accounts_controller_spec.rb 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325
  1. # frozen_string_literal: true
  2. require 'rails_helper'
  3. RSpec.describe AccountsController do
  4. render_views
  5. let(:account) { Fabricate(:account) }
  6. shared_examples 'unapproved account check' do
  7. before { account.user.update(approved: false) }
  8. it 'returns http not found' do
  9. get :show, params: { username: account.username, format: format }
  10. expect(response).to have_http_status(404)
  11. end
  12. end
  13. shared_examples 'permanently suspended account check' do
  14. before do
  15. account.suspend!
  16. account.deletion_request.destroy
  17. end
  18. it 'returns http gone' do
  19. get :show, params: { username: account.username, format: format }
  20. expect(response).to have_http_status(410)
  21. end
  22. end
  23. shared_examples 'temporarily suspended account check' do |code: 403|
  24. before { account.suspend! }
  25. it 'returns appropriate http response code' do
  26. get :show, params: { username: account.username, format: format }
  27. expect(response).to have_http_status(code)
  28. end
  29. end
  30. describe 'GET #show' do
  31. context 'with basic account status checks' do
  32. context 'with HTML' do
  33. let(:format) { 'html' }
  34. it_behaves_like 'unapproved account check'
  35. it_behaves_like 'permanently suspended account check'
  36. it_behaves_like 'temporarily suspended account check'
  37. end
  38. context 'with JSON' do
  39. let(:format) { 'json' }
  40. it_behaves_like 'unapproved account check'
  41. it_behaves_like 'permanently suspended account check'
  42. it_behaves_like 'temporarily suspended account check', code: 200
  43. end
  44. context 'with RSS' do
  45. let(:format) { 'rss' }
  46. it_behaves_like 'unapproved account check'
  47. it_behaves_like 'permanently suspended account check'
  48. it_behaves_like 'temporarily suspended account check'
  49. end
  50. end
  51. context 'with existing statuses' do
  52. let!(:status) { Fabricate(:status, account: account) }
  53. let!(:status_reply) { Fabricate(:status, account: account, thread: Fabricate(:status)) }
  54. let!(:status_self_reply) { Fabricate(:status, account: account, thread: status) }
  55. let!(:status_media) { Fabricate(:status, account: account) }
  56. let!(:status_pinned) { Fabricate(:status, account: account) }
  57. let!(:status_private) { Fabricate(:status, account: account, visibility: :private) }
  58. let!(:status_direct) { Fabricate(:status, account: account, visibility: :direct) }
  59. let!(:status_reblog) { Fabricate(:status, account: account, reblog: Fabricate(:status)) }
  60. before do
  61. status_media.media_attachments << Fabricate(:media_attachment, account: account, type: :image)
  62. account.pinned_statuses << status_pinned
  63. account.pinned_statuses << status_private
  64. end
  65. context 'with HTML' do
  66. let(:format) { 'html' }
  67. shared_examples 'common HTML response' do
  68. it 'returns a standard HTML response', :aggregate_failures do
  69. expect(response).to have_http_status(200)
  70. expect(response.headers['Link'].to_s).to include ActivityPub::TagManager.instance.uri_for(account)
  71. expect(response).to render_template(:show)
  72. end
  73. end
  74. context 'with a normal account in an HTML request' do
  75. before do
  76. get :show, params: { username: account.username, format: format }
  77. end
  78. it_behaves_like 'common HTML response'
  79. end
  80. context 'with replies' do
  81. before do
  82. allow(controller).to receive(:replies_requested?).and_return(true)
  83. get :show, params: { username: account.username, format: format }
  84. end
  85. it_behaves_like 'common HTML response'
  86. end
  87. context 'with media' do
  88. before do
  89. allow(controller).to receive(:media_requested?).and_return(true)
  90. get :show, params: { username: account.username, format: format }
  91. end
  92. it_behaves_like 'common HTML response'
  93. end
  94. context 'with tag' do
  95. let(:tag) { Fabricate(:tag) }
  96. let!(:status_tag) { Fabricate(:status, account: account) }
  97. before do
  98. allow(controller).to receive(:tag_requested?).and_return(true)
  99. status_tag.tags << tag
  100. get :show, params: { username: account.username, format: format, tag: tag.to_param }
  101. end
  102. it_behaves_like 'common HTML response'
  103. end
  104. end
  105. context 'with JSON' do
  106. let(:authorized_fetch_mode) { false }
  107. let(:format) { 'json' }
  108. before do
  109. allow(controller).to receive(:authorized_fetch_mode?).and_return(authorized_fetch_mode)
  110. end
  111. context 'with a normal account in a JSON request' do
  112. before do
  113. get :show, params: { username: account.username, format: format }
  114. end
  115. it 'returns a JSON version of the account', :aggregate_failures do
  116. expect(response).to have_http_status(200)
  117. expect(response.media_type).to eq 'application/activity+json'
  118. expect(body_as_json).to include(:id, :type, :preferredUsername, :inbox, :publicKey, :name, :summary)
  119. end
  120. it_behaves_like 'cacheable response', expects_vary: 'Accept, Accept-Language, Cookie'
  121. context 'with authorized fetch mode' do
  122. let(:authorized_fetch_mode) { true }
  123. it 'returns http unauthorized' do
  124. expect(response).to have_http_status(401)
  125. end
  126. end
  127. end
  128. context 'when signed in' do
  129. let(:user) { Fabricate(:user) }
  130. before do
  131. sign_in(user)
  132. get :show, params: { username: account.username, format: format }
  133. end
  134. it 'returns a private JSON version of the account', :aggregate_failures do
  135. expect(response).to have_http_status(200)
  136. expect(response.media_type).to eq 'application/activity+json'
  137. expect(response.headers['Cache-Control']).to include 'private'
  138. expect(body_as_json).to include(:id, :type, :preferredUsername, :inbox, :publicKey, :name, :summary)
  139. end
  140. end
  141. context 'with signature' do
  142. let(:remote_account) { Fabricate(:account, domain: 'example.com') }
  143. before do
  144. allow(controller).to receive(:signed_request_actor).and_return(remote_account)
  145. get :show, params: { username: account.username, format: format }
  146. end
  147. it 'returns a JSON version of the account', :aggregate_failures do
  148. expect(response).to have_http_status(200)
  149. expect(response.media_type).to eq 'application/activity+json'
  150. expect(body_as_json).to include(:id, :type, :preferredUsername, :inbox, :publicKey, :name, :summary)
  151. end
  152. it_behaves_like 'cacheable response', expects_vary: 'Accept, Accept-Language, Cookie'
  153. context 'with authorized fetch mode' do
  154. let(:authorized_fetch_mode) { true }
  155. it 'returns a private signature JSON version of the account', :aggregate_failures do
  156. expect(response).to have_http_status(200)
  157. expect(response.media_type).to eq 'application/activity+json'
  158. expect(response.headers['Cache-Control']).to include 'private'
  159. expect(response.headers['Vary']).to include 'Signature'
  160. expect(body_as_json).to include(:id, :type, :preferredUsername, :inbox, :publicKey, :name, :summary)
  161. end
  162. end
  163. end
  164. end
  165. context 'with RSS' do
  166. let(:format) { 'rss' }
  167. shared_examples 'common RSS response' do
  168. it 'returns http success' do
  169. expect(response).to have_http_status(200)
  170. end
  171. it_behaves_like 'cacheable response', expects_vary: 'Accept, Accept-Language, Cookie'
  172. end
  173. context 'with a normal account in an RSS request' do
  174. before do
  175. get :show, params: { username: account.username, format: format }
  176. end
  177. it_behaves_like 'common RSS response'
  178. it 'responds with correct statuses', :aggregate_failures do
  179. expect(response.body).to include_status_tag(status_media)
  180. expect(response.body).to include_status_tag(status_self_reply)
  181. expect(response.body).to include_status_tag(status)
  182. expect(response.body).to_not include_status_tag(status_direct)
  183. expect(response.body).to_not include_status_tag(status_private)
  184. expect(response.body).to_not include_status_tag(status_reblog.reblog)
  185. expect(response.body).to_not include_status_tag(status_reply)
  186. end
  187. end
  188. context 'with replies' do
  189. before do
  190. allow(controller).to receive(:replies_requested?).and_return(true)
  191. get :show, params: { username: account.username, format: format }
  192. end
  193. it_behaves_like 'common RSS response'
  194. it 'responds with correct statuses with replies', :aggregate_failures do
  195. expect(response.body).to include_status_tag(status_media)
  196. expect(response.body).to include_status_tag(status_reply)
  197. expect(response.body).to include_status_tag(status_self_reply)
  198. expect(response.body).to include_status_tag(status)
  199. expect(response.body).to_not include_status_tag(status_direct)
  200. expect(response.body).to_not include_status_tag(status_private)
  201. expect(response.body).to_not include_status_tag(status_reblog.reblog)
  202. end
  203. end
  204. context 'with media' do
  205. before do
  206. allow(controller).to receive(:media_requested?).and_return(true)
  207. get :show, params: { username: account.username, format: format }
  208. end
  209. it_behaves_like 'common RSS response'
  210. it 'responds with correct statuses with media', :aggregate_failures do
  211. expect(response.body).to include_status_tag(status_media)
  212. expect(response.body).to_not include_status_tag(status_direct)
  213. expect(response.body).to_not include_status_tag(status_private)
  214. expect(response.body).to_not include_status_tag(status_reblog.reblog)
  215. expect(response.body).to_not include_status_tag(status_reply)
  216. expect(response.body).to_not include_status_tag(status_self_reply)
  217. expect(response.body).to_not include_status_tag(status)
  218. end
  219. end
  220. context 'with tag' do
  221. let(:tag) { Fabricate(:tag) }
  222. let!(:status_tag) { Fabricate(:status, account: account) }
  223. before do
  224. allow(controller).to receive(:tag_requested?).and_return(true)
  225. status_tag.tags << tag
  226. get :show, params: { username: account.username, format: format, tag: tag.to_param }
  227. end
  228. it_behaves_like 'common RSS response'
  229. it 'responds with correct statuses with a tag', :aggregate_failures do
  230. expect(response.body).to include_status_tag(status_tag)
  231. expect(response.body).to_not include_status_tag(status_direct)
  232. expect(response.body).to_not include_status_tag(status_media)
  233. expect(response.body).to_not include_status_tag(status_private)
  234. expect(response.body).to_not include_status_tag(status_reblog.reblog)
  235. expect(response.body).to_not include_status_tag(status_reply)
  236. expect(response.body).to_not include_status_tag(status_self_reply)
  237. expect(response.body).to_not include_status_tag(status)
  238. end
  239. end
  240. end
  241. end
  242. end
  243. def include_status_tag(status)
  244. include ActivityPub::TagManager.instance.url_for(status)
  245. end
  246. end