2019-08-09 17:25:12 +03:00
|
|
|
const should = require('should');
|
2019-10-31 14:10:14 +03:00
|
|
|
const sinon = require('sinon');
|
|
|
|
const moment = require('moment');
|
2019-08-09 17:25:12 +03:00
|
|
|
const supertest = require('supertest');
|
|
|
|
const _ = require('lodash');
|
2020-03-30 18:26:47 +03:00
|
|
|
const labs = require('../../../../../core/server/services/labs');
|
2019-08-09 17:25:12 +03:00
|
|
|
const testUtils = require('../../../../utils');
|
|
|
|
const localUtils = require('./utils');
|
|
|
|
const configUtils = require('../../../../utils/configUtils');
|
|
|
|
const urlUtils = require('../../../../utils/urlUtils');
|
2020-05-27 20:47:53 +03:00
|
|
|
const config = require('../../../../../core/shared/config');
|
2019-08-09 17:25:12 +03:00
|
|
|
|
|
|
|
const ghost = testUtils.startGhost;
|
|
|
|
let request;
|
|
|
|
|
2019-08-13 07:15:22 +03:00
|
|
|
describe('api/canary/content/posts', function () {
|
2019-08-09 17:25:12 +03:00
|
|
|
before(function () {
|
|
|
|
return ghost()
|
|
|
|
.then(function () {
|
|
|
|
request = supertest.agent(config.get('url'));
|
|
|
|
})
|
|
|
|
.then(function () {
|
|
|
|
return testUtils.initFixtures('users:no-owner', 'user:inactive', 'posts', 'tags:extra', 'api_keys');
|
|
|
|
});
|
|
|
|
});
|
|
|
|
|
|
|
|
afterEach(function () {
|
|
|
|
configUtils.restore();
|
|
|
|
urlUtils.restore();
|
|
|
|
});
|
|
|
|
|
|
|
|
const validKey = localUtils.getValidKey();
|
|
|
|
|
2019-09-02 14:51:43 +03:00
|
|
|
it('browse posts', function (done) {
|
|
|
|
request.get(localUtils.API.getApiQuery(`posts/?key=${validKey}`))
|
|
|
|
.set('Origin', testUtils.API.getURL())
|
|
|
|
.expect('Content-Type', /json/)
|
|
|
|
.expect('Cache-Control', testUtils.cacheRules.private)
|
|
|
|
.expect(200)
|
|
|
|
.end(function (err, res) {
|
|
|
|
if (err) {
|
|
|
|
return done(err);
|
|
|
|
}
|
|
|
|
|
|
|
|
res.headers.vary.should.eql('Accept-Encoding');
|
|
|
|
should.exist(res.headers['access-control-allow-origin']);
|
|
|
|
should.not.exist(res.headers['x-cache-invalidate']);
|
|
|
|
|
2020-04-29 18:44:27 +03:00
|
|
|
const jsonResponse = res.body;
|
2019-09-02 14:51:43 +03:00
|
|
|
should.exist(jsonResponse.posts);
|
|
|
|
localUtils.API.checkResponse(jsonResponse, 'posts');
|
|
|
|
jsonResponse.posts.should.have.length(11);
|
|
|
|
localUtils.API.checkResponse(jsonResponse.posts[0], 'post');
|
|
|
|
localUtils.API.checkResponse(jsonResponse.meta.pagination, 'pagination');
|
|
|
|
_.isBoolean(jsonResponse.posts[0].featured).should.eql(true);
|
|
|
|
|
|
|
|
// Default order 'published_at desc' check
|
|
|
|
jsonResponse.posts[0].slug.should.eql('welcome');
|
2021-03-10 17:19:11 +03:00
|
|
|
jsonResponse.posts[6].slug.should.eql('integrations');
|
2019-09-02 14:51:43 +03:00
|
|
|
|
|
|
|
// check meta response for this test
|
|
|
|
jsonResponse.meta.pagination.page.should.eql(1);
|
|
|
|
jsonResponse.meta.pagination.limit.should.eql(15);
|
|
|
|
jsonResponse.meta.pagination.pages.should.eql(1);
|
|
|
|
jsonResponse.meta.pagination.total.should.eql(11);
|
|
|
|
jsonResponse.meta.pagination.hasOwnProperty('next').should.be.true();
|
|
|
|
jsonResponse.meta.pagination.hasOwnProperty('prev').should.be.true();
|
|
|
|
should.not.exist(jsonResponse.meta.pagination.next);
|
|
|
|
should.not.exist(jsonResponse.meta.pagination.prev);
|
|
|
|
|
|
|
|
done();
|
|
|
|
});
|
|
|
|
});
|
|
|
|
|
|
|
|
it('browse posts with related authors/tags also returns primary_author/primary_tag', function (done) {
|
|
|
|
request.get(localUtils.API.getApiQuery(`posts/?key=${validKey}&include=authors,tags`))
|
|
|
|
.set('Origin', testUtils.API.getURL())
|
|
|
|
.expect('Content-Type', /json/)
|
|
|
|
.expect('Cache-Control', testUtils.cacheRules.private)
|
|
|
|
.expect(200)
|
|
|
|
.end(function (err, res) {
|
|
|
|
if (err) {
|
|
|
|
return done(err);
|
|
|
|
}
|
|
|
|
|
|
|
|
res.headers.vary.should.eql('Accept-Encoding');
|
|
|
|
should.exist(res.headers['access-control-allow-origin']);
|
|
|
|
should.not.exist(res.headers['x-cache-invalidate']);
|
|
|
|
|
2020-04-29 18:44:27 +03:00
|
|
|
const jsonResponse = res.body;
|
2019-09-02 14:51:43 +03:00
|
|
|
should.exist(jsonResponse.posts);
|
|
|
|
localUtils.API.checkResponse(jsonResponse, 'posts');
|
|
|
|
jsonResponse.posts.should.have.length(11);
|
|
|
|
localUtils.API.checkResponse(
|
|
|
|
jsonResponse.posts[0],
|
|
|
|
'post',
|
|
|
|
['authors', 'tags', 'primary_tag', 'primary_author'],
|
|
|
|
null
|
|
|
|
);
|
|
|
|
|
|
|
|
localUtils.API.checkResponse(jsonResponse.meta.pagination, 'pagination');
|
|
|
|
_.isBoolean(jsonResponse.posts[0].featured).should.eql(true);
|
|
|
|
|
|
|
|
// Default order 'published_at desc' check
|
|
|
|
jsonResponse.posts[0].slug.should.eql('welcome');
|
2021-03-10 17:19:11 +03:00
|
|
|
jsonResponse.posts[6].slug.should.eql('integrations');
|
2019-09-02 14:51:43 +03:00
|
|
|
|
|
|
|
// check meta response for this test
|
|
|
|
jsonResponse.meta.pagination.page.should.eql(1);
|
|
|
|
jsonResponse.meta.pagination.limit.should.eql(15);
|
|
|
|
jsonResponse.meta.pagination.pages.should.eql(1);
|
|
|
|
jsonResponse.meta.pagination.total.should.eql(11);
|
|
|
|
jsonResponse.meta.pagination.hasOwnProperty('next').should.be.true();
|
|
|
|
jsonResponse.meta.pagination.hasOwnProperty('prev').should.be.true();
|
|
|
|
should.not.exist(jsonResponse.meta.pagination.next);
|
|
|
|
should.not.exist(jsonResponse.meta.pagination.prev);
|
|
|
|
|
|
|
|
done();
|
|
|
|
});
|
|
|
|
});
|
|
|
|
|
2019-08-09 17:25:12 +03:00
|
|
|
it('browse posts with basic page filter should not return pages', function (done) {
|
|
|
|
request.get(localUtils.API.getApiQuery(`posts/?key=${validKey}&filter=page:true`))
|
|
|
|
.expect('Content-Type', /json/)
|
|
|
|
.expect('Cache-Control', testUtils.cacheRules.private)
|
|
|
|
.expect(200)
|
|
|
|
.end(function (err, res) {
|
|
|
|
if (err) {
|
|
|
|
return done(err);
|
|
|
|
}
|
|
|
|
const jsonResponse = res.body;
|
|
|
|
|
|
|
|
should.not.exist(res.headers['x-cache-invalidate']);
|
|
|
|
should.exist(jsonResponse.posts);
|
|
|
|
localUtils.API.checkResponse(jsonResponse, 'posts');
|
|
|
|
localUtils.API.checkResponse(jsonResponse.meta.pagination, 'pagination');
|
|
|
|
jsonResponse.posts.should.have.length(0);
|
|
|
|
|
|
|
|
done();
|
|
|
|
});
|
|
|
|
});
|
|
|
|
|
|
|
|
it('browse posts with basic page filter should not return pages', function (done) {
|
|
|
|
request.get(localUtils.API.getApiQuery(`posts/?key=${validKey}&filter=page:true,featured:true`))
|
|
|
|
.expect('Content-Type', /json/)
|
|
|
|
.expect('Cache-Control', testUtils.cacheRules.private)
|
|
|
|
.expect(200)
|
|
|
|
.end(function (err, res) {
|
|
|
|
if (err) {
|
|
|
|
return done(err);
|
|
|
|
}
|
|
|
|
const jsonResponse = res.body;
|
|
|
|
|
|
|
|
should.not.exist(res.headers['x-cache-invalidate']);
|
|
|
|
should.exist(jsonResponse.posts);
|
|
|
|
localUtils.API.checkResponse(jsonResponse, 'posts');
|
|
|
|
localUtils.API.checkResponse(jsonResponse.meta.pagination, 'pagination');
|
|
|
|
jsonResponse.posts.should.have.length(2);
|
|
|
|
jsonResponse.posts.filter(p => (p.page === true)).should.have.length(0);
|
|
|
|
|
|
|
|
done();
|
|
|
|
});
|
|
|
|
});
|
|
|
|
|
|
|
|
it('browse posts with published and draft status, should not return drafts', function (done) {
|
|
|
|
request.get(localUtils.API.getApiQuery(`posts/?key=${validKey}&filter=status:published,status:draft`))
|
|
|
|
.expect('Content-Type', /json/)
|
|
|
|
.expect('Cache-Control', testUtils.cacheRules.private)
|
|
|
|
.expect(200)
|
|
|
|
.end(function (err, res) {
|
|
|
|
if (err) {
|
|
|
|
return done(err);
|
|
|
|
}
|
|
|
|
const jsonResponse = res.body;
|
|
|
|
|
|
|
|
jsonResponse.posts.should.be.an.Array().with.lengthOf(11);
|
|
|
|
|
|
|
|
done();
|
|
|
|
});
|
|
|
|
});
|
|
|
|
|
Updated Content API resource ordering to be same as slugs in filter
closes #11994
- Adds support for ordering based on slug filter that contains a slug-is-in filter. It is applied only to Content API's resources - post, page, tag, author. The order is applied in the same order in which slugs appear in the filter.
- For, example providing following query parameter filter for any of the above resources: `?filter=slug:[kitchen-sink,bacon,chorizo]`, would filter them by these slugs and order in the same way defined in the filter
- Can be used in handlebars templates in following way: `{{#get "tags" filter="slug:[slugs,of,the,tags,in,order]"}}`
- The property conteining this new order is assigned to `autoOrder` instead of `rawOrder` intentionally. This explicit asstignment would allow distinguishing where the 'orderRaw' comes from the model or the API layer. Apart from adding necessary context this separation makes it easier to refactor separately model layer and API specific ordering in the future
- This commit also fixes default filtering for `author` resource in Content API. The serializer was never used before as it was missing from `serializers/index.js` module.
2020-07-10 09:33:00 +03:00
|
|
|
it('browse posts with slug filter, should order in slug order', function () {
|
2021-03-10 17:19:11 +03:00
|
|
|
return request.get(localUtils.API.getApiQuery(`posts/?key=${validKey}&filter=slug:[write,ghostly-kitchen-sink,grow]`))
|
Updated Content API resource ordering to be same as slugs in filter
closes #11994
- Adds support for ordering based on slug filter that contains a slug-is-in filter. It is applied only to Content API's resources - post, page, tag, author. The order is applied in the same order in which slugs appear in the filter.
- For, example providing following query parameter filter for any of the above resources: `?filter=slug:[kitchen-sink,bacon,chorizo]`, would filter them by these slugs and order in the same way defined in the filter
- Can be used in handlebars templates in following way: `{{#get "tags" filter="slug:[slugs,of,the,tags,in,order]"}}`
- The property conteining this new order is assigned to `autoOrder` instead of `rawOrder` intentionally. This explicit asstignment would allow distinguishing where the 'orderRaw' comes from the model or the API layer. Apart from adding necessary context this separation makes it easier to refactor separately model layer and API specific ordering in the future
- This commit also fixes default filtering for `author` resource in Content API. The serializer was never used before as it was missing from `serializers/index.js` module.
2020-07-10 09:33:00 +03:00
|
|
|
.expect('Content-Type', /json/)
|
|
|
|
.expect('Cache-Control', testUtils.cacheRules.private)
|
|
|
|
.expect(200)
|
|
|
|
.then((res) => {
|
|
|
|
const jsonResponse = res.body;
|
|
|
|
|
|
|
|
jsonResponse.posts.should.be.an.Array().with.lengthOf(3);
|
2021-03-10 17:19:11 +03:00
|
|
|
jsonResponse.posts[0].slug.should.equal('write');
|
Updated Content API resource ordering to be same as slugs in filter
closes #11994
- Adds support for ordering based on slug filter that contains a slug-is-in filter. It is applied only to Content API's resources - post, page, tag, author. The order is applied in the same order in which slugs appear in the filter.
- For, example providing following query parameter filter for any of the above resources: `?filter=slug:[kitchen-sink,bacon,chorizo]`, would filter them by these slugs and order in the same way defined in the filter
- Can be used in handlebars templates in following way: `{{#get "tags" filter="slug:[slugs,of,the,tags,in,order]"}}`
- The property conteining this new order is assigned to `autoOrder` instead of `rawOrder` intentionally. This explicit asstignment would allow distinguishing where the 'orderRaw' comes from the model or the API layer. Apart from adding necessary context this separation makes it easier to refactor separately model layer and API specific ordering in the future
- This commit also fixes default filtering for `author` resource in Content API. The serializer was never used before as it was missing from `serializers/index.js` module.
2020-07-10 09:33:00 +03:00
|
|
|
jsonResponse.posts[1].slug.should.equal('ghostly-kitchen-sink');
|
2021-03-10 17:19:11 +03:00
|
|
|
jsonResponse.posts[2].slug.should.equal('grow');
|
Updated Content API resource ordering to be same as slugs in filter
closes #11994
- Adds support for ordering based on slug filter that contains a slug-is-in filter. It is applied only to Content API's resources - post, page, tag, author. The order is applied in the same order in which slugs appear in the filter.
- For, example providing following query parameter filter for any of the above resources: `?filter=slug:[kitchen-sink,bacon,chorizo]`, would filter them by these slugs and order in the same way defined in the filter
- Can be used in handlebars templates in following way: `{{#get "tags" filter="slug:[slugs,of,the,tags,in,order]"}}`
- The property conteining this new order is assigned to `autoOrder` instead of `rawOrder` intentionally. This explicit asstignment would allow distinguishing where the 'orderRaw' comes from the model or the API layer. Apart from adding necessary context this separation makes it easier to refactor separately model layer and API specific ordering in the future
- This commit also fixes default filtering for `author` resource in Content API. The serializer was never used before as it was missing from `serializers/index.js` module.
2020-07-10 09:33:00 +03:00
|
|
|
});
|
|
|
|
});
|
|
|
|
|
|
|
|
it('browse posts with slug filter should order taking order parameter into account', function () {
|
2021-03-10 17:19:11 +03:00
|
|
|
return request.get(localUtils.API.getApiQuery(`posts/?key=${validKey}&order=slug%20DESC&filter=slug:[write,ghostly-kitchen-sink,grow]`))
|
Updated Content API resource ordering to be same as slugs in filter
closes #11994
- Adds support for ordering based on slug filter that contains a slug-is-in filter. It is applied only to Content API's resources - post, page, tag, author. The order is applied in the same order in which slugs appear in the filter.
- For, example providing following query parameter filter for any of the above resources: `?filter=slug:[kitchen-sink,bacon,chorizo]`, would filter them by these slugs and order in the same way defined in the filter
- Can be used in handlebars templates in following way: `{{#get "tags" filter="slug:[slugs,of,the,tags,in,order]"}}`
- The property conteining this new order is assigned to `autoOrder` instead of `rawOrder` intentionally. This explicit asstignment would allow distinguishing where the 'orderRaw' comes from the model or the API layer. Apart from adding necessary context this separation makes it easier to refactor separately model layer and API specific ordering in the future
- This commit also fixes default filtering for `author` resource in Content API. The serializer was never used before as it was missing from `serializers/index.js` module.
2020-07-10 09:33:00 +03:00
|
|
|
.expect('Content-Type', /json/)
|
|
|
|
.expect('Cache-Control', testUtils.cacheRules.private)
|
|
|
|
.expect(200)
|
|
|
|
.then((res) => {
|
|
|
|
const jsonResponse = res.body;
|
|
|
|
|
|
|
|
jsonResponse.posts.should.be.an.Array().with.lengthOf(3);
|
2021-03-10 17:19:11 +03:00
|
|
|
jsonResponse.posts[0].slug.should.equal('write');
|
|
|
|
jsonResponse.posts[1].slug.should.equal('grow');
|
Updated Content API resource ordering to be same as slugs in filter
closes #11994
- Adds support for ordering based on slug filter that contains a slug-is-in filter. It is applied only to Content API's resources - post, page, tag, author. The order is applied in the same order in which slugs appear in the filter.
- For, example providing following query parameter filter for any of the above resources: `?filter=slug:[kitchen-sink,bacon,chorizo]`, would filter them by these slugs and order in the same way defined in the filter
- Can be used in handlebars templates in following way: `{{#get "tags" filter="slug:[slugs,of,the,tags,in,order]"}}`
- The property conteining this new order is assigned to `autoOrder` instead of `rawOrder` intentionally. This explicit asstignment would allow distinguishing where the 'orderRaw' comes from the model or the API layer. Apart from adding necessary context this separation makes it easier to refactor separately model layer and API specific ordering in the future
- This commit also fixes default filtering for `author` resource in Content API. The serializer was never used before as it was missing from `serializers/index.js` module.
2020-07-10 09:33:00 +03:00
|
|
|
jsonResponse.posts[2].slug.should.equal('ghostly-kitchen-sink');
|
|
|
|
});
|
|
|
|
});
|
|
|
|
|
2019-08-09 17:25:12 +03:00
|
|
|
it('ensure origin header on redirect is not getting lost', function (done) {
|
|
|
|
// NOTE: force a redirect to the admin url
|
|
|
|
configUtils.set('admin:url', 'http://localhost:9999');
|
|
|
|
urlUtils.stubUrlUtilsFromConfig();
|
|
|
|
|
|
|
|
request.get(localUtils.API.getApiQuery(`posts?key=${validKey}`))
|
|
|
|
.set('Origin', 'https://example.com')
|
|
|
|
// 301 Redirects _should_ be cached
|
|
|
|
.expect('Cache-Control', testUtils.cacheRules.year)
|
|
|
|
.expect(301)
|
|
|
|
.end(function (err, res) {
|
|
|
|
if (err) {
|
|
|
|
return done(err);
|
|
|
|
}
|
|
|
|
|
|
|
|
res.headers.vary.should.eql('Accept, Accept-Encoding');
|
|
|
|
res.headers.location.should.eql(`http://localhost:9999/ghost/api/canary/content/posts/?key=${validKey}`);
|
|
|
|
should.exist(res.headers['access-control-allow-origin']);
|
|
|
|
should.not.exist(res.headers['x-cache-invalidate']);
|
|
|
|
done();
|
|
|
|
});
|
|
|
|
});
|
|
|
|
|
|
|
|
it('can\'t read page', function () {
|
|
|
|
return request
|
|
|
|
.get(localUtils.API.getApiQuery(`posts/${testUtils.DataGenerator.Content.posts[5].id}/?key=${validKey}`))
|
|
|
|
.set('Origin', testUtils.API.getURL())
|
|
|
|
.expect('Content-Type', /json/)
|
|
|
|
.expect('Cache-Control', testUtils.cacheRules.private)
|
|
|
|
.expect(404);
|
|
|
|
});
|
|
|
|
|
|
|
|
it('can read post with fields', function () {
|
2021-03-17 09:12:40 +03:00
|
|
|
const complexPostId = testUtils.DataGenerator.Content.posts.find(p => p.slug === 'not-so-short-bit-complex').id;
|
|
|
|
|
2019-08-09 17:25:12 +03:00
|
|
|
return request
|
2021-03-17 09:12:40 +03:00
|
|
|
.get(localUtils.API.getApiQuery(`posts/${complexPostId}/?key=${validKey}&fields=title,slug,excerpt&formats=plaintext`))
|
2019-08-09 17:25:12 +03:00
|
|
|
.set('Origin', testUtils.API.getURL())
|
|
|
|
.expect('Content-Type', /json/)
|
|
|
|
.expect('Cache-Control', testUtils.cacheRules.private)
|
|
|
|
.expect(200)
|
|
|
|
.then((res) => {
|
2021-03-17 09:12:40 +03:00
|
|
|
localUtils.API.checkResponse(res.body.posts[0], 'post', null, null, ['id', 'title', 'slug', 'excerpt', 'plaintext']);
|
|
|
|
|
|
|
|
// excerpt should transform links to absolute URLs
|
|
|
|
res.body.posts[0].excerpt.should.match(/\* Aliquam \[http:\/\/127.0.0.1:2369\/about#nowhere\]/);
|
2019-08-09 17:25:12 +03:00
|
|
|
});
|
|
|
|
});
|
2019-10-31 14:10:14 +03:00
|
|
|
|
|
|
|
describe('content gating', function () {
|
2020-01-08 16:43:21 +03:00
|
|
|
let publicPost;
|
2019-10-31 14:10:14 +03:00
|
|
|
let membersPost;
|
|
|
|
let paidPost;
|
2021-02-18 02:00:26 +03:00
|
|
|
let membersPostWithPaywallCard;
|
2019-10-31 14:10:14 +03:00
|
|
|
|
|
|
|
before(function () {
|
|
|
|
// NOTE: ideally this would be set through Admin API request not a stub
|
|
|
|
sinon.stub(labs, 'isSet').withArgs('members').returns(true);
|
|
|
|
});
|
|
|
|
|
|
|
|
before (function () {
|
2020-01-08 16:43:21 +03:00
|
|
|
publicPost = testUtils.DataGenerator.forKnex.createPost({
|
|
|
|
slug: 'free-to-see',
|
|
|
|
visibility: 'public',
|
|
|
|
published_at: moment().add(15, 'seconds').toDate() // here to ensure sorting is not modified
|
|
|
|
});
|
|
|
|
|
2019-10-31 14:10:14 +03:00
|
|
|
membersPost = testUtils.DataGenerator.forKnex.createPost({
|
|
|
|
slug: 'thou-shalt-not-be-seen',
|
|
|
|
visibility: 'members',
|
|
|
|
published_at: moment().add(45, 'seconds').toDate() // here to ensure sorting is not modified
|
|
|
|
});
|
|
|
|
|
|
|
|
paidPost = testUtils.DataGenerator.forKnex.createPost({
|
|
|
|
slug: 'thou-shalt-be-paid-for',
|
|
|
|
visibility: 'paid',
|
|
|
|
published_at: moment().add(30, 'seconds').toDate() // here to ensure sorting is not modified
|
|
|
|
});
|
|
|
|
|
2021-02-18 02:00:26 +03:00
|
|
|
membersPostWithPaywallCard = testUtils.DataGenerator.forKnex.createPost({
|
|
|
|
slug: 'thou-shalt-have-a-taste',
|
|
|
|
visibility: 'members',
|
|
|
|
mobiledoc: '{"version":"0.3.1","markups":[],"atoms":[],"cards":[["paywall",{}]],"sections":[[1,"p",[[0,[],0,"Free content"]]],[10,0],[1,"p",[[0,[],0,"Members content"]]]]}',
|
|
|
|
html: '<p>Free content</p><!--members-only--><p>Members content</p>',
|
|
|
|
published_at: moment().add(5, 'seconds').toDate()
|
|
|
|
});
|
|
|
|
|
2019-10-31 14:10:14 +03:00
|
|
|
return testUtils.fixtures.insertPosts([
|
2020-01-08 16:43:21 +03:00
|
|
|
publicPost,
|
2019-10-31 14:10:14 +03:00
|
|
|
membersPost,
|
2021-02-18 02:00:26 +03:00
|
|
|
paidPost,
|
|
|
|
membersPostWithPaywallCard
|
2019-10-31 14:10:14 +03:00
|
|
|
]);
|
|
|
|
});
|
|
|
|
|
2020-01-08 16:43:21 +03:00
|
|
|
it('public post fields are always visible', function () {
|
|
|
|
return request
|
|
|
|
.get(localUtils.API.getApiQuery(`posts/${publicPost.id}/?key=${validKey}&fields=slug,html,plaintext&formats=html,plaintext`))
|
|
|
|
.set('Origin', testUtils.API.getURL())
|
|
|
|
.expect('Content-Type', /json/)
|
|
|
|
.expect('Cache-Control', testUtils.cacheRules.private)
|
|
|
|
.expect(200)
|
|
|
|
.then((res) => {
|
|
|
|
const jsonResponse = res.body;
|
|
|
|
should.exist(jsonResponse.posts);
|
|
|
|
const post = jsonResponse.posts[0];
|
|
|
|
|
|
|
|
localUtils.API.checkResponse(post, 'post', null, null, ['id', 'slug', 'html', 'plaintext']);
|
|
|
|
post.slug.should.eql('free-to-see');
|
|
|
|
post.html.should.not.eql('');
|
|
|
|
post.plaintext.should.not.eql('');
|
|
|
|
});
|
|
|
|
});
|
|
|
|
|
2019-10-31 14:10:14 +03:00
|
|
|
it('cannot read members only post content', function () {
|
|
|
|
return request
|
|
|
|
.get(localUtils.API.getApiQuery(`posts/${membersPost.id}/?key=${validKey}`))
|
|
|
|
.set('Origin', testUtils.API.getURL())
|
|
|
|
.expect('Content-Type', /json/)
|
|
|
|
.expect('Cache-Control', testUtils.cacheRules.private)
|
|
|
|
.expect(200)
|
|
|
|
.then((res) => {
|
|
|
|
const jsonResponse = res.body;
|
|
|
|
should.exist(jsonResponse.posts);
|
|
|
|
const post = jsonResponse.posts[0];
|
|
|
|
|
2020-07-06 15:00:15 +03:00
|
|
|
localUtils.API.checkResponse(post, 'post', null, null);
|
2019-10-31 14:10:14 +03:00
|
|
|
post.slug.should.eql('thou-shalt-not-be-seen');
|
|
|
|
post.html.should.eql('');
|
2021-02-18 17:12:06 +03:00
|
|
|
post.excerpt.should.eql('');
|
2019-10-31 14:10:14 +03:00
|
|
|
});
|
|
|
|
});
|
|
|
|
|
|
|
|
it('cannot read paid only post content', function () {
|
|
|
|
return request
|
|
|
|
.get(localUtils.API.getApiQuery(`posts/${paidPost.id}/?key=${validKey}`))
|
|
|
|
.set('Origin', testUtils.API.getURL())
|
|
|
|
.expect('Content-Type', /json/)
|
|
|
|
.expect('Cache-Control', testUtils.cacheRules.private)
|
|
|
|
.expect(200)
|
|
|
|
.then((res) => {
|
|
|
|
const jsonResponse = res.body;
|
|
|
|
should.exist(jsonResponse.posts);
|
|
|
|
const post = jsonResponse.posts[0];
|
|
|
|
|
2020-07-06 15:00:15 +03:00
|
|
|
localUtils.API.checkResponse(post, 'post', null, null);
|
2019-10-31 14:10:14 +03:00
|
|
|
post.slug.should.eql('thou-shalt-be-paid-for');
|
|
|
|
post.html.should.eql('');
|
2021-02-18 17:12:06 +03:00
|
|
|
post.excerpt.should.eql('');
|
2019-10-31 14:10:14 +03:00
|
|
|
});
|
|
|
|
});
|
|
|
|
|
|
|
|
it('cannot read members only post plaintext', function () {
|
|
|
|
return request
|
|
|
|
.get(localUtils.API.getApiQuery(`posts/${membersPost.id}/?key=${validKey}&formats=html,plaintext&fields=html,plaintext`))
|
|
|
|
.set('Origin', testUtils.API.getURL())
|
|
|
|
.expect('Content-Type', /json/)
|
|
|
|
.expect('Cache-Control', testUtils.cacheRules.private)
|
|
|
|
.expect(200)
|
|
|
|
.then((res) => {
|
|
|
|
const jsonResponse = res.body;
|
|
|
|
should.exist(jsonResponse.posts);
|
|
|
|
const post = jsonResponse.posts[0];
|
|
|
|
|
|
|
|
localUtils.API.checkResponse(post, 'post', null, null, ['id', 'html', 'plaintext']);
|
|
|
|
post.html.should.eql('');
|
|
|
|
post.plaintext.should.eql('');
|
|
|
|
});
|
|
|
|
});
|
|
|
|
|
2021-02-18 02:00:26 +03:00
|
|
|
it('can read "free" html and plaintext content of members post when using paywall card', function () {
|
|
|
|
return request
|
2021-02-18 17:12:06 +03:00
|
|
|
.get(localUtils.API.getApiQuery(`posts/${membersPostWithPaywallCard.id}/?key=${validKey}&formats=html,plaintext`))
|
2021-02-18 02:00:26 +03:00
|
|
|
.set('Origin', testUtils.API.getURL())
|
|
|
|
.expect('Content-Type', /json/)
|
|
|
|
.expect('Cache-Control', testUtils.cacheRules.private)
|
|
|
|
.expect(200)
|
|
|
|
.then((res) => {
|
|
|
|
const jsonResponse = res.body;
|
|
|
|
should.exist(jsonResponse.posts);
|
|
|
|
const post = jsonResponse.posts[0];
|
|
|
|
|
2021-02-18 17:12:06 +03:00
|
|
|
localUtils.API.checkResponse(post, 'post', ['plaintext']);
|
2021-02-18 02:00:26 +03:00
|
|
|
post.html.should.eql('<p>Free content</p>');
|
|
|
|
post.plaintext.should.eql('Free content');
|
2021-02-18 17:12:06 +03:00
|
|
|
post.excerpt.should.eql('Free content');
|
2021-02-18 02:00:26 +03:00
|
|
|
});
|
|
|
|
});
|
|
|
|
|
2019-10-31 14:10:14 +03:00
|
|
|
it('cannot browse members only posts content', function () {
|
|
|
|
return request.get(localUtils.API.getApiQuery(`posts/?key=${validKey}`))
|
|
|
|
.set('Origin', testUtils.API.getURL())
|
|
|
|
.expect('Content-Type', /json/)
|
|
|
|
.expect('Cache-Control', testUtils.cacheRules.private)
|
|
|
|
.expect(200)
|
|
|
|
.then((res) => {
|
|
|
|
res.headers.vary.should.eql('Accept-Encoding');
|
|
|
|
should.exist(res.headers['access-control-allow-origin']);
|
|
|
|
should.not.exist(res.headers['x-cache-invalidate']);
|
|
|
|
|
|
|
|
const jsonResponse = res.body;
|
|
|
|
should.exist(jsonResponse.posts);
|
|
|
|
localUtils.API.checkResponse(jsonResponse, 'posts');
|
2021-02-18 02:00:26 +03:00
|
|
|
jsonResponse.posts.should.have.length(15);
|
2020-07-06 15:00:15 +03:00
|
|
|
localUtils.API.checkResponse(jsonResponse.posts[0], 'post', null, null);
|
2019-10-31 14:10:14 +03:00
|
|
|
localUtils.API.checkResponse(jsonResponse.meta.pagination, 'pagination');
|
|
|
|
_.isBoolean(jsonResponse.posts[0].featured).should.eql(true);
|
|
|
|
|
|
|
|
// Default order 'published_at desc' check
|
|
|
|
jsonResponse.posts[0].slug.should.eql('thou-shalt-not-be-seen');
|
|
|
|
jsonResponse.posts[1].slug.should.eql('thou-shalt-be-paid-for');
|
2020-01-08 16:43:21 +03:00
|
|
|
jsonResponse.posts[2].slug.should.eql('free-to-see');
|
2021-02-18 02:00:26 +03:00
|
|
|
jsonResponse.posts[3].slug.should.eql('thou-shalt-have-a-taste');
|
2021-03-10 17:19:11 +03:00
|
|
|
jsonResponse.posts[8].slug.should.eql('sell');
|
2019-10-31 14:10:14 +03:00
|
|
|
|
|
|
|
jsonResponse.posts[0].html.should.eql('');
|
|
|
|
jsonResponse.posts[1].html.should.eql('');
|
2020-01-08 16:43:21 +03:00
|
|
|
jsonResponse.posts[2].html.should.not.eql('');
|
2021-02-18 02:00:26 +03:00
|
|
|
jsonResponse.posts[3].html.should.not.eql('');
|
|
|
|
jsonResponse.posts[8].html.should.not.eql('');
|
2019-10-31 14:10:14 +03:00
|
|
|
|
2021-02-18 17:12:06 +03:00
|
|
|
jsonResponse.posts[0].excerpt.should.eql('');
|
|
|
|
jsonResponse.posts[1].excerpt.should.eql('');
|
|
|
|
jsonResponse.posts[2].excerpt.should.not.eql('');
|
|
|
|
jsonResponse.posts[3].excerpt.should.not.eql('');
|
|
|
|
jsonResponse.posts[8].excerpt.should.not.eql('');
|
|
|
|
|
2019-10-31 14:10:14 +03:00
|
|
|
// check meta response for this test
|
|
|
|
jsonResponse.meta.pagination.page.should.eql(1);
|
|
|
|
jsonResponse.meta.pagination.limit.should.eql(15);
|
|
|
|
jsonResponse.meta.pagination.pages.should.eql(1);
|
2021-02-18 02:00:26 +03:00
|
|
|
jsonResponse.meta.pagination.total.should.eql(15);
|
2019-10-31 14:10:14 +03:00
|
|
|
jsonResponse.meta.pagination.hasOwnProperty('next').should.be.true();
|
|
|
|
jsonResponse.meta.pagination.hasOwnProperty('prev').should.be.true();
|
|
|
|
should.not.exist(jsonResponse.meta.pagination.next);
|
|
|
|
should.not.exist(jsonResponse.meta.pagination.prev);
|
|
|
|
});
|
|
|
|
});
|
|
|
|
});
|
2019-08-09 17:25:12 +03:00
|
|
|
});
|