mirror of
https://github.com/GSA/notifications-api.git
synced 2025-12-16 10:12:32 -05:00
Updates:
* Add endpoint to retrieve provider history * Remove marshmallow schemas when updating a provider * Include created by user when updating a provider
This commit is contained in:
@@ -1,13 +1,13 @@
|
||||
from flask import Blueprint, jsonify, request
|
||||
|
||||
from app.schemas import provider_details_schema
|
||||
|
||||
from app.schemas import provider_details_schema, provider_details_history_schema
|
||||
from app.dao.provider_details_dao import (
|
||||
get_provider_details,
|
||||
get_provider_details_by_id,
|
||||
dao_update_provider_details
|
||||
dao_update_provider_details,
|
||||
dao_get_provider_versions
|
||||
)
|
||||
|
||||
from app.dao.users_dao import get_user_by_id
|
||||
from app.errors import (
|
||||
register_errors,
|
||||
InvalidRequest
|
||||
@@ -29,19 +29,37 @@ def get_provider_by_id(provider_details_id):
|
||||
return jsonify(provider_details=data)
|
||||
|
||||
|
||||
@provider_details.route('/<uuid:provider_details_id>/versions', methods=['GET'])
|
||||
def get_provider_versions(provider_details_id):
|
||||
versions = dao_get_provider_versions(provider_details_id)
|
||||
data = provider_details_history_schema.dump(
|
||||
versions,
|
||||
many=True
|
||||
).data
|
||||
return jsonify(data=data)
|
||||
|
||||
|
||||
@provider_details.route('/<uuid:provider_details_id>', methods=['POST'])
|
||||
def update_provider_details(provider_details_id):
|
||||
fetched_provider_details = get_provider_details_by_id(provider_details_id)
|
||||
valid_keys = {'priority', 'created_by', 'active'}
|
||||
invalid_keys = request.get_json().keys() - valid_keys
|
||||
|
||||
current_data = dict(provider_details_schema.dump(fetched_provider_details).data.items())
|
||||
current_data.update(request.get_json())
|
||||
update_dict = provider_details_schema.load(current_data).data
|
||||
|
||||
invalid_keys = {'identifier', 'version', 'updated_at'} & set(key for key in request.get_json().keys())
|
||||
if invalid_keys:
|
||||
message = "Not permitted to be updated"
|
||||
errors = {key: [message] for key in invalid_keys}
|
||||
raise InvalidRequest(errors, status_code=400)
|
||||
|
||||
dao_update_provider_details(update_dict)
|
||||
return jsonify(provider_details=provider_details_schema.dump(fetched_provider_details).data), 200
|
||||
provider = get_provider_details_by_id(provider_details_id)
|
||||
req_json = request.get_json()
|
||||
|
||||
# Handle created_by differently due to how history entry is created
|
||||
if 'created_by' in req_json:
|
||||
user = get_user_by_id(req_json['created_by'])
|
||||
provider.created_by_id = user.id
|
||||
req_json.pop('created_by')
|
||||
|
||||
for key in req_json:
|
||||
setattr(provider, key, req_json[key])
|
||||
dao_update_provider_details(provider)
|
||||
|
||||
return jsonify(provider_details=provider_details_schema.dump(provider).data), 200
|
||||
|
||||
@@ -155,12 +155,25 @@ class UserUpdatePasswordSchema(BaseSchema):
|
||||
|
||||
|
||||
class ProviderDetailsSchema(BaseSchema):
|
||||
created_by_user = fields.Nested(
|
||||
UserSchema,
|
||||
attribute='created_by',
|
||||
dump_to='created_by',
|
||||
only=['id', 'name', 'email_address'],
|
||||
dump_only=True
|
||||
)
|
||||
|
||||
class Meta:
|
||||
model = models.ProviderDetails
|
||||
exclude = ("provider_rates", "provider_stats")
|
||||
strict = True
|
||||
|
||||
|
||||
class ProviderDetailsHistorySchema(ProviderDetailsSchema):
|
||||
class Meta:
|
||||
model = models.ProviderDetailsHistory
|
||||
|
||||
|
||||
class ServiceSchema(BaseSchema):
|
||||
|
||||
created_by = field_for(models.Service, 'created_by', required=True)
|
||||
@@ -605,5 +618,6 @@ template_history_schema = TemplateHistorySchema()
|
||||
event_schema = EventSchema()
|
||||
organisation_schema = OrganisationSchema()
|
||||
provider_details_schema = ProviderDetailsSchema()
|
||||
provider_details_history_schema = ProviderDetailsHistorySchema()
|
||||
day_schema = DaySchema()
|
||||
unarchived_template_schema = UnarchivedTemplateSchema()
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
import pytest
|
||||
from flask import json
|
||||
|
||||
from app.models import ProviderDetails
|
||||
from app.models import ProviderDetails, ProviderDetailsHistory
|
||||
|
||||
from tests import create_authorization_header
|
||||
|
||||
@@ -45,7 +45,9 @@ def test_get_provider_details_contains_correct_fields(client, notify_db):
|
||||
)
|
||||
json_resp = json.loads(response.get_data(as_text=True))['provider_details']
|
||||
allowed_keys = {
|
||||
"id", "display_name", "identifier", "priority", 'notification_type', "active", "version", "updated_at"
|
||||
"id", "created_by", "display_name",
|
||||
"identifier", "priority", 'notification_type',
|
||||
"active", "version", "updated_at"
|
||||
}
|
||||
assert allowed_keys == set(json_resp[0].keys())
|
||||
|
||||
@@ -92,13 +94,46 @@ def test_should_be_able_to_update_status(client, restore_provider_details):
|
||||
def test_should_not_be_able_to_update_disallowed_fields(client, restore_provider_details, field, value):
|
||||
provider = ProviderDetails.query.first()
|
||||
|
||||
update_resp = client.post(
|
||||
resp = client.post(
|
||||
'/provider-details/{}'.format(provider.id),
|
||||
headers=[('Content-Type', 'application/json'), create_authorization_header()],
|
||||
data=json.dumps({field: value})
|
||||
)
|
||||
assert update_resp.status_code == 400
|
||||
update_resp = json.loads(update_resp.get_data(as_text=True))
|
||||
print(update_resp)
|
||||
assert update_resp['message'][field][0] == 'Not permitted to be updated'
|
||||
assert update_resp['result'] == 'error'
|
||||
resp_json = json.loads(resp.get_data(as_text=True))
|
||||
|
||||
assert resp_json['message'][field][0] == 'Not permitted to be updated'
|
||||
assert resp_json['result'] == 'error'
|
||||
assert resp.status_code == 400
|
||||
|
||||
|
||||
def test_get_provider_versions_contains_correct_fields(client, notify_db):
|
||||
provider = ProviderDetailsHistory.query.first()
|
||||
response = client.get(
|
||||
'/provider-details/{}/versions'.format(provider.id),
|
||||
headers=[create_authorization_header()]
|
||||
)
|
||||
json_resp = json.loads(response.get_data(as_text=True))['data']
|
||||
allowed_keys = {
|
||||
"id", "created_by", "display_name",
|
||||
"identifier", "priority", 'notification_type',
|
||||
"active", "version", "updated_at"
|
||||
}
|
||||
assert allowed_keys == set(json_resp[0].keys())
|
||||
|
||||
|
||||
def test_update_provider_should_store_user_id(client, restore_provider_details, sample_user):
|
||||
provider = ProviderDetails.query.first()
|
||||
|
||||
update_resp_1 = client.post(
|
||||
'/provider-details/{}'.format(provider.id),
|
||||
headers=[('Content-Type', 'application/json'), create_authorization_header()],
|
||||
data=json.dumps({
|
||||
'created_by': sample_user.id,
|
||||
'active': False
|
||||
})
|
||||
)
|
||||
assert update_resp_1.status_code == 200
|
||||
update_resp_1 = json.loads(update_resp_1.get_data(as_text=True))['provider_details']
|
||||
assert update_resp_1['identifier'] == provider.identifier
|
||||
assert not update_resp_1['active']
|
||||
assert not provider.active
|
||||
|
||||
Reference in New Issue
Block a user