Skip to content

Add REST API tests for previewing unpublished posts - #120

Merged
alecgeatches merged 1 commit into
trunkfrom
test/application-password-preview
Oct 7, 2026
Merged

alecgeatches merged 1 commit into
trunkfrom
test/application-password-preview

Conversation

@chriszarate

Copy link
Copy Markdown
Member

Description

A common use of this plugin is a headless frontend (e.g., a Node.js site) that renders previews of unpublished posts. The frontend authenticates to the REST API with an application password. No tests covered this flow. The only related test checked that an anonymous request for a draft fails.

This PR adds tests/rest/test-rest-api-preview.php. Each test creates a real application password and sends it as HTTP Basic credentials, so authentication goes through core's determine_current_user flow like an external client. The tests also check that the request resolves to the expected user, so a test cannot pass by accident as an anonymous request.

The tests assert:

  • An editor with an application password can read draft, pending, future, and private posts.
  • A subscriber with an application password gets an error for a draft.
  • An invalid or revoked application password gets an error for a draft.
  • Autosave revisions are not readable, with or without authentication. This is intended behavior: the API returns saved post content, not unsaved autosave edits.

This PR changes tests only. No plugin code changes.

The tests also pass against fix/vipcms-2342-protected-content.

Steps to Test

  1. Check out PR.
  2. Run wp-env start.
  3. Run composer test -- --filter RestApiPreviewTest and verify that all 9 tests pass.
  4. Run composer test and composer test-multisite and verify that the full suite passes.

Cover the use case of an external system (e.g. a headless frontend)
using application password credentials to preview unpublished posts.

- Editors can read draft, pending, future, and private posts.
- Subscribers, invalid passwords, and revoked passwords are denied.
- Autosaves are not readable, with or without authentication.
@chriszarate
chriszarate requested a review from a team as a code owner October 7, 2026 19:58

@alecgeatches alecgeatches left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

@alecgeatches
alecgeatches merged commit 3e69951 into trunk Oct 7, 2026
20 checks passed
@alecgeatches
alecgeatches deleted the test/application-password-preview branch October 7, 2026 20:19
@alecgeatches alecgeatches mentioned this pull request Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants