mirror of
https://github.com/GSA/notifications-admin.git
synced 2026-08-17 04:59:37 -04:00
Do not verify sms for pending users with email auth
This is to fix a bug where a user creates an account but doesn't complete registration, then they are invited to a service that changes their auth to email_auth, and then when they try to complete registration they are still asked for sms code. It should save users some pain, and reduce number of support tickets.
This commit is contained in:
committed by
Leo Hemsted
parent
262e2ba6e7
commit
8112930e24
@@ -63,6 +63,13 @@ def verify_email(token):
|
||||
return redirect(url_for('main.sign_in'))
|
||||
|
||||
session['user_details'] = {"email": user.email_address, "id": user.id}
|
||||
|
||||
if user.auth_type == 'email_auth':
|
||||
try:
|
||||
return activate_user(user.id)
|
||||
finally:
|
||||
session.pop('user_details', None)
|
||||
|
||||
user.send_verify_code()
|
||||
return redirect(url_for('main.verify'))
|
||||
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
import json
|
||||
import uuid
|
||||
from datetime import datetime
|
||||
from unittest.mock import Mock
|
||||
|
||||
from flask import session as flask_session
|
||||
@@ -128,6 +129,59 @@ def test_verify_email_redirects_to_verify_if_token_valid(
|
||||
assert session['user_details'] == {'email': api_user_pending['email_address'], 'id': api_user_pending['id']}
|
||||
|
||||
|
||||
def test_verify_email_doesnt_verify_sms_if_user_on_email_auth(
|
||||
client_request,
|
||||
mocker,
|
||||
mock_send_verify_code,
|
||||
mock_check_verify_code,
|
||||
mock_activate_user,
|
||||
fake_uuid,
|
||||
):
|
||||
pending_user_with_email_auth = {
|
||||
'id': fake_uuid,
|
||||
'name': 'Test User',
|
||||
'password': 'somepassword',
|
||||
'email_address': 'test@user.gov.uk',
|
||||
'mobile_number': '07700 900762',
|
||||
'state': 'pending',
|
||||
'failed_login_count': 0,
|
||||
'permissions': {},
|
||||
'platform_admin': False,
|
||||
'auth_type': 'email_auth',
|
||||
'password_changed_at': str(datetime.utcnow()),
|
||||
'services': [],
|
||||
'organisations': [],
|
||||
'current_session_id': None,
|
||||
'logged_in_at': None,
|
||||
'email_access_validated_at': None,
|
||||
'can_use_webauthn': False,
|
||||
}
|
||||
mocker.patch('app.user_api_client.get_user', return_value=pending_user_with_email_auth)
|
||||
token_data = {"user_id": pending_user_with_email_auth['id'], "secret_code": 'UNUSED'}
|
||||
mocker.patch('app.main.views.verify.check_token', return_value=json.dumps(token_data))
|
||||
|
||||
with client_request.session_transaction() as session:
|
||||
session['user_details'] = {
|
||||
'email_address': pending_user_with_email_auth['email_address'],
|
||||
'id': pending_user_with_email_auth['id'],
|
||||
}
|
||||
|
||||
client_request.get(
|
||||
'main.verify_email',
|
||||
token='notreal',
|
||||
_expected_redirect=url_for('main.add_service', first='first', _external=True),
|
||||
)
|
||||
|
||||
assert not mock_check_verify_code.called
|
||||
assert not mock_send_verify_code.called
|
||||
|
||||
mock_activate_user.assert_called_once_with(pending_user_with_email_auth['id'])
|
||||
|
||||
# user is logged in
|
||||
with client_request.session_transaction() as session:
|
||||
assert session['user_id'] == pending_user_with_email_auth['id']
|
||||
|
||||
|
||||
def test_verify_email_redirects_to_email_sent_if_token_expired(
|
||||
client_request,
|
||||
mocker,
|
||||
|
||||
Reference in New Issue
Block a user