Add a polymorphic `subject` field that records the subject of the mod action. The subject is the post, user, comment, artist, etc the mod action is for. * The subject for the user ban and unban actions is the user, not the ban itself. * The subject for the user feedback update and deletion actions is the user, not the feedback itself. * The subject for the post undeletion action is the post, not the approval itself. * The subject for the move favorites action is the source post where the favorites were moved from, not the destination post where the favorites were moved to. * The subject for the post permanent delete action is nil, because the post itself is hard deleted. * When a post is permanently deleted, all mod actions related to the post are deleted as well.
111 lines
3.4 KiB
Ruby
111 lines
3.4 KiB
Ruby
require 'test_helper'
|
|
|
|
class UserDeletionTest < ActiveSupport::TestCase
|
|
setup do
|
|
@request = mock
|
|
@request.stubs(:remote_ip).returns("1.1.1.1")
|
|
@request.stubs(:user_agent).returns("Firefox")
|
|
@request.stubs(:session).returns(session_id: "1234")
|
|
end
|
|
|
|
context "an invalid user deletion" do
|
|
context "for an invalid password" do
|
|
should "fail" do
|
|
@user = create(:user)
|
|
@deletion = UserDeletion.new(user: @user, password: "wrongpassword", request: @request)
|
|
@deletion.delete!
|
|
assert_includes(@deletion.errors[:base], "Password is incorrect")
|
|
end
|
|
end
|
|
|
|
context "for an admin" do
|
|
should "fail" do
|
|
@user = create(:admin_user)
|
|
@deletion = UserDeletion.new(user: @user, password: "password", request: @request)
|
|
@deletion.delete!
|
|
assert_includes(@deletion.errors[:base], "Admins cannot delete their account")
|
|
end
|
|
end
|
|
|
|
context "for a banned user" do
|
|
should "fail" do
|
|
@user = create(:banned_user)
|
|
@deletion = UserDeletion.new(user: @user, password: "password", request: @request)
|
|
@deletion.delete!
|
|
assert_includes(@deletion.errors[:base], "You cannot delete your account if you are banned")
|
|
end
|
|
end
|
|
end
|
|
|
|
context "a valid user deletion" do
|
|
setup do
|
|
@user = create(:user, name: "foo", email_address: build(:email_address))
|
|
@deletion = UserDeletion.new(user: @user, password: "password", request: @request)
|
|
end
|
|
|
|
should "blank out the email" do
|
|
@deletion.delete!
|
|
assert_nil(@user.reload.email_address)
|
|
end
|
|
|
|
should "rename the user" do
|
|
@deletion.delete!
|
|
assert_equal("user_#{@user.id}", @user.reload.name)
|
|
end
|
|
|
|
should "generate a user name change request" do
|
|
assert_difference("UserNameChangeRequest.count") do
|
|
@deletion.delete!
|
|
end
|
|
|
|
assert_equal("foo", UserNameChangeRequest.last.original_name)
|
|
assert_equal("user_#{@user.id}", UserNameChangeRequest.last.desired_name)
|
|
end
|
|
|
|
should "reset the password" do
|
|
@deletion.delete!
|
|
assert_equal(false, @user.authenticate_password("password"))
|
|
end
|
|
|
|
should "generate a modaction" do
|
|
@deletion.delete!
|
|
assert_match(/deleted user ##{@user.id}/, ModAction.last.description)
|
|
assert_equal(@user, ModAction.last.subject)
|
|
assert_equal("user_delete", ModAction.last.category)
|
|
assert_equal(@deletion.deleter, ModAction.last.creator)
|
|
end
|
|
|
|
should "remove any favorites" do
|
|
@post = create(:post)
|
|
Favorite.create!(post: @post, user: @user)
|
|
|
|
perform_enqueued_jobs { @deletion.delete! }
|
|
|
|
assert_equal(0, Favorite.count)
|
|
assert_equal(0, @post.reload.fav_count)
|
|
end
|
|
end
|
|
|
|
context "deleting another user's account" do
|
|
should "work for the owner-level user" do
|
|
@user = create(:user)
|
|
@deletion = UserDeletion.new(user: @user, deleter: create(:owner_user))
|
|
|
|
@deletion.delete!
|
|
assert_equal("user_#{@user.id}", @user.reload.name)
|
|
assert_equal("deleted user ##{@user.id}", ModAction.last.description)
|
|
assert_equal(@deletion.deleter, ModAction.last.creator)
|
|
assert_equal(@user, ModAction.last.subject)
|
|
end
|
|
|
|
should "not work for other users" do
|
|
@user = create(:user)
|
|
@deletion = UserDeletion.new(user: @user, deleter: create(:admin_user))
|
|
|
|
@deletion.delete!
|
|
assert_not_equal("user_#{@user.id}", @user.reload.name)
|
|
assert_equal(0, ModAction.count)
|
|
end
|
|
end
|
|
end
|