Files
notifications-admin/tests/app/main/views/test_sign_out.py
Rebecca Law 937c9f2adc Ensure that the session is logged out server side, not just client side.
Anytime a user clicks "sign out" we should be signing them out server side as well. This can be accomplished by setting the Users.current_session_id = null.
I found that the method User.logged_in_elsewhere doesn't need to check if the current_session_id is None. The current_session_ids in the cookie and db (redis or postgres) then the user should be forced to log in again.
2020-02-03 12:24:02 +00:00

49 lines
1.2 KiB
Python

from flask import url_for
from tests.conftest import SERVICE_ONE_ID
def test_render_sign_out_redirects_to_sign_in(
logged_in_client
):
response = logged_in_client.get(
url_for('main.sign_out'))
assert response.status_code == 302
assert response.location == url_for(
'main.index', _external=True)
def test_sign_out_user(
client_request,
mock_get_service,
api_user_active,
mock_get_user,
mock_get_user_by_email,
mock_login,
mock_get_service_templates,
mock_get_jobs,
mock_has_permissions,
mock_get_template_statistics,
mock_get_service_statistics,
mock_get_usage,
mock_get_free_sms_fragment_limit,
mock_get_inbound_sms_summary,
):
with client_request.session_transaction() as session:
assert session.get('user_id') is not None
# Check we are logged in
client_request.get(
'main.service_dashboard',
service_id=SERVICE_ONE_ID,
)
client_request.get(
'main.sign_out',
_expected_status=302,
_expected_redirect=url_for(
'main.index',
_external=True,
)
)
with client_request.session_transaction() as session:
assert session.get('user_id') is None