mirror of
https://github.com/GSA/notifications-api.git
synced 2026-08-25 08:43:55 -04:00
prevent public api from sending archived templates
This commit is contained in:
@@ -1,4 +1,4 @@
|
|||||||
from datetime import datetime, date
|
from datetime import datetime
|
||||||
import statsd
|
import statsd
|
||||||
import itertools
|
import itertools
|
||||||
from flask import (
|
from flask import (
|
||||||
@@ -30,6 +30,7 @@ from app.schemas import (
|
|||||||
notifications_filter_schema,
|
notifications_filter_schema,
|
||||||
notifications_statistics_schema,
|
notifications_statistics_schema,
|
||||||
day_schema,
|
day_schema,
|
||||||
|
unarchived_template_schema
|
||||||
)
|
)
|
||||||
from app.celery.tasks import send_sms, send_email
|
from app.celery.tasks import send_sms, send_email
|
||||||
|
|
||||||
@@ -328,6 +329,10 @@ def send_notification(notification_type):
|
|||||||
service_id=service_id
|
service_id=service_id
|
||||||
)
|
)
|
||||||
|
|
||||||
|
errors = unarchived_template_schema.validate({'archived': template.archived})
|
||||||
|
if errors:
|
||||||
|
return jsonify(result='error', message=errors), 400
|
||||||
|
|
||||||
template_object = Template(template.__dict__, notification.get('personalisation', {}))
|
template_object = Template(template.__dict__, notification.get('personalisation', {}))
|
||||||
if template_object.missing_data:
|
if template_object.missing_data:
|
||||||
return jsonify(
|
return jsonify(
|
||||||
|
|||||||
@@ -13,7 +13,7 @@ from tests.app.conftest import sample_email_template as create_sample_email_temp
|
|||||||
from tests.app.conftest import sample_template as create_sample_template
|
from tests.app.conftest import sample_template as create_sample_template
|
||||||
from flask import (json, current_app, url_for)
|
from flask import (json, current_app, url_for)
|
||||||
from app.models import Service
|
from app.models import Service
|
||||||
from app.dao.templates_dao import dao_get_all_templates_for_service
|
from app.dao.templates_dao import dao_get_all_templates_for_service, dao_update_template
|
||||||
from app.dao.services_dao import dao_update_service
|
from app.dao.services_dao import dao_update_service
|
||||||
from app.dao.notifications_dao import get_notification_by_id, dao_get_notification_statistics_for_service
|
from app.dao.notifications_dao import get_notification_by_id, dao_get_notification_statistics_for_service
|
||||||
from freezegun import freeze_time
|
from freezegun import freeze_time
|
||||||
@@ -564,6 +564,28 @@ def test_send_notification_with_placeholders_replaced(notify_api, sample_templat
|
|||||||
assert encryption.decrypt(app.celery.tasks.send_sms.apply_async.call_args[0][0][2]) == data
|
assert encryption.decrypt(app.celery.tasks.send_sms.apply_async.call_args[0][0][2]) == data
|
||||||
|
|
||||||
|
|
||||||
|
def test_should_not_send_notification_for_archived_template(notify_api, sample_template, mocker):
|
||||||
|
with notify_api.test_request_context():
|
||||||
|
with notify_api.test_client() as client:
|
||||||
|
sample_template.archived = True
|
||||||
|
dao_update_template(sample_template)
|
||||||
|
limit = current_app.config.get('SMS_CHAR_COUNT_LIMIT')
|
||||||
|
json_data = json.dumps({
|
||||||
|
'to': '+447700900855',
|
||||||
|
'template': sample_template.id
|
||||||
|
})
|
||||||
|
endpoint = url_for('notifications.send_notification', notification_type='sms')
|
||||||
|
auth_header = create_authorization_header(service_id=sample_template.service.id)
|
||||||
|
|
||||||
|
resp = client.post(
|
||||||
|
path=endpoint,
|
||||||
|
data=json_data,
|
||||||
|
headers=[('Content-Type', 'application/json'), auth_header])
|
||||||
|
assert resp.status_code == 400
|
||||||
|
json_resp = json.loads(resp.get_data(as_text=True))
|
||||||
|
assert 'Template has been deleted' in json_resp['message']['template']
|
||||||
|
|
||||||
|
|
||||||
def test_send_notification_with_missing_personalisation(notify_api, sample_template_with_placeholders, mocker):
|
def test_send_notification_with_missing_personalisation(notify_api, sample_template_with_placeholders, mocker):
|
||||||
with notify_api.test_request_context():
|
with notify_api.test_request_context():
|
||||||
with notify_api.test_client() as client:
|
with notify_api.test_client() as client:
|
||||||
|
|||||||
Reference in New Issue
Block a user