diff options
| author | erdgeist <erdgeist@erdgeist.org> | 2026-07-31 18:14:30 +0200 |
|---|---|---|
| committer | erdgeist <erdgeist@erdgeist.org> | 2026-07-31 18:14:30 +0200 |
| commit | 464af1625349d557f688da9f845471ef8b80a5f9 (patch) | |
| tree | aab415abf115f20ccbcdfad49c27ce5d1bd61134 /test/controllers | |
| parent | 8c6a6516e1dc5c1b4f12740a6f7b32765b530bb7 (diff) | |
Gate live-content changes on restricted surfaces
publish_draft!, trash!, destroy_from_trash!, attach_asset! and
Asset#destroy_witnessed! now refuse unless the acting user holds redaktion,
and only when the subject is on a restricted surface: the front page, the
updates tree that feeds ~100k subscribers, or disclosure. Drafting,
autosaving, tagging and creating stay free everywhere for everyone.
Enforcement is in the models rather than the controllers, since attach_asset!
and the rest are reachable from rake tasks and internal paths. It follows the
errors.add-plus-bare-raise pattern the rest of Node already uses, so every
existing RecordInvalid rescue reports it with a localised message; only
assets_controller#destroy needed a rescue added.
A nil user is treated as a system context and bypasses the gate. The default
nil on three of those verbs is what makes that reachable, and removing those
defaults once every call site passes a user is the next tightening.
Diffstat (limited to 'test/controllers')
| -rw-r--r-- | test/controllers/nodes_controller_test.rb | 14 |
1 files changed, 14 insertions, 0 deletions
diff --git a/test/controllers/nodes_controller_test.rb b/test/controllers/nodes_controller_test.rb index 0b6e65ee..f15be067 100644 --- a/test/controllers/nodes_controller_test.rb +++ b/test/controllers/nodes_controller_test.rb | |||
| @@ -770,6 +770,20 @@ class NodesControllerTest < ActionController::TestCase | |||
| 770 | assert_select "form[action=?]", node_path(node), count: 1 | 770 | assert_select "form[action=?]", node_path(node), count: 1 |
| 771 | end | 771 | end |
| 772 | 772 | ||
| 773 | test "publishing a restricted node without the redaktion role flashes and does not publish" do | ||
| 774 | login_as :quentin | ||
| 775 | updates = Node.root.children.create!(:slug => "updates") | ||
| 776 | node = updates.children.create!(:slug => "controller-gated") | ||
| 777 | node.reload.draft.update!(:title => "Entwurf") | ||
| 778 | |||
| 779 | put :publish, params: { :id => node.id } | ||
| 780 | |||
| 781 | assert_redirected_to node_path(node) | ||
| 782 | assert_match I18n.t("activerecord.errors.models.node.attributes.base.not_permitted"), | ||
| 783 | flash[:error] | ||
| 784 | assert_nil node.reload.head | ||
| 785 | end | ||
| 786 | |||
| 773 | test "show annotates history rows with their lifecycle" do | 787 | test "show annotates history rows with their lifecycle" do |
| 774 | login_as :quentin | 788 | login_as :quentin |
| 775 | node = Node.root.children.create!(:slug => "history_annotation_test") | 789 | node = Node.root.children.create!(:slug => "history_annotation_test") |
