Commit 6954d50fd3307f25f16ac06f21aebe37cb7059db
1 parent
ea779cc5
Exists in
master
and in
4 other branches
Dashboard security specs
Showing
1 changed file
with
55 additions
and
0 deletions
Show diff stats
| @@ -0,0 +1,55 @@ | @@ -0,0 +1,55 @@ | ||
| 1 | +require 'spec_helper' | ||
| 2 | + | ||
| 3 | +describe "Dashboard access" do | ||
| 4 | + describe "GET /dashboard" do | ||
| 5 | + subject { dashboard_path } | ||
| 6 | + | ||
| 7 | + it { should be_allowed_for :admin } | ||
| 8 | + it { should be_allowed_for :user } | ||
| 9 | + it { should be_denied_for :visitor } | ||
| 10 | + end | ||
| 11 | + | ||
| 12 | + describe "GET /dashboard/issues" do | ||
| 13 | + subject { issues_dashboard_path } | ||
| 14 | + | ||
| 15 | + it { should be_allowed_for :admin } | ||
| 16 | + it { should be_allowed_for :user } | ||
| 17 | + it { should be_denied_for :visitor } | ||
| 18 | + end | ||
| 19 | + | ||
| 20 | + describe "GET /dashboard/merge_requests" do | ||
| 21 | + subject { merge_requests_dashboard_path } | ||
| 22 | + | ||
| 23 | + it { should be_allowed_for :admin } | ||
| 24 | + it { should be_allowed_for :user } | ||
| 25 | + it { should be_denied_for :visitor } | ||
| 26 | + end | ||
| 27 | + | ||
| 28 | + describe "GET /dashboard/projects" do | ||
| 29 | + subject { projects_dashboard_path } | ||
| 30 | + | ||
| 31 | + it { should be_allowed_for :admin } | ||
| 32 | + it { should be_allowed_for :user } | ||
| 33 | + it { should be_denied_for :visitor } | ||
| 34 | + end | ||
| 35 | + | ||
| 36 | + describe "GET /help" do | ||
| 37 | + subject { help_path } | ||
| 38 | + | ||
| 39 | + it { should be_allowed_for :admin } | ||
| 40 | + it { should be_allowed_for :user } | ||
| 41 | + it { should be_denied_for :visitor } | ||
| 42 | + end | ||
| 43 | + | ||
| 44 | + describe "GET /projects/new" do | ||
| 45 | + it { new_project_path.should be_allowed_for :admin } | ||
| 46 | + it { new_project_path.should be_allowed_for :user } | ||
| 47 | + it { new_project_path.should be_denied_for :visitor } | ||
| 48 | + end | ||
| 49 | + | ||
| 50 | + describe "GET /groups/new" do | ||
| 51 | + it { new_group_path.should be_allowed_for :admin } | ||
| 52 | + it { new_group_path.should be_allowed_for :user } | ||
| 53 | + it { new_group_path.should be_denied_for :visitor } | ||
| 54 | + end | ||
| 55 | +end |