ToolJet/test/controllers/organizations_controller_test.rb

52 lines
2.6 KiB
Ruby
Raw Normal View History

# frozen_string_literal: true
require "test_helper"
2021-04-12 04:50:22 +00:00
class OrganizationsControllerTest < ActionDispatch::IntegrationTest
2021-04-29 06:41:23 +00:00
def setup
@org = Organization.create({ name: "ToolJet Test" })
@admin = User.create({ first_name: "Admin", email: "admin@example.com", password: "password",
2021-04-29 06:41:23 +00:00
organization: @org })
@developer = User.create({ first_name: "Dev", email: "dev@example.com", password: "password",
2021-04-29 06:41:23 +00:00
organization: @org })
@viewer = User.create({ first_name: "Viewer", email: "viewer@example.com", password: "password",
2021-04-29 06:41:23 +00:00
organization: @org })
OrganizationUser.create(organization: @org, user: @admin, role: "admin", status: "active")
OrganizationUser.create(organization: @org, user: @developer, role: "developer", status: "active")
OrganizationUser.create(organization: @org, user: @viewer, role: "viewer", status: "active")
2021-04-25 12:41:46 +00:00
@another_org = Organization.create({ name: "Another ToolJet Test" })
@another_org_admin = User.create({ first_name: "Admin", email: "admin@domain.com", password: "password",
2021-04-29 06:41:23 +00:00
organization: @another_org })
OrganizationUser.create(organization: @another_org, user: @another_org_admin, role: "admin", status: "active")
2021-04-29 06:41:23 +00:00
end
2021-04-25 12:41:46 +00:00
test "org users can list users of the org" do
get organization_users_url(@org.id), headers: { "Content-Type": "application/json" }.merge(auth_header(@admin)),
2021-04-29 06:41:23 +00:00
xhr: true
assert_response 200
assert_equal 3, JSON.parse(response.body)["users"].size
2021-04-25 12:41:46 +00:00
2021-04-29 06:41:23 +00:00
get organization_users_url(@org.id),
headers: { "Content-Type": "application/json" }.merge(auth_header(@developer)), xhr: true
2021-04-29 06:41:23 +00:00
assert_response 200
assert_equal 3, JSON.parse(response.body)["users"].size
2021-04-25 12:41:46 +00:00
get organization_users_url(@org.id), headers: { "Content-Type": "application/json" }.merge(auth_header(@viewer)),
2021-04-29 06:41:23 +00:00
xhr: true
assert_response 200
assert_equal 3, JSON.parse(response.body)["users"].size
2021-04-25 12:41:46 +00:00
2021-04-29 06:41:23 +00:00
get organization_users_url(@another_org.id),
headers: { "Content-Type": "application/json" }.merge(auth_header(@another_org_admin)), xhr: true
2021-04-29 06:41:23 +00:00
assert_response 200
assert_equal 1, JSON.parse(response.body)["users"].size
2021-04-25 12:41:46 +00:00
2021-04-29 06:41:23 +00:00
# Even if org id is given, current user's org's users are returned
get organization_users_url(@org.id),
headers: { "Content-Type": "application/json" }.merge(auth_header(@another_org_admin)), xhr: true
2021-04-29 06:41:23 +00:00
assert_response 200
assert_equal 1, JSON.parse(response.body)["users"].size
2021-04-29 06:41:23 +00:00
end
2021-04-12 04:50:22 +00:00
end