Ghost/core/test/functional/routes
Jacob Gable 298077582b ACL and strict rules for Settings API
Ref #2061

- Add canThis permission checks to settings api calls
- Add strict rules about accessing core settings without internal: true
- Omit core settings in browse() call unless internal: true
- Update unit tests to call api.settings with contexts
- Add a couple unit tests for new scenarios
- Update all api.settings calls in the app to call with internal context
- Re-arrange permissions.init in server startup so config.theme.update
can access settings without permissions error
2014-05-07 10:56:03 -05:00
..
api ACL and strict rules for Settings API 2014-05-07 10:56:03 -05:00
admin_test.js updated error handling on all mocha tests 2014-05-05 21:58:58 +01:00
frontend_test.js updated error handling on all mocha tests 2014-05-05 21:58:58 +01:00