aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMiquel Sabaté Solà <mikisabate@gmail.com>2024-07-22 16:59:37 +0200
committerMiquel Sabaté Solà <mikisabate@gmail.com>2024-07-22 16:59:37 +0200
commit8d954606eaf3cf80f2e1374a475b18dcaf79eec0 (patch)
tree69a6ddb02055e1a7d200ac57b342764be8d794cd
parent972f45d97221e1d63f5729602e1f91e3bdfa223c (diff)
downloadoperum-8d954606eaf3cf80f2e1374a475b18dcaf79eec0.tar.gz
operum-8d954606eaf3cf80f2e1374a475b18dcaf79eec0.zip
Do not allow to show non-shared searches
Signed-off-by: Miquel Sabaté Solà <mikisabate@gmail.com>
-rw-r--r--app/controllers/shared_searches_controller.rb2
-rw-r--r--test/controllers/shared_searches_controller_test.rb16
2 files changed, 17 insertions, 1 deletions
diff --git a/app/controllers/shared_searches_controller.rb b/app/controllers/shared_searches_controller.rb
index 066dd3e..7b1005e 100644
--- a/app/controllers/shared_searches_controller.rb
+++ b/app/controllers/shared_searches_controller.rb
@@ -8,6 +8,6 @@ class SharedSearchesController < ApplicationController
end
def show
- @search = Search.find(params[:search_id])
+ @search = Search.where(shared: true).find(params[:search_id])
end
end
diff --git a/test/controllers/shared_searches_controller_test.rb b/test/controllers/shared_searches_controller_test.rb
new file mode 100644
index 0000000..e432316
--- /dev/null
+++ b/test/controllers/shared_searches_controller_test.rb
@@ -0,0 +1,16 @@
+# frozen_string_literal: true
+
+class SharedSearchesControllerTest < ActionDispatch::IntegrationTest
+ # We need the session to be initialized as a signed in user.
+ setup { post sessions_url, params: { username: users(:user).username, password: '12341234' } }
+
+ test 'does not allow to show searches which have not been shared' do
+ get search_shared_url(searches(:search1).id)
+ assert_equal @response.code.to_i, 404
+
+ searches(:search1).update!(shared: true)
+
+ get search_shared_url(searches(:search1).id)
+ assert_equal @response.code.to_i, 200
+ end
+end