Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@
module BetterTogether
class HostDashboardController < ApplicationController # rubocop:todo Style/Documentation
def index # rubocop:todo Metrics/MethodLength
authorize :host_dashboard, :index?
root_classes = [
Community, NavigationArea, Page, Platform, Person, Role, ResourcePermission, User,
Conversation, Message, Category
Expand Down
11 changes: 11 additions & 0 deletions app/policies/better_together/host_dashboard_policy.rb
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
# frozen_string_literal: true

# app/policies/better_together/host_dashboard_policy.rb

module BetterTogether
class HostDashboardPolicy < ApplicationPolicy # rubocop:todo Style/Documentation
def index?
user.present? && user.permitted_to?('manage_platform')
end
end
end
40 changes: 40 additions & 0 deletions spec/controllers/better_together/host_dashboard_controller_spec.rb
Original file line number Diff line number Diff line change
@@ -0,0 +1,40 @@
# frozen_string_literal: true

require 'rails_helper'

RSpec.describe BetterTogether::HostDashboardController, type: :controller do
include Devise::Test::ControllerHelpers
include BetterTogether::DeviseSessionHelpers

routes { BetterTogether::Engine.routes }

before do
configure_host_platform
@request.env['devise.mapping'] = Devise.mappings[:user]
end

describe 'GET #index' do
context 'when user can manage platform' do
let(:user) { BetterTogether::User.find_by(email: '[email protected]') }

before { sign_in user }

it 'returns http success' do
get :index, params: { locale: I18n.default_locale }
expect(response).to be_successful
end
end

context 'when user cannot manage platform' do
let(:user) { create(:user, :confirmed) }

before { sign_in user }

it 'raises Pundit::NotAuthorizedError' do
expect do
get :index, params: { locale: I18n.default_locale }
end.to raise_error(Pundit::NotAuthorizedError)
end
end
end
end
31 changes: 31 additions & 0 deletions spec/policies/better_together/host_dashboard_policy_spec.rb
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
# frozen_string_literal: true

require 'rails_helper'

RSpec.describe BetterTogether::HostDashboardPolicy, type: :policy do
subject(:policy) { described_class.new(user, nil) }

context 'when user can manage platform' do
let(:user) { create(:user, :confirmed, :platform_manager) }

it 'permits access' do
expect(policy.index?).to be(true)
end
end

context 'when user cannot manage platform' do
let(:user) { create(:user, :confirmed) }

it 'denies access' do
expect(policy.index?).to be(false)
end
end

context 'when no user is present' do
let(:user) { nil }

it 'denies access' do
expect(policy.index?).to be(false)
end
end
end
Loading