diff options
author | Azul <azul@leap.se> | 2014-02-08 16:15:46 +0100 |
---|---|---|
committer | Azul <azul@leap.se> | 2014-02-10 14:26:30 +0100 |
commit | cbd757cf151cd61bfdd5637d09f43e4831fec3bb (patch) | |
tree | e5a60f11a2963f0689294d0ebf4f18e93effd099 /users/test/integration/api/update_account_test.rb | |
parent | 758b9a3c30a73fd985943fb7a887f0373be3a833 (diff) |
require token when updating user via API
Diffstat (limited to 'users/test/integration/api/update_account_test.rb')
-rw-r--r-- | users/test/integration/api/update_account_test.rb | 7 |
1 files changed, 7 insertions, 0 deletions
diff --git a/users/test/integration/api/update_account_test.rb b/users/test/integration/api/update_account_test.rb index 16c2357..63429e7 100644 --- a/users/test/integration/api/update_account_test.rb +++ b/users/test/integration/api/update_account_test.rb @@ -12,6 +12,13 @@ class UpdateAccountTest < SrpTest assert_access_denied end + test "require token" do + authenticate + put "http://api.lvh.me:3000/1/users/" + @user.id + '.json', + user_params(password: "No! Verify me instead.") + assert_access_denied + end + test "update password via api" do authenticate update_user password: "No! Verify me instead." |