diff --git a/spec/controllers/people_controller_spec.rb b/spec/controllers/people_controller_spec.rb index 528ba4ace..5cdd125c6 100644 --- a/spec/controllers/people_controller_spec.rb +++ b/spec/controllers/people_controller_spec.rb @@ -122,11 +122,16 @@ describe PeopleController do response.code.should == "404" end - it "404s if no person is found" do + it "404s if no person is found via id" do get :show, :id => 3920397846 response.code.should == "404" end + it "404s if no person is found via username" do + get :show, :username => 'delicious' + response.code.should == "404" + end + it 'does not allow xss attacks' do user2 = bob profile = user2.profile