mirror of
https://github.com/GSA/notifications-admin.git
synced 2026-02-23 03:44:38 -05:00
A user can't be archived if they are the only member of their service with `manage_settings` permission. `notifications-api` returns a `400` and an error message if that is the case, however this PR to remove the `400` error handler https://github.com/alphagov/notifications-admin/pull/3320 stopped the error message from showing. This meant that instead of seeing a message about why a user couldn't be archived, we would just show a `500` error page instead. This change checks the response from `notifications-api` and shows an error banner with a message if the user can't be archived.
53 lines
1.9 KiB
Python
53 lines
1.9 KiB
Python
from flask import flash, redirect, render_template, request, url_for
|
||
from flask_login import current_user
|
||
from notifications_python_client.errors import HTTPError
|
||
|
||
from app import user_api_client
|
||
from app.event_handlers import create_archive_user_event
|
||
from app.main import main
|
||
from app.main.forms import SearchUsersByEmailForm
|
||
from app.models.user import User
|
||
from app.utils import user_is_platform_admin
|
||
|
||
|
||
@main.route("/find-users-by-email", methods=['GET', 'POST'])
|
||
@user_is_platform_admin
|
||
def find_users_by_email():
|
||
form = SearchUsersByEmailForm()
|
||
users_found = None
|
||
if form.validate_on_submit():
|
||
users_found = user_api_client.find_users_by_full_or_partial_email(form.search.data)['data']
|
||
return render_template(
|
||
'views/find-users/find-users-by-email.html',
|
||
form=form,
|
||
users_found=users_found
|
||
)
|
||
|
||
|
||
@main.route("/users/<uuid:user_id>", methods=['GET'])
|
||
@user_is_platform_admin
|
||
def user_information(user_id):
|
||
return render_template(
|
||
'views/find-users/user-information.html',
|
||
user=User.from_id(user_id),
|
||
)
|
||
|
||
|
||
@main.route("/users/<uuid:user_id>/archive", methods=['GET', 'POST'])
|
||
@user_is_platform_admin
|
||
def archive_user(user_id):
|
||
if request.method == 'POST':
|
||
try:
|
||
user_api_client.archive_user(user_id)
|
||
except HTTPError as e:
|
||
if e.status_code == 400 and 'manage_settings' in e.message:
|
||
flash('User can’t be removed from a service - '
|
||
'check all services have another team member with manage_settings')
|
||
return redirect(url_for('main.user_information', user_id=user_id))
|
||
create_archive_user_event(str(user_id), current_user.id)
|
||
|
||
return redirect(url_for('.user_information', user_id=user_id))
|
||
else:
|
||
flash('There\'s no way to reverse this! Are you sure you want to archive this user?', 'delete')
|
||
return user_information(user_id)
|