mirror of
https://github.com/discourse/discourse.git
synced 2024-12-02 22:23:55 +08:00
SECURITY: Do not overwrite permissions on the General category (#21390)
Before this fix if you had modified the default general category settings they would be reset back to the default after a deploy.
This commit is contained in:
parent
0bbbb9edc8
commit
784006c71e
|
@ -92,7 +92,7 @@ module SeedData
|
||||||
permissions: {
|
permissions: {
|
||||||
everyone: :full,
|
everyone: :full,
|
||||||
},
|
},
|
||||||
force_permissions: true,
|
force_permissions: false,
|
||||||
sidebar: true,
|
sidebar: true,
|
||||||
default_composer_category: true,
|
default_composer_category: true,
|
||||||
},
|
},
|
||||||
|
|
|
@ -99,6 +99,25 @@ RSpec.describe SeedData::Categories do
|
||||||
expect(SiteSetting.default_composer_category).to eq(Category.last.id)
|
expect(SiteSetting.default_composer_category).to eq(Category.last.id)
|
||||||
end
|
end
|
||||||
|
|
||||||
|
it "does not overwrite permissions on the General category" do
|
||||||
|
create_category("general_category_id")
|
||||||
|
expect(Category.last.name).to eq("General")
|
||||||
|
category = Category.last
|
||||||
|
|
||||||
|
expect(category.category_groups.count).to eq(0)
|
||||||
|
|
||||||
|
category.set_permissions(staff: :full)
|
||||||
|
category.save!
|
||||||
|
|
||||||
|
expect(category.category_groups.count).to eq(1)
|
||||||
|
|
||||||
|
expect { create_category("general_category_id") }.not_to change { CategoryGroup.count }
|
||||||
|
|
||||||
|
category.reload
|
||||||
|
expect(category.category_groups.count).to eq(1)
|
||||||
|
expect(category.category_groups.first).to have_attributes(permissions(:staff, :full))
|
||||||
|
end
|
||||||
|
|
||||||
it "adds default categories SiteSetting.default_sidebar_categories" do
|
it "adds default categories SiteSetting.default_sidebar_categories" do
|
||||||
create_category("staff_category_id")
|
create_category("staff_category_id")
|
||||||
staff_category = Category.last
|
staff_category = Category.last
|
||||||
|
|
Loading…
Reference in New Issue
Block a user