$resp = $this->post($chapter->getUrl('/create-guest-page'), ['name' => 'My guest page']);
$resp->assertRedirect($chapter->book->getUrl('/page/my-guest-page/edit'));
- $user = User::getDefault();
+ $user = $this->users->guest();
$this->assertDatabaseHas('pages', [
'name' => 'My guest page',
'chapter_id' => $chapter->id,
$resp->assertDontSee($page->name);
}
- public function test_robots_effected_by_public_status()
- {
- $this->get('/robots.txt')->assertSee("User-agent: *\nDisallow: /");
-
- $this->setSettings(['app-public' => 'true']);
-
- $resp = $this->get('/robots.txt');
- $resp->assertSee("User-agent: *\nDisallow:");
- $resp->assertDontSee('Disallow: /');
- }
-
- public function test_robots_effected_by_setting()
- {
- $this->get('/robots.txt')->assertSee("User-agent: *\nDisallow: /");
-
- config()->set('app.allow_robots', true);
-
- $resp = $this->get('/robots.txt');
- $resp->assertSee("User-agent: *\nDisallow:");
- $resp->assertDontSee('Disallow: /');
-
- // Check config overrides app-public setting
- config()->set('app.allow_robots', false);
- $this->setSettings(['app-public' => 'true']);
- $this->get('/robots.txt')->assertSee("User-agent: *\nDisallow: /");
- }
-
public function test_default_favicon_file_created_upon_access()
{
$faviconPath = public_path('favicon.ico');
public function test_public_view_can_take_on_other_roles()
{
$this->setSettings(['app-public' => 'true']);
- $newRole = $this->users->attachNewRole(User::getDefault(), []);
+ $newRole = $this->users->attachNewRole($this->users->guest(), []);
$page = $this->entities->page();
$this->permissions->disableEntityInheritedPermissions($page);
$this->permissions->addEntityPermission($page, ['view', 'update'], $newRole);
$this->withHtml($resp)->assertLinkExists($page->getUrl('/edit'));
}
+
+ public function test_public_user_cannot_view_or_update_their_profile()
+ {
+ $this->setSettings(['app-public' => 'true']);
+ $guest = $this->users->guest();
+
+ $resp = $this->get($guest->getEditUrl());
+ $this->assertPermissionError($resp);
+
+ $resp = $this->put($guest->getEditUrl(), ['name' => 'My new guest name']);
+ $this->assertPermissionError($resp);
+ }
}