stop putting invite user objects in the session

the invited_user objects can be arbitrarily large, and when we put them
in the session we risk going over the session cookie's 4kb size limit.
since https://github.com/alphagov/notifications-admin/pull/3827 was
merged, we store the user id in the session. Now that's been live for a
day or two we can safely stop putting the rich object in the session.

Needed to change a bunch of tests for this to make sure appropriate
mocks were set. Also some tests were accidentally re-using fake_uuid.

Still pop the object when cleaning up sessions. We'll need to remove
that in a future PR.
This commit is contained in:
Leo Hemsted
2021-03-16 17:58:27 +00:00
parent 1a63c2c8be
commit 8a2fec6f18
8 changed files with 68 additions and 167 deletions

View File

@@ -224,7 +224,8 @@ def test_email_address_is_treated_case_insensitively_when_signing_in_as_invited_
api_user_active,
sample_invite,
mock_accept_invite,
mock_send_verify_code
mock_send_verify_code,
mock_get_invited_user_by_id,
):
sample_invite['email_address'] = 'TEST@user.gov.uk'
@@ -234,7 +235,7 @@ def test_email_address_is_treated_case_insensitively_when_signing_in_as_invited_
)
with client.session_transaction() as session:
session['invited_user'] = sample_invite
session['invited_user_id'] = sample_invite['id']
response = client.post(
url_for('main.sign_in'), data={
@@ -244,3 +245,4 @@ def test_email_address_is_treated_case_insensitively_when_signing_in_as_invited_
assert mock_accept_invite.called
assert response.status_code == 302
assert mock_send_verify_code.called
mock_get_invited_user_by_id.assert_called_once_with(sample_invite['id'])