2016-01-27 12:22:32 +00:00
|
|
|
import json
|
2018-02-20 11:22:17 +00:00
|
|
|
import uuid
|
2017-02-24 16:21:41 +00:00
|
|
|
|
2018-02-20 11:22:17 +00:00
|
|
|
import pytest
|
2016-01-27 12:22:32 +00:00
|
|
|
from flask import url_for
|
2018-04-25 14:12:58 +01:00
|
|
|
|
2024-05-16 10:37:37 -04:00
|
|
|
from notifications_utils.url_safe_token import generate_token
|
2021-05-14 18:42:57 +01:00
|
|
|
from tests.conftest import (
|
|
|
|
|
create_api_user_active,
|
2022-03-23 12:40:43 +00:00
|
|
|
create_user,
|
2021-05-14 18:42:57 +01:00
|
|
|
normalize_spaces,
|
|
|
|
|
url_for_endpoint_with_token,
|
|
|
|
|
)
|
2017-02-24 16:21:41 +00:00
|
|
|
|
2016-01-27 12:22:32 +00:00
|
|
|
|
2017-02-03 10:42:01 +00:00
|
|
|
def test_should_show_overview_page(
|
2019-03-26 12:35:32 +00:00
|
|
|
client_request,
|
2017-02-03 10:42:01 +00:00
|
|
|
):
|
2023-08-25 09:12:23 -07:00
|
|
|
page = client_request.get("main.user_profile")
|
2023-10-12 10:21:11 -04:00
|
|
|
assert page.select_one("h1").text.strip() == "User profile"
|
2023-08-25 09:12:23 -07:00
|
|
|
assert "Use platform admin view" not in page
|
|
|
|
|
assert "Security keys" not in page
|
2019-06-13 19:00:17 +01:00
|
|
|
|
|
|
|
|
|
2019-06-14 12:32:47 +01:00
|
|
|
def test_overview_page_shows_disable_for_platform_admin(
|
2023-08-25 09:12:23 -07:00
|
|
|
client_request, platform_admin_user
|
2019-06-13 19:00:17 +01:00
|
|
|
):
|
|
|
|
|
client_request.login(platform_admin_user)
|
2023-08-25 09:12:23 -07:00
|
|
|
page = client_request.get("main.user_profile")
|
2023-10-12 10:21:11 -04:00
|
|
|
assert page.select_one("h1").text.strip() == "User profile"
|
2023-08-25 09:12:23 -07:00
|
|
|
disable_platform_admin_row = page.select_one("#disable-platform-admin")
|
|
|
|
|
assert (
|
|
|
|
|
" ".join(disable_platform_admin_row.text.split())
|
|
|
|
|
== "Use platform admin view Yes Change whether to use platform admin view"
|
|
|
|
|
)
|
2016-05-16 10:29:58 +01:00
|
|
|
|
|
|
|
|
|
2023-08-25 09:12:23 -07:00
|
|
|
def test_should_show_name_page(client_request):
|
|
|
|
|
page = client_request.get(("main.user_profile_name"))
|
|
|
|
|
assert page.select_one("h1").text.strip() == "Change your name"
|
2016-05-16 10:29:58 +01:00
|
|
|
|
|
|
|
|
|
2017-02-03 10:42:01 +00:00
|
|
|
def test_should_redirect_after_name_change(
|
2019-03-26 12:35:32 +00:00
|
|
|
client_request,
|
2017-02-03 10:42:01 +00:00
|
|
|
mock_update_user_attribute,
|
|
|
|
|
):
|
2019-03-26 12:35:32 +00:00
|
|
|
client_request.post(
|
2023-08-25 09:12:23 -07:00
|
|
|
"main.user_profile_name",
|
|
|
|
|
_data={"new_name": "New Name"},
|
2019-03-26 12:35:32 +00:00
|
|
|
_expected_status=302,
|
2023-08-25 09:12:23 -07:00
|
|
|
_expected_redirect=url_for("main.user_profile"),
|
2019-03-26 12:35:32 +00:00
|
|
|
)
|
|
|
|
|
assert mock_update_user_attribute.called is True
|
2016-05-16 10:29:58 +01:00
|
|
|
|
|
|
|
|
|
2017-02-03 10:42:01 +00:00
|
|
|
def test_should_show_email_page(
|
2019-03-26 12:35:32 +00:00
|
|
|
client_request,
|
2017-02-03 10:42:01 +00:00
|
|
|
):
|
2023-08-25 09:12:23 -07:00
|
|
|
page = client_request.get("main.user_profile_email")
|
|
|
|
|
assert page.select_one("h1").text.strip() == "Change your email address"
|
2022-03-23 12:40:43 +00:00
|
|
|
# template is shared with "Change your mobile number" but we don't want to show Delete mobile number link
|
2023-08-25 09:12:23 -07:00
|
|
|
assert "Delete your number" not in page.text
|
2016-05-16 10:29:58 +01:00
|
|
|
|
|
|
|
|
|
2017-02-03 10:42:01 +00:00
|
|
|
def test_should_redirect_after_email_change(
|
2019-03-26 12:35:32 +00:00
|
|
|
client_request,
|
2017-02-03 10:42:01 +00:00
|
|
|
mock_login,
|
2018-02-19 16:53:29 +00:00
|
|
|
mock_email_is_not_already_in_use,
|
2017-02-03 10:42:01 +00:00
|
|
|
):
|
2019-03-26 12:35:32 +00:00
|
|
|
client_request.post(
|
2023-08-25 09:12:23 -07:00
|
|
|
"main.user_profile_email",
|
|
|
|
|
_data={"email_address": "new_notify@notify.gsa.gov"},
|
2019-03-26 12:35:32 +00:00
|
|
|
_expected_status=302,
|
|
|
|
|
_expected_redirect=url_for(
|
2023-08-25 09:12:23 -07:00
|
|
|
"main.user_profile_email_authenticate",
|
|
|
|
|
),
|
2019-03-26 12:35:32 +00:00
|
|
|
)
|
2016-05-16 10:29:58 +01:00
|
|
|
|
2021-12-10 16:56:08 +00:00
|
|
|
assert mock_email_is_not_already_in_use.called
|
|
|
|
|
|
2016-05-16 10:29:58 +01:00
|
|
|
|
2023-08-25 09:12:23 -07:00
|
|
|
@pytest.mark.parametrize(
|
2023-09-08 17:58:06 -04:00
|
|
|
("email_address", "error_message"),
|
2023-08-25 09:12:23 -07:00
|
|
|
[
|
|
|
|
|
(
|
|
|
|
|
"me@example.com",
|
2025-01-13 15:53:57 -05:00
|
|
|
"Enter a public sector email address.",
|
2023-08-25 09:12:23 -07:00
|
|
|
),
|
|
|
|
|
(
|
|
|
|
|
"not_valid",
|
|
|
|
|
"Enter a valid email address",
|
|
|
|
|
), # 2 errors with email address, only first error shown
|
|
|
|
|
],
|
|
|
|
|
)
|
2021-12-10 14:59:18 +00:00
|
|
|
def test_should_show_errors_if_new_email_address_does_not_validate(
|
|
|
|
|
client_request,
|
|
|
|
|
mock_email_is_not_already_in_use,
|
2023-07-12 12:09:44 -04:00
|
|
|
mock_get_organizations,
|
2021-12-10 14:59:18 +00:00
|
|
|
email_address,
|
|
|
|
|
error_message,
|
|
|
|
|
):
|
|
|
|
|
page = client_request.post(
|
2023-08-25 09:12:23 -07:00
|
|
|
"main.user_profile_email",
|
|
|
|
|
_data={"email_address": email_address},
|
2021-12-10 14:59:18 +00:00
|
|
|
_expected_status=200,
|
|
|
|
|
)
|
|
|
|
|
|
2023-08-25 09:12:23 -07:00
|
|
|
assert (
|
|
|
|
|
normalize_spaces(page.find("span", class_="usa-error-message").text)
|
|
|
|
|
== f"Error: {error_message}"
|
|
|
|
|
)
|
2021-12-10 16:56:08 +00:00
|
|
|
# We only call API to check if the email address is already in use if there are no other errors
|
|
|
|
|
assert not mock_email_is_not_already_in_use.called
|
2021-12-10 14:59:18 +00:00
|
|
|
|
|
|
|
|
|
2017-02-03 10:42:01 +00:00
|
|
|
def test_should_show_authenticate_after_email_change(
|
2019-03-26 12:35:32 +00:00
|
|
|
client_request,
|
2017-02-03 10:42:01 +00:00
|
|
|
):
|
2019-03-26 12:35:32 +00:00
|
|
|
with client_request.session_transaction() as session:
|
2023-08-25 09:12:23 -07:00
|
|
|
session["new-email"] = "new_notify@notify.gsa.gov"
|
2016-05-16 10:29:58 +01:00
|
|
|
|
2023-08-25 09:12:23 -07:00
|
|
|
page = client_request.get("main.user_profile_email_authenticate")
|
2019-03-26 12:35:32 +00:00
|
|
|
|
2023-08-25 09:12:23 -07:00
|
|
|
assert "Change your email address" in page.text
|
|
|
|
|
assert "Confirm" in page.text
|
2016-01-27 12:22:32 +00:00
|
|
|
|
|
|
|
|
|
2017-02-03 10:42:01 +00:00
|
|
|
def test_should_render_change_email_continue_after_authenticate_email(
|
2019-03-26 12:35:32 +00:00
|
|
|
client_request,
|
2017-02-03 10:42:01 +00:00
|
|
|
mock_verify_password,
|
|
|
|
|
mock_send_change_email_verification,
|
|
|
|
|
):
|
2019-03-26 12:35:32 +00:00
|
|
|
with client_request.session_transaction() as session:
|
2023-08-25 09:12:23 -07:00
|
|
|
session["new-email"] = "new_notify@notify.gsa.gov"
|
2019-03-26 12:35:32 +00:00
|
|
|
page = client_request.post(
|
2023-08-25 09:12:23 -07:00
|
|
|
"main.user_profile_email_authenticate",
|
|
|
|
|
_data={"password": "12345"},
|
2019-03-26 12:35:32 +00:00
|
|
|
_expected_status=200,
|
|
|
|
|
)
|
2023-08-25 09:12:23 -07:00
|
|
|
assert (
|
|
|
|
|
"Click the link in the email to confirm the change to your email address."
|
|
|
|
|
in page.text
|
|
|
|
|
)
|
2016-10-13 17:05:37 +01:00
|
|
|
|
|
|
|
|
|
2017-02-03 10:42:01 +00:00
|
|
|
def test_should_redirect_to_user_profile_when_user_confirms_email_link(
|
2021-05-12 14:57:21 +01:00
|
|
|
notify_admin,
|
2021-12-31 12:08:14 +00:00
|
|
|
client_request,
|
2017-02-03 10:42:01 +00:00
|
|
|
api_user_active,
|
|
|
|
|
mock_update_user_attribute,
|
|
|
|
|
):
|
2023-08-25 09:12:23 -07:00
|
|
|
token = generate_token(
|
|
|
|
|
payload=json.dumps(
|
|
|
|
|
{"user_id": api_user_active["id"], "email": "new_email@gsa.gov"}
|
|
|
|
|
),
|
|
|
|
|
secret=notify_admin.config["SECRET_KEY"],
|
|
|
|
|
salt=notify_admin.config["DANGEROUS_SALT"],
|
|
|
|
|
)
|
2021-12-31 12:08:14 +00:00
|
|
|
client_request.get_url(
|
|
|
|
|
url_for_endpoint_with_token(
|
2023-08-25 09:12:23 -07:00
|
|
|
"main.user_profile_email_confirm",
|
2021-12-31 12:08:14 +00:00
|
|
|
token=token,
|
|
|
|
|
),
|
2023-08-25 09:12:23 -07:00
|
|
|
_expected_redirect=url_for("main.user_profile"),
|
2021-12-31 12:08:14 +00:00
|
|
|
)
|
2016-01-27 12:22:32 +00:00
|
|
|
|
|
|
|
|
|
2017-02-03 10:42:01 +00:00
|
|
|
def test_should_show_mobile_number_page(
|
2019-03-26 12:35:32 +00:00
|
|
|
client_request,
|
2017-02-03 10:42:01 +00:00
|
|
|
):
|
2023-08-25 09:12:23 -07:00
|
|
|
page = client_request.get(("main.user_profile_mobile_number"))
|
|
|
|
|
assert "Change your mobile number" in page.text
|
|
|
|
|
assert "Delete your number" not in page.text
|
2022-02-23 18:31:00 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_change_your_mobile_number_page_shows_delete_link_if_user_on_email_auth(
|
2023-08-25 09:12:23 -07:00
|
|
|
client_request, api_user_active_email_auth, mocker
|
2022-02-23 18:31:00 +00:00
|
|
|
):
|
2023-01-19 17:29:21 -05:00
|
|
|
client_request.login(api_user_active_email_auth)
|
2023-08-25 09:12:23 -07:00
|
|
|
page = client_request.get(("main.user_profile_mobile_number"))
|
|
|
|
|
assert "Change your mobile number" in page.text
|
|
|
|
|
assert "Delete your number" in page.text
|
2022-02-23 18:31:00 +00:00
|
|
|
|
|
|
|
|
|
2022-03-23 12:40:43 +00:00
|
|
|
def test_change_your_mobile_number_page_doesnt_show_delete_link_if_user_has_no_mobile_number(
|
2023-08-25 09:12:23 -07:00
|
|
|
client_request, fake_uuid, mocker
|
2022-03-23 12:40:43 +00:00
|
|
|
):
|
2023-08-25 09:12:23 -07:00
|
|
|
user = create_user(id=fake_uuid, auth_type="email_auth", mobile_number=None)
|
2023-01-19 17:29:21 -05:00
|
|
|
client_request.login(user)
|
2023-08-25 09:12:23 -07:00
|
|
|
page = client_request.get(("main.user_profile_mobile_number"))
|
|
|
|
|
assert "Change your mobile number" in page.text
|
|
|
|
|
assert "Delete your number" not in page.text
|
2022-03-23 12:40:43 +00:00
|
|
|
|
|
|
|
|
|
2022-02-23 18:31:00 +00:00
|
|
|
def test_confirm_delete_mobile_number(
|
2023-08-25 09:12:23 -07:00
|
|
|
client_request, api_user_active_email_auth, mocker
|
2022-02-23 18:31:00 +00:00
|
|
|
):
|
2023-01-19 17:29:21 -05:00
|
|
|
client_request.login(api_user_active_email_auth)
|
2022-02-23 18:31:00 +00:00
|
|
|
|
|
|
|
|
page = client_request.get(
|
2023-08-25 09:12:23 -07:00
|
|
|
".user_profile_confirm_delete_mobile_number",
|
2022-02-23 18:31:00 +00:00
|
|
|
_test_page_title=False,
|
|
|
|
|
)
|
|
|
|
|
|
2023-08-25 09:12:23 -07:00
|
|
|
assert normalize_spaces(page.select_one(".banner-dangerous").text) == (
|
|
|
|
|
"Are you sure you want to delete your mobile number from Notify? " "Yes, delete"
|
2022-02-23 18:31:00 +00:00
|
|
|
)
|
2023-08-25 09:12:23 -07:00
|
|
|
assert "action" not in page.select_one(".banner-dangerous form")
|
|
|
|
|
assert page.select_one(".banner-dangerous form")["method"] == "post"
|
2022-02-23 18:31:00 +00:00
|
|
|
|
|
|
|
|
|
2023-08-25 09:12:23 -07:00
|
|
|
def test_delete_mobile_number(client_request, api_user_active_email_auth, mocker):
|
2023-01-19 17:29:21 -05:00
|
|
|
client_request.login(api_user_active_email_auth)
|
2023-08-25 09:12:23 -07:00
|
|
|
mock_delete = mocker.patch("app.user_api_client.update_user_attribute")
|
2022-02-23 18:31:00 +00:00
|
|
|
|
|
|
|
|
client_request.post(
|
2023-08-25 09:12:23 -07:00
|
|
|
".user_profile_mobile_number_delete",
|
2022-02-23 18:31:00 +00:00
|
|
|
_expected_redirect=url_for(
|
2023-08-25 09:12:23 -07:00
|
|
|
".user_profile",
|
|
|
|
|
),
|
2022-02-23 18:31:00 +00:00
|
|
|
)
|
|
|
|
|
mock_delete.assert_called_once_with(
|
2023-08-25 09:12:23 -07:00
|
|
|
api_user_active_email_auth["id"], mobile_number=None
|
2022-02-23 18:31:00 +00:00
|
|
|
)
|
2016-01-27 12:22:32 +00:00
|
|
|
|
|
|
|
|
|
2023-08-25 09:12:23 -07:00
|
|
|
@pytest.mark.parametrize(
|
|
|
|
|
"phone_number_to_register_with",
|
|
|
|
|
[
|
|
|
|
|
"+12024900460",
|
|
|
|
|
"+1800-555-5555",
|
|
|
|
|
],
|
|
|
|
|
)
|
2017-02-03 10:42:01 +00:00
|
|
|
def test_should_redirect_after_mobile_number_change(
|
2019-03-26 12:35:32 +00:00
|
|
|
client_request,
|
2017-08-29 14:52:24 +01:00
|
|
|
phone_number_to_register_with,
|
2017-02-03 10:42:01 +00:00
|
|
|
):
|
2019-03-26 12:35:32 +00:00
|
|
|
client_request.post(
|
2023-08-25 09:12:23 -07:00
|
|
|
"main.user_profile_mobile_number",
|
|
|
|
|
_data={"mobile_number": phone_number_to_register_with},
|
2019-03-26 12:35:32 +00:00
|
|
|
_expected_status=302,
|
|
|
|
|
_expected_redirect=url_for(
|
2023-08-25 09:12:23 -07:00
|
|
|
"main.user_profile_mobile_number_authenticate",
|
|
|
|
|
),
|
2019-03-26 12:35:32 +00:00
|
|
|
)
|
|
|
|
|
with client_request.session_transaction() as session:
|
2023-08-25 09:12:23 -07:00
|
|
|
assert session["new-mob"] == phone_number_to_register_with
|
2016-01-27 12:22:32 +00:00
|
|
|
|
|
|
|
|
|
2017-02-03 10:42:01 +00:00
|
|
|
def test_should_redirect_after_mobile_number_authenticate(
|
2019-03-26 12:35:32 +00:00
|
|
|
client_request,
|
2017-02-03 10:42:01 +00:00
|
|
|
mock_verify_password,
|
|
|
|
|
mock_send_verify_code,
|
|
|
|
|
):
|
2019-03-26 12:35:32 +00:00
|
|
|
with client_request.session_transaction() as session:
|
2023-08-25 09:12:23 -07:00
|
|
|
session["new-mob"] = "+12021234123"
|
2016-01-27 12:22:32 +00:00
|
|
|
|
2019-03-26 12:35:32 +00:00
|
|
|
client_request.post(
|
2023-08-25 09:12:23 -07:00
|
|
|
"main.user_profile_mobile_number_authenticate",
|
|
|
|
|
_data={"password": "12345667"},
|
2019-03-26 12:35:32 +00:00
|
|
|
_expected_status=302,
|
|
|
|
|
_expected_redirect=url_for(
|
2023-08-25 09:12:23 -07:00
|
|
|
"main.user_profile_mobile_number_confirm",
|
|
|
|
|
),
|
2019-03-26 12:35:32 +00:00
|
|
|
)
|
2016-01-27 12:22:32 +00:00
|
|
|
|
|
|
|
|
|
2017-02-03 10:42:01 +00:00
|
|
|
def test_should_show_confirm_after_mobile_number_change(
|
2019-03-26 12:35:32 +00:00
|
|
|
client_request,
|
2017-02-03 10:42:01 +00:00
|
|
|
):
|
2019-03-26 12:35:32 +00:00
|
|
|
with client_request.session_transaction() as session:
|
2023-08-25 09:12:23 -07:00
|
|
|
session["new-mob-password-confirmed"] = True
|
|
|
|
|
page = client_request.get("main.user_profile_mobile_number_confirm")
|
2016-01-27 12:22:32 +00:00
|
|
|
|
2023-08-25 09:12:23 -07:00
|
|
|
assert "Change your mobile number" in page.text
|
|
|
|
|
assert "Confirm" in page.text
|
2016-01-27 12:22:32 +00:00
|
|
|
|
|
|
|
|
|
2023-08-25 09:12:23 -07:00
|
|
|
@pytest.mark.parametrize(
|
|
|
|
|
"phone_number_to_register_with",
|
|
|
|
|
[
|
|
|
|
|
"+12020900460",
|
|
|
|
|
"+1800-555-555",
|
|
|
|
|
],
|
|
|
|
|
)
|
2017-02-03 10:42:01 +00:00
|
|
|
def test_should_redirect_after_mobile_number_confirm(
|
2019-03-26 12:35:32 +00:00
|
|
|
client_request,
|
2017-02-24 16:21:41 +00:00
|
|
|
mocker,
|
2017-02-03 10:42:01 +00:00
|
|
|
mock_update_user_attribute,
|
|
|
|
|
mock_check_verify_code,
|
2017-08-29 14:52:24 +01:00
|
|
|
phone_number_to_register_with,
|
2017-02-03 10:42:01 +00:00
|
|
|
):
|
2019-12-19 16:59:07 +00:00
|
|
|
user_before = create_api_user_active(with_unique_id=True)
|
|
|
|
|
user_after = create_api_user_active(with_unique_id=True)
|
2023-08-25 09:12:23 -07:00
|
|
|
user_before["current_session_id"] = str(uuid.UUID(int=1))
|
|
|
|
|
user_after["current_session_id"] = str(uuid.UUID(int=2))
|
2017-02-24 16:21:41 +00:00
|
|
|
|
2023-01-19 17:29:21 -05:00
|
|
|
client_request.login(user_before)
|
2023-08-25 09:12:23 -07:00
|
|
|
mocker.patch("app.user_api_client.get_user", side_effect=[user_after])
|
2017-02-24 16:21:41 +00:00
|
|
|
|
2019-03-26 12:35:32 +00:00
|
|
|
with client_request.session_transaction() as session:
|
2023-08-25 09:12:23 -07:00
|
|
|
session["new-mob-password-confirmed"] = True
|
|
|
|
|
session["new-mob"] = phone_number_to_register_with
|
|
|
|
|
session["current_session_id"] = user_before["current_session_id"]
|
2017-02-24 16:21:41 +00:00
|
|
|
|
2019-03-26 12:35:32 +00:00
|
|
|
client_request.post(
|
2023-08-25 09:12:23 -07:00
|
|
|
"main.user_profile_mobile_number_confirm",
|
|
|
|
|
_data={"sms_code": "123456"},
|
2019-03-26 12:35:32 +00:00
|
|
|
_expected_status=302,
|
|
|
|
|
_expected_redirect=url_for(
|
2023-08-25 09:12:23 -07:00
|
|
|
"main.user_profile",
|
|
|
|
|
),
|
2019-03-26 12:35:32 +00:00
|
|
|
)
|
2016-01-27 12:22:32 +00:00
|
|
|
|
2017-02-24 16:21:41 +00:00
|
|
|
# make sure the current_session_id has changed to what the API returned
|
2019-03-26 12:35:32 +00:00
|
|
|
with client_request.session_transaction() as session:
|
2023-08-25 09:12:23 -07:00
|
|
|
assert session["current_session_id"] == user_after["current_session_id"]
|
2017-02-24 16:21:41 +00:00
|
|
|
|
2016-01-27 12:22:32 +00:00
|
|
|
|
2017-02-03 10:42:01 +00:00
|
|
|
def test_should_show_password_page(
|
2019-03-26 12:35:32 +00:00
|
|
|
client_request,
|
2017-02-03 10:42:01 +00:00
|
|
|
):
|
2023-08-25 09:12:23 -07:00
|
|
|
page = client_request.get(("main.user_profile_password"))
|
2016-01-27 12:22:32 +00:00
|
|
|
|
2023-08-25 09:12:23 -07:00
|
|
|
assert page.select_one("h1").text.strip() == "Change your password"
|
2016-01-27 12:22:32 +00:00
|
|
|
|
|
|
|
|
|
2017-02-03 10:42:01 +00:00
|
|
|
def test_should_redirect_after_password_change(
|
2019-03-26 12:35:32 +00:00
|
|
|
client_request,
|
2017-02-07 13:32:20 +00:00
|
|
|
mock_update_user_password,
|
2017-02-03 10:42:01 +00:00
|
|
|
mock_verify_password,
|
|
|
|
|
):
|
2019-03-26 12:35:32 +00:00
|
|
|
client_request.post(
|
2023-08-25 09:12:23 -07:00
|
|
|
"main.user_profile_password",
|
2019-03-26 12:35:32 +00:00
|
|
|
_data={
|
2023-08-25 09:12:23 -07:00
|
|
|
"new_password": "the new password",
|
|
|
|
|
"old_password": "the old password",
|
2019-03-26 12:35:32 +00:00
|
|
|
},
|
|
|
|
|
_expected_status=302,
|
|
|
|
|
_expected_redirect=url_for(
|
2023-08-25 09:12:23 -07:00
|
|
|
"main.user_profile",
|
2019-03-26 12:35:32 +00:00
|
|
|
),
|
|
|
|
|
)
|
2016-10-28 11:45:05 +01:00
|
|
|
|
|
|
|
|
|
2017-02-03 10:42:01 +00:00
|
|
|
def test_non_gov_user_cannot_see_change_email_link(
|
2019-03-26 12:35:32 +00:00
|
|
|
client_request,
|
|
|
|
|
api_nongov_user_active,
|
2023-07-12 12:09:44 -04:00
|
|
|
mock_get_organizations,
|
2017-02-03 10:42:01 +00:00
|
|
|
):
|
2019-03-26 12:35:32 +00:00
|
|
|
client_request.login(api_nongov_user_active)
|
2023-08-25 09:12:23 -07:00
|
|
|
page = client_request.get("main.user_profile")
|
|
|
|
|
assert not page.find("a", {"href": url_for("main.user_profile_email")})
|
2023-10-12 10:21:11 -04:00
|
|
|
assert page.select_one("h1").text.strip() == "User profile"
|
2016-10-28 11:45:05 +01:00
|
|
|
|
|
|
|
|
|
2017-02-03 10:42:01 +00:00
|
|
|
def test_non_gov_user_cannot_access_change_email_page(
|
2019-03-26 12:35:32 +00:00
|
|
|
client_request,
|
|
|
|
|
api_nongov_user_active,
|
2023-07-12 12:09:44 -04:00
|
|
|
mock_get_organizations,
|
2017-02-03 10:42:01 +00:00
|
|
|
):
|
2019-03-26 12:35:32 +00:00
|
|
|
client_request.login(api_nongov_user_active)
|
2023-08-25 09:12:23 -07:00
|
|
|
client_request.get("main.user_profile_email", _expected_status=403)
|
2019-06-13 19:00:17 +01:00
|
|
|
|
|
|
|
|
|
2019-06-14 12:32:47 +01:00
|
|
|
def test_normal_user_doesnt_see_disable_platform_admin(client_request):
|
2023-08-25 09:12:23 -07:00
|
|
|
client_request.get(
|
|
|
|
|
"main.user_profile_disable_platform_admin_view", _expected_status=403
|
|
|
|
|
)
|
2019-06-13 19:00:17 +01:00
|
|
|
|
|
|
|
|
|
2023-08-25 09:12:23 -07:00
|
|
|
def test_platform_admin_can_see_disable_platform_admin_page(
|
|
|
|
|
client_request, platform_admin_user
|
|
|
|
|
):
|
2019-06-13 19:00:17 +01:00
|
|
|
client_request.login(platform_admin_user)
|
2023-08-25 09:12:23 -07:00
|
|
|
page = client_request.get("main.user_profile_disable_platform_admin_view")
|
2019-06-13 19:00:17 +01:00
|
|
|
|
2023-08-25 09:12:23 -07:00
|
|
|
assert page.select_one("h1").text.strip() == "Use platform admin view"
|
|
|
|
|
assert page.select_one("input[checked]")["value"] == "True"
|
2019-06-13 19:00:17 +01:00
|
|
|
|
|
|
|
|
|
2019-06-14 12:32:47 +01:00
|
|
|
def test_can_disable_platform_admin(client_request, platform_admin_user):
|
2019-06-13 19:00:17 +01:00
|
|
|
client_request.login(platform_admin_user)
|
|
|
|
|
|
|
|
|
|
with client_request.session_transaction() as session:
|
2023-08-25 09:12:23 -07:00
|
|
|
assert "disable_platform_admin_view" not in session
|
2019-06-13 19:00:17 +01:00
|
|
|
|
|
|
|
|
client_request.post(
|
2023-08-25 09:12:23 -07:00
|
|
|
"main.user_profile_disable_platform_admin_view",
|
|
|
|
|
_data={"enabled": False},
|
2019-06-13 19:00:17 +01:00
|
|
|
_expected_status=302,
|
2023-08-25 09:12:23 -07:00
|
|
|
_expected_redirect=url_for("main.user_profile"),
|
2019-06-13 19:00:17 +01:00
|
|
|
)
|
|
|
|
|
|
|
|
|
|
with client_request.session_transaction() as session:
|
2023-08-25 09:12:23 -07:00
|
|
|
assert session["disable_platform_admin_view"] is True
|
2019-06-13 19:00:17 +01:00
|
|
|
|
|
|
|
|
|
2019-06-14 12:32:47 +01:00
|
|
|
def test_can_reenable_platform_admin(client_request, platform_admin_user):
|
2019-06-13 19:00:17 +01:00
|
|
|
client_request.login(platform_admin_user)
|
|
|
|
|
|
|
|
|
|
with client_request.session_transaction() as session:
|
2023-08-25 09:12:23 -07:00
|
|
|
session["disable_platform_admin_view"] = True
|
2019-06-13 19:00:17 +01:00
|
|
|
|
|
|
|
|
client_request.post(
|
2023-08-25 09:12:23 -07:00
|
|
|
"main.user_profile_disable_platform_admin_view",
|
|
|
|
|
_data={"enabled": True},
|
2019-06-13 19:00:17 +01:00
|
|
|
_expected_status=302,
|
2023-08-25 09:12:23 -07:00
|
|
|
_expected_redirect=url_for("main.user_profile"),
|
2019-06-13 19:00:17 +01:00
|
|
|
)
|
|
|
|
|
|
|
|
|
|
with client_request.session_transaction() as session:
|
2023-08-25 09:12:23 -07:00
|
|
|
assert session["disable_platform_admin_view"] is False
|