test_threads_editor_api.py 19 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593
  1. import json
  2. from django.core.urlresolvers import reverse
  3. from django.utils.encoding import smart_str
  4. from misago.acl.testutils import override_acl
  5. from misago.categories.models import Category
  6. from misago.users.testutils import AuthenticatedUserTestCase
  7. from .. import testutils
  8. class EditorApiTestCase(AuthenticatedUserTestCase):
  9. def setUp(self):
  10. super(EditorApiTestCase, self).setUp()
  11. self.category = Category.objects.get(slug='first-category')
  12. def override_acl(self, acl=None):
  13. final_acl = self.user.acl['categories'][self.category.pk]
  14. final_acl.update({
  15. 'can_see': 1,
  16. 'can_browse': 1,
  17. 'can_see_all_threads': 1,
  18. 'can_start_threads': 0,
  19. 'can_reply_threads': 0,
  20. 'can_edit_threads': 0,
  21. 'can_edit_posts': 0,
  22. 'can_hide_own_threads': 0,
  23. 'can_hide_own_posts': 0,
  24. 'thread_edit_time': 0,
  25. 'post_edit_time': 0,
  26. 'can_hide_threads': 0,
  27. 'can_hide_posts': 0,
  28. 'can_protect_posts': 0,
  29. 'can_move_posts': 0,
  30. 'can_merge_posts': 0,
  31. 'can_pin_threads': 0,
  32. 'can_close_threads': 0,
  33. 'can_move_threads': 0,
  34. 'can_merge_threads': 0,
  35. 'can_split_threads': 0,
  36. 'can_approve_content': 0,
  37. 'can_report_content': 0,
  38. 'can_see_reports': 0,
  39. 'can_see_posts_likes': 0,
  40. 'can_like_posts': 0,
  41. 'can_hide_events': 0,
  42. })
  43. if acl:
  44. final_acl.update(acl)
  45. browseable_categories = []
  46. if final_acl['can_browse']:
  47. browseable_categories.append(self.category.pk)
  48. override_acl(self.user, {
  49. 'browseable_categories': browseable_categories,
  50. 'categories': {
  51. self.category.pk: final_acl
  52. }
  53. })
  54. class ThreadPostEditorApiTests(EditorApiTestCase):
  55. def setUp(self):
  56. super(ThreadPostEditorApiTests, self).setUp()
  57. self.api_link = reverse('misago:api:thread-editor')
  58. def test_anonymous_user_request(self):
  59. """endpoint validates if user is authenticated"""
  60. self.logout_user()
  61. response = self.client.get(self.api_link)
  62. self.assertContains(response, "You need to be signed in", status_code=403)
  63. def test_category_visibility_validation(self):
  64. """endpoint omits non-browseable categories"""
  65. self.override_acl({'can_browse': 0})
  66. response = self.client.get(self.api_link)
  67. self.assertContains(response, "No categories that allow new threads", status_code=403)
  68. def test_category_disallowing_new_threads(self):
  69. """endpoint omits category disallowing starting threads"""
  70. self.override_acl({
  71. 'can_start_threads': 0,
  72. })
  73. response = self.client.get(self.api_link)
  74. self.assertContains(response, "No categories that allow new threads", status_code=403)
  75. def test_category_closed_disallowing_new_threads(self):
  76. """endpoint omits closed category"""
  77. self.override_acl({
  78. 'can_start_threads': 2,
  79. 'can_close_threads': 0,
  80. })
  81. self.category.is_closed = True
  82. self.category.save()
  83. response = self.client.get(self.api_link)
  84. self.assertContains(response, "No categories that allow new threads", status_code=403)
  85. def test_category_closed_allowing_new_threads(self):
  86. """endpoint adds closed category that allows new threads"""
  87. self.override_acl({
  88. 'can_start_threads': 2,
  89. 'can_close_threads': 1,
  90. })
  91. self.category.is_closed = True
  92. self.category.save()
  93. response = self.client.get(self.api_link)
  94. self.assertEqual(response.status_code, 200)
  95. response_json = json.loads(smart_str(response.content))
  96. self.assertEqual(response_json[0], {
  97. 'id': self.category.pk,
  98. 'name': self.category.name,
  99. 'level': 0,
  100. 'post': {
  101. 'close': True,
  102. 'hide': False,
  103. 'pin': 0
  104. }
  105. })
  106. def test_category_allowing_new_threads(self):
  107. """endpoint adds category that allows new threads"""
  108. self.override_acl({
  109. 'can_start_threads': 2,
  110. })
  111. response = self.client.get(self.api_link)
  112. self.assertEqual(response.status_code, 200)
  113. response_json = json.loads(smart_str(response.content))
  114. self.assertEqual(response_json[0], {
  115. 'id': self.category.pk,
  116. 'name': self.category.name,
  117. 'level': 0,
  118. 'post': {
  119. 'close': False,
  120. 'hide': False,
  121. 'pin': 0
  122. }
  123. })
  124. def test_category_allowing_closing_threads(self):
  125. """endpoint adds category that allows new closed threads"""
  126. self.override_acl({
  127. 'can_start_threads': 2,
  128. 'can_close_threads': 1,
  129. })
  130. response = self.client.get(self.api_link)
  131. self.assertEqual(response.status_code, 200)
  132. response_json = json.loads(smart_str(response.content))
  133. self.assertEqual(response_json[0], {
  134. 'id': self.category.pk,
  135. 'name': self.category.name,
  136. 'level': 0,
  137. 'post': {
  138. 'close': True,
  139. 'hide': False,
  140. 'pin': 0
  141. }
  142. })
  143. def test_category_allowing_locally_pinned_threads(self):
  144. """endpoint adds category that allows locally pinned threads"""
  145. self.override_acl({
  146. 'can_start_threads': 2,
  147. 'can_pin_threads': 1,
  148. })
  149. response = self.client.get(self.api_link)
  150. self.assertEqual(response.status_code, 200)
  151. response_json = json.loads(smart_str(response.content))
  152. self.assertEqual(response_json[0], {
  153. 'id': self.category.pk,
  154. 'name': self.category.name,
  155. 'level': 0,
  156. 'post': {
  157. 'close': False,
  158. 'hide': False,
  159. 'pin': 1
  160. }
  161. })
  162. def test_category_allowing_globally_pinned_threads(self):
  163. """endpoint adds category that allows globally pinned threads"""
  164. self.override_acl({
  165. 'can_start_threads': 2,
  166. 'can_pin_threads': 2,
  167. })
  168. response = self.client.get(self.api_link)
  169. self.assertEqual(response.status_code, 200)
  170. response_json = json.loads(smart_str(response.content))
  171. self.assertEqual(response_json[0], {
  172. 'id': self.category.pk,
  173. 'name': self.category.name,
  174. 'level': 0,
  175. 'post': {
  176. 'close': False,
  177. 'hide': False,
  178. 'pin': 2
  179. }
  180. })
  181. def test_category_allowing_hidden_threads(self):
  182. """endpoint adds category that allows globally pinned threads"""
  183. self.override_acl({
  184. 'can_start_threads': 2,
  185. 'can_hide_threads': 1,
  186. })
  187. response = self.client.get(self.api_link)
  188. self.assertEqual(response.status_code, 200)
  189. response_json = json.loads(smart_str(response.content))
  190. self.assertEqual(response_json[0], {
  191. 'id': self.category.pk,
  192. 'name': self.category.name,
  193. 'level': 0,
  194. 'post': {
  195. 'close': 0,
  196. 'hide': 1,
  197. 'pin': 0
  198. }
  199. })
  200. self.override_acl({
  201. 'can_start_threads': 2,
  202. 'can_hide_threads': 2,
  203. })
  204. response = self.client.get(self.api_link)
  205. self.assertEqual(response.status_code, 200)
  206. response_json = json.loads(smart_str(response.content))
  207. self.assertEqual(response_json[0], {
  208. 'id': self.category.pk,
  209. 'name': self.category.name,
  210. 'level': 0,
  211. 'post': {
  212. 'close': False,
  213. 'hide': True,
  214. 'pin': 0
  215. }
  216. })
  217. class ThreadReplyEditorApiTests(EditorApiTestCase):
  218. def setUp(self):
  219. super(ThreadReplyEditorApiTests, self).setUp()
  220. self.thread = testutils.post_thread(category=self.category)
  221. self.api_link = reverse('misago:api:thread-post-editor', kwargs={
  222. 'thread_pk': self.thread.pk
  223. })
  224. def test_anonymous_user_request(self):
  225. """endpoint validates if user is authenticated"""
  226. self.logout_user()
  227. response = self.client.get(self.api_link)
  228. self.assertContains(response, "You have to sign in to reply threads.", status_code=403)
  229. def test_thread_visibility(self):
  230. """thread's visibility is validated"""
  231. self.override_acl({'can_see': 0})
  232. response = self.client.get(self.api_link)
  233. self.assertEqual(response.status_code, 404)
  234. self.override_acl({'can_browse': 0})
  235. response = self.client.get(self.api_link)
  236. self.assertEqual(response.status_code, 404)
  237. self.override_acl({'can_see_all_threads': 0})
  238. response = self.client.get(self.api_link)
  239. self.assertEqual(response.status_code, 404)
  240. def test_no_reply_permission(self):
  241. """permssion to reply is validated"""
  242. self.override_acl({
  243. 'can_reply_threads': 0
  244. })
  245. response = self.client.get(self.api_link)
  246. self.assertContains(response, "You can't reply to threads in this category.", status_code=403)
  247. def test_closed_category(self):
  248. """permssion to reply in closed category is validated"""
  249. self.override_acl({
  250. 'can_reply_threads': 1,
  251. 'can_close_threads': 0
  252. })
  253. self.category.is_closed = True
  254. self.category.save()
  255. response = self.client.get(self.api_link)
  256. self.assertContains(response, "This category is closed. You can't reply to threads in it.", status_code=403)
  257. # allow to post in closed category
  258. self.override_acl({
  259. 'can_reply_threads': 1,
  260. 'can_close_threads': 1
  261. })
  262. response = self.client.get(self.api_link)
  263. self.assertEqual(response.status_code, 200)
  264. def test_closed_thread(self):
  265. """permssion to reply in closed thread is validated"""
  266. self.override_acl({
  267. 'can_reply_threads': 1,
  268. 'can_close_threads': 0
  269. })
  270. self.thread.is_closed = True
  271. self.thread.save()
  272. response = self.client.get(self.api_link)
  273. self.assertContains(response, "You can't reply to closed threads in this category.", status_code=403)
  274. # allow to post in closed thread
  275. self.override_acl({
  276. 'can_reply_threads': 1,
  277. 'can_close_threads': 1
  278. })
  279. response = self.client.get(self.api_link)
  280. self.assertEqual(response.status_code, 200)
  281. def test_allow_reply_thread(self):
  282. """api returns 200 code if thread reply is allowed"""
  283. self.override_acl({
  284. 'can_reply_threads': 1
  285. })
  286. response = self.client.get(self.api_link)
  287. self.assertEqual(response.status_code, 200)
  288. def test_reply_to_visibility(self):
  289. """api validates replied post visibility"""
  290. self.override_acl({
  291. 'can_reply_threads': 1
  292. })
  293. # unapproved reply can't be replied to
  294. unapproved_reply = testutils.reply_thread(self.thread, is_unapproved=True)
  295. response = self.client.get('{}?reply={}'.format(self.api_link, unapproved_reply.pk))
  296. self.assertEqual(response.status_code, 404)
  297. # hidden reply can't be replied to
  298. self.override_acl({
  299. 'can_reply_threads': 1
  300. })
  301. hidden_reply = testutils.reply_thread(self.thread, is_hidden=True)
  302. response = self.client.get('{}?reply={}'.format(self.api_link, hidden_reply.pk))
  303. self.assertContains(response, "You can't reply to hidden posts", status_code=403)
  304. def test_reply_to_other_thread_post(self):
  305. """api validates is replied post belongs to same thread"""
  306. other_thread = testutils.post_thread(category=self.category)
  307. reply_to = testutils.reply_thread(other_thread)
  308. response = self.client.get('{}?reply={}'.format(self.api_link, reply_to.pk))
  309. self.assertEqual(response.status_code, 404)
  310. def test_reply_to(self):
  311. """api includes replied to post details in response"""
  312. self.override_acl({
  313. 'can_reply_threads': 1
  314. })
  315. reply_to = testutils.reply_thread(self.thread)
  316. response = self.client.get('{}?reply={}'.format(self.api_link, reply_to.pk))
  317. self.assertEqual(response.status_code, 200)
  318. self.assertEqual(json.loads(smart_str(response.content)), {
  319. 'id': reply_to.pk,
  320. 'post': reply_to.original,
  321. 'poster': reply_to.poster_name
  322. })
  323. class EditReplyEditorApiTests(EditorApiTestCase):
  324. def setUp(self):
  325. super(EditReplyEditorApiTests, self).setUp()
  326. self.thread = testutils.post_thread(category=self.category)
  327. self.post = testutils.reply_thread(self.thread, poster=self.user)
  328. self.api_link = reverse('misago:api:thread-post-editor', kwargs={
  329. 'thread_pk': self.thread.pk,
  330. 'pk': self.post.pk
  331. })
  332. def test_anonymous_user_request(self):
  333. """endpoint validates if user is authenticated"""
  334. self.logout_user()
  335. response = self.client.get(self.api_link)
  336. self.assertContains(response, "You have to sign in to edit posts.", status_code=403)
  337. def test_thread_visibility(self):
  338. """thread's visibility is validated"""
  339. self.override_acl({'can_see': 0})
  340. response = self.client.get(self.api_link)
  341. self.assertEqual(response.status_code, 404)
  342. self.override_acl({'can_browse': 0})
  343. response = self.client.get(self.api_link)
  344. self.assertEqual(response.status_code, 404)
  345. self.override_acl({'can_see_all_threads': 0})
  346. response = self.client.get(self.api_link)
  347. self.assertEqual(response.status_code, 404)
  348. def test_no_edit_permission(self):
  349. """permssion to edit is validated"""
  350. self.override_acl({
  351. 'can_edit_posts': 0
  352. })
  353. response = self.client.get(self.api_link)
  354. self.assertContains(response, "You can't edit posts in this category.", status_code=403)
  355. def test_closed_category(self):
  356. """permssion to edit in closed category is validated"""
  357. self.override_acl({
  358. 'can_edit_posts': 1,
  359. 'can_close_threads': 0
  360. })
  361. self.category.is_closed = True
  362. self.category.save()
  363. response = self.client.get(self.api_link)
  364. self.assertContains(response, "This category is closed. You can't edit posts in it.", status_code=403)
  365. # allow to edit in closed category
  366. self.override_acl({
  367. 'can_edit_posts': 1,
  368. 'can_close_threads': 1
  369. })
  370. response = self.client.get(self.api_link)
  371. self.assertEqual(response.status_code, 200)
  372. def test_closed_thread(self):
  373. """permssion to edit in closed thread is validated"""
  374. self.override_acl({
  375. 'can_edit_posts': 1,
  376. 'can_close_threads': 0
  377. })
  378. self.thread.is_closed = True
  379. self.thread.save()
  380. response = self.client.get(self.api_link)
  381. self.assertContains(response, "This thread is closed. You can't edit posts in it.", status_code=403)
  382. # allow to edit in closed thread
  383. self.override_acl({
  384. 'can_edit_posts': 1,
  385. 'can_close_threads': 1
  386. })
  387. response = self.client.get(self.api_link)
  388. self.assertEqual(response.status_code, 200)
  389. def test_protected_post(self):
  390. """permssion to edit protected post is validated"""
  391. self.override_acl({
  392. 'can_edit_posts': 1,
  393. 'can_protect_posts': 0
  394. })
  395. self.post.is_protected = True
  396. self.post.save()
  397. response = self.client.get(self.api_link)
  398. self.assertContains(response, "This post is protected. You can't edit it.", status_code=403)
  399. # allow to post in closed thread
  400. self.override_acl({
  401. 'can_edit_posts': 1,
  402. 'can_protect_posts': 1
  403. })
  404. response = self.client.get(self.api_link)
  405. self.assertEqual(response.status_code, 200)
  406. def test_post_visibility(self):
  407. """edited posts visibility is validated"""
  408. self.override_acl({
  409. 'can_edit_posts': 1
  410. })
  411. self.post.is_hidden = True;
  412. self.post.save()
  413. response = self.client.get(self.api_link)
  414. self.assertContains(response, "This post is hidden, you can't edit it.", status_code=403)
  415. # allow hidden edition
  416. self.override_acl({
  417. 'can_edit_posts': 1,
  418. 'can_hide_posts': 1
  419. })
  420. response = self.client.get(self.api_link)
  421. self.assertEqual(response.status_code, 200)
  422. # test unapproved post
  423. self.post.is_hidden = False;
  424. self.post.poster = None;
  425. self.post.save()
  426. self.override_acl({
  427. 'can_edit_posts': 2,
  428. 'can_approve_content': 0
  429. })
  430. self.post.is_unapproved = True;
  431. self.post.save()
  432. response = self.client.get(self.api_link)
  433. self.assertEqual(response.status_code, 404)
  434. # allow unapproved edition
  435. self.override_acl({
  436. 'can_edit_posts': 2,
  437. 'can_approve_content': 1
  438. })
  439. response = self.client.get(self.api_link)
  440. self.assertEqual(response.status_code, 200)
  441. def test_other_user_post(self):
  442. """api validates if other user's post can be edited"""
  443. self.override_acl({
  444. 'can_edit_posts': 1,
  445. })
  446. self.post.poster = None;
  447. self.post.save()
  448. response = self.client.get(self.api_link)
  449. self.assertContains(response, "You can't edit other users posts in this category.", status_code=403)
  450. # allow other users post edition
  451. self.override_acl({
  452. 'can_edit_posts': 2,
  453. })
  454. response = self.client.get(self.api_link)
  455. self.assertEqual(response.status_code, 200)
  456. def test_edit(self):
  457. """endpoint returns valid configuration for editor"""
  458. self.override_acl({
  459. 'can_edit_posts': 1,
  460. })
  461. response = self.client.get(self.api_link)
  462. self.assertEqual(response.status_code, 200)
  463. self.assertEqual(json.loads(smart_str(response.content)), {
  464. 'id': self.post.pk,
  465. 'api': self.post.get_api_url(),
  466. 'post': self.post.original,
  467. 'can_protect': False,
  468. 'is_protected': self.post.is_protected,
  469. 'poster': self.post.poster_name
  470. })