]> git.openstreetmap.org Git - rails.git/commitdiff
Only the sender of a message should be able to mark it as read/unread
authorTom Hughes <tom@compton.nu>
Fri, 28 Jun 2024 23:14:42 +0000 (00:14 +0100)
committerTom Hughes <tom@compton.nu>
Fri, 28 Jun 2024 23:14:42 +0000 (00:14 +0100)
app/controllers/messages_controller.rb
test/controllers/messages_controller_test.rb

index 779174e255ffc915fe14f44c67e2710b8cb87cba..e4d6c70d9afb5809ef87fbf0d92588bfc465fc53 100644 (file)
@@ -117,7 +117,7 @@ class MessagesController < ApplicationController
 
   # Set the message as being read or unread.
   def mark
-    @message = Message.where(:recipient => current_user).or(Message.where(:sender => current_user)).find(params[:message_id])
+    @message = current_user.messages.find(params[:message_id])
     if params[:mark] == "unread"
       message_read = false
       notice = t ".as_unread"
index db3a200b644711b40bfd91fbffcb20510c443878..3f19b5819b9f9e10ceb02b0d541830c0da20eec6 100644 (file)
@@ -369,10 +369,10 @@ class MessagesControllerTest < ActionDispatch::IntegrationTest
   ##
   # test the mark action
   def test_mark
-    user = create(:user)
+    sender_user = create(:user)
     recipient_user = create(:user)
     other_user = create(:user)
-    message = create(:message, :unread, :sender => user, :recipient => recipient_user)
+    message = create(:message, :unread, :sender => sender_user, :recipient => recipient_user)
 
     # Check that the marking a message requires us to login
     post message_mark_path(message)
@@ -386,6 +386,14 @@ class MessagesControllerTest < ActionDispatch::IntegrationTest
     assert_response :not_found
     assert_template "no_such_message"
 
+    # Login as the message sender_user
+    session_for(sender_user)
+
+    # Check that marking a message we sent fails
+    post message_mark_path(message)
+    assert_response :not_found
+    assert_template "no_such_message"
+
     # Login as the message recipient_user
     session_for(recipient_user)