test_threads_editor_api.py 20 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635
  1. import json
  2. from django.core.urlresolvers import reverse
  3. from django.utils.encoding import smart_str
  4. from misago.acl.testutils import override_acl
  5. from misago.categories.models import Category
  6. from misago.users.testutils import AuthenticatedUserTestCase
  7. from .. import testutils
  8. class EditorApiTestCase(AuthenticatedUserTestCase):
  9. def setUp(self):
  10. super(EditorApiTestCase, self).setUp()
  11. self.category = Category.objects.get(slug='first-category')
  12. def override_acl(self, acl=None):
  13. final_acl = self.user.acl['categories'][self.category.pk]
  14. final_acl.update({
  15. 'can_see': 1,
  16. 'can_browse': 1,
  17. 'can_see_all_threads': 1,
  18. 'can_start_threads': 0,
  19. 'can_reply_threads': 0,
  20. 'can_edit_threads': 0,
  21. 'can_edit_posts': 0,
  22. 'can_hide_own_threads': 0,
  23. 'can_hide_own_posts': 0,
  24. 'thread_edit_time': 0,
  25. 'post_edit_time': 0,
  26. 'can_hide_threads': 0,
  27. 'can_hide_posts': 0,
  28. 'can_protect_posts': 0,
  29. 'can_move_posts': 0,
  30. 'can_merge_posts': 0,
  31. 'can_pin_threads': 0,
  32. 'can_close_threads': 0,
  33. 'can_move_threads': 0,
  34. 'can_merge_threads': 0,
  35. 'can_approve_content': 0,
  36. 'can_report_content': 0,
  37. 'can_see_reports': 0,
  38. 'can_see_posts_likes': 0,
  39. 'can_like_posts': 0,
  40. 'can_hide_events': 0,
  41. })
  42. if acl:
  43. final_acl.update(acl)
  44. browseable_categories = []
  45. if final_acl['can_browse']:
  46. browseable_categories.append(self.category.pk)
  47. override_acl(self.user, {
  48. 'browseable_categories': browseable_categories,
  49. 'categories': {
  50. self.category.pk: final_acl
  51. }
  52. })
  53. class ThreadPostEditorApiTests(EditorApiTestCase):
  54. def setUp(self):
  55. super(ThreadPostEditorApiTests, self).setUp()
  56. self.api_link = reverse('misago:api:thread-editor')
  57. def test_anonymous_user_request(self):
  58. """endpoint validates if user is authenticated"""
  59. self.logout_user()
  60. response = self.client.get(self.api_link)
  61. self.assertContains(response, "You need to be signed in", status_code=403)
  62. def test_category_visibility_validation(self):
  63. """endpoint omits non-browseable categories"""
  64. self.override_acl({'can_browse': 0})
  65. response = self.client.get(self.api_link)
  66. self.assertContains(response, "No categories that allow new threads", status_code=403)
  67. def test_category_disallowing_new_threads(self):
  68. """endpoint omits category disallowing starting threads"""
  69. self.override_acl({
  70. 'can_start_threads': 0,
  71. })
  72. response = self.client.get(self.api_link)
  73. self.assertContains(response, "No categories that allow new threads", status_code=403)
  74. def test_category_closed_disallowing_new_threads(self):
  75. """endpoint omits closed category"""
  76. self.override_acl({
  77. 'can_start_threads': 2,
  78. 'can_close_threads': 0,
  79. })
  80. self.category.is_closed = True
  81. self.category.save()
  82. response = self.client.get(self.api_link)
  83. self.assertContains(response, "No categories that allow new threads", status_code=403)
  84. def test_category_closed_allowing_new_threads(self):
  85. """endpoint adds closed category that allows new threads"""
  86. self.override_acl({
  87. 'can_start_threads': 2,
  88. 'can_close_threads': 1,
  89. })
  90. self.category.is_closed = True
  91. self.category.save()
  92. response = self.client.get(self.api_link)
  93. self.assertEqual(response.status_code, 200)
  94. response_json = json.loads(smart_str(response.content))
  95. self.assertEqual(response_json[0], {
  96. 'id': self.category.pk,
  97. 'name': self.category.name,
  98. 'level': 0,
  99. 'post': {
  100. 'close': True,
  101. 'hide': False,
  102. 'pin': 0
  103. }
  104. })
  105. def test_category_allowing_new_threads(self):
  106. """endpoint adds category that allows new threads"""
  107. self.override_acl({
  108. 'can_start_threads': 2,
  109. })
  110. response = self.client.get(self.api_link)
  111. self.assertEqual(response.status_code, 200)
  112. response_json = json.loads(smart_str(response.content))
  113. self.assertEqual(response_json[0], {
  114. 'id': self.category.pk,
  115. 'name': self.category.name,
  116. 'level': 0,
  117. 'post': {
  118. 'close': False,
  119. 'hide': False,
  120. 'pin': 0
  121. }
  122. })
  123. def test_category_allowing_closing_threads(self):
  124. """endpoint adds category that allows new closed threads"""
  125. self.override_acl({
  126. 'can_start_threads': 2,
  127. 'can_close_threads': 1,
  128. })
  129. response = self.client.get(self.api_link)
  130. self.assertEqual(response.status_code, 200)
  131. response_json = json.loads(smart_str(response.content))
  132. self.assertEqual(response_json[0], {
  133. 'id': self.category.pk,
  134. 'name': self.category.name,
  135. 'level': 0,
  136. 'post': {
  137. 'close': True,
  138. 'hide': False,
  139. 'pin': 0
  140. }
  141. })
  142. def test_category_allowing_locally_pinned_threads(self):
  143. """endpoint adds category that allows locally pinned threads"""
  144. self.override_acl({
  145. 'can_start_threads': 2,
  146. 'can_pin_threads': 1,
  147. })
  148. response = self.client.get(self.api_link)
  149. self.assertEqual(response.status_code, 200)
  150. response_json = json.loads(smart_str(response.content))
  151. self.assertEqual(response_json[0], {
  152. 'id': self.category.pk,
  153. 'name': self.category.name,
  154. 'level': 0,
  155. 'post': {
  156. 'close': False,
  157. 'hide': False,
  158. 'pin': 1
  159. }
  160. })
  161. def test_category_allowing_globally_pinned_threads(self):
  162. """endpoint adds category that allows globally pinned threads"""
  163. self.override_acl({
  164. 'can_start_threads': 2,
  165. 'can_pin_threads': 2,
  166. })
  167. response = self.client.get(self.api_link)
  168. self.assertEqual(response.status_code, 200)
  169. response_json = json.loads(smart_str(response.content))
  170. self.assertEqual(response_json[0], {
  171. 'id': self.category.pk,
  172. 'name': self.category.name,
  173. 'level': 0,
  174. 'post': {
  175. 'close': False,
  176. 'hide': False,
  177. 'pin': 2
  178. }
  179. })
  180. def test_category_allowing_hidden_threads(self):
  181. """endpoint adds category that allows globally pinned threads"""
  182. self.override_acl({
  183. 'can_start_threads': 2,
  184. 'can_hide_threads': 1,
  185. })
  186. response = self.client.get(self.api_link)
  187. self.assertEqual(response.status_code, 200)
  188. response_json = json.loads(smart_str(response.content))
  189. self.assertEqual(response_json[0], {
  190. 'id': self.category.pk,
  191. 'name': self.category.name,
  192. 'level': 0,
  193. 'post': {
  194. 'close': 0,
  195. 'hide': 1,
  196. 'pin': 0
  197. }
  198. })
  199. self.override_acl({
  200. 'can_start_threads': 2,
  201. 'can_hide_threads': 2,
  202. })
  203. response = self.client.get(self.api_link)
  204. self.assertEqual(response.status_code, 200)
  205. response_json = json.loads(smart_str(response.content))
  206. self.assertEqual(response_json[0], {
  207. 'id': self.category.pk,
  208. 'name': self.category.name,
  209. 'level': 0,
  210. 'post': {
  211. 'close': False,
  212. 'hide': True,
  213. 'pin': 0
  214. }
  215. })
  216. class ThreadReplyEditorApiTests(EditorApiTestCase):
  217. def setUp(self):
  218. super(ThreadReplyEditorApiTests, self).setUp()
  219. self.thread = testutils.post_thread(category=self.category)
  220. self.api_link = reverse('misago:api:thread-post-editor', kwargs={
  221. 'thread_pk': self.thread.pk
  222. })
  223. def test_anonymous_user_request(self):
  224. """endpoint validates if user is authenticated"""
  225. self.logout_user()
  226. response = self.client.get(self.api_link)
  227. self.assertContains(response, "You have to sign in to reply threads.", status_code=403)
  228. def test_thread_visibility(self):
  229. """thread's visibility is validated"""
  230. self.override_acl({'can_see': 0})
  231. response = self.client.get(self.api_link)
  232. self.assertEqual(response.status_code, 404)
  233. self.override_acl({'can_browse': 0})
  234. response = self.client.get(self.api_link)
  235. self.assertEqual(response.status_code, 404)
  236. self.override_acl({'can_see_all_threads': 0})
  237. response = self.client.get(self.api_link)
  238. self.assertEqual(response.status_code, 404)
  239. def test_no_reply_permission(self):
  240. """permssion to reply is validated"""
  241. self.override_acl({
  242. 'can_reply_threads': 0
  243. })
  244. response = self.client.get(self.api_link)
  245. self.assertContains(response, "You can't reply to threads in this category.", status_code=403)
  246. def test_closed_category(self):
  247. """permssion to reply in closed category is validated"""
  248. self.override_acl({
  249. 'can_reply_threads': 1,
  250. 'can_close_threads': 0
  251. })
  252. self.category.is_closed = True
  253. self.category.save()
  254. response = self.client.get(self.api_link)
  255. self.assertContains(response, "This category is closed. You can't reply to threads in it.", status_code=403)
  256. # allow to post in closed category
  257. self.override_acl({
  258. 'can_reply_threads': 1,
  259. 'can_close_threads': 1
  260. })
  261. response = self.client.get(self.api_link)
  262. self.assertEqual(response.status_code, 200)
  263. def test_closed_thread(self):
  264. """permssion to reply in closed thread is validated"""
  265. self.override_acl({
  266. 'can_reply_threads': 1,
  267. 'can_close_threads': 0
  268. })
  269. self.thread.is_closed = True
  270. self.thread.save()
  271. response = self.client.get(self.api_link)
  272. self.assertContains(response, "You can't reply to closed threads in this category.", status_code=403)
  273. # allow to post in closed thread
  274. self.override_acl({
  275. 'can_reply_threads': 1,
  276. 'can_close_threads': 1
  277. })
  278. response = self.client.get(self.api_link)
  279. self.assertEqual(response.status_code, 200)
  280. def test_allow_reply_thread(self):
  281. """api returns 200 code if thread reply is allowed"""
  282. self.override_acl({
  283. 'can_reply_threads': 1
  284. })
  285. response = self.client.get(self.api_link)
  286. self.assertEqual(response.status_code, 200)
  287. def test_reply_to_visibility(self):
  288. """api validates replied post visibility"""
  289. self.override_acl({
  290. 'can_reply_threads': 1
  291. })
  292. # unapproved reply can't be replied to
  293. unapproved_reply = testutils.reply_thread(self.thread, is_unapproved=True)
  294. response = self.client.get('{}?reply={}'.format(self.api_link, unapproved_reply.pk))
  295. self.assertEqual(response.status_code, 404)
  296. # hidden reply can't be replied to
  297. self.override_acl({
  298. 'can_reply_threads': 1
  299. })
  300. hidden_reply = testutils.reply_thread(self.thread, is_hidden=True)
  301. response = self.client.get('{}?reply={}'.format(self.api_link, hidden_reply.pk))
  302. self.assertContains(response, "You can't reply to hidden posts", status_code=403)
  303. def test_reply_to_other_thread_post(self):
  304. """api validates is replied post belongs to same thread"""
  305. other_thread = testutils.post_thread(category=self.category)
  306. reply_to = testutils.reply_thread(other_thread)
  307. response = self.client.get('{}?reply={}'.format(self.api_link, reply_to.pk))
  308. self.assertEqual(response.status_code, 404)
  309. def test_reply_to_event(self):
  310. """events can't be edited"""
  311. self.override_acl({
  312. 'can_reply_threads': 1
  313. })
  314. reply_to = testutils.reply_thread(self.thread, is_event=True)
  315. response = self.client.get('{}?reply={}'.format(self.api_link, reply_to.pk))
  316. self.assertContains(response, "You can't reply to events.", status_code=403)
  317. def test_reply_to(self):
  318. """api includes replied to post details in response"""
  319. self.override_acl({
  320. 'can_reply_threads': 1
  321. })
  322. reply_to = testutils.reply_thread(self.thread)
  323. response = self.client.get('{}?reply={}'.format(self.api_link, reply_to.pk))
  324. self.assertEqual(response.status_code, 200)
  325. self.assertEqual(json.loads(smart_str(response.content)), {
  326. 'id': reply_to.pk,
  327. 'post': reply_to.original,
  328. 'poster': reply_to.poster_name
  329. })
  330. class EditReplyEditorApiTests(EditorApiTestCase):
  331. def setUp(self):
  332. super(EditReplyEditorApiTests, self).setUp()
  333. self.thread = testutils.post_thread(category=self.category)
  334. self.post = testutils.reply_thread(self.thread, poster=self.user)
  335. self.api_link = reverse('misago:api:thread-post-editor', kwargs={
  336. 'thread_pk': self.thread.pk,
  337. 'pk': self.post.pk
  338. })
  339. def test_anonymous_user_request(self):
  340. """endpoint validates if user is authenticated"""
  341. self.logout_user()
  342. response = self.client.get(self.api_link)
  343. self.assertContains(response, "You have to sign in to edit posts.", status_code=403)
  344. def test_thread_visibility(self):
  345. """thread's visibility is validated"""
  346. self.override_acl({'can_see': 0})
  347. response = self.client.get(self.api_link)
  348. self.assertEqual(response.status_code, 404)
  349. self.override_acl({'can_browse': 0})
  350. response = self.client.get(self.api_link)
  351. self.assertEqual(response.status_code, 404)
  352. self.override_acl({'can_see_all_threads': 0})
  353. response = self.client.get(self.api_link)
  354. self.assertEqual(response.status_code, 404)
  355. def test_no_edit_permission(self):
  356. """permssion to edit is validated"""
  357. self.override_acl({
  358. 'can_edit_posts': 0
  359. })
  360. response = self.client.get(self.api_link)
  361. self.assertContains(response, "You can't edit posts in this category.", status_code=403)
  362. def test_closed_category(self):
  363. """permssion to edit in closed category is validated"""
  364. self.override_acl({
  365. 'can_edit_posts': 1,
  366. 'can_close_threads': 0
  367. })
  368. self.category.is_closed = True
  369. self.category.save()
  370. response = self.client.get(self.api_link)
  371. self.assertContains(response, "This category is closed. You can't edit posts in it.", status_code=403)
  372. # allow to edit in closed category
  373. self.override_acl({
  374. 'can_edit_posts': 1,
  375. 'can_close_threads': 1
  376. })
  377. response = self.client.get(self.api_link)
  378. self.assertEqual(response.status_code, 200)
  379. def test_closed_thread(self):
  380. """permssion to edit in closed thread is validated"""
  381. self.override_acl({
  382. 'can_edit_posts': 1,
  383. 'can_close_threads': 0
  384. })
  385. self.thread.is_closed = True
  386. self.thread.save()
  387. response = self.client.get(self.api_link)
  388. self.assertContains(response, "This thread is closed. You can't edit posts in it.", status_code=403)
  389. # allow to edit in closed thread
  390. self.override_acl({
  391. 'can_edit_posts': 1,
  392. 'can_close_threads': 1
  393. })
  394. response = self.client.get(self.api_link)
  395. self.assertEqual(response.status_code, 200)
  396. def test_protected_post(self):
  397. """permssion to edit protected post is validated"""
  398. self.override_acl({
  399. 'can_edit_posts': 1,
  400. 'can_protect_posts': 0
  401. })
  402. self.post.is_protected = True
  403. self.post.save()
  404. response = self.client.get(self.api_link)
  405. self.assertContains(response, "This post is protected. You can't edit it.", status_code=403)
  406. # allow to post in closed thread
  407. self.override_acl({
  408. 'can_edit_posts': 1,
  409. 'can_protect_posts': 1
  410. })
  411. response = self.client.get(self.api_link)
  412. self.assertEqual(response.status_code, 200)
  413. def test_post_visibility(self):
  414. """edited posts visibility is validated"""
  415. self.override_acl({
  416. 'can_edit_posts': 1
  417. })
  418. self.post.is_hidden = True;
  419. self.post.save()
  420. response = self.client.get(self.api_link)
  421. self.assertContains(response, "This post is hidden, you can't edit it.", status_code=403)
  422. # allow hidden edition
  423. self.override_acl({
  424. 'can_edit_posts': 1,
  425. 'can_hide_posts': 1
  426. })
  427. response = self.client.get(self.api_link)
  428. self.assertEqual(response.status_code, 200)
  429. # test unapproved post
  430. self.post.is_hidden = False;
  431. self.post.poster = None;
  432. self.post.save()
  433. self.override_acl({
  434. 'can_edit_posts': 2,
  435. 'can_approve_content': 0
  436. })
  437. self.post.is_unapproved = True;
  438. self.post.save()
  439. response = self.client.get(self.api_link)
  440. self.assertEqual(response.status_code, 404)
  441. # allow unapproved edition
  442. self.override_acl({
  443. 'can_edit_posts': 2,
  444. 'can_approve_content': 1
  445. })
  446. response = self.client.get(self.api_link)
  447. self.assertEqual(response.status_code, 200)
  448. def test_post_is_event(self):
  449. """events can't be edited"""
  450. self.override_acl()
  451. self.post.is_event = True
  452. self.post.save()
  453. response = self.client.get(self.api_link)
  454. self.assertContains(response, "Events can't be edited.", status_code=403)
  455. def test_other_user_post(self):
  456. """api validates if other user's post can be edited"""
  457. self.override_acl({
  458. 'can_edit_posts': 1,
  459. })
  460. self.post.poster = None;
  461. self.post.save()
  462. response = self.client.get(self.api_link)
  463. self.assertContains(response, "You can't edit other users posts in this category.", status_code=403)
  464. # allow other users post edition
  465. self.override_acl({
  466. 'can_edit_posts': 2,
  467. })
  468. response = self.client.get(self.api_link)
  469. self.assertEqual(response.status_code, 200)
  470. def test_edit_first_post_hidden(self):
  471. """endpoint returns valid configuration for editor of hidden thread's first post"""
  472. self.override_acl({
  473. 'can_hide_threads': 1,
  474. 'can_edit_posts': 2
  475. })
  476. self.thread.is_hidden = True
  477. self.thread.save()
  478. self.thread.first_post.is_hidden = True
  479. self.thread.first_post.save()
  480. api_link = reverse('misago:api:thread-post-editor', kwargs={
  481. 'thread_pk': self.thread.pk,
  482. 'pk': self.thread.first_post.pk
  483. })
  484. response = self.client.get(api_link)
  485. self.assertEqual(response.status_code, 200)
  486. def test_edit(self):
  487. """endpoint returns valid configuration for editor"""
  488. self.override_acl({
  489. 'can_edit_posts': 1,
  490. })
  491. response = self.client.get(self.api_link)
  492. self.assertEqual(response.status_code, 200)
  493. self.assertEqual(json.loads(smart_str(response.content)), {
  494. 'id': self.post.pk,
  495. 'api': self.post.get_api_url(),
  496. 'post': self.post.original,
  497. 'can_protect': False,
  498. 'is_protected': self.post.is_protected,
  499. 'poster': self.post.poster_name
  500. })