test(channels): cover invite-link permissions for member and admin
Some checks failed
CI / test (push) Failing after 2m19s
Some checks failed
CI / test (push) Failing after 2m19s
This commit is contained in:
@@ -917,6 +917,58 @@ async def test_group_member_cannot_create_invite_link(client, db_session):
|
||||
assert member_invite_link.status_code == 403
|
||||
|
||||
|
||||
async def test_channel_member_cannot_create_invite_link(client, db_session):
|
||||
owner = await _create_verified_user(client, db_session, "channel_invite_owner@example.com", "channel_invite_owner", "strongpass123")
|
||||
member = await _create_verified_user(client, db_session, "channel_invite_member@example.com", "channel_invite_member", "strongpass123")
|
||||
|
||||
me_member = await client.get("/api/v1/auth/me", headers={"Authorization": f"Bearer {member['access_token']}"})
|
||||
member_id = me_member.json()["id"]
|
||||
|
||||
create_channel = await client.post(
|
||||
"/api/v1/chats",
|
||||
headers={"Authorization": f"Bearer {owner['access_token']}"},
|
||||
json={"type": ChatType.CHANNEL.value, "title": "Channel invite rights", "member_ids": [member_id]},
|
||||
)
|
||||
assert create_channel.status_code == 200
|
||||
chat_id = create_channel.json()["id"]
|
||||
|
||||
member_invite_link = await client.post(
|
||||
f"/api/v1/chats/{chat_id}/invite-link",
|
||||
headers={"Authorization": f"Bearer {member['access_token']}"},
|
||||
)
|
||||
assert member_invite_link.status_code == 403
|
||||
|
||||
|
||||
async def test_channel_admin_can_create_invite_link(client, db_session):
|
||||
owner = await _create_verified_user(client, db_session, "channel_invite_owner2@example.com", "channel_invite_owner2", "strongpass123")
|
||||
admin = await _create_verified_user(client, db_session, "channel_invite_admin@example.com", "channel_invite_admin", "strongpass123")
|
||||
|
||||
me_admin = await client.get("/api/v1/auth/me", headers={"Authorization": f"Bearer {admin['access_token']}"})
|
||||
admin_id = me_admin.json()["id"]
|
||||
|
||||
create_channel = await client.post(
|
||||
"/api/v1/chats",
|
||||
headers={"Authorization": f"Bearer {owner['access_token']}"},
|
||||
json={"type": ChatType.CHANNEL.value, "title": "Channel invite admin", "member_ids": [admin_id]},
|
||||
)
|
||||
assert create_channel.status_code == 200
|
||||
chat_id = create_channel.json()["id"]
|
||||
|
||||
promote_admin = await client.patch(
|
||||
f"/api/v1/chats/{chat_id}/members/{admin_id}/role",
|
||||
headers={"Authorization": f"Bearer {owner['access_token']}"},
|
||||
json={"role": "admin"},
|
||||
)
|
||||
assert promote_admin.status_code == 200
|
||||
|
||||
admin_invite_link = await client.post(
|
||||
f"/api/v1/chats/{chat_id}/invite-link",
|
||||
headers={"Authorization": f"Bearer {admin['access_token']}"},
|
||||
)
|
||||
assert admin_invite_link.status_code == 200
|
||||
assert isinstance(admin_invite_link.json().get("token"), str)
|
||||
|
||||
|
||||
async def test_join_by_invite_with_invalid_token_returns_not_found(client, db_session):
|
||||
user = await _create_verified_user(client, db_session, "invite_invalid_user@example.com", "invite_invalid_user", "strongpass123")
|
||||
|
||||
|
||||
Reference in New Issue
Block a user