mirror of
				https://github.com/go-gitea/gitea.git
				synced 2025-10-29 10:57:44 +09:00 
			
		
		
		
	Remove local clones & make hooks run on merge/edit/upload (#6672)
* Add options to git.Clone to make it more capable * Begin the process of removing the local copy and tidy up * Remove Wiki LocalCopy Checkouts * Remove the last LocalRepo helpers * Remove WithTemporaryFile * Enable push-hooks for these routes * Ensure tests cope with hooks Signed-off-by: Andrew Thornton <art27@cantab.net> * Remove Repository.LocalCopyPath() * Move temporary repo to use the standard temporary path * Fix the tests Signed-off-by: Andrew Thornton <art27@cantab.net> * Remove LocalWikiPath * Fix missing remove Signed-off-by: Andrew Thornton <art27@cantab.net> * Use AppURL for Oauth user link (#6894) * Use AppURL for Oauth user link Fix #6843 * Update oauth.go * Update oauth.go * internal/ssh: ignore env command totally (#6825) * ssh: ignore env command totally * Remove commented code Needed fix described in issue #6889 * Escape the commit message on issues update and title in telegram hook (#6901) * update sdk to latest (#6903) * improve description of branch protection (fix #6886) (#6906) The branch protection description text were not quite accurate. * Fix logging documentation (#6904) * ENABLE_MACARON_REDIRECT should be REDIRECT_MACARON_LOG * Allow DISABLE_ROUTER_LOG to be set in the [log] section * [skip ci] Updated translations via Crowdin * Move sdk structs to modules/structs (#6905) * move sdk structs to moduels/structs * fix tests * fix fmt * fix swagger * fix vendor
This commit is contained in:
		| @@ -7,6 +7,7 @@ package integrations | ||||
| import ( | ||||
| 	"fmt" | ||||
| 	"net/http" | ||||
| 	"net/url" | ||||
| 	"testing" | ||||
|  | ||||
| 	"code.gitea.io/gitea/models" | ||||
| @@ -37,34 +38,50 @@ func getDeleteFileOptions() *api.DeleteFileOptions { | ||||
| } | ||||
|  | ||||
| func TestAPIDeleteFile(t *testing.T) { | ||||
| 	prepareTestEnv(t) | ||||
| 	user2 := models.AssertExistsAndLoadBean(t, &models.User{ID: 2}).(*models.User)               // owner of the repo1 & repo16 | ||||
| 	user3 := models.AssertExistsAndLoadBean(t, &models.User{ID: 3}).(*models.User)               // owner of the repo3, is an org | ||||
| 	user4 := models.AssertExistsAndLoadBean(t, &models.User{ID: 4}).(*models.User)               // owner of neither repos | ||||
| 	repo1 := models.AssertExistsAndLoadBean(t, &models.Repository{ID: 1}).(*models.Repository)   // public repo | ||||
| 	repo3 := models.AssertExistsAndLoadBean(t, &models.Repository{ID: 3}).(*models.Repository)   // public repo | ||||
| 	repo16 := models.AssertExistsAndLoadBean(t, &models.Repository{ID: 16}).(*models.Repository) // private repo | ||||
| 	fileID := 0 | ||||
| 	onGiteaRun(t, func(t *testing.T, u *url.URL) { | ||||
| 		user2 := models.AssertExistsAndLoadBean(t, &models.User{ID: 2}).(*models.User)               // owner of the repo1 & repo16 | ||||
| 		user3 := models.AssertExistsAndLoadBean(t, &models.User{ID: 3}).(*models.User)               // owner of the repo3, is an org | ||||
| 		user4 := models.AssertExistsAndLoadBean(t, &models.User{ID: 4}).(*models.User)               // owner of neither repos | ||||
| 		repo1 := models.AssertExistsAndLoadBean(t, &models.Repository{ID: 1}).(*models.Repository)   // public repo | ||||
| 		repo3 := models.AssertExistsAndLoadBean(t, &models.Repository{ID: 3}).(*models.Repository)   // public repo | ||||
| 		repo16 := models.AssertExistsAndLoadBean(t, &models.Repository{ID: 16}).(*models.Repository) // private repo | ||||
| 		fileID := 0 | ||||
|  | ||||
| 	// Get user2's token | ||||
| 	session := loginUser(t, user2.Name) | ||||
| 	token2 := getTokenForLoggedInUser(t, session) | ||||
| 	session = emptyTestSession(t) | ||||
| 	// Get user4's token | ||||
| 	session = loginUser(t, user4.Name) | ||||
| 	token4 := getTokenForLoggedInUser(t, session) | ||||
| 	session = emptyTestSession(t) | ||||
| 		// Get user2's token | ||||
| 		session := loginUser(t, user2.Name) | ||||
| 		token2 := getTokenForLoggedInUser(t, session) | ||||
| 		session = emptyTestSession(t) | ||||
| 		// Get user4's token | ||||
| 		session = loginUser(t, user4.Name) | ||||
| 		token4 := getTokenForLoggedInUser(t, session) | ||||
| 		session = emptyTestSession(t) | ||||
|  | ||||
| 	// Test deleting a file in repo1 which user2 owns, try both with branch and empty branch | ||||
| 	for _, branch := range [...]string{ | ||||
| 		"master", // Branch | ||||
| 		"",       // Empty branch | ||||
| 	} { | ||||
| 		// Test deleting a file in repo1 which user2 owns, try both with branch and empty branch | ||||
| 		for _, branch := range [...]string{ | ||||
| 			"master", // Branch | ||||
| 			"",       // Empty branch | ||||
| 		} { | ||||
| 			fileID++ | ||||
| 			treePath := fmt.Sprintf("delete/file%d.txt", fileID) | ||||
| 			createFile(user2, repo1, treePath) | ||||
| 			deleteFileOptions := getDeleteFileOptions() | ||||
| 			deleteFileOptions.BranchName = branch | ||||
| 			url := fmt.Sprintf("/api/v1/repos/%s/%s/contents/%s?token=%s", user2.Name, repo1.Name, treePath, token2) | ||||
| 			req := NewRequestWithJSON(t, "DELETE", url, &deleteFileOptions) | ||||
| 			resp := session.MakeRequest(t, req, http.StatusOK) | ||||
| 			var fileResponse api.FileResponse | ||||
| 			DecodeJSON(t, resp, &fileResponse) | ||||
| 			assert.NotNil(t, fileResponse) | ||||
| 			assert.Nil(t, fileResponse.Content) | ||||
| 		} | ||||
|  | ||||
| 		// Test deleting file and making the delete in a new branch | ||||
| 		fileID++ | ||||
| 		treePath := fmt.Sprintf("delete/file%d.txt", fileID) | ||||
| 		createFile(user2, repo1, treePath) | ||||
| 		deleteFileOptions := getDeleteFileOptions() | ||||
| 		deleteFileOptions.BranchName = branch | ||||
| 		deleteFileOptions.BranchName = repo1.DefaultBranch | ||||
| 		deleteFileOptions.NewBranchName = "new_branch" | ||||
| 		url := fmt.Sprintf("/api/v1/repos/%s/%s/contents/%s?token=%s", user2.Name, repo1.Name, treePath, token2) | ||||
| 		req := NewRequestWithJSON(t, "DELETE", url, &deleteFileOptions) | ||||
| 		resp := session.MakeRequest(t, req, http.StatusOK) | ||||
| @@ -72,92 +89,77 @@ func TestAPIDeleteFile(t *testing.T) { | ||||
| 		DecodeJSON(t, resp, &fileResponse) | ||||
| 		assert.NotNil(t, fileResponse) | ||||
| 		assert.Nil(t, fileResponse.Content) | ||||
| 	} | ||||
|  | ||||
| 	// Test deleting file and making the delete in a new branch | ||||
| 	fileID++ | ||||
| 	treePath := fmt.Sprintf("delete/file%d.txt", fileID) | ||||
| 	createFile(user2, repo1, treePath) | ||||
| 	deleteFileOptions := getDeleteFileOptions() | ||||
| 	deleteFileOptions.BranchName = repo1.DefaultBranch | ||||
| 	deleteFileOptions.NewBranchName = "new_branch" | ||||
| 	url := fmt.Sprintf("/api/v1/repos/%s/%s/contents/%s?token=%s", user2.Name, repo1.Name, treePath, token2) | ||||
| 	req := NewRequestWithJSON(t, "DELETE", url, &deleteFileOptions) | ||||
| 	resp := session.MakeRequest(t, req, http.StatusOK) | ||||
| 	var fileResponse api.FileResponse | ||||
| 	DecodeJSON(t, resp, &fileResponse) | ||||
| 	assert.NotNil(t, fileResponse) | ||||
| 	assert.Nil(t, fileResponse.Content) | ||||
| 		// Test deleting a file with the wrong SHA | ||||
| 		fileID++ | ||||
| 		treePath = fmt.Sprintf("delete/file%d.txt", fileID) | ||||
| 		createFile(user2, repo1, treePath) | ||||
| 		deleteFileOptions = getDeleteFileOptions() | ||||
| 		correctSHA := deleteFileOptions.SHA | ||||
| 		deleteFileOptions.SHA = "badsha" | ||||
| 		url = fmt.Sprintf("/api/v1/repos/%s/%s/contents/%s?token=%s", user2.Name, repo1.Name, treePath, token2) | ||||
| 		req = NewRequestWithJSON(t, "DELETE", url, &deleteFileOptions) | ||||
| 		resp = session.MakeRequest(t, req, http.StatusInternalServerError) | ||||
| 		expectedAPIError := context.APIError{ | ||||
| 			Message: "sha does not match [given: " + deleteFileOptions.SHA + ", expected: " + correctSHA + "]", | ||||
| 			URL:     base.DocURL, | ||||
| 		} | ||||
| 		var apiError context.APIError | ||||
| 		DecodeJSON(t, resp, &apiError) | ||||
| 		assert.Equal(t, expectedAPIError, apiError) | ||||
|  | ||||
| 	// Test deleting a file with the wrong SHA | ||||
| 	fileID++ | ||||
| 	treePath = fmt.Sprintf("delete/file%d.txt", fileID) | ||||
| 	createFile(user2, repo1, treePath) | ||||
| 	deleteFileOptions = getDeleteFileOptions() | ||||
| 	correctSHA := deleteFileOptions.SHA | ||||
| 	deleteFileOptions.SHA = "badsha" | ||||
| 	url = fmt.Sprintf("/api/v1/repos/%s/%s/contents/%s?token=%s", user2.Name, repo1.Name, treePath, token2) | ||||
| 	req = NewRequestWithJSON(t, "DELETE", url, &deleteFileOptions) | ||||
| 	resp = session.MakeRequest(t, req, http.StatusInternalServerError) | ||||
| 	expectedAPIError := context.APIError{ | ||||
| 		Message: "sha does not match [given: " + deleteFileOptions.SHA + ", expected: " + correctSHA + "]", | ||||
| 		URL:     base.DocURL, | ||||
| 	} | ||||
| 	var apiError context.APIError | ||||
| 	DecodeJSON(t, resp, &apiError) | ||||
| 	assert.Equal(t, expectedAPIError, apiError) | ||||
| 		// Test creating a file in repo1 by user4 who does not have write access | ||||
| 		fileID++ | ||||
| 		treePath = fmt.Sprintf("delete/file%d.txt", fileID) | ||||
| 		createFile(user2, repo16, treePath) | ||||
| 		deleteFileOptions = getDeleteFileOptions() | ||||
| 		url = fmt.Sprintf("/api/v1/repos/%s/%s/contents/%s?token=%s", user2.Name, repo16.Name, treePath, token4) | ||||
| 		req = NewRequestWithJSON(t, "DELETE", url, &deleteFileOptions) | ||||
| 		session.MakeRequest(t, req, http.StatusNotFound) | ||||
|  | ||||
| 	// Test creating a file in repo1 by user4 who does not have write access | ||||
| 	fileID++ | ||||
| 	treePath = fmt.Sprintf("delete/file%d.txt", fileID) | ||||
| 	createFile(user2, repo16, treePath) | ||||
| 	deleteFileOptions = getDeleteFileOptions() | ||||
| 	url = fmt.Sprintf("/api/v1/repos/%s/%s/contents/%s?token=%s", user2.Name, repo16.Name, treePath, token4) | ||||
| 	req = NewRequestWithJSON(t, "DELETE", url, &deleteFileOptions) | ||||
| 	session.MakeRequest(t, req, http.StatusNotFound) | ||||
| 		// Tests a repo with no token given so will fail | ||||
| 		fileID++ | ||||
| 		treePath = fmt.Sprintf("delete/file%d.txt", fileID) | ||||
| 		createFile(user2, repo16, treePath) | ||||
| 		deleteFileOptions = getDeleteFileOptions() | ||||
| 		url = fmt.Sprintf("/api/v1/repos/%s/%s/contents/%s", user2.Name, repo16.Name, treePath) | ||||
| 		req = NewRequestWithJSON(t, "DELETE", url, &deleteFileOptions) | ||||
| 		session.MakeRequest(t, req, http.StatusNotFound) | ||||
|  | ||||
| 	// Tests a repo with no token given so will fail | ||||
| 	fileID++ | ||||
| 	treePath = fmt.Sprintf("delete/file%d.txt", fileID) | ||||
| 	createFile(user2, repo16, treePath) | ||||
| 	deleteFileOptions = getDeleteFileOptions() | ||||
| 	url = fmt.Sprintf("/api/v1/repos/%s/%s/contents/%s", user2.Name, repo16.Name, treePath) | ||||
| 	req = NewRequestWithJSON(t, "DELETE", url, &deleteFileOptions) | ||||
| 	session.MakeRequest(t, req, http.StatusNotFound) | ||||
| 		// Test using access token for a private repo that the user of the token owns | ||||
| 		fileID++ | ||||
| 		treePath = fmt.Sprintf("delete/file%d.txt", fileID) | ||||
| 		createFile(user2, repo16, treePath) | ||||
| 		deleteFileOptions = getDeleteFileOptions() | ||||
| 		url = fmt.Sprintf("/api/v1/repos/%s/%s/contents/%s?token=%s", user2.Name, repo16.Name, treePath, token2) | ||||
| 		req = NewRequestWithJSON(t, "DELETE", url, &deleteFileOptions) | ||||
| 		session.MakeRequest(t, req, http.StatusOK) | ||||
|  | ||||
| 	// Test using access token for a private repo that the user of the token owns | ||||
| 	fileID++ | ||||
| 	treePath = fmt.Sprintf("delete/file%d.txt", fileID) | ||||
| 	createFile(user2, repo16, treePath) | ||||
| 	deleteFileOptions = getDeleteFileOptions() | ||||
| 	url = fmt.Sprintf("/api/v1/repos/%s/%s/contents/%s?token=%s", user2.Name, repo16.Name, treePath, token2) | ||||
| 	req = NewRequestWithJSON(t, "DELETE", url, &deleteFileOptions) | ||||
| 	session.MakeRequest(t, req, http.StatusOK) | ||||
| 		// Test using org repo "user3/repo3" where user2 is a collaborator | ||||
| 		fileID++ | ||||
| 		treePath = fmt.Sprintf("delete/file%d.txt", fileID) | ||||
| 		createFile(user3, repo3, treePath) | ||||
| 		deleteFileOptions = getDeleteFileOptions() | ||||
| 		url = fmt.Sprintf("/api/v1/repos/%s/%s/contents/%s?token=%s", user3.Name, repo3.Name, treePath, token2) | ||||
| 		req = NewRequestWithJSON(t, "DELETE", url, &deleteFileOptions) | ||||
| 		session.MakeRequest(t, req, http.StatusOK) | ||||
|  | ||||
| 	// Test using org repo "user3/repo3" where user2 is a collaborator | ||||
| 	fileID++ | ||||
| 	treePath = fmt.Sprintf("delete/file%d.txt", fileID) | ||||
| 	createFile(user3, repo3, treePath) | ||||
| 	deleteFileOptions = getDeleteFileOptions() | ||||
| 	url = fmt.Sprintf("/api/v1/repos/%s/%s/contents/%s?token=%s", user3.Name, repo3.Name, treePath, token2) | ||||
| 	req = NewRequestWithJSON(t, "DELETE", url, &deleteFileOptions) | ||||
| 	session.MakeRequest(t, req, http.StatusOK) | ||||
| 		// Test using org repo "user3/repo3" with no user token | ||||
| 		fileID++ | ||||
| 		treePath = fmt.Sprintf("delete/file%d.txt", fileID) | ||||
| 		createFile(user3, repo3, treePath) | ||||
| 		deleteFileOptions = getDeleteFileOptions() | ||||
| 		url = fmt.Sprintf("/api/v1/repos/%s/%s/contents/%s", user3.Name, repo3.Name, treePath) | ||||
| 		req = NewRequestWithJSON(t, "DELETE", url, &deleteFileOptions) | ||||
| 		session.MakeRequest(t, req, http.StatusNotFound) | ||||
|  | ||||
| 	// Test using org repo "user3/repo3" with no user token | ||||
| 	fileID++ | ||||
| 	treePath = fmt.Sprintf("delete/file%d.txt", fileID) | ||||
| 	createFile(user3, repo3, treePath) | ||||
| 	deleteFileOptions = getDeleteFileOptions() | ||||
| 	url = fmt.Sprintf("/api/v1/repos/%s/%s/contents/%s", user3.Name, repo3.Name, treePath) | ||||
| 	req = NewRequestWithJSON(t, "DELETE", url, &deleteFileOptions) | ||||
| 	session.MakeRequest(t, req, http.StatusNotFound) | ||||
|  | ||||
| 	// Test using repo "user2/repo1" where user4 is a NOT collaborator | ||||
| 	fileID++ | ||||
| 	treePath = fmt.Sprintf("delete/file%d.txt", fileID) | ||||
| 	createFile(user2, repo1, treePath) | ||||
| 	deleteFileOptions = getDeleteFileOptions() | ||||
| 	url = fmt.Sprintf("/api/v1/repos/%s/%s/contents/%s?token=%s", user2.Name, repo1.Name, treePath, token4) | ||||
| 	req = NewRequestWithJSON(t, "DELETE", url, &deleteFileOptions) | ||||
| 	session.MakeRequest(t, req, http.StatusForbidden) | ||||
| 		// Test using repo "user2/repo1" where user4 is a NOT collaborator | ||||
| 		fileID++ | ||||
| 		treePath = fmt.Sprintf("delete/file%d.txt", fileID) | ||||
| 		createFile(user2, repo1, treePath) | ||||
| 		deleteFileOptions = getDeleteFileOptions() | ||||
| 		url = fmt.Sprintf("/api/v1/repos/%s/%s/contents/%s?token=%s", user2.Name, repo1.Name, treePath, token4) | ||||
| 		req = NewRequestWithJSON(t, "DELETE", url, &deleteFileOptions) | ||||
| 		session.MakeRequest(t, req, http.StatusForbidden) | ||||
| 	}) | ||||
| } | ||||
|   | ||||
		Reference in New Issue
	
	Block a user