Repository navigation
Add REST API tests for previewing unpublished posts - #120
Merged
Merged
Conversation
Cover the use case of an external system (e.g. a headless frontend) using application password credentials to preview unpublished posts. - Editors can read draft, pending, future, and private posts. - Subscribers, invalid passwords, and revoked passwords are denied. - Autosaves are not readable, with or without authentication.
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
A common use of this plugin is a headless frontend (e.g., a Node.js site) that renders previews of unpublished posts. The frontend authenticates to the REST API with an application password. No tests covered this flow. The only related test checked that an anonymous request for a draft fails.
This PR adds
tests/rest/test-rest-api-preview.php. Each test creates a real application password and sends it as HTTP Basic credentials, so authentication goes through core'sdetermine_current_userflow like an external client. The tests also check that the request resolves to the expected user, so a test cannot pass by accident as an anonymous request.The tests assert:
draft,pending,future, andprivateposts.This PR changes tests only. No plugin code changes.
The tests also pass against
fix/vipcms-2342-protected-content.Steps to Test
wp-env start.composer test -- --filter RestApiPreviewTestand verify that all 9 tests pass.composer testandcomposer test-multisiteand verify that the full suite passes.