Merge branch 'main' of https://github.com/GSA/notifications-admin into 1216-login-gov-pre-sign-in-page

This commit is contained in:
Jonathan Bobel
2024-02-27 11:53:57 -05:00
10 changed files with 122 additions and 58 deletions

View File

@@ -76,6 +76,7 @@ def service_dashboard(service_id):
"notifications": aggregate_notifications_by_job.get(job["id"], []),
}
for job in job_response
if aggregate_notifications_by_job.get(job["id"], [])
]
return render_template(
"views/dashboard/dashboard.html",

View File

@@ -41,7 +41,7 @@
<h3>To create and format your message</h3>
<ol class="list">
<li>All messages start from a template</li>
<li>Click “Send Messages”. Youll see existing templates.</li>
<li>Click “<a href={{ url_for('.choose_template', service_id=current_service.id) }}>Send Messages</a>”. Youll see existing templates.</li>
<li>Add a new template or choose an existing template and select Edit.</li>
</ol>
@@ -120,7 +120,7 @@
{# Identify your program #}
<h2 class="padding-top-1" id="identify-program">Identify your program</h2>
<h2 class="padding-top-1" id="indentify-program">Identify your program</h2>
<p>You can help your recipients identify your texts as legitimate by customizing your messages to clearly state who they
are from. Consider using the program or benefit name that is most familiar to your recipients.</p>

View File

@@ -30,7 +30,7 @@ more parts towards the allowance if you:</p>
</ul>
<h3 class="font-body-lg" id="long-text-messages">Long text messages</h3>
<p>If a text message is longer than 160 characters (including spaces), it counts as more than one message.</p>
<p>If a text message is longer than 160 characters (including spaces), it counts as more than one message part.</p>
<div class="bottom-gutter-3-2">
{% call mapping_table(

View File

@@ -50,9 +50,9 @@
<li>Message send/failure analytics</li>
</ul>
<h3id="next">Next</h3>
<h3 id="next">Next</h3>
<p>If the pilot is successful, we hope to recruit additional high-impact partners to improve outcomes for low-income individuals and families.</p>
<p>If the pilot is successful, we hope to recruit additional partners to improve outcomes for low-income individuals and families.</p>
<p>Goals during this stage:</p>

View File

@@ -65,9 +65,9 @@
<h3 class="font-body-lg">Protect sensitive information</h3>
<p>Some messages include sensitive information like security codes or password reset links.</p>
<p>If youre sending a message with sensitive information, you can choose to hide those details on the Notify dashboard once the message has been sent. This means that only the message recipient will be able to see that information.</p>
<img src="{{ asset_url('images/product/security-review-message.png') }}"
alt="Screenshot of a test message in review with the link to 'hide personalization after sending' circled.">
<h2 class="font-body-lg" id="user-permissions-signing-in">User permissions and signing in</h2>
<p>You can set different user permissions in Notify. This lets you control who in your team has access to certain parts of the service.</p>
<h3 class="font-body-lg">Two-factor authentication</h3>
<p>To sign in to Notify, youll need to enter:</p>
<ul class="list list-bullet">
@@ -76,11 +76,6 @@
</ul>
<p>If signing in with a text message is a problem for your team, <a class="usa-link" href="{{ url_for('main.support') }}">contact us</a> to find out about using an email link instead.</p>
<img src="{{ asset_url('images/product/security-review-message.png') }}"
alt="Screenshot of a teat message in review with the link to 'hide personalization after sending' circled.">
<h4>How to hide PII after sending a message</h4>
<h3>User permissions and signing in</h3>
<p>You can set different user permissions in Notify. This lets you control who in your team has access to certain parts of
the service.</p>
@@ -93,32 +88,4 @@
</ul>
<p>If signing in with a text message is a problem for your team, <a href="https://beta.notify.gov/support">contact us</a> to find out about using an email link instead.</p>
<!-- <h2 class="font-body-lg" id="information-risk-management">Information risk management</h2>
<p>Our approach to information risk management follows NCSC guidance. It assesses:</p>
<ul class="list list-bullet">
<li>how Notify is built</li>
<li>the infrastructure Notify is built upon</li>
<li>support for the Notify service</li>
</ul>
<p>This approach also applies to the service providers Notify uses to send messages.</p> -->
<!-- <h2 class="font-body-lg" id="how-we-manage-risk">How we manage risks on Notify</h2>
<p>Things we do to manage risks on Notify include:</p>
<ul class="list list-bullet">
<li>formal risk assessments based on <a class="usa-link" href="http://www.iso.org/iso/catalogue_detail?csnumber=56742">ISO 27005:2011</a> and National Cyber Security Centre guidance</li>
<li><a class="usa-link" href="https://www.ncsc.gov.uk/information/check-penetration-testing">CHECK</a>-based testing, both annually and when any major changes are made to Notify</li>
<li>residual risk statement preparation and active management of the risk treatment plan</li>
<li>regular updates to the Privacy Impact Assessment</li>
<li>security impact assessments</li>
</ul> -->
<!-- <h2 class="font-body-lg" id="cabinet-office-approval">Cabinet Office approval</h2>
<p>Notify has been assessed and approved by the Cabinet Office Senior Information Risk Officer (SIRO). The SIRO checks this approval once a year.</p>
<p>Notify also has approval from the Office of the Governments SIRO to host data within the EEA.</p>
<h2 class="font-body-lg" id="classifications-and-security-vetting">Classifications and security vetting</h2>
<p>You can use Notify to send messages classified as OFFICIAL or OFFICIAL-SENSITIVE under the <a class="usa-link" href="https://www.gov.uk/government/publications/government-security-classifications">Government Security Classifications</a> policy.</p>
<p>Notify does not process data classified as SECRET or TOP SECRET.</p>
<p>The Notify team has Security Check (SC) level clearance from <a class="usa-link" href="https://www.gov.uk/government/organizations/united-kingdom-security-vetting">United Kingdom Security Vetting</a> (UKSV).</p> -->
{% endblock %}

View File

@@ -13,9 +13,9 @@
<h1 class="font-body-2xl margin-bottom-3">Contact us</h1>
<p>Notify is designed to be easy to use.</p>
<ul class="list list-bullet">
<li>For information on personalization and data preparation, see <a href="/using-notify/guidance">Guidance</a>.</li>
<li>For help interpreting delivery reports, see <a href="/using-notify/delivery-status">Delivery Status</a>.</li>
<li>For details on pricing and what counts as a message part, see <a href="/using-notify/pricing"></a>Pricing.</li>
<li>For information on personalization and data preparation, see <a href={{ url_for("main.guidance_index") }}>Guidance</a>.</li>
<li>For help interpreting delivery reports, see <a href={{ url_for("main.message_status") }}>Delivery Status</a>.</li>
<li>For details on pricing and what counts as a message part, see <a href={{ url_for("main.pricing") }}>Pricing</a>.</li>
</ul>
<p>If you have other questions, we are available at <a class="usa-link" href="mailto:notify-support@gsa.gov">notify-support@gsa.gov</a>.</p>

View File

@@ -106,6 +106,104 @@ All of the E2E tests are found in the `tests/end_to_end` folder and are
written as `pytest` scripts using
[Playwright's Python Framework](https://playwright.dev/python/docs/writing-tests).
Inside the `tests/end_to_end` folder you'll see a `conftest.py` file,
which is similar to the one found in the root `tests` folder but is
specific to the E2E tests.
There a few fixtures defined in here, but the two most important at this
time are these:
- `end_to_end_context`: A Playwright context object needed to interact
with a browser instance.
- `authenticated_page`: A Playwright page object that has gone through
the sign in process the E2E user is authenticated.
In short, if you're starting a test from scratch and testing pages that
do not require authentication, you'll start with the
`end_to_end_context` fixture and work from there.
Any test that requires you to be authenticated, you'll start with the
`authenticated_page` object as that'll have taken care of getting
everything set for you and logged into the site with the E2E test user.
### Creating a new test file
If you want to create a new test file to help organize tests (a great
idea!), it will be handy to import the Playwright `expect` and set the
base URL/URI for yourself, like this:
```python
from playwright.sync_api import expect
E2E_TEST_URI = os.getenv("NOTIFY_E2E_TEST_URI")
```
By importing Playwright's `expect` object for tests and setting
something like `E2E_TEST_URI` for yourself, it will make writing tests
much easier.
### Using the fixtures
To use the `authenticated_page` or `end_to_end_context` fixtures, you
start by defining a test function and then passing in the fixture you
need as a positional argument. This works the same as the other
functions defined to create a test for pytest.
For example, the test for the landing page starts with this:
```python
def test_landing_page(end_to_end_context):
# Open a new page and go to the site.
page = end_to_end_context.browser.new_page()
page.goto(f"{E2E_TEST_URI}/")
# Check to make sure that we've arrived at the next page.
page.wait_for_load_state("domcontentloaded")
...
```
Note the passing in of the `end_to_end_context` fixture - there is no
need to import this or anything, just pass it into the function. pytest
takes care of everything else for you.
The second line that defines a `page` variable is a convenience, since
you'll be referencing the page object a lot. This is recommended to
help keep tests readable while keeping fixture names descriptive.
If you need to test an authenticate page, such as the accounts page,
use the `authenticated_page` fixture instead, like so:
```python
def test_add_new_service_workflow(authenticated_page):
page = authenticated_page
...
```
Again, it's helpful to assign the fixture to a `page` variable for easy
reference throughout the test.
Lastly, if you need want access to the Playwright context object that is
used behind the page fixtures, you can reference it directly as well
using the `end_to_end_context` fixture:
```python
def test_add_new_service_workflow(authenticated_page, end_to_end_context):
page = authenticated_page
# Prepare for adding a new service later in the test.
current_date_time = datetime.datetime.now()
new_service_name = "E2E Federal Test Service {now} - {browser_type}".format(
now=current_date_time.strftime("%m/%d/%Y %H:%M:%S"),
browser_type=end_to_end_context.browser.browser_type.name,
)
...
```
In this example, I've used the context to get to the browser object
itself to get the name of the browser for test data.
## Maintaining E2E Tests with GitHub

View File

@@ -68,12 +68,6 @@ def login_for_end_to_end_testing(browser):
context.storage_state(path=auth_state_path)
@pytest.fixture(scope="session")
def end_to_end_context(browser):
context = browser.new_context()
return context
@pytest.fixture(scope="session")
def end_to_end_authenticated_context(browser):
# Create and load a previously authenticated context for Playwright E2E
@@ -89,17 +83,25 @@ def end_to_end_authenticated_context(browser):
@pytest.fixture(scope="session")
def authenticated_page(end_to_end_context):
# Open a new page and go to the staging site.
page = end_to_end_context.new_page()
def end_to_end_context(browser):
context = browser.new_context()
return context
@pytest.fixture(scope="session")
def authenticated_page(end_to_end_context):
# Open a new page and go to the site.
page = end_to_end_context.new_page()
page.goto(f"{E2E_TEST_URI}/")
sign_in_button = page.get_by_role("link", name="Sign in")
# Wait for the next page to fully load.
page.wait_for_load_state("domcontentloaded")
# Sign in to the site - E2E test accounts are set to flow through.
sign_in_button = page.get_by_role("link", name="Sign in")
sign_in_button.click()
# Wait for the next page to fully load.
page.wait_for_load_state("domcontentloaded")
return page

View File

@@ -9,10 +9,6 @@ E2E_TEST_URI = os.getenv("NOTIFY_E2E_TEST_URI")
def test_add_new_service_workflow(authenticated_page, end_to_end_context):
page = authenticated_page
page.goto(f"{E2E_TEST_URI}/")
# Wait for the next page to fully load.
page.wait_for_load_state("domcontentloaded")
# Prepare for adding a new service later in the test.
current_date_time = datetime.datetime.now()

View File

@@ -7,7 +7,7 @@ E2E_TEST_URI = os.getenv("NOTIFY_E2E_TEST_URI")
def test_landing_page(end_to_end_context):
# Open a new page and go to the staging site.
# Open a new page and go to the site.
page = end_to_end_context.browser.new_page()
page.goto(f"{E2E_TEST_URI}/")