3 class DiaryEntryControllerTest < ActionController::TestCase
4 fixtures :users, :user_roles, :diary_entries, :diary_comments, :languages, :friends
6 include ActionView::Helpers::NumberHelper
9 # test all routes which lead to this controller
12 { :path => "/diary", :method => :get },
13 { :controller => "diary_entry", :action => "list" }
16 { :path => "/diary/language", :method => :get },
17 { :controller => "diary_entry", :action => "list", :language => "language" }
20 { :path => "/user/username/diary", :method => :get },
21 { :controller => "diary_entry", :action => "list", :display_name => "username" }
24 { :path => "/diary/friends", :method => :get },
25 { :controller => "diary_entry", :action => "list", :friends => true }
28 { :path => "/diary/nearby", :method => :get },
29 { :controller => "diary_entry", :action => "list", :nearby => true }
33 { :path => "/diary/rss", :method => :get },
34 { :controller => "diary_entry", :action => "rss", :format => :rss }
37 { :path => "/diary/language/rss", :method => :get },
38 { :controller => "diary_entry", :action => "rss", :language => "language", :format => :rss }
41 { :path => "/user/username/diary/rss", :method => :get },
42 { :controller => "diary_entry", :action => "rss", :display_name => "username", :format => :rss }
46 { :path => "/user/username/diary/comments", :method => :get },
47 { :controller => "diary_entry", :action => "comments", :display_name => "username" }
50 { :path => "/user/username/diary/comments/1", :method => :get },
51 { :controller => "diary_entry", :action => "comments", :display_name => "username", :page => "1" }
55 { :path => "/diary/new", :method => :get },
56 { :controller => "diary_entry", :action => "new" }
59 { :path => "/diary/new", :method => :post },
60 { :controller => "diary_entry", :action => "new" }
63 { :path => "/user/username/diary/1", :method => :get },
64 { :controller => "diary_entry", :action => "view", :display_name => "username", :id => "1" }
67 { :path => "/user/username/diary/1/edit", :method => :get },
68 { :controller => "diary_entry", :action => "edit", :display_name => "username", :id => "1" }
71 { :path => "/user/username/diary/1/edit", :method => :post },
72 { :controller => "diary_entry", :action => "edit", :display_name => "username", :id => "1" }
75 { :path => "/user/username/diary/1/newcomment", :method => :post },
76 { :controller => "diary_entry", :action => "comment", :display_name => "username", :id => "1" }
79 { :path => "/user/username/diary/1/hide", :method => :post },
80 { :controller => "diary_entry", :action => "hide", :display_name => "username", :id => "1" }
83 { :path => "/user/username/diary/1/hidecomment/2", :method => :post },
84 { :controller => "diary_entry", :action => "hidecomment", :display_name => "username", :id => "1", :comment => "2" }
89 # Make sure that you are redirected to the login page when you
92 assert_response :redirect
93 assert_redirected_to :controller => :user, :action => :login, :referer => "/diary/new"
95 # Now try again when logged in
96 get :new, {}, { :user => users(:normal_user).id }
97 assert_response :success
98 assert_select "title", :text => /New Diary Entry/, :count => 1
99 assert_select "div.content-heading", :count => 1 do
100 assert_select "h1", :text => /New Diary Entry/, :count => 1
102 assert_select "div#content", :count => 1 do
103 assert_select "form[action='/diary/new'][method=post]", :count => 1 do
104 assert_select "input#diary_entry_title[name='diary_entry[title]']", :count => 1
105 assert_select "textarea#diary_entry_body[name='diary_entry[body]']", :text => "", :count => 1
106 assert_select "select#diary_entry_language_code", :count => 1
107 assert_select "input#latitude[name='diary_entry[latitude]']", :count => 1
108 assert_select "input#longitude[name='diary_entry[longitude]']", :count => 1
109 assert_select "input[name=commit][type=submit][value=Save]", :count => 1
110 assert_select "input[name=commit][type=submit][value=Edit]", :count => 1
111 assert_select "input[name=commit][type=submit][value=Preview]", :count => 1
112 assert_select "input", :count => 7
116 new_title = "New Title"
117 new_body = "This is a new body for the diary entry"
119 new_longitude = "2.2"
120 new_language_code = "en"
122 # Now try creating a invalid diary entry with an empty body
123 assert_no_difference "DiaryEntry.count" do
124 post :new, { :commit => "save",
125 :diary_entry => { :title => new_title, :body => "", :latitude => new_latitude,
126 :longitude => new_longitude, :language_code => new_language_code } },
127 { :user => users(:normal_user).id }
129 assert_response :success
130 assert_template :edit
132 # Now try creating a diary entry
133 assert_difference "DiaryEntry.count", 1 do
134 post :new, { :commit => "save",
135 :diary_entry => { :title => new_title, :body => new_body, :latitude => new_latitude,
136 :longitude => new_longitude, :language_code => new_language_code } },
137 { :user => users(:normal_user).id }
139 assert_response :redirect
140 assert_redirected_to :action => :list, :display_name => users(:normal_user).display_name
141 entry = DiaryEntry.order(:id).last
142 assert_equal users(:normal_user).id, entry.user_id
143 assert_equal new_title, entry.title
144 assert_equal new_body, entry.body
145 assert_equal new_latitude.to_f, entry.latitude
146 assert_equal new_longitude.to_f, entry.longitude
147 assert_equal new_language_code, entry.language_code
151 # Generate some spammy content
152 spammy_title = "Spam Spam Spam Spam Spam"
153 spammy_body = 1.upto(50).map { |n| "http://example.com/spam#{n}" }.join(" ")
155 # Try creating a spammy diary entry
156 assert_difference "DiaryEntry.count", 1 do
157 post :new, { :commit => "save",
158 :diary_entry => { :title => spammy_title, :body => spammy_body, :language_code => "en" } },
159 { :user => users(:normal_user).id }
161 assert_response :redirect
162 assert_redirected_to :action => :list, :display_name => users(:normal_user).display_name
163 entry = DiaryEntry.order(:id).last
164 assert_equal users(:normal_user).id, entry.user_id
165 assert_equal spammy_title, entry.title
166 assert_equal spammy_body, entry.body
167 assert_equal "en", entry.language_code
168 assert_equal "suspended", User.find(users(:normal_user).id).status
170 # Follow the redirect
171 get :list, { :display_name => users(:normal_user).display_name }, { :user => users(:normal_user).id }
172 assert_response :redirect
173 assert_redirected_to :controller => :user, :action => :suspended
177 entry = diary_entries(:normal_user_entry_1)
179 # Make sure that you are redirected to the login page when you are
180 # not logged in, without and with the id of the entry you want to edit
181 get :edit, :display_name => entry.user.display_name, :id => entry.id
182 assert_response :redirect
183 assert_redirected_to :controller => :user, :action => :login, :referer => "/user/#{entry.user.display_name}/diary/#{entry.id}/edit"
185 # Verify that you get a not found error, when you pass a bogus id
186 get :edit, { :display_name => entry.user.display_name, :id => 9999 }, { :user => entry.user.id }
187 assert_response :not_found
188 assert_select "div.content-heading", :count => 1 do
189 assert_select "h2", :text => "No entry with the id: 9999", :count => 1
192 # Verify that you get redirected to view if you are not the user
193 # that created the entry
194 get :edit, { :display_name => entry.user.display_name, :id => entry.id }, { :user => users(:public_user).id }
195 assert_response :redirect
196 assert_redirected_to :action => :view, :display_name => entry.user.display_name, :id => entry.id
198 # Now pass the id, and check that you can edit it, when using the same
199 # user as the person who created the entry
200 get :edit, { :display_name => entry.user.display_name, :id => entry.id }, { :user => entry.user.id }
201 assert_response :success
202 assert_select "title", :text => /Edit diary entry/, :count => 1
203 assert_select "div.content-heading", :count => 1 do
204 assert_select "h1", :text => /Edit diary entry/, :count => 1
206 assert_select "div#content", :count => 1 do
207 assert_select "form[action='/user/#{entry.user.display_name}/diary/#{entry.id}/edit'][method=post]", :count => 1 do
208 assert_select "input#diary_entry_title[name='diary_entry[title]'][value='#{entry.title}']", :count => 1
209 assert_select "textarea#diary_entry_body[name='diary_entry[body]']", :text => entry.body, :count => 1
210 assert_select "select#diary_entry_language_code", :count => 1
211 assert_select "input#latitude[name='diary_entry[latitude]']", :count => 1
212 assert_select "input#longitude[name='diary_entry[longitude]']", :count => 1
213 assert_select "input[name=commit][type=submit][value=Save]", :count => 1
214 assert_select "input[name=commit][type=submit][value=Edit]", :count => 1
215 assert_select "input[name=commit][type=submit][value=Preview]", :count => 1
216 assert_select "input", :count => 7
220 # Now lets see if you can edit the diary entry
221 new_title = "New Title"
222 new_body = "This is a new body for the diary entry"
224 new_longitude = "2.2"
225 new_language_code = "en"
226 post :edit, { :display_name => entry.user.display_name, :id => entry.id, :commit => "save",
227 :diary_entry => { :title => new_title, :body => new_body, :latitude => new_latitude,
228 :longitude => new_longitude, :language_code => new_language_code } },
229 { :user => entry.user.id }
230 assert_response :redirect
231 assert_redirected_to :action => :view, :display_name => entry.user.display_name, :id => entry.id
233 # Now check that the new data is rendered, when logged in
234 get :view, { :display_name => entry.user.display_name, :id => entry.id }, { :user => entry.user.id }
235 assert_response :success
236 assert_template "diary_entry/view"
237 assert_select "title", :text => /Users' diaries | /, :count => 1
238 assert_select "div.content-heading", :count => 1 do
239 assert_select "h2", :text => /#{entry.user.display_name}'s diary/, :count => 1
241 assert_select "div#content", :count => 1 do
242 assert_select "div.post_heading", :text => /#{new_title}/, :count => 1
243 # This next line won't work if the text has been run through the htmlize function
244 # due to formatting that could be introduced
245 assert_select "p", :text => /#{new_body}/, :count => 1
246 assert_select "abbr[class='geo'][title='#{number_with_precision(new_latitude, :precision => 4)}; #{number_with_precision(new_longitude, :precision => 4)}']", :count => 1
247 # As we're not logged in, check that you cannot edit
248 # print @response.body
249 assert_select "a[href='/user/#{entry.user.display_name}/diary/#{entry.id}/edit']", :text => "Edit this entry", :count => 1
252 # and when not logged in as the user who wrote the entry
253 get :view, { :display_name => entry.user.display_name, :id => entry.id }, { :user => entry.user.id }
254 assert_response :success
255 assert_template "diary_entry/view"
256 assert_select "title", :text => /Users' diaries | /, :count => 1
257 assert_select "div.content-heading", :count => 1 do
258 assert_select "h2", :text => /#{users(:normal_user).display_name}'s diary/, :count => 1
260 assert_select "div#content", :count => 1 do
261 assert_select "div.post_heading", :text => /#{new_title}/, :count => 1
262 # This next line won't work if the text has been run through the htmlize function
263 # due to formatting that could be introduced
264 assert_select "p", :text => /#{new_body}/, :count => 1
265 assert_select "abbr[class=geo][title='#{number_with_precision(new_latitude, :precision => 4)}; #{number_with_precision(new_longitude, :precision => 4)}']", :count => 1
266 # As we're not logged in, check that you cannot edit
267 assert_select "li[class='hidden show_if_user_#{entry.user.id}']", :count => 1 do
268 assert_select "a[href='/user/#{entry.user.display_name}/diary/#{entry.id}/edit']", :text => "Edit this entry", :count => 1
274 get :edit, { :display_name => users(:normal_user).display_name, :id => diary_entries(:normal_user_entry_1).id }, { :user => users(:normal_user).id }
275 assert_response :success
276 assert_select "span[class=translation_missing]", false, "Missing translation in edit diary entry"
280 entry = diary_entries(:normal_user_entry_1)
282 # Make sure that you are denied when you are not logged in
283 post :comment, :display_name => entry.user.display_name, :id => entry.id
284 assert_response :forbidden
286 # Verify that you get a not found error, when you pass a bogus id
287 post :comment, { :display_name => entry.user.display_name, :id => 9999 }, { :user => users(:public_user).id }
288 assert_response :not_found
289 assert_select "div.content-heading", :count => 1 do
290 assert_select "h2", :text => "No entry with the id: 9999", :count => 1
293 # Now try an invalid comment with an empty body
294 assert_no_difference "ActionMailer::Base.deliveries.size" do
295 assert_no_difference "DiaryComment.count" do
296 post :comment, { :display_name => entry.user.display_name, :id => entry.id, :diary_comment => { :body => "" } }, { :user => users(:public_user).id }
299 assert_response :success
300 assert_template :view
302 # Now try again with the right id
303 assert_difference "ActionMailer::Base.deliveries.size", 1 do
304 assert_difference "DiaryComment.count", 1 do
305 post :comment, { :display_name => entry.user.display_name, :id => entry.id, :diary_comment => { :body => "New comment" } }, { :user => users(:public_user).id }
308 assert_response :redirect
309 assert_redirected_to :action => :view, :display_name => entry.user.display_name, :id => entry.id
310 email = ActionMailer::Base.deliveries.first
311 assert_equal [users(:normal_user).email], email.to
312 assert_equal "[OpenStreetMap] #{users(:public_user).display_name} commented on your diary entry", email.subject
313 assert_match /New comment/, email.text_part.decoded
314 assert_match /New comment/, email.html_part.decoded
315 ActionMailer::Base.deliveries.clear
316 comment = DiaryComment.order(:id).last
317 assert_equal entry.id, comment.diary_entry_id
318 assert_equal users(:public_user).id, comment.user_id
319 assert_equal "New comment", comment.body
321 # Now view the diary entry, and check the new comment is present
322 get :view, :display_name => entry.user.display_name, :id => entry.id
323 assert_response :success
324 assert_select ".diary-comment", :count => 1 do
325 assert_select "#comment#{comment.id}", :count => 1 do
326 assert_select "a[href='/user/#{users(:public_user).display_name}']", :text => users(:public_user).display_name, :count => 1
328 assert_select ".richtext", :text => /New comment/, :count => 1
332 def test_comment_spammy
333 # Find the entry to comment on
334 entry = diary_entries(:normal_user_entry_1)
336 # Generate some spammy content
337 spammy_text = 1.upto(50).map { |n| "http://example.com/spam#{n}" }.join(" ")
339 # Try creating a spammy comment
340 assert_difference "ActionMailer::Base.deliveries.size", 1 do
341 assert_difference "DiaryComment.count", 1 do
342 post :comment, { :display_name => entry.user.display_name, :id => entry.id, :diary_comment => { :body => spammy_text } }, { :user => users(:public_user).id }
345 assert_response :redirect
346 assert_redirected_to :action => :view, :display_name => entry.user.display_name, :id => entry.id
347 email = ActionMailer::Base.deliveries.first
348 assert_equal [users(:normal_user).email], email.to
349 assert_equal "[OpenStreetMap] #{users(:public_user).display_name} commented on your diary entry", email.subject
350 assert_match %r{http://example.com/spam}, email.text_part.decoded
351 assert_match %r{http://example.com/spam}, email.html_part.decoded
352 ActionMailer::Base.deliveries.clear
353 comment = DiaryComment.order(:id).last
354 assert_equal entry.id, comment.diary_entry_id
355 assert_equal users(:public_user).id, comment.user_id
356 assert_equal spammy_text, comment.body
357 assert_equal "suspended", User.find(users(:public_user).id).status
359 # Follow the redirect
360 get :list, { :display_name => users(:normal_user).display_name }, { :user => users(:public_user).id }
361 assert_response :redirect
362 assert_redirected_to :controller => :user, :action => :suspended
364 # Now view the diary entry, and check the new comment is not present
365 get :view, :display_name => entry.user.display_name, :id => entry.id
366 assert_response :success
367 assert_select ".diary-comment", :count => 0
371 # Try a list of all diary entries
373 check_diary_list :normal_user_entry_1, :normal_user_geo_entry, :public_user_entry_1
377 # Try a list of diary entries for a valid user
378 get :list, :display_name => users(:normal_user).display_name
379 check_diary_list :normal_user_entry_1, :normal_user_geo_entry
381 # Try a list of diary entries for an invalid user
382 get :list, :display_name => "No Such User"
383 assert_response :not_found
384 assert_template "user/no_such_user"
387 def test_list_friends
388 # Try a list of diary entries for your friends when not logged in
389 get :list, :friends => true
390 assert_response :redirect
391 assert_redirected_to :controller => :user, :action => :login, :referer => "/diary/friends"
393 # Try a list of diary entries for your friends when logged in
394 get :list, { :friends => true }, { :user => users(:normal_user).id }
395 check_diary_list :public_user_entry_1
396 get :list, { :friends => true }, { :user => users(:public_user).id }
401 # Try a list of diary entries for nearby users when not logged in
402 get :list, :nearby => true
403 assert_response :redirect
404 assert_redirected_to :controller => :user, :action => :login, :referer => "/diary/nearby"
406 # Try a list of diary entries for nearby users when logged in
407 get :list, { :nearby => true }, { :user => users(:german_user).id }
408 check_diary_list :public_user_entry_1
409 get :list, { :nearby => true }, { :user => users(:public_user).id }
413 def test_list_language
414 # Try a list of diary entries in english
415 get :list, :language => "en"
416 check_diary_list :normal_user_entry_1, :public_user_entry_1
418 # Try a list of diary entries in german
419 get :list, :language => "de"
420 check_diary_list :normal_user_geo_entry
422 # Try a list of diary entries in slovenian
423 get :list, :language => "sl"
428 get :rss, :format => :rss
429 assert_response :success, "Should be able to get a diary RSS"
430 assert_select "rss", :count => 1 do
431 assert_select "channel", :count => 1 do
432 assert_select "channel>title", :count => 1
433 assert_select "image", :count => 1
434 assert_select "channel>item", :count => 3
439 def test_rss_language
440 get :rss, :language => diary_entries(:normal_user_entry_1).language_code, :format => :rss
441 assert_response :success, "Should be able to get a specific language diary RSS"
442 assert_select "rss>channel>item", :count => 2 # , "Diary entries should be filtered by language"
445 # def test_rss_nonexisting_language
446 # get :rss, {:language => 'xx', :format => :rss}
447 # assert_response :not_found, "Should not be able to get a nonexisting language diary RSS"
450 def test_rss_language_with_no_entries
451 get :rss, :language => "sl", :format => :rss
452 assert_response :success, "Should be able to get a specific language diary RSS"
453 assert_select "rss>channel>item", :count => 0 # , "Diary entries should be filtered by language"
457 get :rss, :display_name => users(:normal_user).display_name, :format => :rss
458 assert_response :success, "Should be able to get a specific users diary RSS"
459 assert_select "rss>channel>item", :count => 2 # , "Diary entries should be filtered by user"
462 def test_rss_nonexisting_user
463 # Try a user that has never existed
464 get :rss, :display_name => "fakeUsername76543", :format => :rss
465 assert_response :not_found, "Should not be able to get a nonexisting users diary RSS"
467 # Try a suspended user
468 get :rss, :display_name => users(:suspended_user).display_name, :format => :rss
469 assert_response :not_found, "Should not be able to get a suspended users diary RSS"
472 get :rss, :display_name => users(:deleted_user).display_name, :format => :rss
473 assert_response :not_found, "Should not be able to get a deleted users diary RSS"
477 # Try a normal entry that should work
478 get :view, :display_name => users(:normal_user).display_name, :id => diary_entries(:normal_user_entry_1).id
479 assert_response :success
480 assert_template :view
482 # Try a deleted entry
483 get :view, :display_name => users(:normal_user).display_name, :id => diary_entries(:deleted_entry).id
484 assert_response :not_found
486 # Try an entry by a suspended user
487 get :view, :display_name => users(:suspended_user).display_name, :id => diary_entries(:entry_by_suspended_user).id
488 assert_response :not_found
490 # Try an entry by a deleted user
491 get :view, :display_name => users(:deleted_user).display_name, :id => diary_entries(:entry_by_deleted_user).id
492 assert_response :not_found
495 def test_view_hidden_comments
496 # Get a diary entry that has hidden comments
497 get :view, :display_name => users(:normal_user).display_name, :id => diary_entries(:normal_user_geo_entry).id
498 assert_response :success
499 assert_template :view
500 assert_select "div.comments" do
501 assert_select "p#comment1", :count => 1 # visible comment
502 assert_select "p#comment2", :count => 0 # comment by suspended user
503 assert_select "p#comment3", :count => 0 # comment by deleted user
504 assert_select "p#comment4", :count => 0 # hidden comment
509 # Try without logging in
510 post :hide, :display_name => users(:normal_user).display_name, :id => diary_entries(:normal_user_entry_1).id
511 assert_response :forbidden
512 assert_equal true, DiaryEntry.find(diary_entries(:normal_user_entry_1).id).visible
514 # Now try as a normal user
515 post :hide, { :display_name => users(:normal_user).display_name, :id => diary_entries(:normal_user_entry_1).id }, { :user => users(:normal_user).id }
516 assert_response :redirect
517 assert_redirected_to :action => :view, :display_name => users(:normal_user).display_name, :id => diary_entries(:normal_user_entry_1).id
518 assert_equal true, DiaryEntry.find(diary_entries(:normal_user_entry_1).id).visible
520 # Finally try as an administrator
521 post :hide, { :display_name => users(:normal_user).display_name, :id => diary_entries(:normal_user_entry_1).id }, { :user => users(:administrator_user).id }
522 assert_response :redirect
523 assert_redirected_to :action => :list, :display_name => users(:normal_user).display_name
524 assert_equal false, DiaryEntry.find(diary_entries(:normal_user_entry_1).id).visible
528 # Try without logging in
529 post :hidecomment, :display_name => users(:normal_user).display_name, :id => diary_entries(:normal_user_geo_entry).id, :comment => diary_comments(:comment_for_geo_post).id
530 assert_response :forbidden
531 assert_equal true, DiaryComment.find(diary_comments(:comment_for_geo_post).id).visible
533 # Now try as a normal user
534 post :hidecomment, { :display_name => users(:normal_user).display_name, :id => diary_entries(:normal_user_geo_entry).id, :comment => diary_comments(:comment_for_geo_post).id }, { :user => users(:normal_user).id }
535 assert_response :redirect
536 assert_redirected_to :action => :view, :display_name => users(:normal_user).display_name, :id => diary_entries(:normal_user_geo_entry).id
537 assert_equal true, DiaryComment.find(diary_comments(:comment_for_geo_post).id).visible
539 # Finally try as an administrator
540 post :hidecomment, { :display_name => users(:normal_user).display_name, :id => diary_entries(:normal_user_geo_entry).id, :comment => diary_comments(:comment_for_geo_post).id }, { :user => users(:administrator_user).id }
541 assert_response :redirect
542 assert_redirected_to :action => :view, :display_name => users(:normal_user).display_name, :id => diary_entries(:normal_user_geo_entry).id
543 assert_equal false, DiaryComment.find(diary_comments(:comment_for_geo_post).id).visible
547 # Test a user with no comments
548 get :comments, :display_name => users(:normal_user).display_name
549 assert_response :success
550 assert_template :comments
551 assert_select "table.messages" do
552 assert_select "tr", :count => 1 # header, no comments
555 # Test a user with a comment
556 get :comments, :display_name => users(:public_user).display_name
557 assert_response :success
558 assert_template :comments
559 assert_select "table.messages" do
560 assert_select "tr", :count => 2 # header and one comment
563 # Test a suspended user
564 get :comments, :display_name => users(:suspended_user).display_name
565 assert_response :not_found
567 # Test a deleted user
568 get :comments, :display_name => users(:deleted_user).display_name
569 assert_response :not_found
574 def check_diary_list(*entries)
575 assert_response :success
576 assert_template "list"
577 assert_no_missing_translations
578 assert_select "div.diary_post", entries.count
580 entries.each do |entry|
581 entry = diary_entries(entry)
582 assert_select "a[href=?]", "/user/#{entry.user.display_name}/diary/#{entry.id}"