2021-06-16 15:00:07 +03:00
|
|
|
defmodule PlausibleWeb.Site.InvitationControllerTest do
|
2023-10-02 15:57:57 +03:00
|
|
|
use PlausibleWeb.ConnCase, async: true
|
2021-06-16 15:00:07 +03:00
|
|
|
use Plausible.Repo
|
|
|
|
use Bamboo.Test
|
|
|
|
|
|
|
|
setup [:create_user, :log_in]
|
|
|
|
|
|
|
|
describe "POST /sites/invitations/:invitation_id/accept" do
|
|
|
|
test "converts the invitation into a membership", %{conn: conn, user: user} do
|
|
|
|
site = insert(:site)
|
|
|
|
|
|
|
|
invitation =
|
|
|
|
insert(:invitation,
|
|
|
|
site_id: site.id,
|
|
|
|
inviter: build(:user),
|
|
|
|
email: user.email,
|
|
|
|
role: :admin
|
|
|
|
)
|
|
|
|
|
2023-07-11 11:52:09 +03:00
|
|
|
conn = post(conn, "/sites/invitations/#{invitation.invitation_id}/accept")
|
|
|
|
|
|
|
|
assert Phoenix.Flash.get(conn.assigns.flash, :success) ==
|
|
|
|
"You now have access to #{site.domain}"
|
|
|
|
|
|
|
|
assert redirected_to(conn) == "/#{site.domain}"
|
2021-06-16 15:00:07 +03:00
|
|
|
|
|
|
|
refute Repo.exists?(from(i in Plausible.Auth.Invitation, where: i.email == ^user.email))
|
|
|
|
|
|
|
|
membership = Repo.get_by(Plausible.Site.Membership, user_id: user.id, site_id: site.id)
|
|
|
|
assert membership.role == :admin
|
|
|
|
end
|
|
|
|
|
2023-07-11 11:52:09 +03:00
|
|
|
test "does not crash if clicked for the 2nd time in another tab", %{conn: conn, user: user} do
|
|
|
|
site = insert(:site)
|
|
|
|
|
|
|
|
invitation =
|
|
|
|
insert(:invitation,
|
|
|
|
site_id: site.id,
|
|
|
|
inviter: build(:user),
|
|
|
|
email: user.email,
|
|
|
|
role: :admin
|
|
|
|
)
|
|
|
|
|
|
|
|
c1 = post(conn, "/sites/invitations/#{invitation.invitation_id}/accept")
|
|
|
|
assert redirected_to(c1) == "/#{site.domain}"
|
|
|
|
|
|
|
|
assert Phoenix.Flash.get(c1.assigns.flash, :success) ==
|
|
|
|
"You now have access to #{site.domain}"
|
|
|
|
|
|
|
|
c2 = post(conn, "/sites/invitations/#{invitation.invitation_id}/accept")
|
|
|
|
assert redirected_to(c2) == "/sites"
|
|
|
|
|
|
|
|
assert Phoenix.Flash.get(c2.assigns.flash, :error) ==
|
|
|
|
"Invitation missing or already accepted"
|
|
|
|
end
|
2022-08-11 13:15:33 +03:00
|
|
|
end
|
2021-06-16 15:00:07 +03:00
|
|
|
|
2022-08-11 13:15:33 +03:00
|
|
|
describe "POST /sites/invitations/:invitation_id/accept - ownership transfer" do
|
|
|
|
test "downgrades previous owner to admin", %{conn: conn, user: user} do
|
2021-06-16 15:00:07 +03:00
|
|
|
old_owner = insert(:user)
|
|
|
|
site = insert(:site, members: [old_owner])
|
|
|
|
|
|
|
|
invitation =
|
|
|
|
insert(:invitation, site_id: site.id, inviter: old_owner, email: user.email, role: :owner)
|
|
|
|
|
|
|
|
post(conn, "/sites/invitations/#{invitation.invitation_id}/accept")
|
|
|
|
|
|
|
|
refute Repo.exists?(from(i in Plausible.Auth.Invitation, where: i.email == ^user.email))
|
|
|
|
|
|
|
|
old_owner_membership =
|
|
|
|
Repo.get_by(Plausible.Site.Membership, user_id: old_owner.id, site_id: site.id)
|
|
|
|
|
|
|
|
assert old_owner_membership.role == :admin
|
|
|
|
|
|
|
|
new_owner_membership =
|
|
|
|
Repo.get_by(Plausible.Site.Membership, user_id: user.id, site_id: site.id)
|
|
|
|
|
|
|
|
assert new_owner_membership.role == :owner
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
describe "POST /sites/invitations/:invitation_id/reject" do
|
2023-10-02 15:57:57 +03:00
|
|
|
test "rejects the invitation", %{conn: conn, user: user} do
|
2021-06-16 15:00:07 +03:00
|
|
|
site = insert(:site)
|
|
|
|
|
|
|
|
invitation =
|
|
|
|
insert(:invitation,
|
|
|
|
site_id: site.id,
|
|
|
|
inviter: build(:user),
|
|
|
|
email: user.email,
|
|
|
|
role: :admin
|
|
|
|
)
|
|
|
|
|
2023-10-02 15:57:57 +03:00
|
|
|
conn = post(conn, "/sites/invitations/#{invitation.invitation_id}/reject")
|
2021-06-16 15:00:07 +03:00
|
|
|
|
2023-10-02 15:57:57 +03:00
|
|
|
assert redirected_to(conn, 302) == "/sites"
|
2021-06-16 15:00:07 +03:00
|
|
|
|
2023-10-02 15:57:57 +03:00
|
|
|
refute Repo.reload(invitation)
|
|
|
|
end
|
2021-06-16 15:00:07 +03:00
|
|
|
|
2023-10-02 15:57:57 +03:00
|
|
|
test "renders error for non-existent invitation", %{conn: conn} do
|
|
|
|
conn = post(conn, "/sites/invitations/does-not-exist/reject")
|
2021-06-16 15:00:07 +03:00
|
|
|
|
2023-10-02 15:57:57 +03:00
|
|
|
assert redirected_to(conn, 302) == "/sites"
|
2021-06-16 15:00:07 +03:00
|
|
|
|
2023-10-02 15:57:57 +03:00
|
|
|
assert Phoenix.Flash.get(conn.assigns.flash, :error) ==
|
|
|
|
"Invitation missing or already accepted"
|
2021-06-16 15:00:07 +03:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2022-10-27 09:39:34 +03:00
|
|
|
describe "DELETE /sites/:website/invitations/:invitation_id" do
|
|
|
|
test "removes the invitation", %{conn: conn, user: user} do
|
|
|
|
site = insert(:site, memberships: [build(:site_membership, user: user, role: :admin)])
|
2021-06-16 15:00:07 +03:00
|
|
|
|
|
|
|
invitation =
|
|
|
|
insert(:invitation,
|
|
|
|
site_id: site.id,
|
|
|
|
inviter: build(:user),
|
|
|
|
email: "jane@example.com",
|
|
|
|
role: :admin
|
|
|
|
)
|
|
|
|
|
2023-09-25 12:55:19 +03:00
|
|
|
conn =
|
|
|
|
delete(
|
|
|
|
conn,
|
|
|
|
Routes.invitation_path(conn, :remove_invitation, site.domain, invitation.invitation_id)
|
|
|
|
)
|
|
|
|
|
|
|
|
assert redirected_to(conn, 302) == "/#{site.domain}/settings/people"
|
2021-06-16 15:00:07 +03:00
|
|
|
|
2023-10-02 15:57:57 +03:00
|
|
|
refute Repo.reload(invitation)
|
2021-06-16 15:00:07 +03:00
|
|
|
end
|
2022-10-27 09:39:34 +03:00
|
|
|
|
|
|
|
test "fails to remove an invitation with insufficient permission", %{conn: conn, user: user} do
|
|
|
|
site = insert(:site, memberships: [build(:site_membership, user: user, role: :viewer)])
|
|
|
|
|
|
|
|
invitation =
|
|
|
|
insert(:invitation,
|
|
|
|
site_id: site.id,
|
|
|
|
inviter: build(:user),
|
|
|
|
email: "jane@example.com",
|
|
|
|
role: :admin
|
|
|
|
)
|
|
|
|
|
|
|
|
delete(
|
|
|
|
conn,
|
|
|
|
Routes.invitation_path(conn, :remove_invitation, site.domain, invitation.invitation_id)
|
|
|
|
)
|
|
|
|
|
2023-10-02 15:57:57 +03:00
|
|
|
assert Repo.reload(invitation)
|
2022-10-27 09:39:34 +03:00
|
|
|
end
|
|
|
|
|
|
|
|
test "fails to remove an invitation from the outside", %{conn: my_conn, user: me} do
|
|
|
|
my_site = insert(:site)
|
|
|
|
insert(:site_membership, site: my_site, user: me, role: "owner")
|
|
|
|
|
|
|
|
other_user = insert(:user)
|
|
|
|
other_site = insert(:site)
|
|
|
|
insert(:site_membership, site: other_site, user: other_user, role: "owner")
|
|
|
|
|
|
|
|
invitation =
|
|
|
|
insert(:invitation,
|
|
|
|
site_id: other_site.id,
|
|
|
|
inviter: other_user,
|
|
|
|
email: "jane@example.com",
|
|
|
|
role: :admin
|
|
|
|
)
|
|
|
|
|
|
|
|
remove_invitation_path =
|
|
|
|
Routes.invitation_path(
|
|
|
|
my_conn,
|
|
|
|
:remove_invitation,
|
|
|
|
other_site.domain,
|
|
|
|
invitation.invitation_id
|
|
|
|
)
|
|
|
|
|
|
|
|
delete(my_conn, remove_invitation_path)
|
|
|
|
|
2023-10-02 15:57:57 +03:00
|
|
|
assert Repo.reload(invitation)
|
|
|
|
end
|
|
|
|
|
|
|
|
test "renders error for non-existent invitation", %{conn: conn, user: user} do
|
|
|
|
site = insert(:site, memberships: [build(:site_membership, user: user, role: :admin)])
|
|
|
|
|
|
|
|
remove_invitation_path =
|
|
|
|
Routes.invitation_path(
|
|
|
|
conn,
|
|
|
|
:remove_invitation,
|
|
|
|
site.domain,
|
|
|
|
"does_not_exist"
|
|
|
|
)
|
|
|
|
|
|
|
|
conn = delete(conn, remove_invitation_path)
|
|
|
|
|
|
|
|
assert redirected_to(conn, 302) == "/#{site.domain}/settings/people"
|
|
|
|
|
|
|
|
assert Phoenix.Flash.get(conn.assigns.flash, :error) ==
|
|
|
|
"Invitation missing or already removed"
|
2022-10-27 09:39:34 +03:00
|
|
|
end
|
2021-06-16 15:00:07 +03:00
|
|
|
end
|
|
|
|
end
|