test_thread_postpatch_api.py 27 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863
  1. # -*- coding: utf-8 -*-
  2. from __future__ import unicode_literals
  3. import json
  4. from datetime import timedelta
  5. from django.core.urlresolvers import reverse
  6. from django.utils import timezone
  7. from misago.acl.testutils import override_acl
  8. from misago.categories.models import Category
  9. from misago.users.testutils import AuthenticatedUserTestCase
  10. from .. import testutils
  11. from ..models import Post, Thread
  12. class ThreadPostPatchApiTestCase(AuthenticatedUserTestCase):
  13. def setUp(self):
  14. super(ThreadPostPatchApiTestCase, self).setUp()
  15. self.category = Category.objects.get(slug='first-category')
  16. self.thread = testutils.post_thread(category=self.category)
  17. self.post = testutils.reply_thread(self.thread, poster=self.user)
  18. self.api_link = reverse('misago:api:thread-post-detail', kwargs={
  19. 'thread_pk': self.thread.pk,
  20. 'pk': self.post.pk
  21. })
  22. def patch(self, api_link, ops):
  23. return self.client.patch(api_link, json.dumps(ops), content_type="application/json")
  24. def refresh_post(self):
  25. self.post = self.thread.post_set.get(pk=self.post.pk)
  26. def override_acl(self, extra_acl=None):
  27. new_acl = self.user.acl
  28. new_acl['categories'][self.category.pk].update({
  29. 'can_see': 1,
  30. 'can_browse': 1,
  31. 'can_start_threads': 0,
  32. 'can_reply_threads': 0,
  33. 'can_edit_posts': 1
  34. })
  35. if extra_acl:
  36. new_acl['categories'][self.category.pk].update(extra_acl)
  37. override_acl(self.user, new_acl)
  38. class PostAddAclApiTests(ThreadPostPatchApiTestCase):
  39. def test_add_acl_true(self):
  40. """api adds current event's acl to response"""
  41. response = self.patch(self.api_link, [
  42. {'op': 'add', 'path': 'acl', 'value': True}
  43. ])
  44. self.assertEqual(response.status_code, 200)
  45. response_json = response.json()
  46. self.assertTrue(response_json['acl'])
  47. def test_add_acl_false(self):
  48. """if value is false, api won't add acl to the response, but will set empty key"""
  49. response = self.patch(self.api_link, [
  50. {'op': 'add', 'path': 'acl', 'value': False}
  51. ])
  52. self.assertEqual(response.status_code, 200)
  53. response_json = response.json()
  54. self.assertIsNone(response_json['acl'])
  55. response = self.patch(self.api_link, [
  56. {'op': 'add', 'path': 'acl', 'value': True}
  57. ])
  58. self.assertEqual(response.status_code, 200)
  59. class PostProtectApiTests(ThreadPostPatchApiTestCase):
  60. def test_protect_post(self):
  61. """api makes it possible to protect post"""
  62. self.override_acl({
  63. 'can_protect_posts': 1
  64. })
  65. response = self.patch(self.api_link, [
  66. {'op': 'replace', 'path': 'is-protected', 'value': True}
  67. ])
  68. self.assertEqual(response.status_code, 200)
  69. self.refresh_post()
  70. self.assertTrue(self.post.is_protected)
  71. def test_unprotect_post(self):
  72. """api makes it possible to unprotect protected post"""
  73. self.post.is_protected = True
  74. self.post.save()
  75. self.override_acl({
  76. 'can_protect_posts': 1
  77. })
  78. response = self.patch(self.api_link, [
  79. {'op': 'replace', 'path': 'is-protected', 'value': False}
  80. ])
  81. self.assertEqual(response.status_code, 200)
  82. self.refresh_post()
  83. self.assertFalse(self.post.is_protected)
  84. def test_protect_post_no_permission(self):
  85. """api validates permission to protect post"""
  86. self.override_acl({
  87. 'can_protect_posts': 0
  88. })
  89. response = self.patch(self.api_link, [
  90. {'op': 'replace', 'path': 'is-protected', 'value': True}
  91. ])
  92. self.assertEqual(response.status_code, 400)
  93. response_json = response.json()
  94. self.assertEqual(response_json['detail'][0], "You can't protect posts in this category.")
  95. self.refresh_post()
  96. self.assertFalse(self.post.is_protected)
  97. def test_unprotect_post_no_permission(self):
  98. """api validates permission to unprotect post"""
  99. self.post.is_protected = True
  100. self.post.save()
  101. self.override_acl({
  102. 'can_protect_posts': 0
  103. })
  104. response = self.patch(self.api_link, [
  105. {'op': 'replace', 'path': 'is-protected', 'value': False}
  106. ])
  107. self.assertEqual(response.status_code, 400)
  108. response_json = response.json()
  109. self.assertEqual(response_json['detail'][0], "You can't protect posts in this category.")
  110. self.refresh_post()
  111. self.assertTrue(self.post.is_protected)
  112. def test_unprotect_post_not_editable(self):
  113. """api validates if we can edit post we want to protect"""
  114. self.override_acl({
  115. 'can_edit_posts': 0,
  116. 'can_protect_posts': 1
  117. })
  118. response = self.patch(self.api_link, [
  119. {'op': 'replace', 'path': 'is-protected', 'value': True}
  120. ])
  121. self.assertEqual(response.status_code, 400)
  122. response_json = response.json()
  123. self.assertEqual(response_json['detail'][0], "You can't protect posts you can't edit.")
  124. self.refresh_post()
  125. self.assertFalse(self.post.is_protected)
  126. class PostApproveApiTests(ThreadPostPatchApiTestCase):
  127. def test_approve_post(self):
  128. """api makes it possible to approve post"""
  129. self.post.is_unapproved = True
  130. self.post.save()
  131. self.override_acl({
  132. 'can_approve_content': 1
  133. })
  134. response = self.patch(self.api_link, [
  135. {'op': 'replace', 'path': 'is-unapproved', 'value': False}
  136. ])
  137. self.assertEqual(response.status_code, 200)
  138. self.refresh_post()
  139. self.assertFalse(self.post.is_unapproved)
  140. def test_unapprove_post(self):
  141. """unapproving posts is not supported by api"""
  142. self.override_acl({
  143. 'can_approve_content': 1
  144. })
  145. response = self.patch(self.api_link, [
  146. {'op': 'replace', 'path': 'is-unapproved', 'value': True}
  147. ])
  148. self.assertEqual(response.status_code, 200)
  149. self.refresh_post()
  150. self.assertFalse(self.post.is_unapproved)
  151. def test_approve_post_no_permission(self):
  152. """api validates approval permission"""
  153. self.post.is_unapproved = True
  154. self.post.save()
  155. self.override_acl({
  156. 'can_approve_content': 0
  157. })
  158. response = self.patch(self.api_link, [
  159. {'op': 'replace', 'path': 'is-unapproved', 'value': False}
  160. ])
  161. self.assertEqual(response.status_code, 400)
  162. response_json = response.json()
  163. self.assertEqual(response_json['detail'][0], "You can't approve posts in this category.")
  164. self.refresh_post()
  165. self.assertTrue(self.post.is_unapproved)
  166. def test_approve_first_post(self):
  167. """api approve first post fails"""
  168. self.post.is_unapproved = True
  169. self.post.save()
  170. self.thread.set_first_post(self.post)
  171. self.thread.save()
  172. self.override_acl({
  173. 'can_approve_content': 1
  174. })
  175. response = self.patch(self.api_link, [
  176. {'op': 'replace', 'path': 'is-unapproved', 'value': False}
  177. ])
  178. self.assertEqual(response.status_code, 400)
  179. response_json = response.json()
  180. self.assertEqual(response_json['detail'][0], "You can't approve thread's first post.")
  181. self.refresh_post()
  182. self.assertTrue(self.post.is_unapproved)
  183. def test_approve_hidden_post(self):
  184. """api approve hidden post fails"""
  185. self.post.is_unapproved = True
  186. self.post.is_hidden = True
  187. self.post.save()
  188. self.override_acl({
  189. 'can_approve_content': 1
  190. })
  191. response = self.patch(self.api_link, [
  192. {'op': 'replace', 'path': 'is-unapproved', 'value': False}
  193. ])
  194. self.assertEqual(response.status_code, 400)
  195. response_json = response.json()
  196. self.assertEqual(response_json['detail'][0], "You can't approve posts the content you can't see.")
  197. self.refresh_post()
  198. self.assertTrue(self.post.is_unapproved)
  199. class PostHideApiTests(ThreadPostPatchApiTestCase):
  200. def test_hide_post(self):
  201. """api makes it possible to hide post"""
  202. self.override_acl({
  203. 'can_hide_posts': 1
  204. })
  205. response = self.patch(self.api_link, [
  206. {'op': 'replace', 'path': 'is-hidden', 'value': True}
  207. ])
  208. self.assertEqual(response.status_code, 200)
  209. self.refresh_post()
  210. self.assertTrue(self.post.is_hidden)
  211. def test_show_post(self):
  212. """api makes it possible to unhide post"""
  213. self.post.is_hidden = True
  214. self.post.save()
  215. self.refresh_post()
  216. self.assertTrue(self.post.is_hidden)
  217. self.override_acl({
  218. 'can_hide_posts': 1
  219. })
  220. response = self.patch(self.api_link, [
  221. {'op': 'replace', 'path': 'is-hidden', 'value': False}
  222. ])
  223. self.assertEqual(response.status_code, 200)
  224. self.refresh_post()
  225. self.assertFalse(self.post.is_hidden)
  226. def test_hide_own_post(self):
  227. """api makes it possible to hide owned post"""
  228. self.override_acl({
  229. 'can_hide_own_posts': 1
  230. })
  231. response = self.patch(self.api_link, [
  232. {'op': 'replace', 'path': 'is-hidden', 'value': True}
  233. ])
  234. self.assertEqual(response.status_code, 200)
  235. self.refresh_post()
  236. self.assertTrue(self.post.is_hidden)
  237. def test_show_own_post(self):
  238. """api makes it possible to unhide owned post"""
  239. self.post.is_hidden = True
  240. self.post.save()
  241. self.refresh_post()
  242. self.assertTrue(self.post.is_hidden)
  243. self.override_acl({
  244. 'can_hide_own_posts': 1
  245. })
  246. response = self.patch(self.api_link, [
  247. {'op': 'replace', 'path': 'is-hidden', 'value': False}
  248. ])
  249. self.assertEqual(response.status_code, 200)
  250. self.refresh_post()
  251. self.assertFalse(self.post.is_hidden)
  252. def test_hide_post_no_permission(self):
  253. """api hide post with no permission fails"""
  254. self.override_acl({
  255. 'can_hide_posts': 0
  256. })
  257. response = self.patch(self.api_link, [
  258. {'op': 'replace', 'path': 'is-hidden', 'value': True}
  259. ])
  260. self.assertEqual(response.status_code, 400)
  261. response_json = response.json()
  262. self.assertEqual(response_json['detail'][0], "You can't hide posts in this category.")
  263. self.refresh_post()
  264. self.assertFalse(self.post.is_hidden)
  265. def test_show_post_no_permission(self):
  266. """api unhide post with no permission fails"""
  267. self.post.is_hidden = True
  268. self.post.save()
  269. self.refresh_post()
  270. self.assertTrue(self.post.is_hidden)
  271. self.override_acl({
  272. 'can_hide_posts': 0
  273. })
  274. response = self.patch(self.api_link, [
  275. {'op': 'replace', 'path': 'is-hidden', 'value': False}
  276. ])
  277. self.assertEqual(response.status_code, 400)
  278. response_json = response.json()
  279. self.assertEqual(response_json['detail'][0], "You can't reveal posts in this category.")
  280. self.refresh_post()
  281. self.assertTrue(self.post.is_hidden)
  282. def test_hide_own_protected_post(self):
  283. """api validates if we are trying to hide protected post"""
  284. self.post.is_protected = True
  285. self.post.save()
  286. self.override_acl({
  287. 'can_protect_posts': 0,
  288. 'can_hide_own_posts': 1
  289. })
  290. response = self.patch(self.api_link, [
  291. {'op': 'replace', 'path': 'is-hidden', 'value': True}
  292. ])
  293. self.assertEqual(response.status_code, 400)
  294. response_json = response.json()
  295. self.assertEqual(response_json['detail'][0], "This post is protected. You can't hide it.")
  296. self.refresh_post()
  297. self.assertFalse(self.post.is_hidden)
  298. def test_show_own_protected_post(self):
  299. """api validates if we are trying to reveal protected post"""
  300. self.post.is_hidden = True
  301. self.post.save()
  302. self.override_acl({
  303. 'can_protect_posts': 0,
  304. 'can_hide_own_posts': 1
  305. })
  306. self.post.is_protected = True
  307. self.post.save()
  308. response = self.patch(self.api_link, [
  309. {'op': 'replace', 'path': 'is-hidden', 'value': False}
  310. ])
  311. self.assertEqual(response.status_code, 400)
  312. response_json = response.json()
  313. self.assertEqual(response_json['detail'][0], "This post is protected. You can't reveal it.")
  314. self.refresh_post()
  315. self.assertTrue(self.post.is_hidden)
  316. def test_hide_other_user_post(self):
  317. """api validates post ownership when hiding"""
  318. self.post.poster = None
  319. self.post.save()
  320. self.override_acl({
  321. 'can_hide_own_posts': 1
  322. })
  323. response = self.patch(self.api_link, [
  324. {'op': 'replace', 'path': 'is-hidden', 'value': True}
  325. ])
  326. self.assertEqual(response.status_code, 400)
  327. response_json = response.json()
  328. self.assertEqual(response_json['detail'][0], "You can't hide other users posts in this category.")
  329. self.refresh_post()
  330. self.assertFalse(self.post.is_hidden)
  331. def test_show_other_user_post(self):
  332. """api validates post ownership when revealing"""
  333. self.post.is_hidden = True
  334. self.post.poster = None
  335. self.post.save()
  336. self.override_acl({
  337. 'can_hide_own_posts': 1
  338. })
  339. response = self.patch(self.api_link, [
  340. {'op': 'replace', 'path': 'is-hidden', 'value': False}
  341. ])
  342. self.assertEqual(response.status_code, 400)
  343. response_json = response.json()
  344. self.assertEqual(response_json['detail'][0], "You can't reveal other users posts in this category.")
  345. self.refresh_post()
  346. self.assertTrue(self.post.is_hidden)
  347. def test_hide_own_post_after_edit_time(self):
  348. """api validates if we are trying to hide post after edit time"""
  349. self.post.posted_on = timezone.now() - timedelta(minutes=10)
  350. self.post.save()
  351. self.override_acl({
  352. 'post_edit_time': 1,
  353. 'can_hide_own_posts': 1
  354. })
  355. response = self.patch(self.api_link, [
  356. {'op': 'replace', 'path': 'is-hidden', 'value': True}
  357. ])
  358. self.assertEqual(response.status_code, 400)
  359. response_json = response.json()
  360. self.assertEqual(response_json['detail'][0], "You can't hide posts that are older than 1 minute.")
  361. self.refresh_post()
  362. self.assertFalse(self.post.is_hidden)
  363. def test_show_own_post_after_edit_time(self):
  364. """api validates if we are trying to reveal post after edit time"""
  365. self.post.is_hidden = True
  366. self.post.posted_on = timezone.now() - timedelta(minutes=10)
  367. self.post.save()
  368. self.override_acl({
  369. 'post_edit_time': 1,
  370. 'can_hide_own_posts': 1
  371. })
  372. response = self.patch(self.api_link, [
  373. {'op': 'replace', 'path': 'is-hidden', 'value': False}
  374. ])
  375. self.assertEqual(response.status_code, 400)
  376. response_json = response.json()
  377. self.assertEqual(response_json['detail'][0], "You can't reveal posts that are older than 1 minute.")
  378. self.refresh_post()
  379. self.assertTrue(self.post.is_hidden)
  380. def test_hide_post_in_closed_thread(self):
  381. """api validates if we are trying to hide post in closed thread"""
  382. self.thread.is_closed = True
  383. self.thread.save()
  384. self.override_acl({
  385. 'can_hide_own_posts': 1
  386. })
  387. response = self.patch(self.api_link, [
  388. {'op': 'replace', 'path': 'is-hidden', 'value': True}
  389. ])
  390. self.assertEqual(response.status_code, 400)
  391. response_json = response.json()
  392. self.assertEqual(response_json['detail'][0], "This thread is closed. You can't hide posts in it.")
  393. self.refresh_post()
  394. self.assertFalse(self.post.is_hidden)
  395. def test_show_post_in_closed_thread(self):
  396. """api validates if we are trying to reveal post in closed thread"""
  397. self.thread.is_closed = True
  398. self.thread.save()
  399. self.post.is_hidden = True
  400. self.post.save()
  401. self.override_acl({
  402. 'can_hide_own_posts': 1
  403. })
  404. response = self.patch(self.api_link, [
  405. {'op': 'replace', 'path': 'is-hidden', 'value': False}
  406. ])
  407. self.assertEqual(response.status_code, 400)
  408. response_json = response.json()
  409. self.assertEqual(response_json['detail'][0], "This thread is closed. You can't reveal posts in it.")
  410. self.refresh_post()
  411. self.assertTrue(self.post.is_hidden)
  412. def test_hide_post_in_closed_category(self):
  413. """api validates if we are trying to hide post in closed category"""
  414. self.category.is_closed = True
  415. self.category.save()
  416. self.override_acl({
  417. 'can_hide_own_posts': 1
  418. })
  419. response = self.patch(self.api_link, [
  420. {'op': 'replace', 'path': 'is-hidden', 'value': True}
  421. ])
  422. self.assertEqual(response.status_code, 400)
  423. response_json = response.json()
  424. self.assertEqual(response_json['detail'][0], "This category is closed. You can't hide posts in it.")
  425. self.refresh_post()
  426. self.assertFalse(self.post.is_hidden)
  427. def test_show_post_in_closed_category(self):
  428. """api validates if we are trying to reveal post in closed category"""
  429. self.category.is_closed = True
  430. self.category.save()
  431. self.post.is_hidden = True
  432. self.post.save()
  433. self.override_acl({
  434. 'can_hide_own_posts': 1
  435. })
  436. response = self.patch(self.api_link, [
  437. {'op': 'replace', 'path': 'is-hidden', 'value': False}
  438. ])
  439. self.assertEqual(response.status_code, 400)
  440. response_json = response.json()
  441. self.assertEqual(response_json['detail'][0], "This category is closed. You can't reveal posts in it.")
  442. self.refresh_post()
  443. self.assertTrue(self.post.is_hidden)
  444. def test_hide_first_post(self):
  445. """api hide first post fails"""
  446. self.thread.set_first_post(self.post)
  447. self.thread.save()
  448. self.override_acl({
  449. 'can_hide_posts': 1
  450. })
  451. response = self.patch(self.api_link, [
  452. {'op': 'replace', 'path': 'is-hidden', 'value': True}
  453. ])
  454. self.assertEqual(response.status_code, 400)
  455. response_json = response.json()
  456. self.assertEqual(response_json['detail'][0], "You can't hide thread's first post.")
  457. def test_show_first_post(self):
  458. """api unhide first post fails"""
  459. self.thread.set_first_post(self.post)
  460. self.thread.save()
  461. self.override_acl({
  462. 'can_hide_posts': 1
  463. })
  464. response = self.patch(self.api_link, [
  465. {'op': 'replace', 'path': 'is-hidden', 'value': False}
  466. ])
  467. self.assertEqual(response.status_code, 400)
  468. response_json = response.json()
  469. self.assertEqual(response_json['detail'][0], "You can't reveal thread's first post.")
  470. class PostLikeApiTests(ThreadPostPatchApiTestCase):
  471. def like_post(self):
  472. self.post.postlike_set.create(
  473. category=self.category,
  474. thread=self.thread,
  475. user=self.user,
  476. user_name=self.user.username,
  477. user_slug=self.user.slug,
  478. user_ip='127.0.0.1'
  479. )
  480. self.post.likes += 1
  481. self.post.last_likes = [
  482. {
  483. 'username': self.user.username,
  484. 'slug': self.user.slug,
  485. 'url': self.user.get_absolute_url()
  486. }
  487. ]
  488. self.post.save()
  489. def test_like_no_see_permission(self):
  490. """api validates user's permission to see posts likes"""
  491. self.override_acl({
  492. 'can_see_posts_likes': 0
  493. })
  494. response = self.patch(self.api_link, [
  495. {'op': 'replace', 'path': 'is-liked', 'value': True}
  496. ])
  497. self.assertContains(response, "You can't like posts in this category.", status_code=400)
  498. def test_like_no_like_permission(self):
  499. """api validates user's permission to see posts likes"""
  500. self.override_acl({
  501. 'can_like_posts': False
  502. })
  503. response = self.patch(self.api_link, [
  504. {'op': 'replace', 'path': 'is-liked', 'value': True}
  505. ])
  506. self.assertContains(response, "You can't like posts in this category.", status_code=400)
  507. def test_like_post(self):
  508. """api adds user like to post"""
  509. response = self.patch(self.api_link, [
  510. {'op': 'replace', 'path': 'is-liked', 'value': True}
  511. ])
  512. self.assertEqual(response.status_code, 200)
  513. response_json = response.json()
  514. self.assertEqual(response_json['likes'], 1)
  515. self.assertEqual(response_json['is_liked'], True)
  516. self.assertEqual(response_json['last_likes'], [
  517. {
  518. 'username': self.user.username,
  519. 'slug': self.user.slug,
  520. 'url': self.user.get_absolute_url()
  521. }
  522. ])
  523. post = Post.objects.get(pk=self.post.pk)
  524. self.assertEqual(post.likes, response_json['likes'])
  525. self.assertEqual(post.last_likes, response_json['last_likes'])
  526. def test_unlike_post(self):
  527. """api removes user like from post"""
  528. self.like_post()
  529. response = self.patch(self.api_link, [
  530. {'op': 'replace', 'path': 'is-liked', 'value': False}
  531. ])
  532. self.assertEqual(response.status_code, 200)
  533. response_json = response.json()
  534. self.assertEqual(response_json['likes'], 0)
  535. self.assertEqual(response_json['is_liked'], False)
  536. self.assertEqual(response_json['last_likes'], [])
  537. post = Post.objects.get(pk=self.post.pk)
  538. self.assertEqual(post.likes, response_json['likes'])
  539. self.assertEqual(post.last_likes, response_json['last_likes'])
  540. def test_like_post_no_change(self):
  541. """api does no state change if we are linking liked post"""
  542. self.like_post()
  543. response = self.patch(self.api_link, [
  544. {'op': 'replace', 'path': 'is-liked', 'value': True}
  545. ])
  546. self.assertEqual(response.status_code, 200)
  547. response_json = response.json()
  548. self.assertEqual(response_json['likes'], 1)
  549. self.assertEqual(response_json['is_liked'], True)
  550. self.assertEqual(response_json['last_likes'], [
  551. {
  552. 'username': self.user.username,
  553. 'slug': self.user.slug,
  554. 'url': self.user.get_absolute_url()
  555. }
  556. ])
  557. post = Post.objects.get(pk=self.post.pk)
  558. self.assertEqual(post.likes, response_json['likes'])
  559. self.assertEqual(post.last_likes, response_json['last_likes'])
  560. def test_unlike_post_no_change(self):
  561. """api does no state change if we are unlinking unliked post"""
  562. response = self.patch(self.api_link, [
  563. {'op': 'replace', 'path': 'is-liked', 'value': False}
  564. ])
  565. self.assertEqual(response.status_code, 200)
  566. response_json = response.json()
  567. self.assertEqual(response_json['likes'], 0)
  568. self.assertEqual(response_json['is_liked'], False)
  569. self.assertEqual(response_json['last_likes'], [])
  570. class ThreadEventPatchApiTestCase(ThreadPostPatchApiTestCase):
  571. def setUp(self):
  572. super(ThreadEventPatchApiTestCase, self).setUp()
  573. self.event = testutils.reply_thread(self.thread, poster=self.user, is_event=True)
  574. self.api_link = reverse('misago:api:thread-post-detail', kwargs={
  575. 'thread_pk': self.thread.pk,
  576. 'pk': self.event.pk
  577. })
  578. def refresh_event(self):
  579. self.event = self.thread.post_set.get(pk=self.event.pk)
  580. class EventAnonPatchApiTests(ThreadEventPatchApiTestCase):
  581. def test_anonymous_user(self):
  582. """anonymous users can't change event state"""
  583. self.logout_user()
  584. response = self.patch(self.api_link, [
  585. {'op': 'add', 'path': 'acl', 'value': True}
  586. ])
  587. self.assertEqual(response.status_code, 403)
  588. class EventAddAclApiTests(ThreadEventPatchApiTestCase):
  589. def test_add_acl_true(self):
  590. """api adds current event's acl to response"""
  591. response = self.patch(self.api_link, [
  592. {'op': 'add', 'path': 'acl', 'value': True}
  593. ])
  594. self.assertEqual(response.status_code, 200)
  595. response_json = response.json()
  596. self.assertTrue(response_json['acl'])
  597. def test_add_acl_false(self):
  598. """if value is false, api won't add acl to the response, but will set empty key"""
  599. response = self.patch(self.api_link, [
  600. {'op': 'add', 'path': 'acl', 'value': False}
  601. ])
  602. self.assertEqual(response.status_code, 200)
  603. response_json = response.json()
  604. self.assertIsNone(response_json['acl'])
  605. response = self.patch(self.api_link, [
  606. {'op': 'add', 'path': 'acl', 'value': True}
  607. ])
  608. self.assertEqual(response.status_code, 200)
  609. class EventHideApiTests(ThreadEventPatchApiTestCase):
  610. def test_hide_event(self):
  611. """api makes it possible to hide event"""
  612. self.override_acl({
  613. 'can_hide_events': 1
  614. })
  615. response = self.patch(self.api_link, [
  616. {'op': 'replace', 'path': 'is-hidden', 'value': True}
  617. ])
  618. self.assertEqual(response.status_code, 200)
  619. self.refresh_event()
  620. self.assertTrue(self.event.is_hidden)
  621. def test_show_event(self):
  622. """api makes it possible to unhide event"""
  623. self.event.is_hidden = True
  624. self.event.save()
  625. self.refresh_event()
  626. self.assertTrue(self.event.is_hidden)
  627. self.override_acl({
  628. 'can_hide_events': 1
  629. })
  630. response = self.patch(self.api_link, [
  631. {'op': 'replace', 'path': 'is-hidden', 'value': False}
  632. ])
  633. self.assertEqual(response.status_code, 200)
  634. self.refresh_event()
  635. self.assertFalse(self.event.is_hidden)
  636. def test_hide_event_no_permission(self):
  637. """api hide event with no permission fails"""
  638. self.override_acl({
  639. 'can_hide_events': 0
  640. })
  641. response = self.patch(self.api_link, [
  642. {'op': 'replace', 'path': 'is-hidden', 'value': True}
  643. ])
  644. self.assertEqual(response.status_code, 400)
  645. response_json = response.json()
  646. self.assertEqual(response_json['detail'][0], "You don't have permission to hide this event.")
  647. self.refresh_event()
  648. self.assertFalse(self.event.is_hidden)
  649. def test_show_event_no_permission(self):
  650. """api unhide event with no permission fails"""
  651. self.event.is_hidden = True
  652. self.event.save()
  653. self.refresh_event()
  654. self.assertTrue(self.event.is_hidden)
  655. self.override_acl({
  656. 'can_hide_events': 0
  657. })
  658. response = self.patch(self.api_link, [
  659. {'op': 'replace', 'path': 'is-hidden', 'value': False}
  660. ])
  661. self.assertEqual(response.status_code, 404)