X-Git-Url: https://git.openstreetmap.org./rails.git/blobdiff_plain/8c0f5752809f7a21aa62babc05f35a8f881d2141..605d7a5f694ca2e3310f65267c50f20d2a7ee5cd:/test/controllers/api/notes_controller_test.rb diff --git a/test/controllers/api/notes_controller_test.rb b/test/controllers/api/notes_controller_test.rb index 5f69e6a2a..17ceb1b9e 100644 --- a/test/controllers/api/notes_controller_test.rb +++ b/test/controllers/api/notes_controller_test.rb @@ -230,6 +230,17 @@ module Api assert_equal note, subscription.note end + def test_create_no_scope_fail + user = create(:user) + auth_header = bearer_authorization_header user, :scopes => %w[read_prefs] + + assert_no_difference "Note.count" do + post api_notes_path(:lat => -1.0, :lon => -1.0, :text => "This is a description", :format => "json"), :headers => auth_header + + assert_response :forbidden + end + end + def test_comment_success open_note_with_comment = create(:note_with_comments) user = create(:user)