Commit 6954d50fd3307f25f16ac06f21aebe37cb7059db
1 parent
ea779cc5
Exists in
master
and in
4 other branches
Dashboard security specs
Showing
1 changed file
with
55 additions
and
0 deletions
Show diff stats
@@ -0,0 +1,55 @@ | @@ -0,0 +1,55 @@ | ||
1 | +require 'spec_helper' | ||
2 | + | ||
3 | +describe "Dashboard access" do | ||
4 | + describe "GET /dashboard" do | ||
5 | + subject { dashboard_path } | ||
6 | + | ||
7 | + it { should be_allowed_for :admin } | ||
8 | + it { should be_allowed_for :user } | ||
9 | + it { should be_denied_for :visitor } | ||
10 | + end | ||
11 | + | ||
12 | + describe "GET /dashboard/issues" do | ||
13 | + subject { issues_dashboard_path } | ||
14 | + | ||
15 | + it { should be_allowed_for :admin } | ||
16 | + it { should be_allowed_for :user } | ||
17 | + it { should be_denied_for :visitor } | ||
18 | + end | ||
19 | + | ||
20 | + describe "GET /dashboard/merge_requests" do | ||
21 | + subject { merge_requests_dashboard_path } | ||
22 | + | ||
23 | + it { should be_allowed_for :admin } | ||
24 | + it { should be_allowed_for :user } | ||
25 | + it { should be_denied_for :visitor } | ||
26 | + end | ||
27 | + | ||
28 | + describe "GET /dashboard/projects" do | ||
29 | + subject { projects_dashboard_path } | ||
30 | + | ||
31 | + it { should be_allowed_for :admin } | ||
32 | + it { should be_allowed_for :user } | ||
33 | + it { should be_denied_for :visitor } | ||
34 | + end | ||
35 | + | ||
36 | + describe "GET /help" do | ||
37 | + subject { help_path } | ||
38 | + | ||
39 | + it { should be_allowed_for :admin } | ||
40 | + it { should be_allowed_for :user } | ||
41 | + it { should be_denied_for :visitor } | ||
42 | + end | ||
43 | + | ||
44 | + describe "GET /projects/new" do | ||
45 | + it { new_project_path.should be_allowed_for :admin } | ||
46 | + it { new_project_path.should be_allowed_for :user } | ||
47 | + it { new_project_path.should be_denied_for :visitor } | ||
48 | + end | ||
49 | + | ||
50 | + describe "GET /groups/new" do | ||
51 | + it { new_group_path.should be_allowed_for :admin } | ||
52 | + it { new_group_path.should be_allowed_for :user } | ||
53 | + it { new_group_path.should be_denied_for :visitor } | ||
54 | + end | ||
55 | +end |