mirror of
https://github.com/go-gitea/gitea.git
synced 2026-10-01 20:59:45 +09:00
Backport #39501 by @silverwind Several handlers skipped checks that their sibling routes or settings already enforce. This brings them in line. - Push mirror API honors `DISABLE_NEW_PUSH` and checks the caller's permission - Media API serves small files with the usual content headers - Issue attachment API ignores comment attachments - Push-to-create respects `FORCE_PRIVATE` - Profile feeds and follow actions respect `ENABLE_FEED` and owner visibility - Tag delete route refuses release tags - Refresh token grant only accepts refresh tokens - Gitea migrations bound the source's page size Co-authored-by: silverwind <me@silverwind.io> Co-authored-by: bircni <bircni@icloud.com>
This commit is contained in:
@@ -84,6 +84,7 @@ func testViewLimitedAndPrivateUserAndRename(t *testing.T) {
|
||||
org22 := unittest.AssertExistsAndLoadBean(t, &user_model.User{ID: 22})
|
||||
req := NewRequest(t, "GET", "/"+org22.Name)
|
||||
MakeRequest(t, req, http.StatusNotFound)
|
||||
MakeRequest(t, NewRequest(t, "GET", "/"+org22.Name).SetHeader("Accept", "application/rss+xml"), http.StatusNotFound)
|
||||
|
||||
session := loginUser(t, "user1")
|
||||
oldName := org22.Name
|
||||
@@ -106,6 +107,8 @@ func testViewLimitedAndPrivateUserAndRename(t *testing.T) {
|
||||
org23 := unittest.AssertExistsAndLoadBean(t, &user_model.User{ID: 23})
|
||||
req = NewRequest(t, "GET", "/"+org23.Name)
|
||||
MakeRequest(t, req, http.StatusNotFound)
|
||||
strangerSession := loginUser(t, "user4")
|
||||
strangerSession.MakeRequest(t, NewRequest(t, "POST", "/"+org23.Name+"?action=follow"), http.StatusNotFound)
|
||||
|
||||
oldName = org23.Name
|
||||
newName = "org23_renamed"
|
||||
@@ -127,6 +130,8 @@ func testViewLimitedAndPrivateUserAndRename(t *testing.T) {
|
||||
user31 := unittest.AssertExistsAndLoadBean(t, &user_model.User{ID: 31})
|
||||
req = NewRequest(t, "GET", "/"+user31.Name)
|
||||
MakeRequest(t, req, http.StatusNotFound)
|
||||
MakeRequest(t, NewRequest(t, "GET", "/"+user31.Name).SetHeader("Accept", "application/rss+xml"), http.StatusNotFound)
|
||||
strangerSession.MakeRequest(t, NewRequest(t, "POST", "/"+user31.Name+"?action=follow"), http.StatusNotFound)
|
||||
|
||||
oldName = user31.Name
|
||||
newName = "user31_renamed"
|
||||
@@ -330,6 +335,10 @@ func testGetUserRss(t *testing.T) {
|
||||
session := loginUser(t, "user2")
|
||||
req = NewRequestf(t, "GET", "/non-existent-user.rss")
|
||||
session.MakeRequest(t, req, http.StatusNotFound)
|
||||
|
||||
defer test.MockVariableValue(&setting.Other.EnableFeed, false)()
|
||||
MakeRequest(t, NewRequestf(t, "GET", "/%s.rss", user34), http.StatusNotFound)
|
||||
MakeRequest(t, NewRequestf(t, "GET", "/%s", user34).SetHeader("Accept", "application/rss+xml"), http.StatusNotFound)
|
||||
}
|
||||
|
||||
func testUserListStopWatches(t *testing.T) {
|
||||
|
||||
Reference in New Issue
Block a user