mirror of
https://github.com/GSA/notifications-admin.git
synced 2026-08-18 21:49:37 -04:00
Merge pull request #3931 from alphagov/refactor-email-verify-webauthn
Refactor email revalidation check
This commit is contained in:
@@ -1,7 +1,6 @@
|
||||
import pytest
|
||||
from bs4 import BeautifulSoup
|
||||
from flask import url_for
|
||||
from freezegun import freeze_time
|
||||
|
||||
from tests.conftest import (
|
||||
SERVICE_ONE_ID,
|
||||
@@ -11,6 +10,11 @@ from tests.conftest import (
|
||||
)
|
||||
|
||||
|
||||
@pytest.fixture
|
||||
def mock_email_validated_recently(mocker):
|
||||
return mocker.patch('app.main.views.two_factor.email_needs_revalidating', return_value=False)
|
||||
|
||||
|
||||
@pytest.mark.parametrize('request_url', ['two_factor_email_sent', 'revalidate_email_sent'])
|
||||
@pytest.mark.parametrize('redirect_url', [None, f'/services/{SERVICE_ONE_ID}/templates'])
|
||||
@pytest.mark.parametrize('email_resent, page_title', [
|
||||
@@ -71,7 +75,6 @@ def test_should_render_two_factor_page(
|
||||
)['href'] == url_for('main.check_and_resend_text_code', next=redirect_url)
|
||||
|
||||
|
||||
@freeze_time('2020-01-27T12:00:00')
|
||||
def test_should_login_user_and_should_redirect_to_next_url(
|
||||
client,
|
||||
api_user_active,
|
||||
@@ -79,12 +82,12 @@ def test_should_login_user_and_should_redirect_to_next_url(
|
||||
mock_get_user_by_email,
|
||||
mock_check_verify_code,
|
||||
mock_create_event,
|
||||
mock_email_validated_recently,
|
||||
):
|
||||
with client.session_transaction() as session:
|
||||
session['user_details'] = {
|
||||
'id': api_user_active['id'],
|
||||
'email': api_user_active['email_address']}
|
||||
api_user_active['email_access_validated_at'] = '2020-01-23T11:35:21.726132Z'
|
||||
|
||||
response = client.post(url_for('main.two_factor_sms', next='/services/{}'.format(SERVICE_ONE_ID)),
|
||||
data={'sms_code': '12345'})
|
||||
@@ -96,7 +99,6 @@ def test_should_login_user_and_should_redirect_to_next_url(
|
||||
)
|
||||
|
||||
|
||||
@freeze_time('2020-01-27T12:00:00')
|
||||
def test_should_send_email_and_redirect_to_info_page_if_user_needs_to_revalidate_email(
|
||||
client,
|
||||
api_user_active,
|
||||
@@ -107,7 +109,7 @@ def test_should_send_email_and_redirect_to_info_page_if_user_needs_to_revalidate
|
||||
mocker
|
||||
):
|
||||
mocker.patch('app.user_api_client.get_user', return_value=api_user_active)
|
||||
api_user_active['email_access_validated_at'] = '2019-03-23T11:35:21.726132Z'
|
||||
mocker.patch('app.main.views.two_factor.email_needs_revalidating', return_value=True)
|
||||
with client.session_transaction() as session:
|
||||
session['user_details'] = {
|
||||
'id': api_user_active['id'],
|
||||
@@ -124,7 +126,6 @@ def test_should_send_email_and_redirect_to_info_page_if_user_needs_to_revalidate
|
||||
mock_send_verify_code.assert_called_with(api_user_active['id'], 'email', None, mocker.ANY)
|
||||
|
||||
|
||||
@freeze_time('2020-01-27T12:00:00')
|
||||
def test_should_login_user_and_not_redirect_to_external_url(
|
||||
client,
|
||||
api_user_active,
|
||||
@@ -133,12 +134,12 @@ def test_should_login_user_and_not_redirect_to_external_url(
|
||||
mock_check_verify_code,
|
||||
mock_get_services_with_one_service,
|
||||
mock_create_event,
|
||||
mock_email_validated_recently,
|
||||
):
|
||||
with client.session_transaction() as session:
|
||||
session['user_details'] = {
|
||||
'id': api_user_active['id'],
|
||||
'email': api_user_active['email_address']}
|
||||
api_user_active['email_access_validated_at'] = '2020-01-23T11:35:21.726132Z'
|
||||
|
||||
response = client.post(url_for('main.two_factor_sms', next='http://www.google.com'),
|
||||
data={'sms_code': '12345'})
|
||||
@@ -149,7 +150,6 @@ def test_should_login_user_and_not_redirect_to_external_url(
|
||||
@pytest.mark.parametrize('platform_admin', (
|
||||
True, False,
|
||||
))
|
||||
@freeze_time('2020-01-27T12:00:00')
|
||||
def test_should_login_user_and_redirect_to_show_accounts(
|
||||
client,
|
||||
api_user_active,
|
||||
@@ -157,13 +157,13 @@ def test_should_login_user_and_redirect_to_show_accounts(
|
||||
mock_get_user_by_email,
|
||||
mock_check_verify_code,
|
||||
mock_create_event,
|
||||
mock_email_validated_recently,
|
||||
platform_admin,
|
||||
):
|
||||
with client.session_transaction() as session:
|
||||
session['user_details'] = {
|
||||
'id': api_user_active['id'],
|
||||
'email': api_user_active['email_address']}
|
||||
api_user_active['email_access_validated_at'] = '2020-01-23T11:35:21.726132Z'
|
||||
api_user_active['platform_admin'] = platform_admin
|
||||
|
||||
response = client.post(url_for('main.two_factor_sms'),
|
||||
@@ -192,7 +192,6 @@ def test_should_return_200_with_sms_code_error_when_sms_code_is_wrong(
|
||||
assert 'Code not found' in response.get_data(as_text=True)
|
||||
|
||||
|
||||
@freeze_time('2020-01-27T12:00:00')
|
||||
def test_should_login_user_when_multiple_valid_codes_exist(
|
||||
client,
|
||||
api_user_active,
|
||||
@@ -201,19 +200,18 @@ def test_should_login_user_when_multiple_valid_codes_exist(
|
||||
mock_check_verify_code,
|
||||
mock_get_services_with_one_service,
|
||||
mock_create_event,
|
||||
mock_email_validated_recently,
|
||||
):
|
||||
with client.session_transaction() as session:
|
||||
session['user_details'] = {
|
||||
'id': api_user_active['id'],
|
||||
'email': api_user_active['email_address']}
|
||||
api_user_active['email_access_validated_at'] = '2020-01-23T11:35:21.726132Z'
|
||||
|
||||
response = client.post(url_for('main.two_factor_sms'),
|
||||
data={'sms_code': '23456'})
|
||||
assert response.status_code == 302
|
||||
|
||||
|
||||
@freeze_time('2020-01-27T12:00:00')
|
||||
def test_two_factor_should_set_password_when_new_password_exists_in_session(
|
||||
client,
|
||||
api_user_active,
|
||||
@@ -222,13 +220,13 @@ def test_two_factor_should_set_password_when_new_password_exists_in_session(
|
||||
mock_get_services_with_one_service,
|
||||
mock_update_user_password,
|
||||
mock_create_event,
|
||||
mock_email_validated_recently,
|
||||
):
|
||||
with client.session_transaction() as session:
|
||||
session['user_details'] = {
|
||||
'id': api_user_active['id'],
|
||||
'email': api_user_active['email_address'],
|
||||
'password': 'changedpassword'}
|
||||
api_user_active['email_access_validated_at'] = '2020-01-23T11:35:21.726132Z'
|
||||
|
||||
response = client.post(url_for('main.two_factor_sms'),
|
||||
data={'sms_code': '12345'})
|
||||
@@ -279,7 +277,6 @@ def test_two_factor_get_should_redirect_to_sign_in_if_user_not_in_session(
|
||||
)
|
||||
|
||||
|
||||
@freeze_time('2020-01-27T12:00:00')
|
||||
def test_two_factor_should_activate_pending_user(
|
||||
client,
|
||||
mocker,
|
||||
@@ -287,10 +284,10 @@ def test_two_factor_should_activate_pending_user(
|
||||
mock_check_verify_code,
|
||||
mock_create_event,
|
||||
mock_activate_user,
|
||||
mock_email_validated_recently,
|
||||
):
|
||||
mocker.patch('app.user_api_client.get_user', return_value=api_user_pending)
|
||||
mocker.patch('app.service_api_client.get_services', return_value={'data': []})
|
||||
api_user_pending['email_access_validated_at'] = '2020-01-23T11:35:21.726132Z'
|
||||
with client.session_transaction() as session:
|
||||
session['user_details'] = {
|
||||
'id': api_user_pending['id'],
|
||||
|
||||
@@ -4,7 +4,6 @@ from unittest.mock import ANY, Mock
|
||||
import pytest
|
||||
from fido2 import cbor
|
||||
from flask import url_for
|
||||
from freezegun.api import freeze_time
|
||||
|
||||
from app.models.webauthn_credential import RegistrationError, WebAuthnCredential
|
||||
|
||||
@@ -336,7 +335,6 @@ def test_complete_authentication_clears_session(
|
||||
assert 'webauthn_authentication_state' not in session
|
||||
|
||||
|
||||
@freeze_time('2020-01-30')
|
||||
@pytest.mark.parametrize('url_kwargs, expected_redirect', [
|
||||
({}, '/accounts-or-dashboard'),
|
||||
({'next': '/bar'}, '/bar'),
|
||||
@@ -350,7 +348,6 @@ def test_verify_webauthn_login_signs_user_in(
|
||||
expected_redirect,
|
||||
):
|
||||
platform_admin_user['auth_type'] = 'webauthn_auth'
|
||||
platform_admin_user['email_access_validated_at'] = '2020-01-25T00:00:00.000000Z'
|
||||
|
||||
with client.session_transaction() as session:
|
||||
session['user_details'] = {
|
||||
@@ -360,6 +357,7 @@ def test_verify_webauthn_login_signs_user_in(
|
||||
mocker.patch('app.user_api_client.get_user', return_value=platform_admin_user)
|
||||
mocker.patch('app.main.views.webauthn_credentials._verify_webauthn_authentication')
|
||||
mocker.patch('app.user_api_client.complete_webauthn_login_attempt', return_value=(True, None))
|
||||
mocker.patch('app.main.views.webauthn_credentials.email_needs_revalidating', return_value=False)
|
||||
|
||||
resp = client.post(url_for('main.webauthn_complete_authentication', **url_kwargs))
|
||||
|
||||
@@ -397,7 +395,6 @@ def test_verify_webauthn_login_signs_user_in_doesnt_sign_user_in_if_api_rejects(
|
||||
assert resp.status_code == 403
|
||||
|
||||
|
||||
@freeze_time('2020-04-30')
|
||||
def test_verify_webauthn_login_signs_user_in_sends_revalidation_email_if_needed(
|
||||
client,
|
||||
mocker,
|
||||
@@ -405,7 +402,6 @@ def test_verify_webauthn_login_signs_user_in_sends_revalidation_email_if_needed(
|
||||
platform_admin_user,
|
||||
):
|
||||
platform_admin_user['auth_type'] = 'webauthn_auth'
|
||||
platform_admin_user['email_access_validated_at'] = '2020-01-25T00:00:00.000000Z'
|
||||
user_details = {
|
||||
'id': platform_admin_user['id'],
|
||||
'email': platform_admin_user['email_address']
|
||||
@@ -417,6 +413,7 @@ def test_verify_webauthn_login_signs_user_in_sends_revalidation_email_if_needed(
|
||||
mocker.patch('app.user_api_client.get_user', return_value=platform_admin_user)
|
||||
mocker.patch('app.main.views.webauthn_credentials._verify_webauthn_authentication')
|
||||
mocker.patch('app.user_api_client.complete_webauthn_login_attempt', return_value=(True, None))
|
||||
mocker.patch('app.main.views.webauthn_credentials.email_needs_revalidating', return_value=True)
|
||||
|
||||
resp = client.post(url_for('main.webauthn_complete_authentication'))
|
||||
|
||||
|
||||
Reference in New Issue
Block a user