-
Notifications
You must be signed in to change notification settings - Fork 527
/
security_spec.rb
158 lines (121 loc) · 3.5 KB
/
security_spec.rb
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
require 'spec_helper'
RSpec::Matchers.define :allow do |method|
match do |subject|
subject.allow?(method)
end
end
describe Draper::Security do
subject(:security) { Draper::Security.new }
context "when newly initialized" do
it "allows any method" do
security.should allow :foo
end
end
describe "#denies" do
it "raises an error when there are no arguments" do
expect{security.denies}.to raise_error ArgumentError
end
end
context "when using denies" do
before { security.denies :foo, :bar }
it "denies the listed methods" do
security.should_not allow :foo
security.should_not allow :bar
end
it "allows other methods" do
security.should allow :baz
end
it "accepts multiple denies" do
expect{security.denies :baz}.not_to raise_error
end
it "does not accept denies_all" do
expect{security.denies_all}.to raise_error ArgumentError
end
it "does not accept allows" do
expect{security.allows :baz}.to raise_error ArgumentError
end
context "when using mulitple denies" do
before { security.denies :baz }
it "still denies the original methods" do
security.should_not allow :foo
security.should_not allow :bar
end
it "denies the additional methods" do
security.should_not allow :baz
end
it "allows other methods" do
security.should allow :qux
end
end
context "with strings" do
before { security.denies "baz" }
it "denies the method" do
security.should_not allow :baz
end
end
end
context "when using denies_all" do
before { security.denies_all }
it "denies all methods" do
security.should_not allow :foo
end
it "accepts multiple denies_all" do
expect{security.denies_all}.not_to raise_error
end
it "does not accept denies" do
expect{security.denies :baz}.to raise_error ArgumentError
end
it "does not accept allows" do
expect{security.allows :baz}.to raise_error ArgumentError
end
context "when using mulitple denies_all" do
before { security.denies_all }
it "still denies all methods" do
security.should_not allow :foo
end
end
end
describe "#allows" do
it "raises an error when there are no arguments" do
expect{security.allows}.to raise_error ArgumentError
end
end
context "when using allows" do
before { security.allows :foo, :bar }
it "allows the listed methods" do
security.should allow :foo
security.should allow :bar
end
it "denies other methods" do
security.should_not allow :baz
end
it "accepts multiple allows" do
expect{security.allows :baz}.not_to raise_error
end
it "does not accept denies" do
expect{security.denies :baz}.to raise_error ArgumentError
end
it "does not accept denies_all" do
expect{security.denies_all}.to raise_error ArgumentError
end
context "when using mulitple allows" do
before { security.allows :baz }
it "still allows the original methods" do
security.should allow :foo
security.should allow :bar
end
it "allows the additional methods" do
security.should allow :baz
end
it "denies other methods" do
security.should_not allow :qux
end
end
context "with strings" do
before { security.allows "baz" }
it "allows the method" do
security.should allow :baz
end
end
end
end