This commit is contained in:
@@ -11,6 +11,7 @@ import (
|
||||
"net/http/httptest"
|
||||
"net/url"
|
||||
"os"
|
||||
"path"
|
||||
"path/filepath"
|
||||
"strings"
|
||||
"sync/atomic"
|
||||
@@ -505,9 +506,18 @@ func TestPhotoUploadAndRemove(t *testing.T) {
|
||||
if !strings.Contains(rec.Body.String(), "Profile photo updated.") {
|
||||
t.Fatalf("body = %s", rec.Body.String())
|
||||
}
|
||||
if f.users.Find("admin").Photo == "" {
|
||||
photo := f.users.Find("admin").Photo
|
||||
if photo == "" {
|
||||
t.Fatal("photo not stored on the user")
|
||||
}
|
||||
// The photo is account state, not a library tile: it lives under
|
||||
// avatars/ and the media library does not list it.
|
||||
if !strings.HasPrefix(photo, "/media/avatars/") {
|
||||
t.Fatalf("photo url = %q, want the avatar namespace", photo)
|
||||
}
|
||||
if media := f.storeObj.ListMedia(); len(media) != 0 {
|
||||
t.Fatalf("the avatar leaked into the library: %v", media)
|
||||
}
|
||||
|
||||
rec = postForm(t, f, "/admin/settings/photo/remove", url.Values{"_csrf": {csrf}}, cookie)
|
||||
if !strings.Contains(rec.Body.String(), "Profile photo removed.") {
|
||||
@@ -516,6 +526,44 @@ func TestPhotoUploadAndRemove(t *testing.T) {
|
||||
if f.users.Find("admin").Photo != "" {
|
||||
t.Fatal("photo not cleared")
|
||||
}
|
||||
if _, err := f.storeObj.MediaPath(strings.TrimPrefix(photo, "/media/")); err == nil {
|
||||
t.Fatal("the avatar file survived the removal")
|
||||
}
|
||||
}
|
||||
|
||||
// Installations that predate the avatar directory kept their photos flat
|
||||
// in the media directory; those files still serve, but the library hides
|
||||
// every URL an account photo references, so the tiles stay content-only.
|
||||
func TestMediaLibraryHidesAccountPhotos(t *testing.T) {
|
||||
f := newFixture(t)
|
||||
cookie := login(t, f, "admin", "correct-horse-9")
|
||||
|
||||
webpData := append([]byte("RIFF"), 0, 0, 0, 0)
|
||||
webpData = append(webpData, []byte("WEBPVP8 ")...)
|
||||
legacy, err := f.storeObj.StoreUpload("legacy.png", webpData)
|
||||
if err != nil {
|
||||
t.Fatalf("StoreUpload: %v", err)
|
||||
}
|
||||
if _, err := f.users.UpdatePhoto("admin", legacy); err != nil {
|
||||
t.Fatalf("UpdatePhoto: %v", err)
|
||||
}
|
||||
plain, err := f.storeObj.StoreUpload("plain.png", webpData)
|
||||
if err != nil {
|
||||
t.Fatalf("StoreUpload: %v", err)
|
||||
}
|
||||
|
||||
req := httptest.NewRequest(http.MethodGet, "/admin/media", nil)
|
||||
req.AddCookie(cookie)
|
||||
body := f.do(t, req).Body.String()
|
||||
// The tile is identified by its data-name attribute: the signed-in
|
||||
// user's topbar avatar legitimately carries the photo URL too, so a
|
||||
// bare name search would match the chrome, not the library.
|
||||
if strings.Contains(body, `data-name="`+path.Base(legacy)+`"`) {
|
||||
t.Fatal("the account photo appears as a library tile")
|
||||
}
|
||||
if !strings.Contains(body, `data-name="`+path.Base(plain)+`"`) {
|
||||
t.Fatal("an ordinary media file is missing from the library")
|
||||
}
|
||||
}
|
||||
|
||||
func TestWebhookTestDelivery(t *testing.T) {
|
||||
|
||||
Reference in New Issue
Block a user