):
- super().setUp()
- self.event = testutils.reply_thread(self.thread, poster=self.user, is_event=True)
- self.api_link = reverse(
- 'misago:api:thread-post-detail',
- kwargs={
- 'thread_pk': self.thread.pk,
- 'pk': self.event.pk,
- }
- )
- def refresh_event(self):
- self.event = self.thread.post_set.get(pk=self.event.pk)
- class EventAnonPatchApiTests(ThreadEventPatchApiTestCase):
- def test_anonymous_user(self):
- """anonymous users can't change event state"""
- self.logout_user()
- response = self.patch(self.api_link, [
- {
- 'op': 'add',
- 'path': 'acl',
- 'value': True,
- },
- ])
- self.assertEqual(response.status_code, 403)
- class EventAddAclApiTests(ThreadEventPatchApiTestCase):
- def test_add_acl_true(self):
- """api adds current event's acl to response"""
- response = self.patch(self.api_link, [
- {
- 'op': 'add',
- 'path': 'acl',
- 'value': True,
- },
- ])
- self.assertEqual(response.status_code, 200)
- response_json = response.json()
- self.assertTrue(response_json['acl'])
- def test_add_acl_false(self):
- """if value is false, api won't add acl to the response, but will set empty key"""
- response = self.patch(self.api_link, [
- {
- 'op': 'add',
- 'path': 'acl',
- 'value': False,
- },
- ])
- self.assertEqual(response.status_code, 200)
- response_json = response.json()
- self.assertIsNone(response_json['acl'])
- response = self.patch(self.api_link, [
- {
- 'op': 'add',
- 'path': 'acl',
- 'value': True,
- },
- ])
- self.assertEqual(response.status_code, 200)
- class EventHideApiTests(ThreadEventPatchApiTestCase):
- def test_hide_event(self):
- """api makes it possible to hide event"""
- self.override_acl({'can_hide_events': 1})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-hidden',
- 'value': True,
- },
- ]
- )
- self.assertEqual(response.status_code, 200)
- self.refresh_event()
- self.assertTrue(self.event.is_hidden)
- def test_show_event(self):
- """api makes it possible to unhide event"""
- self.event.is_hidden = True
- self.event.save()
- self.refresh_event()
- self.assertTrue(self.event.is_hidden)
- self.override_acl({'can_hide_events': 1})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-hidden',
- 'value': False,
- },
- ]
- )
- self.assertEqual(response.status_code, 200)
- self.refresh_event()
- self.assertFalse(self.event.is_hidden)
- def test_hide_event_no_permission(self):
- """api hide event with no permission fails"""
- self.override_acl({'can_hide_events': 0})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-hidden',
- 'value': True,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(
- response_json['detail'][0], "You can't hide events in this category."
- )
- self.refresh_event()
- self.assertFalse(self.event.is_hidden)
- def test_hide_event_closed_thread_no_permission(self):
- """api hide event in closed thread with no permission fails"""
- self.override_acl({
- 'can_hide_events': 1,
- 'can_close_threads': 0,
- })
- self.thread.is_closed = True
- self.thread.save()
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-hidden',
- 'value': True,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(
- response_json['detail'][0], "This thread is closed. You can't hide events in it."
- )
- self.refresh_event()
- self.assertFalse(self.event.is_hidden)
- def test_hide_event_closed_category_no_permission(self):
- """api hide event in closed category with no permission fails"""
- self.override_acl({
- 'can_hide_events': 1,
- 'can_close_threads': 0,
- })
- self.category.is_closed = True
- self.category.save()
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-hidden',
- 'value': True,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(
- response_json['detail'][0], "This category is closed. You can't hide events in it."
- )
- self.refresh_event()
- self.assertFalse(self.event.is_hidden)
- def test_show_event_no_permission(self):
- """api unhide event with no permission fails"""
- self.event.is_hidden = True
- self.event.save()
- self.refresh_event()
- self.assertTrue(self.event.is_hidden)
- self.override_acl({'can_hide_events': 0})
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-hidden',
- 'value': False,
- },
- ]
- )
- self.assertEqual(response.status_code, 404)
- def test_show_event_closed_thread_no_permission(self):
- """api show event in closed thread with no permission fails"""
- self.event.is_hidden = True
- self.event.save()
- self.override_acl({
- 'can_hide_events': 1,
- 'can_close_threads': 0,
- })
- self.thread.is_closed = True
- self.thread.save()
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-hidden',
- 'value': False,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(
- response_json['detail'][0], "This thread is closed. You can't reveal events in it."
- )
- self.refresh_event()
- self.assertTrue(self.event.is_hidden)
- def test_show_event_closed_category_no_permission(self):
- """api show event in closed category with no permission fails"""
- self.event.is_hidden = True
- self.event.save()
- self.override_acl({
- 'can_hide_events': 1,
- 'can_close_threads': 0,
- })
- self.category.is_closed = True
- self.category.save()
- response = self.patch(
- self.api_link, [
- {
- 'op': 'replace',
- 'path': 'is-hidden',
- 'value': False,
- },
- ]
- )
- self.assertEqual(response.status_code, 400)
- response_json = response.json()
- self.assertEqual(
- response_json['detail'][0], "This category is closed. You can't reveal events in it."
- )
- self.refresh_event()
- self.assertTrue(self.event.is_hidden)
|