Merge pull request #1523 from dbarbera/avatar_formats_fix

add image authorization on upload_avatar
This commit is contained in:
Régis Hanol
2013-10-14 05:33:25 -07:00
2 changed files with 10 additions and 0 deletions

View File

@@ -966,6 +966,12 @@ describe UsersController do
response.status.should eq 413
end
it 'rejects unauthorized images' do
SiteSetting.stubs(:authorized_image?).returns(false)
xhr :post, :upload_avatar, username: user.username, file: avatar
response.status.should eq 422
end
it 'is successful' do
upload = Fabricate(:upload)
Upload.expects(:create_for).returns(upload)