mirror of
https://github.com/basecamp/once-campfire.git
synced 2026-09-13 03:52:05 +09:00
eceec2898b
A preview belongs to the page it previews, so both URLs point somewhere else. An absolute URL on our own host passed the scheme and host checks, and every reader's browser fetched it with their session attached, which turns a message into a GET request made on the reader's behalf. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0186eyzivcTn6wqjEE4Wnxdt
97 lines
3.1 KiB
Ruby
97 lines
3.1 KiB
Ruby
require "test_helper"
|
|
|
|
class RoomsControllerTest < ActionDispatch::IntegrationTest
|
|
setup do
|
|
sign_in :david
|
|
end
|
|
|
|
test "index redirects to the user's last room" do
|
|
get rooms_url
|
|
assert_redirected_to room_url(users(:david).rooms.last)
|
|
end
|
|
|
|
test "show" do
|
|
get room_url(users(:david).rooms.last)
|
|
assert_response :success
|
|
end
|
|
|
|
test "shows records the last room visited in a cookie" do
|
|
get room_url(users(:david).rooms.last)
|
|
assert response.cookies[:last_room] = users(:david).rooms.last.id
|
|
end
|
|
|
|
test "show renders a link preview written by hand without its off-scheme image and link" do
|
|
room = rooms(:watercooler)
|
|
post room_messages_url(room, format: :turbo_stream), params: { message: {
|
|
body: link_preview_body(href: "javascript:alert(1)", url: "data:image/svg+xml;base64,PHN2Zy8+"),
|
|
client_message_id: "hand-written-preview" } }
|
|
assert_response :success
|
|
|
|
get room_url(room)
|
|
|
|
assert_response :success
|
|
assert_no_match /javascript:alert/, response.body
|
|
assert_no_match /data:image\/svg/, response.body
|
|
assert_match "Free cookies", response.body
|
|
end
|
|
|
|
test "show renders a link preview written by hand without its image pointed at this Campfire" do
|
|
room = rooms(:watercooler)
|
|
own_url = room_url(room, host: "www.example.com")
|
|
post room_messages_url(room, format: :turbo_stream), params: { message: {
|
|
body: link_preview_body(href: own_url, url: own_url),
|
|
client_message_id: "same-host-preview" } }
|
|
assert_response :success
|
|
|
|
get room_url(room)
|
|
|
|
assert_response :success
|
|
assert_no_match %r{<img src="#{Regexp.escape(own_url)}"}, response.body
|
|
assert_no_match %r{<a rel="noreferrer" target="_blank" href="#{Regexp.escape(own_url)}"}, response.body
|
|
assert_match "Free cookies", response.body
|
|
end
|
|
|
|
test "show renders an unfurled link preview" do
|
|
room = rooms(:watercooler)
|
|
post room_messages_url(room, format: :turbo_stream), params: { message: {
|
|
body: link_preview_body(href: "https://example.com/page", url: "https://example.com/image.png"),
|
|
client_message_id: "unfurled-preview" } }
|
|
assert_response :success
|
|
|
|
get room_url(room)
|
|
|
|
assert_response :success
|
|
assert_match %r{<img src="https://example\.com/image\.png"}, response.body
|
|
assert_match %r{href="https://example\.com/page"}, response.body
|
|
end
|
|
|
|
test "destroy" do
|
|
assert_turbo_stream_broadcasts :rooms, count: 1 do
|
|
assert_difference -> { Room.count }, -1 do
|
|
delete room_url(rooms(:designers))
|
|
end
|
|
end
|
|
end
|
|
|
|
test "destroy only allowed for creators or those who can administer" do
|
|
sign_in :jz
|
|
|
|
assert_no_difference -> { Room.count } do
|
|
delete room_url(rooms(:designers))
|
|
assert_response :forbidden
|
|
end
|
|
|
|
rooms(:designers).update! creator: users(:jz)
|
|
|
|
assert_difference -> { Room.count }, -1 do
|
|
delete room_url(rooms(:designers))
|
|
end
|
|
end
|
|
|
|
private
|
|
def link_preview_body(href:, url:)
|
|
%(<div><action-text-attachment content-type="application/vnd.actiontext.opengraph-embed" ) +
|
|
%(href="#{href}" url="#{url}" filename="Free cookies" caption="Cookies here"></action-text-attachment></div>)
|
|
end
|
|
end
|