Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Further changes for bug #11174 #9

Merged
merged 1 commit into from
Apr 25, 2012
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 9 additions & 1 deletion plone/app/portlets/browser/configure.zcml
Original file line number Diff line number Diff line change
Expand Up @@ -161,9 +161,17 @@
name="+"
class=".adding.PortletAdding"
allowed_interface="plone.app.portlets.browser.interfaces.IPortletAdding"
permission="plone.app.portlets.ManageOwnPortlets"
permission="plone.app.portlets.ManagePortlets"
/>

<browser:view
for="plone.app.portlets.interfaces.IUserPortletAssignmentMapping"
name="+"
class="plone.app.portlets.browser.adding.PortletAdding"
allowed_interface="plone.app.portlets.browser.interfaces.IPortletAdding"
permission="plone.app.portlets.ManageOwnPortlets" />


<class class=".adding.PortletAdding">
<require
permission="plone.app.portlets.ManagePortlets"
Expand Down
58 changes: 58 additions & 0 deletions plone/app/portlets/tests/testMemberDashboard.txt
Original file line number Diff line number Diff line change
@@ -1,8 +1,10 @@
Setup::

>>> user1, pass1 = u'user1', 'pass1'
>>> user2, pass2 = u'user2', 'pass2'
>>> uf = portal.acl_users
>>> uf.userFolderAddUser(user1, pass1, ['Member'], [])
>>> uf.userFolderAddUser(user2, pass2, ['Member'], [])
>>> import re


Expand Down Expand Up @@ -38,3 +40,59 @@ Let's try to add a Calendar portlet and then remove it
>>> browser.open(portalURL+'/@@manage-dashboard')
>>> bool(re.search('\<\/span\>\s+Calendar\s+\<\/div\>', browser.contents))
False

Now, let's try to add a portlet using the addview

>>> browser.open(portalURL+'/@@manage-dashboard')
>>> browser.open(portalURL + "/++dashboard++plone.dashboard1+user1/+/portlets.Calendar?referer="+portalURL)
>>> browser.open(portalURL+'/@@manage-dashboard')
>>> bool(re.search('\<\/span\>\s+Calendar\s+\<\/div\>', browser.contents))
True
>>> browser.getLink(url="delete-portlet?name=calendar").click()
>>> browser.open(portalURL+'/@@manage-dashboard')
>>> bool(re.search('\<\/span\>\s+Calendar\s+\<\/div\>', browser.contents))
False

Using the addview, let's see that we cannot add a portlet for another user

>>> browser.open(portalURL+'/@@manage-dashboard')
>>> browser.open(portalURL + "/++dashboard++plone.dashboard1+user2/+/portlets.Calendar?referer="+portalURL)
>>> browser.open(portalURL+'/@@manage-dashboard')
>>> bool(re.search('\<\/span\>\s+Calendar\s+\<\/div\>', browser.contents))
False

>>> browser.open(portalURL + '/logout')

>>> browser.open(portalURL + '/login_form')
>>> browser.getControl(name='__ac_name').value = 'user2'
>>> browser.getControl(name='__ac_password').value = 'pass2'
>>> browser.getControl(name='submit').click()

>>> browser.open(portalURL+'/@@manage-dashboard')
>>> bool(re.search('\<\/span\>\s+Calendar\s+\<\/div\>', browser.contents))
False

Now, we try to open the @@manage-portlets view and also try to call the addview
for a portlet. We shouldn't be able to do any of this

>>> browser.open(portalURL+'/@@manage-portlets')
>>> "Insufficient Privileges" in browser.contents
True
>>> browser.open(portalURL + "/++contextportlets++plone.leftcolumn/+/portlets.Calendar")
>>> "Insufficient Privileges" in browser.contents
True

Finally, if we add the "Member" role to the "Portlets: Manage portlets" permission, we should be able to call
those views

>>> portal.manage_permission('Portlets: Manage portlets', roles=['Manager', 'Member'], acquire=0)
>>> browser.open(portalURL+'/@@manage-portlets')
>>> "Insufficient Privileges" in browser.contents
False
>>> bool(re.search('\<\/span\>\s+Calendar\s+\<\/div\>', browser.contents))
False
>>> browser.open(portalURL + "/++contextportlets++plone.leftcolumn/+/portlets.Calendar")
>>> "Insufficient Privileges" in browser.contents
False
>>> bool(re.search('\<\/span\>\s+Calendar\s+\<\/div\>', browser.contents))
True