show error for cross-environment API key usage
This commit is contained in:
committed by
Pete Matsyburka
parent
90d86b58c2
commit
3c616a824c
@@ -3,10 +3,12 @@
|
||||
require 'rails_helper'
|
||||
|
||||
describe 'Templates API', type: :request do
|
||||
let!(:account) { create(:account) }
|
||||
let!(:author) { create(:user, account:) }
|
||||
let!(:folder) { create(:template_folder, account:) }
|
||||
let!(:template_preferences) { { 'request_email_subject' => 'Subject text', 'request_email_body' => 'Body Text' } }
|
||||
let(:account) { create(:account, :with_testing_account) }
|
||||
let(:testing_account) { account.testing_accounts.first }
|
||||
let(:author) { create(:user, account:) }
|
||||
let(:testing_author) { create(:user, account: testing_account) }
|
||||
let(:folder) { create(:template_folder, account:) }
|
||||
let(:template_preferences) { { 'request_email_subject' => 'Subject text', 'request_email_body' => 'Body Text' } }
|
||||
|
||||
describe 'GET /api/templates' do
|
||||
it 'returns a list of templates' do
|
||||
@@ -48,6 +50,38 @@ describe 'Templates API', type: :request do
|
||||
expect(response).to have_http_status(:ok)
|
||||
expect(response.parsed_body).to eq(JSON.parse(template_body(template).to_json))
|
||||
end
|
||||
|
||||
it 'returns an authorization error if test account API token is used with a production template' do
|
||||
template = create(:template, account:,
|
||||
author:,
|
||||
folder:,
|
||||
external_id: SecureRandom.base58(10),
|
||||
preferences: template_preferences)
|
||||
|
||||
get "/api/templates/#{template.id}", headers: { 'x-auth-token': testing_author.access_token.token }
|
||||
|
||||
expect(response).to have_http_status(:forbidden)
|
||||
expect(response.parsed_body).to eq(
|
||||
JSON.parse({ error: "Template #{template.id} not found using testing API key; " \
|
||||
'Use production API key to access production templates.' }.to_json)
|
||||
)
|
||||
end
|
||||
|
||||
it 'returns an authorization error if production account API token is used with a test template' do
|
||||
template = create(:template, account: testing_account,
|
||||
author: testing_author,
|
||||
folder:,
|
||||
external_id: SecureRandom.base58(10),
|
||||
preferences: template_preferences)
|
||||
|
||||
get "/api/templates/#{template.id}", headers: { 'x-auth-token': author.access_token.token }
|
||||
|
||||
expect(response).to have_http_status(:forbidden)
|
||||
expect(response.parsed_body).to eq(
|
||||
JSON.parse({ error: "Template #{template.id} not found using production API key; " \
|
||||
'Use testing API key to access testing templates.' }.to_json)
|
||||
)
|
||||
end
|
||||
end
|
||||
|
||||
describe 'PUT /api/templates' do
|
||||
|
||||
Reference in New Issue
Block a user