diff --git a/.github/workflows/checks.yml b/.github/workflows/checks.yml index be0a6cc66..f50ee1bcc 100644 --- a/.github/workflows/checks.yml +++ b/.github/workflows/checks.yml @@ -157,7 +157,7 @@ jobs: - uses: ./.github/actions/setup-project - name: Create requirements.txt run: poetry export --without-hashes --format=requirements.txt > requirements.txt - - uses: pypa/gh-action-pip-audit@v1.0.6 + - uses: pypa/gh-action-pip-audit@v1.0.8 with: inputs: requirements.txt - name: Run npm audit diff --git a/app/main/views/dashboard.py b/app/main/views/dashboard.py index 4d5aca14d..8453ef369 100644 --- a/app/main/views/dashboard.py +++ b/app/main/views/dashboard.py @@ -134,11 +134,17 @@ def template_usage(service_id): months=months, stats=stats, most_used_template_count=max( - max( - (template["requested_count"] for template in month["templates_used"]), - default=0, - ) - for month in months + ( + max( + ( + template["requested_count"] + for template in month["templates_used"] + ), + default=0, + ) + for month in months + ), + default=0, ), years=get_tuples_of_financial_years( partial(url_for, ".template_usage", service_id=service_id), @@ -155,31 +161,16 @@ def usage(service_id): year, current_financial_year = requested_and_current_financial_year(request) free_sms_allowance = billing_api_client.get_free_sms_fragment_limit_for_year( - service_id, year + service_id ) + units = billing_api_client.get_monthly_usage_for_service(service_id, year) + yearly_usage = billing_api_client.get_annual_usage_for_service(service_id, year) more_stats = format_monthly_stats_to_list( service_api_client.get_monthly_notification_stats(service_id, year)["data"] ) - if year == current_financial_year: - # This includes Oct, Nov, Dec - # but we don't need next year's data yet - more_stats = [ - month - for month in more_stats - if month["name"] in ["October", "November", "December"] - ] - elif year == (current_financial_year + 1): - # This is all the other months - # and we need last year's data - more_stats = [ - month - for month in more_stats - if month["name"] not in ["October", "November", "December"] - ] - return render_template( "views/usage.html", months=list(get_monthly_usage_breakdown(year, units, more_stats)), @@ -341,8 +332,15 @@ def get_dashboard_partials(service_id): dashboard_totals = (get_dashboard_totals(stats),) free_sms_allowance = billing_api_client.get_free_sms_fragment_limit_for_year( current_service.id, - get_current_financial_year(), ) + # These 2 calls will update the dashboard sms allowance count while in trial mode. + billing_api_client.get_monthly_usage_for_service( + service_id, get_current_financial_year() + ) + billing_api_client.create_or_update_free_sms_fragment_limit( + service_id, free_sms_fragment_limit=free_sms_allowance + ) + yearly_usage = billing_api_client.get_annual_usage_for_service( service_id, get_current_financial_year(), @@ -433,13 +431,7 @@ def aggregate_status_types(counts_dict): def get_months_for_financial_year(year, time_format="%B"): - return [ - month.strftime(time_format) - for month in ( - get_months_for_year(10, 13, year) + get_months_for_year(1, 10, year + 1) - ) - if month < datetime.now() - ] + return [month.strftime(time_format) for month in (get_months_for_year(1, 13, year))] def get_months_for_year(start, end, year): diff --git a/app/main/views/sign_in.py b/app/main/views/sign_in.py index 6de46b023..ee427322e 100644 --- a/app/main/views/sign_in.py +++ b/app/main/views/sign_in.py @@ -6,6 +6,7 @@ import jwt import requests from flask import ( Markup, + Response, abort, current_app, flash, @@ -26,6 +27,7 @@ from app.main.views.verify import activate_user from app.models.user import InvitedUser, User from app.utils import hide_from_search_engines from app.utils.login import is_safe_redirect_url +from app.utils.time import is_less_than_days_ago def _reformat_keystring(orig): @@ -100,20 +102,47 @@ def _do_login_dot_gov(): user_email, user_uuid = _get_user_email_and_uuid(access_token) redirect_url = request.args.get("next") user = user_api_client.get_user_by_uuid_or_email(user_uuid, user_email) - activate_user(user["id"]) + + # Check if the email needs to be revalidated + is_fresh_email = is_less_than_days_ago( + user["email_access_validated_at"], 90 + ) + if not is_fresh_email: + return verify_email(user, redirect_url) + + usr = User.from_email_address(user["email_address"]) + activate_user(usr.id) except BaseException as be: # noqa B036 current_app.logger.error(be) error(401) - return redirect(url_for("main.show_accounts_or_dashboard", next=redirect_url)) # end login.gov +def verify_email(user, redirect_url): + user_api_client.send_verify_code(user["id"], "email", None, redirect_url) + title = "Email resent" if request.args.get("email_resent") else "Check your email" + redirect_url = request.args.get("next") + return render_template( + "views/re-validate-email-sent.html", title=title, redirect_url=redirect_url + ) + + @main.route("/sign-in", methods=(["GET", "POST"])) @hide_from_search_engines def sign_in(): - _do_login_dot_gov() + # If we have to revalidated the email, send the message + # via email and redirect to the "verify your email page" + # and don't proceed further with login + email_verify_template = _do_login_dot_gov() + if ( + email_verify_template + and not isinstance(email_verify_template, Response) + and "Check your email" in email_verify_template + ): + return email_verify_template + redirect_url = request.args.get("next") if os.getenv("NOTIFY_E2E_TEST_EMAIL"): @@ -197,7 +226,6 @@ def sign_in(): form=form, again=bool(redirect_url), other_device=other_device, - login_gov_enabled=True, password_reset_url=password_reset_url, initial_signin_url=url, ) diff --git a/app/templates/error/500.html b/app/templates/error/500.html index af86388d7..aca8332df 100644 --- a/app/templates/error/500.html +++ b/app/templates/error/500.html @@ -7,7 +7,7 @@ Sorry, we can't deliver what you asked for right now.

- Please try again later or email us for more information.

+ Please try again later or email us for more information.

diff --git a/app/templates/views/service-settings/set-auth-type.html b/app/templates/views/service-settings/set-auth-type.html index 263740222..2fd5259f8 100644 --- a/app/templates/views/service-settings/set-auth-type.html +++ b/app/templates/views/service-settings/set-auth-type.html @@ -16,28 +16,9 @@
{{ page_header('Sign-in method') }} - {% if 'email_auth' in current_service.permissions %} -

- Email link or text message code -

-

- Your team members can sign in with either a text message code - or an email link. -

-

- You can set the sign-in method for individual team members. -

- {% else %} -

- Text message code -

-

- Your team members sign in with a text message code. -

-

- Contact us if signing in with a text message is a problem for your team. -

- {% endif %} +

Your username, password, and multi-factor authentication options are handled by Login.gov.

+

To make changes, head to Login.gov and sign-in with your credentials.

+

Any changes made to your Login.gov account will automatically be synced with Notify.gov.

diff --git a/app/templates/views/set-up-your-profile.html b/app/templates/views/set-up-your-profile.html index 8f37d3617..e774a921f 100644 --- a/app/templates/views/set-up-your-profile.html +++ b/app/templates/views/set-up-your-profile.html @@ -16,7 +16,7 @@ Set up your profile {{ form.name(param_extensions={}) }}
{{ form.mobile_number(param_extensions={ - "hint": {"text": "We'll send you a security code by text message"}, + "hint": {"text": "We need your number so you can send yourself test texts"}, }) }}