Delete cached users and templates when archiving a service

When the admin app gets user objects from the API, these include a dict
of permissions by service for what the user can do to that services.
Permissions for inactive services are not included in the response as
per:
87cb6f2597/app/dao/permissions_dao.py (L66)

However, this causes a bug where a service is archived but cached user
data still tells us that the user has permissions to view the service.
This should not be the case and causes errors where users can still see
the archived service page, it's settings, and even request to go live
for it, because they are using old cached data for the user.

We solve this by deleting the users who are part of the service from the
cache.

We also delete the templates for this service from the cache as the
templates are also archived when we ask the API to archive the service
as per:
d95c0131e0/app/service/rest.py (L597)

Note, one decision I had to make was whether to delete the user cache
for just active team members or also invited users. Assuming an invited
user can't see the service until they've accepted their invite anyway, it
shouldn't make any difference whether we delete their cache or not.
This commit is contained in:
David McDonald
2020-05-22 11:19:49 +01:00
parent 930b565510
commit a65ada0d7e
4 changed files with 16 additions and 3 deletions

View File

@@ -129,7 +129,12 @@ class ServiceAPIClient(NotifyAdminAPIClient):
return self.update_service(service_id, **properties)
@cache.delete('service-{service_id}')
def archive_service(self, service_id):
@cache.delete('service-{service_id}-templates')
def archive_service(self, service_id, service_users):
# We need to purge the cache for the services users as otherwise, although they will have had their permissions
# removed in the DB, they would still have permissions in the cache to view/edit/manage this service
for user in service_users:
cache.delete(f'user-{user.id}')
return self.post('/service/{}/archive'.format(service_id), data=None)
@cache.delete('service-{service_id}')