]> cat aescling's git repositories - mastodon.git/commitdiff
Auth sign out (#2511)
authorMatt Jankowski <mjankowski@thoughtbot.com>
Tue, 2 May 2017 21:37:58 +0000 (17:37 -0400)
committerEugen Rochko <eugen@zeonfederated.com>
Tue, 2 May 2017 21:37:58 +0000 (23:37 +0200)
* Add a spec for signing out

* Add spec showing that suspended user gets a 403 forbidden on sign out

* Allow suspended account users to sign out

app/controllers/auth/sessions_controller.rb
spec/controllers/auth/sessions_controller_spec.rb

index 4a5e0da6ef8a9780da98de70dadf2b94109094a1..1aa84a3548358245c8cd862534f445c56974929f 100644 (file)
@@ -6,6 +6,7 @@ class Auth::SessionsController < Devise::SessionsController
   layout 'auth'
 
   skip_before_action :require_no_authentication, only: [:create]
+  skip_before_action :check_suspension, only: [:destroy]
   prepend_before_action :authenticate_with_two_factor, if: :two_factor_enabled?, only: [:create]
 
   def create
index 393908d97bcf86b026b1b85c93ed595c31fd15e0..a2298180afcb44ef401e8791fdd3701299779ba4 100644 (file)
@@ -16,6 +16,33 @@ RSpec.describe Auth::SessionsController, type: :controller do
     end
   end
 
+  describe 'DELETE #destroy' do
+    let(:user) { Fabricate(:user) }
+
+    before do
+      request.env['devise.mapping'] = Devise.mappings[:user]
+    end
+
+    context 'with a regular user' do
+      it 'redirects to home after sign out' do
+        sign_in(user, scope: :user)
+        delete :destroy
+
+        expect(response).to redirect_to(root_path)
+      end
+    end
+
+    context 'with a suspended user' do
+      it 'redirects to home after sign out' do
+        Fabricate(:account, user: user, suspended: true)
+        sign_in(user, scope: :user)
+        delete :destroy
+
+        expect(response).to redirect_to(root_path)
+      end
+    end
+  end
+
   describe 'POST #create' do
     before do
       request.env['devise.mapping'] = Devise.mappings[:user]