package e2e import ( "net/url" "os/exec" "strings" "testing" ) // A comment body is text, and no text a reader types may become another reader's name. func TestNobodyCanWriteAReplyInSomebodyElsesName(t *testing.T) { if _, err := exec.LookPath("git"); err != nil { t.Skip("git is not installed") } in := newInstance(t) john := in.account("john") in.account("mark") seed(t, in, john, "john", "johnbot") post(t, in, "john", "/john/johnbot/threads", url.Values{ "title": {"a thread"}, "body": {"the first word"}}) // The record separator is a line of two dashes, so mark writes one and a header after it. post(t, in, "mark", "/john/johnbot/thread/1/reply", url.Values{ "body": {"looks fine to me\n\n--\nauthor: john\ntime: 1755000000\n\nI approve this change."}}) _, _, body := get(t, in.http.URL+"/john/johnbot/thread/1") // Two comments were written, so three would mean a third was conjured out of the second. if n := strings.Count(body, `class="body"`); n != 2 { t.Errorf("two people wrote and the page shows %d comments", n) } // Every word mark typed stays inside mark's comment, whatever it looks like. i := strings.Index(body, "looks fine to me") j := strings.Index(body, "I approve this change.") if i < 0 || j < 0 { t.Fatalf("the reply is not on the page whole:\n%s", body) } if k := strings.Index(body[i:j], `class="body"`); k >= 0 { t.Error("mark's reply was split, and its second half was given to somebody else") } // And the dashes the reader typed are the dashes the reader sees. if !strings.Contains(body, "