【发布时间】:2012-03-07 13:30:07
【问题描述】:
因此,我们在 Rails 3.2 应用程序的许多领域都设置了 attr_accessible 和 attr_protected。目前,我们真的不进行测试以确保这些字段受到保护。
所以我决定用谷歌搜索一些答案并偶然发现了这个解决方案:
RSpec::Matchers.define :be_accessible do |attribute|
match do |response|
response.send("#{attribute}=", :foo)
response.send("#{attribute}").eql? :foo
end
description { "be accessible :#{attribute}" }
failure_message_for_should { ":#{attribute} should be accessible" }
failure_message_for_should_not { ":#{attribute} should not be accessible" }
end
但此解决方案仅测试该方法是否响应。我需要的是一种方法来测试属性是否可以批量分配。我真的很喜欢这种语法
it { should_not be_accessible :field_name }
it { should be_accessible :some_field }
有没有人能更好地解决这个问题?
【问题讨论】:
-
考虑使用 Permitters 或 Strong Parameters 代替批量分配安全性(attr_accessible + attr_protected),这在 Rails 4 中将消失。
-
已经在生产中使用它。这是 ForbiddenAttributes 不是主流时的事情。
标签: ruby-on-rails rspec rspec2 rspec-rails