has_roles_examples.rb 7.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271
  1. # Requires: let(:group_access_instance) { ... }
  2. # Requires: let(:new_group_access_instance) { ... }
  3. RSpec.shared_examples 'HasRoles' do
  4. context 'role' do
  5. let(:group_access_instance_inactive) do
  6. group_access_instance.update!(active: false)
  7. group_access_instance
  8. end
  9. let(:role) { create(:role) }
  10. let(:group_instance) { create(:group) }
  11. let(:group_role) { create(:group) }
  12. let(:group_inactive) { create(:group, active: false) }
  13. context '#role_access?' do
  14. it 'responds to role_access?' do
  15. expect(group_access_instance).to respond_to(:role_access?)
  16. end
  17. context 'active Role' do
  18. before(:each) do
  19. role.group_names_access_map = {
  20. group_role.name => 'read',
  21. }
  22. group_access_instance.roles.push(role)
  23. group_access_instance.save
  24. end
  25. context 'Group ID parameter' do
  26. include_examples '#role_access? call' do
  27. let(:group_parameter) { group_role.id }
  28. end
  29. end
  30. context 'Group parameter' do
  31. include_examples '#role_access? call' do
  32. let(:group_parameter) { group_role }
  33. end
  34. end
  35. it 'prevents inactive Group' do
  36. role.group_names_access_map = {
  37. group_inactive.name => 'read',
  38. }
  39. expect(group_access_instance.group_access?(group_inactive.id, 'read')).to be false
  40. end
  41. end
  42. it 'prevents inactive Role' do
  43. role_inactive = create(:role, active: false)
  44. role_inactive.group_names_access_map = {
  45. group_role.name => 'read',
  46. }
  47. group_access_instance.roles.push(role_inactive)
  48. group_access_instance.save
  49. expect(group_access_instance.group_access?(group_role.id, 'read')).to be false
  50. end
  51. end
  52. context '.role_access_ids' do
  53. before(:each) do
  54. role.group_names_access_map = {
  55. group_role.name => 'read',
  56. }
  57. group_access_instance.roles.push(role)
  58. group_access_instance.save
  59. end
  60. it 'responds to role_access_ids' do
  61. expect(described_class).to respond_to(:role_access_ids)
  62. end
  63. it 'lists only active instance IDs' do
  64. role.group_names_access_map = {
  65. group_role.name => 'read',
  66. }
  67. group_access_instance_inactive.roles.push(role)
  68. group_access_instance_inactive.save
  69. group_access_instance_inactive.save
  70. result = described_class.role_access_ids(group_role.id, 'read')
  71. expect(result).not_to include(group_access_instance_inactive.id)
  72. end
  73. context 'Group ID parameter' do
  74. include_examples '.role_access_ids call' do
  75. let(:group_parameter) { group_role.id }
  76. end
  77. end
  78. context 'Group parameter' do
  79. include_examples '.role_access_ids call' do
  80. let(:group_parameter) { group_role }
  81. end
  82. end
  83. end
  84. context 'group' do
  85. before(:each) do
  86. role.group_names_access_map = {
  87. group_role.name => 'read',
  88. }
  89. group_access_instance.roles.push(role)
  90. group_access_instance.save
  91. group_access_instance.group_names_access_map = {
  92. group_instance.name => 'read',
  93. }
  94. end
  95. context '#group_access?' do
  96. it 'falls back to #role_access?' do
  97. expect(group_access_instance).to receive(:role_access?)
  98. group_access_instance.group_access?(group_role, 'read')
  99. end
  100. it "doesn't fall back to #role_access? if not needed" do
  101. expect(group_access_instance).not_to receive(:role_access?)
  102. group_access_instance.group_access?(group_instance, 'read')
  103. end
  104. end
  105. context '#group_ids_access' do
  106. before(:each) do
  107. role.group_names_access_map = {
  108. group_role.name => 'read',
  109. }
  110. group_access_instance.roles.push(role)
  111. group_access_instance.save
  112. group_access_instance.group_names_access_map = {
  113. group_instance.name => 'read',
  114. }
  115. end
  116. it 'lists only active Group IDs' do
  117. role.group_names_access_map = {
  118. group_role.name => 'read',
  119. group_inactive.name => 'read',
  120. }
  121. result = group_access_instance.group_ids_access('read')
  122. expect(result).not_to include(group_inactive.id)
  123. end
  124. context 'single access' do
  125. it 'lists access Group IDs' do
  126. result = group_access_instance.group_ids_access('read')
  127. expect(result).to include(group_role.id)
  128. end
  129. it "doesn't list for no access" do
  130. result = group_access_instance.group_ids_access('change')
  131. expect(result).not_to include(group_role.id)
  132. end
  133. it "doesn't contain duplicate IDs" do
  134. group_access_instance.group_names_access_map = {
  135. group_role.name => 'read',
  136. }
  137. result = group_access_instance.group_ids_access('read')
  138. expect(result.uniq).to eq(result)
  139. end
  140. end
  141. context 'access list' do
  142. it 'lists access Group IDs' do
  143. result = group_access_instance.group_ids_access(%w[read change])
  144. expect(result).to include(group_role.id)
  145. end
  146. it "doesn't list for no access" do
  147. result = group_access_instance.group_ids_access(%w[change create])
  148. expect(result).not_to include(group_role.id)
  149. end
  150. it "doesn't contain duplicate IDs" do
  151. group_access_instance.group_names_access_map = {
  152. group_role.name => 'read',
  153. }
  154. result = group_access_instance.group_ids_access(%w[read create])
  155. expect(result.uniq).to eq(result)
  156. end
  157. end
  158. end
  159. context '.group_access_ids' do
  160. it 'includes the result of .role_access_ids' do
  161. result = described_class.group_access_ids(group_role, 'read')
  162. expect(result).to include(group_access_instance.id)
  163. end
  164. it "doesn't contain duplicate IDs" do
  165. group_access_instance.group_names_access_map = {
  166. group_role.name => 'read',
  167. }
  168. result = described_class.group_access_ids(group_role, 'read')
  169. expect(result.uniq).to eq(result)
  170. end
  171. end
  172. end
  173. end
  174. end
  175. RSpec.shared_examples '#role_access? call' do
  176. context 'single access' do
  177. it 'checks positive' do
  178. expect(group_access_instance.role_access?(group_parameter, 'read')).to be true
  179. end
  180. it 'checks negative' do
  181. expect(group_access_instance.role_access?(group_parameter, 'change')).to be false
  182. end
  183. end
  184. context 'access list' do
  185. it 'checks positive' do
  186. expect(group_access_instance.role_access?(group_parameter, %w[read change])).to be true
  187. end
  188. it 'checks negative' do
  189. expect(group_access_instance.role_access?(group_parameter, %w[change create])).to be false
  190. end
  191. end
  192. end
  193. RSpec.shared_examples '.role_access_ids call' do
  194. context 'single access' do
  195. it 'lists access IDs' do
  196. expect(described_class.role_access_ids(group_parameter, 'read')).to include(group_access_instance.id)
  197. end
  198. it 'excludes non access IDs' do
  199. expect(described_class.role_access_ids(group_parameter, 'change')).not_to include(group_access_instance.id)
  200. end
  201. end
  202. context 'access list' do
  203. it 'lists access IDs' do
  204. expect(described_class.role_access_ids(group_parameter, %w[read change])).to include(group_access_instance.id)
  205. end
  206. it 'excludes non access IDs' do
  207. expect(described_class.role_access_ids(group_parameter, %w[change create])).not_to include(group_access_instance.id)
  208. end
  209. end
  210. end