Skip to content

Instantly share code, notes, and snippets.

@coorasse
Created February 27, 2019 07:24
Show Gist options
  • Save coorasse/b5ce12190f84f4490cd21e6299d798a7 to your computer and use it in GitHub Desktop.
Save coorasse/b5ce12190f84f4490cd21e6299d798a7 to your computer and use it in GitHub Desktop.
begin
require 'bundler/inline'
rescue LoadError => e
$stderr.puts 'Bundler version 1.10 or later is required. Please update your Bundler'
raise e
end
gemfile(true) do
source 'https://rubygems.org'
gem 'rails', '5.2.0' # use correct rails version
gem 'cancancan' # use correct cancancan version
gem 'sqlite3', '1.3.9' # use another DB if necessary
end
require 'active_record'
require 'cancancan'
require 'cancan/model_adapters/active_record_adapter'
require 'cancan/model_adapters/active_record_4_adapter'
require 'cancan/model_adapters/active_record_5_adapter'
require 'minitest/autorun'
require 'logger'
# This connection will do for database-independent bug reports.
ActiveRecord::Base.establish_connection(adapter: 'sqlite3', database: ':memory:')
ActiveRecord::Base.logger = Logger.new(STDOUT)
# create your tables here
ActiveRecord::Schema.define do
create_table :reviews, force: true do |t|
end
create_table :reviews_stores, force: true do |t|
t.references :review
t.references :store
end
create_table :stores, force: true do |t|
end
end
class Review < ActiveRecord::Base
has_many :reviews_stores
has_many :stores, through: :reviews_stores
end
class ReviewsStore < ActiveRecord::Base
belongs_to :store
belongs_to :review
end
class Store < ActiveRecord::Base
has_many :reviews_stores
has_many :reviews, through: :reviews_stores
end
class Ability
include CanCan::Ability
def initialize(user)
can :read, Review, stores: {id: 1}
cannot :read, Review, stores: {id: 2}
end
end
class BugTest < Minitest::Test
def test_bug
store1 = Store.create! { |t| t.id = 1 }
store2 = Store.create! { |t| t.id = 2 }
review = Review.create!(stores: [store1, store2])
ability = Ability.new(nil)
assert_equal ability.can?(:read, review), false
assert_equal Review.accessible_by(ability, :read), []
end
end
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment