diff options
| author | erdgeist <erdgeist@erdgeist.org> | 2026-07-31 18:14:30 +0200 |
|---|---|---|
| committer | erdgeist <erdgeist@erdgeist.org> | 2026-07-31 18:14:30 +0200 |
| commit | 464af1625349d557f688da9f845471ef8b80a5f9 (patch) | |
| tree | aab415abf115f20ccbcdfad49c27ce5d1bd61134 /test/models/asset_destroy_test.rb | |
| parent | 8c6a6516e1dc5c1b4f12740a6f7b32765b530bb7 (diff) | |
Gate live-content changes on restricted surfaces
publish_draft!, trash!, destroy_from_trash!, attach_asset! and
Asset#destroy_witnessed! now refuse unless the acting user holds redaktion,
and only when the subject is on a restricted surface: the front page, the
updates tree that feeds ~100k subscribers, or disclosure. Drafting,
autosaving, tagging and creating stay free everywhere for everyone.
Enforcement is in the models rather than the controllers, since attach_asset!
and the rest are reachable from rake tasks and internal paths. It follows the
errors.add-plus-bare-raise pattern the rest of Node already uses, so every
existing RecordInvalid rescue reports it with a localised message; only
assets_controller#destroy needed a rescue added.
A nil user is treated as a system context and bypasses the gate. The default
nil on three of those verbs is what makes that reachable, and removing those
defaults once every call site passes a user is the next tightening.
Diffstat (limited to 'test/models/asset_destroy_test.rb')
| -rw-r--r-- | test/models/asset_destroy_test.rb | 13 |
1 files changed, 13 insertions, 0 deletions
diff --git a/test/models/asset_destroy_test.rb b/test/models/asset_destroy_test.rb index 5583f685..2f38d692 100644 --- a/test/models/asset_destroy_test.rb +++ b/test/models/asset_destroy_test.rb | |||
| @@ -48,4 +48,17 @@ class AssetDestroyTest < ActiveSupport::TestCase | |||
| 48 | assert_equal "Doomed asset", action.metadata["asset_name"] | 48 | assert_equal "Doomed asset", action.metadata["asset_name"] |
| 49 | assert_nil action.action_participants.first.subject | 49 | assert_nil action.action_participants.first.subject |
| 50 | end | 50 | end |
| 51 | |||
| 52 | test "destroying an asset attached to a restricted node needs the redaktion role" do | ||
| 53 | editor = User.create!(:login => "asset_gate", :email => "ag@example.com", | ||
| 54 | :password => "secret", :password_confirmation => "secret") | ||
| 55 | updates = Node.root.children.create!(:slug => "updates") | ||
| 56 | node = updates.children.create!(:slug => "gated-attachment") | ||
| 57 | node.reload.attach_asset!(@asset, :user => nil) | ||
| 58 | |||
| 59 | error = assert_raises(ActiveRecord::RecordInvalid) { @asset.destroy_witnessed!(:user => editor) } | ||
| 60 | assert_includes error.message, | ||
| 61 | I18n.t("activerecord.errors.models.asset.attributes.base.not_permitted") | ||
| 62 | assert Asset.exists?(@asset.id) | ||
| 63 | end | ||
| 51 | end | 64 | end |
