Files
railsgoat/spec/vulnerabilities/url_access_spec.rb
T
2013-10-09 11:07:13 -04:00

15 lines
326 B
Ruby

require 'spec_helper'
feature 'url access' do
before do
UserFixture.reset_all_users
@normal_user = UserFixture.normal_user
end
scenario 'attack', :js => true do
login @normal_user
visit '/admin/1/dashboard'
pending(:if => verifying_fixed?) { current_path.should == '/admin/1/dashboard' }
end
end