2012-05-21 14:58:26 +12:00
|
|
|
<?php
|
|
|
|
/**
|
|
|
|
* @package blog
|
|
|
|
* @subpackage tests
|
|
|
|
*/
|
|
|
|
class BlogHolderFunctionalTest extends FunctionalTest {
|
|
|
|
|
|
|
|
static $fixture_file = 'blog/tests/BlogHolderFunctionalTest.yml';
|
2010-09-06 06:24:05 +00:00
|
|
|
static $origlThemes;
|
2012-05-21 14:58:26 +12:00
|
|
|
|
|
|
|
function setUp() {
|
|
|
|
parent::setUp();
|
2010-09-06 06:24:05 +00:00
|
|
|
self::$origlThemes = SSViewer::current_theme();
|
|
|
|
SSViewer::set_theme(null);
|
2012-05-21 14:58:26 +12:00
|
|
|
|
|
|
|
$blogHolder = $this->objFromFixture('BlogHolder', 'blogholder');
|
|
|
|
$blogHolder->publish('Stage', 'Live');
|
|
|
|
$blogEntry = $this->objFromFixture('BlogEntry', 'entry1');
|
|
|
|
$blogEntry->publish('Stage', 'Live');
|
|
|
|
}
|
|
|
|
|
2010-09-06 06:24:05 +00:00
|
|
|
function tearDown(){
|
|
|
|
SSViewer::set_theme(self::$origlThemes);
|
|
|
|
parent::tearDown();
|
|
|
|
}
|
|
|
|
|
2012-05-21 14:58:26 +12:00
|
|
|
function testFrontendBlogPostRequiresPermission() {
|
|
|
|
// get valid SecurityID (from comments form, would usually be copy/pasted)
|
|
|
|
$blogEntry = $this->objFromFixture('BlogEntry', 'entry1');
|
|
|
|
$response = $this->get($blogEntry->RelativeLink());
|
|
|
|
$securityID = Session::get('SecurityID');
|
|
|
|
|
|
|
|
// without login
|
|
|
|
$data = array(
|
|
|
|
'Title'=>'Disallowed',
|
|
|
|
'Author'=>'Disallowed',
|
|
|
|
'BlogPost'=>'Disallowed',
|
|
|
|
'action_postblog' => 'Post blog entry',
|
|
|
|
'SecurityID' => $securityID
|
|
|
|
);
|
|
|
|
$response = $this->post('blog/BlogEntryForm', $data);
|
|
|
|
$this->assertFalse(DataObject::get_one('BlogEntry', sprintf("\"Title\" = 'Disallowed'")));
|
|
|
|
|
|
|
|
// with login
|
|
|
|
$blogEditor = $this->objFromFixture('Member', 'blog_editor');
|
|
|
|
$this->session()->inst_set('loggedInAs', $blogEditor->ID);
|
|
|
|
Permission::flush_permission_cache();
|
|
|
|
$data = array(
|
|
|
|
'Title'=>'Allowed',
|
|
|
|
'Author'=>'Allowed',
|
|
|
|
'BlogPost'=>'Allowed',
|
|
|
|
'action_postblog' => 'Post blog entry',
|
|
|
|
'SecurityID' => $securityID
|
|
|
|
);
|
|
|
|
$response = $this->post('blog/BlogEntryForm', $data);
|
|
|
|
|
|
|
|
$this->assertInstanceOf('BlogEntry', DataObject::get_one('BlogEntry', sprintf("\"Title\" = 'Allowed'")));
|
2012-05-21 15:58:40 +12:00
|
|
|
|
2012-05-21 14:58:26 +12:00
|
|
|
}
|
|
|
|
}
|