only users that have approved usernames may comment

This commit is contained in:
Wyatt Johnson
2018-01-29 15:29:55 -07:00
parent 73cbe4ab4b
commit 985fc05a47
2 changed files with 41 additions and 1 deletions
+3 -1
View File
@@ -15,7 +15,9 @@ module.exports = (user, perm) => {
case types.EDIT_COMMENT:
// Anyone can do these things if they aren't suspended, banned, or blocked
// as they're editing their username.
return !['UNSET', 'REJECTED'].includes(user.status.username.status);
return !['UNSET', 'REJECTED', 'CHANGED'].includes(
user.status.username.status
);
case types.ADD_COMMENT_TAG:
case types.REMOVE_COMMENT_TAG:
@@ -270,6 +270,44 @@ describe('graph.mutations.createComment', () => {
});
});
describe('user with different username statuses', () => {
beforeEach(() => AssetModel.create({ id: '123' }));
[
{ status: 'UNSET', error: true },
{ status: 'SET', error: false },
{ status: 'APPROVED', error: false },
{ status: 'REJECTED', error: true },
{ status: 'CHANGED', error: true },
].forEach(({ status, error }) => {
describe(`user.status.username.status=${status}`, () => {
it(`${error ? 'can not' : 'can'} create a comment`, async () => {
const context = new Context({
user: new UserModel({ status: { username: { status } } }),
});
const { data, errors } = await graphql(schema, query, {}, context);
if (errors) {
console.error(errors);
}
expect(errors).to.be.undefined;
if (error) {
expect(data.createComment).to.have.property('errors').not.null;
expect(data.createComment).to.have.property('comment').null;
} else {
if (data.createComment.errors) {
console.error(data.createComment.errors);
}
expect(data.createComment).to.have.property('errors').null;
expect(data.createComment).to.have.property('comment').not.null;
}
});
});
});
});
describe('users with different roles', () => {
beforeEach(() => AssetModel.create({ id: '123' }));