diff options
| -rw-r--r-- | users/app/controllers/v1/users_controller.rb | 3 | ||||
| -rw-r--r-- | users/test/integration/api/account_flow_test.rb | 10 | 
2 files changed, 11 insertions, 2 deletions
diff --git a/users/app/controllers/v1/users_controller.rb b/users/app/controllers/v1/users_controller.rb index e8e8f00..9b5997d 100644 --- a/users/app/controllers/v1/users_controller.rb +++ b/users/app/controllers/v1/users_controller.rb @@ -12,8 +12,9 @@ module V1      end      def update +      # For now, only allow public key to be updated via the API. Eventually we might want to store in a config what attributes can be updated via the API.        @user = User.find_by_param(params[:id]) -      @user.update_attributes(params[:user]) +      @user.update_attributes(:public_key => params[:user][:public_key])        respond_with @user      end diff --git a/users/test/integration/api/account_flow_test.rb b/users/test/integration/api/account_flow_test.rb index b763be5..653f7d9 100644 --- a/users/test/integration/api/account_flow_test.rb +++ b/users/test/integration/api/account_flow_test.rb @@ -96,7 +96,15 @@ class AccountFlowTest < ActiveSupport::TestCase      test_public_key = 'asdlfkjslfdkjasd'      put "http://api.lvh.me:3000/1/users/" + @user.id + '.json', :user => {:public_key => test_public_key}, :format => :json      @user.reload -    assert_equal @user.public_key, test_public_key +    assert_equal test_public_key, @user.public_key +  end + +  test "cannot update login via api" do +    server_auth = @srp.authenticate(self) +    original_login = @user.login +    put "http://api.lvh.me:3000/1/users/" + @user.id + '.json', :user => {:login => 'failed_login_name'}, :format => :json +    @user.reload +    assert_equal original_login, @user.login    end  end  | 
