Chris@1296: # Redmine - project management software Chris@1296: # Copyright (C) 2006-2012 Jean-Philippe Lang Chris@1296: # Chris@1296: # This program is free software; you can redistribute it and/or Chris@1296: # modify it under the terms of the GNU General Public License Chris@1296: # as published by the Free Software Foundation; either version 2 Chris@1296: # of the License, or (at your option) any later version. Chris@1296: # Chris@1296: # This program is distributed in the hope that it will be useful, Chris@1296: # but WITHOUT ANY WARRANTY; without even the implied warranty of Chris@1296: # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the Chris@1296: # GNU General Public License for more details. Chris@1296: # Chris@1296: # You should have received a copy of the GNU General Public License Chris@1296: # along with this program; if not, write to the Free Software Chris@1296: # Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA. Chris@1296: Chris@1296: require File.expand_path('../../../../test_helper', __FILE__) Chris@1296: Chris@1296: class Redmine::SafeAttributesTest < ActiveSupport::TestCase Chris@1296: fixtures :users Chris@1296: Chris@1296: class Base Chris@1296: def attributes=(attrs) Chris@1296: attrs.each do |key, value| Chris@1296: send("#{key}=", value) Chris@1296: end Chris@1296: end Chris@1296: end Chris@1296: Chris@1296: class Person < Base Chris@1296: attr_accessor :firstname, :lastname, :login Chris@1296: include Redmine::SafeAttributes Chris@1296: safe_attributes :firstname, :lastname Chris@1296: safe_attributes :login, :if => lambda {|person, user| user.admin?} Chris@1296: end Chris@1296: Chris@1296: class Book < Base Chris@1296: attr_accessor :title Chris@1296: include Redmine::SafeAttributes Chris@1296: safe_attributes :title Chris@1296: end Chris@1296: Chris@1296: def test_safe_attribute_names Chris@1296: p = Person.new Chris@1296: user = User.anonymous Chris@1296: assert_equal ['firstname', 'lastname'], p.safe_attribute_names(user) Chris@1296: assert p.safe_attribute?('firstname', user) Chris@1296: assert !p.safe_attribute?('login', user) Chris@1296: Chris@1296: p = Person.new Chris@1296: user = User.find(1) Chris@1296: assert_equal ['firstname', 'lastname', 'login'], p.safe_attribute_names(user) Chris@1296: assert p.safe_attribute?('firstname', user) Chris@1296: assert p.safe_attribute?('login', user) Chris@1296: end Chris@1296: Chris@1296: def test_safe_attribute_names_without_user Chris@1296: p = Person.new Chris@1296: User.current = nil Chris@1296: assert_equal ['firstname', 'lastname'], p.safe_attribute_names Chris@1296: assert p.safe_attribute?('firstname') Chris@1296: assert !p.safe_attribute?('login') Chris@1296: Chris@1296: p = Person.new Chris@1296: User.current = User.find(1) Chris@1296: assert_equal ['firstname', 'lastname', 'login'], p.safe_attribute_names Chris@1296: assert p.safe_attribute?('firstname') Chris@1296: assert p.safe_attribute?('login') Chris@1296: end Chris@1296: Chris@1296: def test_set_safe_attributes Chris@1296: p = Person.new Chris@1296: p.send('safe_attributes=', {'firstname' => 'John', 'lastname' => 'Smith', 'login' => 'jsmith'}, User.anonymous) Chris@1296: assert_equal 'John', p.firstname Chris@1296: assert_equal 'Smith', p.lastname Chris@1296: assert_nil p.login Chris@1296: Chris@1296: p = Person.new Chris@1296: User.current = User.find(1) Chris@1296: p.send('safe_attributes=', {'firstname' => 'John', 'lastname' => 'Smith', 'login' => 'jsmith'}, User.find(1)) Chris@1296: assert_equal 'John', p.firstname Chris@1296: assert_equal 'Smith', p.lastname Chris@1296: assert_equal 'jsmith', p.login Chris@1296: end Chris@1296: Chris@1296: def test_set_safe_attributes_without_user Chris@1296: p = Person.new Chris@1296: User.current = nil Chris@1296: p.safe_attributes = {'firstname' => 'John', 'lastname' => 'Smith', 'login' => 'jsmith'} Chris@1296: assert_equal 'John', p.firstname Chris@1296: assert_equal 'Smith', p.lastname Chris@1296: assert_nil p.login Chris@1296: Chris@1296: p = Person.new Chris@1296: User.current = User.find(1) Chris@1296: p.safe_attributes = {'firstname' => 'John', 'lastname' => 'Smith', 'login' => 'jsmith'} Chris@1296: assert_equal 'John', p.firstname Chris@1296: assert_equal 'Smith', p.lastname Chris@1296: assert_equal 'jsmith', p.login Chris@1296: end Chris@1296: end