test_thread_postmerge_api.py 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426
  1. # -*- coding: utf-8 -*-
  2. from __future__ import unicode_literals
  3. import json
  4. from django.urls import reverse
  5. from misago.acl.testutils import override_acl
  6. from misago.categories.models import Category
  7. from misago.threads import testutils
  8. from misago.threads.models import Post, Thread
  9. from misago.threads.serializers.moderation import POSTS_MERGE_LIMIT
  10. from misago.users.testutils import AuthenticatedUserTestCase
  11. class ThreadPostMergeApiTestCase(AuthenticatedUserTestCase):
  12. def setUp(self):
  13. super(ThreadPostMergeApiTestCase, self).setUp()
  14. self.category = Category.objects.get(slug='first-category')
  15. self.thread = testutils.post_thread(category=self.category)
  16. self.post = testutils.reply_thread(self.thread, poster=self.user)
  17. self.api_link = reverse(
  18. 'misago:api:thread-post-merge', kwargs={
  19. 'thread_pk': self.thread.pk,
  20. }
  21. )
  22. self.override_acl()
  23. def refresh_thread(self):
  24. self.thread = Thread.objects.get(pk=self.thread.pk)
  25. def override_acl(self, extra_acl=None):
  26. new_acl = self.user.acl_cache
  27. new_acl['categories'][self.category.pk].update({
  28. 'can_see': 1,
  29. 'can_browse': 1,
  30. 'can_start_threads': 0,
  31. 'can_reply_threads': 0,
  32. 'can_edit_posts': 1,
  33. 'can_approve_content': 0,
  34. 'can_merge_posts': 1,
  35. })
  36. if extra_acl:
  37. new_acl['categories'][self.category.pk].update(extra_acl)
  38. override_acl(self.user, new_acl)
  39. def test_anonymous_user(self):
  40. """you need to authenticate to merge posts"""
  41. self.logout_user()
  42. response = self.client.post(
  43. self.api_link,
  44. json.dumps({}),
  45. content_type="application/json",
  46. )
  47. self.assertEqual(response.status_code, 403)
  48. def test_no_permission(self):
  49. """api validates permission to merge"""
  50. self.override_acl({'can_merge_posts': 0})
  51. response = self.client.post(
  52. self.api_link,
  53. json.dumps({}),
  54. content_type="application/json",
  55. )
  56. self.assertContains(response, "You can't merge posts in this thread.", status_code=403)
  57. def test_empty_data(self):
  58. """api handles empty data"""
  59. response = self.client.post(
  60. self.api_link, json.dumps({}), content_type="application/json"
  61. )
  62. self.assertContains(
  63. response, "You have to select at least two posts to merge.", status_code=400
  64. )
  65. def test_invalid_data(self):
  66. """api handles post that is invalid type"""
  67. self.override_acl()
  68. response = self.client.post(self.api_link, '[]', content_type="application/json")
  69. self.assertContains(response, "Invalid data. Expected a dictionary", status_code=400)
  70. self.override_acl()
  71. response = self.client.post(self.api_link, '123', content_type="application/json")
  72. self.assertContains(response, "Invalid data. Expected a dictionary", status_code=400)
  73. self.override_acl()
  74. response = self.client.post(self.api_link, '"string"', content_type="application/json")
  75. self.assertContains(response, "Invalid data. Expected a dictionary", status_code=400)
  76. self.override_acl()
  77. response = self.client.post(self.api_link, 'malformed', content_type="application/json")
  78. self.assertContains(response, "JSON parse error", status_code=400)
  79. def test_no_posts_ids(self):
  80. """api rejects no posts ids"""
  81. response = self.client.post(
  82. self.api_link,
  83. json.dumps({
  84. 'posts': []
  85. }),
  86. content_type="application/json",
  87. )
  88. self.assertContains(
  89. response, "You have to select at least two posts to merge.", status_code=400
  90. )
  91. def test_invalid_posts_data(self):
  92. """api handles invalid data"""
  93. response = self.client.post(
  94. self.api_link,
  95. json.dumps({
  96. 'posts': 'string'
  97. }),
  98. content_type="application/json",
  99. )
  100. self.assertContains(
  101. response, "Expected a list of items but got type", status_code=400
  102. )
  103. def test_invalid_posts_ids(self):
  104. """api handles invalid post id"""
  105. response = self.client.post(
  106. self.api_link,
  107. json.dumps({
  108. 'posts': [1, 2, 'string']
  109. }),
  110. content_type="application/json",
  111. )
  112. self.assertContains(
  113. response, "One or more post ids received were invalid.", status_code=400
  114. )
  115. def test_one_post_id(self):
  116. """api rejects one post id"""
  117. response = self.client.post(
  118. self.api_link,
  119. json.dumps({
  120. 'posts': [1]
  121. }),
  122. content_type="application/json",
  123. )
  124. self.assertContains(
  125. response, "You have to select at least two posts to merge.", status_code=400
  126. )
  127. def test_merge_limit(self):
  128. """api rejects more posts than merge limit"""
  129. response = self.client.post(
  130. self.api_link,
  131. json.dumps({
  132. 'posts': list(range(POSTS_MERGE_LIMIT + 1))
  133. }),
  134. content_type="application/json",
  135. )
  136. self.assertContains(
  137. response, "No more than {} posts can be merged".format(POSTS_MERGE_LIMIT), status_code=400
  138. )
  139. def test_merge_event(self):
  140. """api recjects events"""
  141. event = testutils.reply_thread(self.thread, is_event=True, poster=self.user)
  142. response = self.client.post(
  143. self.api_link,
  144. json.dumps({
  145. 'posts': [self.post.pk, event.pk]
  146. }),
  147. content_type="application/json",
  148. )
  149. self.assertContains(response, "Events can't be merged.", status_code=400)
  150. def test_merge_notfound_pk(self):
  151. """api recjects nonexistant pk's"""
  152. response = self.client.post(
  153. self.api_link,
  154. json.dumps({
  155. 'posts': [self.post.pk, self.post.pk * 1000]
  156. }),
  157. content_type="application/json",
  158. )
  159. self.assertContains(
  160. response, "One or more posts to merge could not be found.", status_code=400
  161. )
  162. def test_merge_cross_threads(self):
  163. """api recjects attempt to merge with post made in other thread"""
  164. other_thread = testutils.post_thread(category=self.category)
  165. other_post = testutils.reply_thread(other_thread, poster=self.user)
  166. response = self.client.post(
  167. self.api_link,
  168. json.dumps({
  169. 'posts': [self.post.pk, other_post.pk]
  170. }),
  171. content_type="application/json",
  172. )
  173. self.assertContains(
  174. response, "One or more posts to merge could not be found.", status_code=400
  175. )
  176. def test_merge_authenticated_with_guest_post(self):
  177. """api recjects attempt to merge with post made by deleted user"""
  178. other_post = testutils.reply_thread(self.thread)
  179. response = self.client.post(
  180. self.api_link,
  181. json.dumps({
  182. 'posts': [self.post.pk, other_post.pk]
  183. }),
  184. content_type="application/json",
  185. )
  186. self.assertContains(
  187. response, "Posts made by different users can't be merged.", status_code=400
  188. )
  189. def test_merge_guest_with_authenticated_post(self):
  190. """api recjects attempt to merge with post made by deleted user"""
  191. other_post = testutils.reply_thread(self.thread)
  192. response = self.client.post(
  193. self.api_link,
  194. json.dumps({
  195. 'posts': [other_post.pk, self.post.pk]
  196. }),
  197. content_type="application/json",
  198. )
  199. self.assertContains(
  200. response, "Posts made by different users can't be merged.", status_code=400
  201. )
  202. def test_merge_guest_posts_different_usernames(self):
  203. """api recjects attempt to merge posts made by different guests"""
  204. response = self.client.post(
  205. self.api_link,
  206. json.dumps({
  207. 'posts': [
  208. testutils.reply_thread(self.thread, poster="Bob").pk,
  209. testutils.reply_thread(self.thread, poster="Miku").pk,
  210. ]
  211. }),
  212. content_type="application/json",
  213. )
  214. self.assertContains(
  215. response, "Posts made by different users can't be merged.", status_code=400
  216. )
  217. def test_merge_different_visibility(self):
  218. """api recjects attempt to merge posts with different visibility"""
  219. self.override_acl({'can_hide_posts': 1})
  220. response = self.client.post(
  221. self.api_link,
  222. json.dumps({
  223. 'posts': [
  224. testutils.reply_thread(self.thread, poster="Bob", is_hidden=True).pk,
  225. testutils.reply_thread(self.thread, poster="Bob", is_hidden=False).pk,
  226. ]
  227. }),
  228. content_type="application/json",
  229. )
  230. self.assertContains(
  231. response, "Posts with different visibility can't be merged.", status_code=400
  232. )
  233. def test_merge_different_approval(self):
  234. """api recjects attempt to merge posts with different approval"""
  235. self.override_acl({'can_approve_content': 1})
  236. response = self.client.post(
  237. self.api_link,
  238. json.dumps({
  239. 'posts': [
  240. testutils.reply_thread(self.thread, poster="Bob", is_unapproved=True).pk,
  241. testutils.reply_thread(self.thread, poster="Bob", is_unapproved=False).pk,
  242. ]
  243. }),
  244. content_type="application/json",
  245. )
  246. self.assertContains(
  247. response, "Posts with different visibility can't be merged.", status_code=400
  248. )
  249. def test_closed_thread(self):
  250. """api validates permission to merge in closed thread"""
  251. self.thread.is_closed = True
  252. self.thread.save()
  253. posts = [
  254. testutils.reply_thread(self.thread, poster=self.user).pk,
  255. testutils.reply_thread(self.thread, poster=self.user).pk,
  256. ]
  257. response = self.client.post(
  258. self.api_link,
  259. json.dumps({'posts': posts}),
  260. content_type="application/json",
  261. )
  262. self.assertContains(
  263. response,
  264. "This thread is closed. You can't merge posts in it.",
  265. status_code=400,
  266. )
  267. # allow closing threads
  268. self.override_acl({'can_close_threads': 1})
  269. response = self.client.post(
  270. self.api_link,
  271. json.dumps({'posts': posts}),
  272. content_type="application/json",
  273. )
  274. self.assertEqual(response.status_code, 200)
  275. def test_closed_category(self):
  276. """api validates permission to merge in closed category"""
  277. self.category.is_closed = True
  278. self.category.save()
  279. posts = [
  280. testutils.reply_thread(self.thread, poster=self.user).pk,
  281. testutils.reply_thread(self.thread, poster=self.user).pk,
  282. ]
  283. response = self.client.post(
  284. self.api_link,
  285. json.dumps({'posts': posts}),
  286. content_type="application/json",
  287. )
  288. self.assertContains(
  289. response,
  290. "This category is closed. You can't merge posts in it.",
  291. status_code=400,
  292. )
  293. # allow closing threads
  294. self.override_acl({'can_close_threads': 1})
  295. response = self.client.post(
  296. self.api_link,
  297. json.dumps({'posts': posts}),
  298. content_type="application/json",
  299. )
  300. self.assertEqual(response.status_code, 200)
  301. def test_merge_posts(self):
  302. """api merges two posts"""
  303. post_a = testutils.reply_thread(self.thread, poster=self.user, message="Battęry")
  304. post_b = testutils.reply_thread(self.thread, poster=self.user, message="Hórse")
  305. thread_replies = self.thread.replies
  306. response = self.client.post(
  307. self.api_link,
  308. json.dumps({
  309. 'posts': [post_a.pk, post_b.pk]
  310. }),
  311. content_type="application/json",
  312. )
  313. self.assertEqual(response.status_code, 200)
  314. self.refresh_thread()
  315. self.assertEqual(self.thread.replies, thread_replies - 1)
  316. with self.assertRaises(Post.DoesNotExist):
  317. Post.objects.get(pk=post_b.pk)
  318. merged_post = Post.objects.get(pk=post_a.pk)
  319. self.assertEqual(merged_post.parsed, '{}\n{}'.format(post_a.parsed, post_b.parsed))
  320. def test_merge_hidden_posts(self):
  321. """api merges two hidden posts"""
  322. self.override_acl({'can_hide_posts': 1})
  323. response = self.client.post(
  324. self.api_link,
  325. json.dumps({
  326. 'posts': [
  327. testutils.reply_thread(self.thread, poster=self.user, is_hidden=True).pk,
  328. testutils.reply_thread(self.thread, poster=self.user, is_hidden=True).pk,
  329. ]
  330. }),
  331. content_type="application/json",
  332. )
  333. self.assertEqual(response.status_code, 200)
  334. def test_merge_unapproved_posts(self):
  335. """api merges two unapproved posts"""
  336. self.override_acl({'can_approve_content': 1})
  337. response = self.client.post(
  338. self.api_link,
  339. json.dumps({
  340. 'posts': [
  341. testutils.reply_thread(self.thread, poster=self.user, is_unapproved=True).pk,
  342. testutils.reply_thread(self.thread, poster=self.user, is_unapproved=True).pk,
  343. ]
  344. }),
  345. content_type="application/json",
  346. )
  347. self.assertEqual(response.status_code, 200)
  348. def test_merge_with_hidden_thread(self):
  349. """api recjects attempt to merge posts with different visibility"""
  350. self.thread.first_post.is_hidden = True
  351. self.thread.first_post.poster = self.user
  352. self.thread.first_post.save()
  353. post_visible = testutils.reply_thread(self.thread, poster=self.user, is_hidden=False)
  354. self.override_acl({'can_hide_threads': 1})
  355. response = self.client.post(
  356. self.api_link,
  357. json.dumps({
  358. 'posts': [self.thread.first_post.pk, post_visible.pk]
  359. }),
  360. content_type="application/json",
  361. )
  362. self.assertEqual(response.status_code, 200)