Let offering managers read the offerings catalogue
CI / Tests (PHP 8.1) (pull_request) Successful in 46s
CI / No Debug Code (pull_request) Successful in 2s
CI / Tests (PHP 8.2) (pull_request) Successful in 56s
CI / PHPStan (pull_request) Successful in 2m56s
CI / Coding Standards (pull_request) Successful in 2m58s
CI / Tests (PHP 8.3) (pull_request) Successful in 2m41s
CI / Build Plugin Zip (pull_request) Skipped
CI / Tests (PHP 8.1) (pull_request) Successful in 46s
CI / No Debug Code (pull_request) Successful in 2s
CI / Tests (PHP 8.2) (pull_request) Successful in 56s
CI / PHPStan (pull_request) Successful in 2m56s
CI / Coding Standards (pull_request) Successful in 2m58s
CI / Tests (PHP 8.3) (pull_request) Successful in 2m41s
CI / Build Plugin Zip (pull_request) Skipped
The block editor's group-class picker fetches GET /offerings, whose permission callback only accepted book_lesson — a capability held by students alone. Administrators and instructors editing a page were rejected with a 403 and the picker silently rendered an empty list. Read access now accepts book_lesson or manage_offerings. The listing is unchanged: active offerings only, public ones plus the invite-only classes the caller has been granted, without the e-transfer email. Closes #121 Co-Authored-By: Claude Opus 5 <[email protected]>
This commit is contained in:
@@ -5,6 +5,7 @@ namespace Unsupervised\Schedular\Tests\Unit\Offering;
|
||||
|
||||
use Brain\Monkey\Functions;
|
||||
use Mockery;
|
||||
use Unsupervised\Schedular\Auth\RoleManager;
|
||||
use Unsupervised\Schedular\GroupClass\GroupAccessRepository;
|
||||
use Unsupervised\Schedular\Offering\Offering;
|
||||
use Unsupervised\Schedular\Offering\OfferingEndpoint;
|
||||
@@ -119,6 +120,42 @@ class OfferingEndpointTest extends TestCase
|
||||
self::assertArrayNotHasKey('etransfer_email', $data[0]);
|
||||
}
|
||||
|
||||
public function testCanReadAllowsStudentsWhoMayBook(): void
|
||||
{
|
||||
Functions\when('is_user_logged_in')->justReturn(true);
|
||||
Functions\when('current_user_can')->alias(
|
||||
static fn (string $cap): bool => RoleManager::CAP_BOOK_LESSON === $cap
|
||||
);
|
||||
|
||||
self::assertTrue($this->endpoint->canRead());
|
||||
}
|
||||
|
||||
public function testCanReadAllowsOfferingManagersWhoCannotBook(): void
|
||||
{
|
||||
Functions\when('is_user_logged_in')->justReturn(true);
|
||||
Functions\when('current_user_can')->alias(
|
||||
static fn (string $cap): bool => RoleManager::CAP_MANAGE_OFFERINGS === $cap
|
||||
);
|
||||
|
||||
self::assertTrue($this->endpoint->canRead());
|
||||
}
|
||||
|
||||
public function testCanReadRejectsLoggedInUserWithNeitherCapability(): void
|
||||
{
|
||||
Functions\when('is_user_logged_in')->justReturn(true);
|
||||
Functions\when('current_user_can')->justReturn(false);
|
||||
|
||||
self::assertFalse($this->endpoint->canRead());
|
||||
}
|
||||
|
||||
public function testCanReadRejectsLoggedOutVisitors(): void
|
||||
{
|
||||
Functions\when('is_user_logged_in')->justReturn(false);
|
||||
Functions\when('current_user_can')->justReturn(true);
|
||||
|
||||
self::assertFalse($this->endpoint->canRead());
|
||||
}
|
||||
|
||||
public function testCreateRejectsTitleLongerThanColumnLimit(): void
|
||||
{
|
||||
Functions\when('sanitize_text_field')->returnArg();
|
||||
|
||||
Reference in New Issue
Block a user