From 5d8a99f10429168e6471fdd1843f5045a10a84b3 Mon Sep 17 00:00:00 2001 From: Sebastian Ziebell Date: Wed, 6 Feb 2013 16:45:38 +0100 Subject: [PATCH] Test to check a user must be part of the team to see project. --- spec/requests/api/projects_spec.rb | 6 ++++++ 1 file changed, 6 insertions(+), 0 deletions(-) diff --git a/spec/requests/api/projects_spec.rb b/spec/requests/api/projects_spec.rb index 8351b4b..b9f42ac 100644 --- a/spec/requests/api/projects_spec.rb +++ b/spec/requests/api/projects_spec.rb @@ -89,6 +89,12 @@ describe Gitlab::API do response.status.should == 404 json_response['message'].should == '404 Not Found' end + + it "should return a 404 error if user is not a member" do + other_user = create(:user) + get api("/projects/#{project.id}", other_user) + response.status.should == 404 + end end describe "GET /projects/:id/repository/branches" do -- libgit2 0.21.2