Files
grecia/spec/system/management/account_spec.rb
taitus e2138145a5 Avoid management actions when no user is selected
Many management actions only make sense if a user has been selected
beforehand.

We updated :check_verified_user method to be able to check  actions that need to
have a user selected in order to avoid exceptions.

We need this control as :only_verified_user is not restrictive enough. The reason is
that the :managed_user method used in the :only_verified_user if it does not find a
user it does an initializce (find_or_initialize_by). This causes that when we have
"skip_verification" to true, it returns this non-persisted user as "verified".

These changes affect the actions of Account, Budgets and Proposals Controller
when no user is selected.
2021-04-07 20:49:31 +02:00

126 lines
3.4 KiB
Ruby

require "rails_helper"
describe "Account" do
scenario "Should not allow unverified users to edit their account" do
user = create(:user)
login_managed_user(user)
login_as_manager
click_link "Reset password via email"
expect(page).to have_content "No verified user logged in yet"
end
scenario "Delete a user account" do
user = create(:user, :level_two)
login_managed_user(user)
login_as_manager
visit management_account_path
click_link "Delete user"
accept_confirm { click_link "Delete account" }
expect(page).to have_content "User account deleted."
expect(user.reload.erase_reason).to eq "Deleted by manager: manager_user_#{Manager.last.user_id}"
end
scenario "Send reset password email to currently managed user session" do
user = create(:user, :level_three)
login_managed_user(user)
login_as_manager
click_link "Reset password via email"
click_link "Send reset password email"
expect(page).to have_content "Email correctly sent."
email = ActionMailer::Base.deliveries.last
expect(email).to have_text "Change your password"
end
scenario "Manager changes the password by hand (writen by them)" do
user = create(:user, :level_three)
login_managed_user(user)
login_as_manager
click_link "Reset password manually"
find(:css, "input[id$='user_password']").set("new_password")
click_button "Save password"
expect(page).to have_content "Password reseted successfully"
logout
login_through_form_with_email_and_password(user.email, "new_password")
expect(page).to have_content "You have been signed in successfully."
end
scenario "Manager generates random password" do
user = create(:user, :level_three)
login_managed_user(user)
login_as_manager
click_link "Reset password manually"
click_link "Generate random password"
new_password = find_field("user_password").value
click_button "Save password"
expect(page).to have_content "Password reseted successfully"
logout
login_through_form_with_email_and_password(user.username, new_password)
expect(page).to have_content "You have been signed in successfully."
end
scenario "The password is printed" do
user = create(:user, :level_three)
login_managed_user(user)
login_as_manager
click_link "Reset password manually"
find(:css, "input[id$='user_password']").set("another_new_password")
click_button "Save password"
expect(page).to have_content "Password reseted successfully"
expect(page).to have_css("a[href='javascript:window.print();']", text: "Print password")
expect(page).to have_css("div.for-print-only", text: "another_new_password", visible: :hidden)
end
describe "When a user has not been selected" do
before do
Setting["feature.user.skip_verification"] = "true"
end
scenario "we can't reset password via email" do
login_as_manager
click_link "Reset password via email"
expect(page).to have_content "To perform this action you must select a user"
expect(page).to have_current_path management_document_verifications_path
end
scenario "we can't reset password manually" do
login_as_manager
click_link "Reset password manually"
expect(page).to have_content "To perform this action you must select a user"
expect(page).to have_current_path management_document_verifications_path
end
end
end