diff --git a/spec/controllers/admin/organizations_controller_spec.rb b/spec/controllers/admin/organizations_controller_spec.rb index abe5005b..801cce83 100644 --- a/spec/controllers/admin/organizations_controller_spec.rb +++ b/spec/controllers/admin/organizations_controller_spec.rb @@ -167,5 +167,32 @@ describe Admin::OrganizationsController do end end end + + describe 'POST #assign_org_admins' do + let(:org_admin_role) { Role.find_by(name: 'organization_admin', resource: organization) } + + before do + post :assign_org_admins, id: organization.id, + user: { email: user.email } + end + + it 'assigns organization_admin role' do + expect(user.roles).to eq [org_admin_role] + end + end + + describe 'DELETE #unassign_org_admins' do + let(:org_admin_role) { Role.find_by(name: 'organization_admin', resource: organization) } + let!(:org_admin_user) { create(:user, role_ids: [org_admin_role.id]) } + + before do + delete :unassign_org_admins, id: organization.id, + user: { email: org_admin_user.email } + end + + it 'unassigns organization_admin role' do + expect(org_admin_user.reload.roles).to eq [] + end + end end end diff --git a/spec/controllers/admin/roles_controller_spec.rb b/spec/controllers/admin/roles_controller_spec.rb index d5cdc67e..dcc81313 100644 --- a/spec/controllers/admin/roles_controller_spec.rb +++ b/spec/controllers/admin/roles_controller_spec.rb @@ -1,7 +1,6 @@ require 'spec_helper' describe Admin::RolesController do - let(:conference) { create(:conference) } let(:organizer_role) { Role.find_by(name: 'organizer', resource: conference) } let(:cfp_role) { Role.find_by(name: 'cfp', resource: conference) } diff --git a/spec/features/roles_spec.rb b/spec/features/roles_spec.rb index ebdeacaf..ba9e5d4c 100644 --- a/spec/features/roles_spec.rb +++ b/spec/features/roles_spec.rb @@ -98,6 +98,51 @@ feature Role do end end + context 'organization_admin' do + let!(:organization) { create(:organization) } + let!(:org_admin_role) { Role.find_by(name: 'organization_admin', resource: organization) } + let!(:organization_admin) { create(:user, role_ids: [org_admin_role.id]) } + let(:user_with_no_role) { create :user } + let!(:other_organization) { create(:organization) } + + before do + sign_in organization_admin + visit admin_organizations_path + end + + context 'for the organization it belongs to' do + scenario 'successfully adds role organization_admin' do + click_link('Admins', href: admins_admin_organization_path(organization.id)) + + fill_in 'user_email', with: user_with_no_role.email + click_button 'Add' + user_with_no_role.reload + + expect(user_with_no_role.has_role?('organization_admin', organization)).to eq true + end + + scenario 'successfully removes role organization_admin' do + click_link('Admins', href: admins_admin_organization_path(organization.id)) + + first('tr').find('.btn-danger').click + expect(organization_admin.has_role?('organization_admin', organization)).to eq false + end + end + + context 'for the organizations it does not belong to' do + scenario 'does not successfully add role organization_admin' do + click_link('Admins', href: admins_admin_organization_path(other_organization.id)) + + expect(page.has_field?('user_email')).to eq false + end + + scenario 'does not successfully removes role organization_admin' do + click_link('Admins', href: admins_admin_organization_path(other_organization.id)) + expect(page.has_css?('.btn-danger')).to eq false + end + end + end + context 'organizer' do Role.all.each.map(&:name).each do |role| it_behaves_like 'successfully', role, 'organizer' diff --git a/spec/models/admin_ability_spec.rb b/spec/models/admin_ability_spec.rb index 805dd621..f148b2ae 100644 --- a/spec/models/admin_ability_spec.rb +++ b/spec/models/admin_ability_spec.rb @@ -63,7 +63,7 @@ describe 'User with admin role' do it{ should_not be_able_to(:update, Role.find_by(name: 'organization_admin', resource: other_organization)) } it{ should_not be_able_to(:edit, Role.find_by(name: 'organization_admin', resource: other_organization)) } - it{ should_not be_able_to(:show, Role.find_by(name: 'organization_admin', resource: other_organization)) } + it{ should be_able_to(:admins, organization) } it{ should_not be_able_to(:new, User.new) } it{ should_not be_able_to(:create, User.new) } @@ -127,6 +127,8 @@ describe 'User with admin role' do let(:other_organization) { create(:organization) } let(:other_conference) { create(:conference, organization: other_organization) } + it{ should be_able_to(:assign_org_admins, organization) } + it{ should be_able_to(:unassign_org_admins, organization) } it{ should be_able_to(:manage, my_conference) } it{ should be_able_to(:read, organization) } it{ should be_able_to(:update, organization) } @@ -137,6 +139,8 @@ describe 'User with admin role' do it{ should_not be_able_to(:create, Conference.new(organization_id: other_organization.id)) } it{ should_not be_able_to(:new, Organization.new) } it{ should_not be_able_to(:create, Organization.new) } + + it_behaves_like 'user with any role' end context 'when user has the role organizer' do @@ -214,6 +218,9 @@ describe 'User with admin role' do it{ should be_able_to(:manage, resource) } + it{ should_not be_able_to(:assign_org_admins, organization) } + it{ should_not be_able_to(:unassign_org_admins, organization) } + %w[organizer cfp info_desk volunteers_coordinator].each do |role| it{ should be_able_to(:toggle_user, Role.find_by(name: role, resource: my_conference)) } it{ should be_able_to(:edit, Role.find_by(name: role, resource: my_conference)) } @@ -299,6 +306,8 @@ describe 'User with admin role' do it{ should be_able_to(:index, resource) } it{ should be_able_to(:show, resource) } it{ should be_able_to(:update, resource) } + it{ should_not be_able_to(:assign_org_admins, organization) } + it{ should_not be_able_to(:unassign_org_admins, organization) } it_behaves_like 'user with any role' it_behaves_like 'user with non-organizer role', 'cfp' @@ -366,6 +375,8 @@ describe 'User with admin role' do it{ should be_able_to(:index, resource) } it{ should be_able_to(:show, resource) } it{ should be_able_to(:update, resource) } + it{ should_not be_able_to(:assign_org_admins, organization) } + it{ should_not be_able_to(:unassign_org_admins, organization) } it_behaves_like 'user with any role' it_behaves_like 'user with non-organizer role', 'info_desk' @@ -433,6 +444,8 @@ describe 'User with admin role' do it{ should be_able_to(:index, resource) } it{ should be_able_to(:show, resource) } it{ should be_able_to(:update, resource) } + it{ should_not be_able_to(:assign_org_admins, organization) } + it{ should_not be_able_to(:unassign_org_admins, organization) } it 'should be_able to :manage Vposition' it 'should be_able to :manage Vday' @@ -509,6 +522,9 @@ describe 'User with admin role' do it{ should_not be_able_to(:edit, my_self_organized_track) } it{ should_not be_able_to(:update, my_self_organized_track) } + it{ should_not be_able_to(:assign_org_admins, organization) } + it{ should_not be_able_to(:unassign_org_admins, organization) } + it_behaves_like 'user with any role' it_behaves_like 'user with non-organizer role', 'track_organizer' end