macro_policy_spec.rb 2.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105
  1. # Copyright (C) 2012-2025 Zammad Foundation, https://zammad-foundation.org/
  2. require 'rails_helper'
  3. describe MacroPolicy do
  4. subject { described_class.new(user, record) }
  5. let(:record) { create(:macro, groups:) }
  6. context 'when user is admin' do
  7. let(:user) { create(:admin) }
  8. context 'when macro is not active' do
  9. before { record.update! active: false }
  10. let(:groups) { [] }
  11. it { is_expected.to permit_actions(:show, :create, :update, :destroy) }
  12. end
  13. context 'when macro has group user does not have access to' do
  14. let(:groups) { [create(:group)] }
  15. it { is_expected.to permit_actions(:show, :create, :update, :destroy) }
  16. end
  17. end
  18. context 'when user is agent' do
  19. let(:group) { create(:group) }
  20. let(:user) { create(:agent, groups: [group]) }
  21. context 'when macro has no group' do
  22. let(:groups) { [] }
  23. it { is_expected.to permit_action(:show) }
  24. it { is_expected.to forbid_actions(:create, :update, :destroy) }
  25. context 'when macro is not active' do
  26. before { record.update! active: false }
  27. it { is_expected.to forbid_actions(:show, :create, :update, :destroy) }
  28. end
  29. end
  30. context 'when macro has group user has access to' do
  31. let(:groups) { [group, create(:group)] }
  32. it { is_expected.to permit_action(:show) }
  33. it { is_expected.to forbid_actions(:create, :update, :destroy) }
  34. context 'when macro is not active' do
  35. before { record.update! active: false }
  36. it { is_expected.to forbid_actions(:show, :create, :update, :destroy) }
  37. end
  38. end
  39. context 'when macro has group user no access to' do
  40. let(:groups) { [create(:group)] }
  41. it { is_expected.to forbid_actions(:show, :create, :update, :destroy) }
  42. end
  43. context "when macro has group user has 'read' access to" do
  44. context 'when roles are used' do
  45. let(:groups) do
  46. group = create(:group)
  47. role = create(:role, :agent)
  48. role.group_ids_access_map = { group.id => 'read' }
  49. role.save!
  50. user.roles = [role]
  51. user.save!
  52. [group]
  53. end
  54. it { is_expected.to permit_action(:show) }
  55. it { is_expected.to forbid_actions(:create, :update, :destroy) }
  56. end
  57. context 'when groups are used' do
  58. let(:groups) do
  59. group = create(:group)
  60. user.group_ids_access_map = { group.id => 'read' }
  61. user.save!
  62. [group]
  63. end
  64. it { is_expected.to permit_action(:show) }
  65. it { is_expected.to forbid_actions(:create, :update, :destroy) }
  66. end
  67. end
  68. end
  69. context 'when user is customer' do
  70. let(:user) { create(:customer) }
  71. let(:groups) { [] }
  72. it { is_expected.to forbid_actions(:show, :create, :update, :destroy) }
  73. end
  74. end