Merge branch 'codex/tur-98-team-action-404' into 'master'

TUR-98: fix team action not-found responses

See merge request turniere/turniere-backend!53
This commit is contained in:
Daniel Schädler 2026-04-23 18:10:21 +00:00
commit 7f795b765d
5 changed files with 75 additions and 0 deletions

View File

@ -5,6 +5,7 @@ class TeamActionItemsController < ApplicationController
before_action :authenticate_user!, only: %i[update]
before_action -> { require_owner! @team_action_item.owner }, only: %i[update]
before_action -> { require_writable_tournament!(@team_action_item.tournament) }, only: %i[update]
rescue_from ActiveRecord::RecordNotFound, with: :render_not_found_error
# PATCH /team_action_items/1
def update

View File

@ -6,6 +6,7 @@ class TeamActionListsController < ApplicationController
before_action -> { require_owner! @tournament.owner }, only: %i[update_item]
before_action -> { require_writable_tournament!(@tournament) }, only: %i[update_item]
before_action :set_team_action_item, only: %i[update_item]
rescue_from ActiveRecord::RecordNotFound, with: :render_not_found_error
# PATCH /tournaments/:tournament_id/team_action_lists/:key/teams/:team_id
def update_item

View File

@ -49,5 +49,19 @@ RSpec.describe TeamActionItemsController, type: :controller do
expect(response).to have_http_status(:forbidden)
end
end
context 'when item is missing' do
let(:owner) { create(:user) }
before do
apply_authentication_headers_for owner
end
it 'returns not found' do
patch :update, params: { id: 999_999_999, completed: true }
expect(response).to have_http_status(:not_found)
end
end
end
end

View File

@ -70,5 +70,39 @@ RSpec.describe TeamActionListsController, type: :controller do
expect(response).to have_http_status(:forbidden)
end
end
context 'when list key is missing' do
before do
apply_authentication_headers_for tournament.owner
end
it 'returns not found' do
patch :update_item, params: {
tournament_id: tournament.to_param,
key: 'unknown_key',
team_id: team.to_param,
completed: true
}
expect(response).to have_http_status(:not_found)
end
end
context 'when team is missing from list context' do
before do
apply_authentication_headers_for tournament.owner
end
it 'returns not found' do
patch :update_item, params: {
tournament_id: tournament.to_param,
key: list.key,
team_id: 999_999_999,
completed: true
}
expect(response).to have_http_status(:not_found)
end
end
end
end

View File

@ -90,6 +90,31 @@ RSpec.describe 'Tournament sync test HTTP E2E' do
expect(playoff_token_item_completed?(follower_after_update, team_name: second_item.dig(:team, :name))).to eq(true)
end
it 'returns 404 for missing team action resources on both update routes' do
leader = create_group_stage_tournament(name_prefix: 'Missing Action Resource Leader')
finish_group_stage_and_create_playoffs!(leader.fetch(:id))
leader_after_playoffs = fetch_tournament(leader.fetch(:id))
token_list = find_playoff_token_list!(leader_after_playoffs)
first_item = token_list.fetch(:team_action_items).first
missing_item_update = client.patch('/team_action_items/999999999', body: { completed: true })
expect(missing_item_update[:status]).to eq(404)
missing_list_update = client.patch(
"/tournaments/#{leader.fetch(:id)}/team_action_lists/unknown_key/teams/#{first_item.dig(:team, :id)}",
body: { completed: true }
)
expect(missing_list_update[:status]).to eq(404)
missing_team_update = client.patch(
"/tournaments/#{leader.fetch(:id)}/team_action_lists/group_stage_survivor_playoff_tokens/teams/999999999",
body: { completed: true }
)
expect(missing_team_update[:status]).to eq(404)
end
def login_client
api_client = TurniereE2E::ApiClient.new(base_url: base_url)
response = api_client.login!(email: owner_email, password: owner_password)