123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283 |
- # -*- coding: utf-8 -*-
- """
- Tests for /api/v2/users subpath endpoints.
- """
- from time import sleep
- import pytest
- import transaction
-
- from tracim_backend import models
- from tracim_backend.lib.core.content import ContentApi
- from tracim_backend.lib.core.user import UserApi
- from tracim_backend.lib.core.group import GroupApi
- from tracim_backend.lib.core.workspace import WorkspaceApi
- from tracim_backend.models import get_tm_session
- from tracim_backend.models.contents import ContentTypeLegacy as ContentType
- from tracim_backend.models.revision_protection import new_revision
- from tracim_backend.tests import FunctionalTest
- from tracim_backend.fixtures.content import Content as ContentFixtures
- from tracim_backend.fixtures.users_and_groups import Base as BaseFixture
-
-
- class TestUserRecentlyActiveContentEndpoint(FunctionalTest):
- """
- Tests for /api/v2/users/{user_id}/workspaces/{workspace_id}/contents/recently_active # nopep8
- """
- fixtures = [BaseFixture]
-
- def test_api__get_recently_active_content__ok__200__nominal_case(self):
-
- # init DB
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- workspace_api = WorkspaceApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config
-
- )
- workspace = WorkspaceApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- ).create_workspace(
- 'test workspace',
- save_now=True
- )
- workspace2 = WorkspaceApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- ).create_workspace(
- 'test workspace2',
- save_now=True
- )
-
- api = ContentApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- main_folder_workspace2 = api.create(ContentType.Folder, workspace2, None, 'Hepla', '', True) # nopep8
- main_folder = api.create(ContentType.Folder, workspace, None, 'this is randomized folder', '', True) # nopep8
- # creation order test
- firstly_created = api.create(ContentType.Page, workspace, main_folder, 'creation_order_test', '', True) # nopep8
- secondly_created = api.create(ContentType.Page, workspace, main_folder, 'another creation_order_test', '', True) # nopep8
- # update order test
- firstly_created_but_recently_updated = api.create(ContentType.Page, workspace, main_folder, 'update_order_test', '', True) # nopep8
- secondly_created_but_not_updated = api.create(ContentType.Page, workspace, main_folder, 'another update_order_test', '', True) # nopep8
- with new_revision(
- session=dbsession,
- tm=transaction.manager,
- content=firstly_created_but_recently_updated,
- ):
- firstly_created_but_recently_updated.description = 'Just an update'
- api.save(firstly_created_but_recently_updated)
- # comment change order
- firstly_created_but_recently_commented = api.create(ContentType.Page, workspace, main_folder, 'this is randomized label content', '', True) # nopep8
- secondly_created_but_not_commented = api.create(ContentType.Page, workspace, main_folder, 'this is another randomized label content', '', True) # nopep8
- comments = api.create_comment(workspace, firstly_created_but_recently_commented, 'juste a super comment', True) # nopep8
- content_workspace_2 = api.create(ContentType.Page, workspace2,main_folder_workspace2, 'content_workspace_2', '',True) # nopep8
- dbsession.flush()
- transaction.commit()
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'admin@admin.admin',
- 'admin@admin.admin'
- )
- )
- res = self.testapp.get('/api/v2/users/1/workspaces/{}/contents/recently_active'.format(workspace.workspace_id), status=200) # nopep8
- res = res.json_body
- assert len(res) == 7
- for elem in res:
- assert isinstance(elem['content_id'], int)
- assert isinstance(elem['content_type'], str)
- assert elem['content_type'] != 'comments'
- assert isinstance(elem['is_archived'], bool)
- assert isinstance(elem['is_deleted'], bool)
- assert isinstance(elem['label'], str)
- assert isinstance(elem['parent_id'], int) or elem['parent_id'] is None
- assert isinstance(elem['show_in_ui'], bool)
- assert isinstance(elem['slug'], str)
- assert isinstance(elem['status'], str)
- assert isinstance(elem['sub_content_types'], list)
- for sub_content_type in elem['sub_content_types']:
- assert isinstance(sub_content_type, str)
- assert isinstance(elem['workspace_id'], int)
- # comment is newest than page2
- assert res[0]['content_id'] == firstly_created_but_recently_commented.content_id
- assert res[1]['content_id'] == secondly_created_but_not_commented.content_id
- # last updated content is newer than other one despite creation
- # of the other is more recent
- assert res[2]['content_id'] == firstly_created_but_recently_updated.content_id
- assert res[3]['content_id'] == secondly_created_but_not_updated.content_id
- # creation order is inverted here as last created is last active
- assert res[4]['content_id'] == secondly_created.content_id
- assert res[5]['content_id'] == firstly_created.content_id
- # folder subcontent modification does not change folder order
- assert res[6]['content_id'] == main_folder.content_id
-
- def test_api__get_recently_active_content__ok__200__limit_2_multiple(self):
- # TODO - G.M - 2018-07-20 - Better fix for this test, do not use sleep()
- # anymore to fix datetime lack of precision.
-
- # init DB
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- workspace_api = WorkspaceApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config
-
- )
- workspace = WorkspaceApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- ).create_workspace(
- 'test workspace',
- save_now=True
- )
- workspace2 = WorkspaceApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- ).create_workspace(
- 'test workspace2',
- save_now=True
- )
-
- api = ContentApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- main_folder_workspace2 = api.create(ContentType.Folder, workspace2, None, 'Hepla', '', True) # nopep8
- main_folder = api.create(ContentType.Folder, workspace, None, 'this is randomized folder', '', True) # nopep8
- # creation order test
- firstly_created = api.create(ContentType.Page, workspace, main_folder, 'creation_order_test', '', True) # nopep8
- secondly_created = api.create(ContentType.Page, workspace, main_folder, 'another creation_order_test', '', True) # nopep8
- # update order test
- firstly_created_but_recently_updated = api.create(ContentType.Page, workspace, main_folder, 'update_order_test', '', True) # nopep8
- secondly_created_but_not_updated = api.create(ContentType.Page, workspace, main_folder, 'another update_order_test', '', True) # nopep8
- with new_revision(
- session=dbsession,
- tm=transaction.manager,
- content=firstly_created_but_recently_updated,
- ):
- firstly_created_but_recently_updated.description = 'Just an update'
- api.save(firstly_created_but_recently_updated)
- # comment change order
- firstly_created_but_recently_commented = api.create(ContentType.Page, workspace, main_folder, 'this is randomized label content', '', True) # nopep8
- secondly_created_but_not_commented = api.create(ContentType.Page, workspace, main_folder, 'this is another randomized label content', '', True) # nopep8
- comments = api.create_comment(workspace, firstly_created_but_recently_commented, 'juste a super comment', True) # nopep8
- content_workspace_2 = api.create(ContentType.Page, workspace2,main_folder_workspace2, 'content_workspace_2', '',True) # nopep8
- dbsession.flush()
- transaction.commit()
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'admin@admin.admin',
- 'admin@admin.admin'
- )
- )
- params = {
- 'limit': 2,
- }
- res = self.testapp.get(
- '/api/v2/users/1/workspaces/{}/contents/recently_active'.format(workspace.workspace_id), # nopep8
- status=200,
- params=params
- ) # nopep8
- res = res.json_body
- assert len(res) == 2
- for elem in res:
- assert isinstance(elem['content_id'], int)
- assert isinstance(elem['content_type'], str)
- assert elem['content_type'] != 'comments'
- assert isinstance(elem['is_archived'], bool)
- assert isinstance(elem['is_deleted'], bool)
- assert isinstance(elem['label'], str)
- assert isinstance(elem['parent_id'], int) or elem['parent_id'] is None
- assert isinstance(elem['show_in_ui'], bool)
- assert isinstance(elem['slug'], str)
- assert isinstance(elem['status'], str)
- assert isinstance(elem['sub_content_types'], list)
- for sub_content_type in elem['sub_content_types']:
- assert isinstance(sub_content_type, str)
- assert isinstance(elem['workspace_id'], int)
- # comment is newest than page2
- assert res[0]['content_id'] == firstly_created_but_recently_commented.content_id
- assert res[1]['content_id'] == secondly_created_but_not_commented.content_id
-
- params = {
- 'limit': 2,
- 'before_content_id': secondly_created_but_not_commented.content_id, # nopep8
- }
- res = self.testapp.get(
- '/api/v2/users/1/workspaces/{}/contents/recently_active'.format(workspace.workspace_id), # nopep8
- status=200,
- params=params
- )
- res = res.json_body
- assert len(res) == 2
- # last updated content is newer than other one despite creation
- # of the other is more recent
- assert res[0]['content_id'] == firstly_created_but_recently_updated.content_id
- assert res[1]['content_id'] == secondly_created_but_not_updated.content_id
-
-
- class TestUserReadStatusEndpoint(FunctionalTest):
- """
- Tests for /api/v2/users/{user_id}/workspaces/{workspace_id}/contents/read_status # nopep8
- """
- def test_api__get_read_status__ok__200__all(self):
-
- # init DB
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- workspace_api = WorkspaceApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config
-
- )
- workspace = WorkspaceApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- ).create_workspace(
- 'test workspace',
- save_now=True
- )
- workspace2 = WorkspaceApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- ).create_workspace(
- 'test workspace2',
- save_now=True
- )
-
- api = ContentApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- main_folder_workspace2 = api.create(ContentType.Folder, workspace2, None, 'Hepla', '', True) # nopep8
- main_folder = api.create(ContentType.Folder, workspace, None, 'this is randomized folder', '', True) # nopep8
- # creation order test
- firstly_created = api.create(ContentType.Page, workspace, main_folder, 'creation_order_test', '', True) # nopep8
- secondly_created = api.create(ContentType.Page, workspace, main_folder, 'another creation_order_test', '', True) # nopep8
- # update order test
- firstly_created_but_recently_updated = api.create(ContentType.Page, workspace, main_folder, 'update_order_test', '', True) # nopep8
- secondly_created_but_not_updated = api.create(ContentType.Page, workspace, main_folder, 'another update_order_test', '', True) # nopep8
- with new_revision(
- session=dbsession,
- tm=transaction.manager,
- content=firstly_created_but_recently_updated,
- ):
- firstly_created_but_recently_updated.description = 'Just an update'
- api.save(firstly_created_but_recently_updated)
- # comment change order
- firstly_created_but_recently_commented = api.create(ContentType.Page, workspace, main_folder, 'this is randomized label content', '', True) # nopep8
- secondly_created_but_not_commented = api.create(ContentType.Page, workspace, main_folder, 'this is another randomized label content', '', True) # nopep8
- comments = api.create_comment(workspace, firstly_created_but_recently_commented, 'juste a super comment', True) # nopep8
- content_workspace_2 = api.create(ContentType.Page, workspace2,main_folder_workspace2, 'content_workspace_2', '',True) # nopep8
- dbsession.flush()
- transaction.commit()
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'admin@admin.admin',
- 'admin@admin.admin'
- )
- )
- res = self.testapp.get('/api/v2/users/1/workspaces/{}/contents/read_status'.format(workspace.workspace_id), status=200) # nopep8
- res = res.json_body
- assert len(res) == 7
- for elem in res:
- assert isinstance(elem['content_id'], int)
- assert isinstance(elem['read_by_user'], bool)
- # comment is newest than page2
- assert res[0]['content_id'] == firstly_created_but_recently_commented.content_id
- assert res[1]['content_id'] == secondly_created_but_not_commented.content_id
- # last updated content is newer than other one despite creation
- # of the other is more recent
- assert res[2]['content_id'] == firstly_created_but_recently_updated.content_id
- assert res[3]['content_id'] == secondly_created_but_not_updated.content_id
- # creation order is inverted here as last created is last active
- assert res[4]['content_id'] == secondly_created.content_id
- assert res[5]['content_id'] == firstly_created.content_id
- # folder subcontent modification does not change folder order
- assert res[6]['content_id'] == main_folder.content_id
-
- def test_api__get_read_status__ok__200__nominal_case(self):
-
- # init DB
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- workspace_api = WorkspaceApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config
-
- )
- workspace = WorkspaceApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- ).create_workspace(
- 'test workspace',
- save_now=True
- )
- workspace2 = WorkspaceApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- ).create_workspace(
- 'test workspace2',
- save_now=True
- )
-
- api = ContentApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- main_folder_workspace2 = api.create(ContentType.Folder, workspace2, None, 'Hepla', '', True) # nopep8
- main_folder = api.create(ContentType.Folder, workspace, None, 'this is randomized folder', '', True) # nopep8
- # creation order test
- firstly_created = api.create(ContentType.Page, workspace, main_folder, 'creation_order_test', '', True) # nopep8
- secondly_created = api.create(ContentType.Page, workspace, main_folder, 'another creation_order_test', '', True) # nopep8
- # update order test
- firstly_created_but_recently_updated = api.create(ContentType.Page, workspace, main_folder, 'update_order_test', '', True) # nopep8
- secondly_created_but_not_updated = api.create(ContentType.Page, workspace, main_folder, 'another update_order_test', '', True) # nopep8
- with new_revision(
- session=dbsession,
- tm=transaction.manager,
- content=firstly_created_but_recently_updated,
- ):
- firstly_created_but_recently_updated.description = 'Just an update'
- api.save(firstly_created_but_recently_updated)
- # comment change order
- firstly_created_but_recently_commented = api.create(ContentType.Page, workspace, main_folder, 'this is randomized label content', '', True) # nopep8
- secondly_created_but_not_commented = api.create(ContentType.Page, workspace, main_folder, 'this is another randomized label content', '', True) # nopep8
- comments = api.create_comment(workspace, firstly_created_but_recently_commented, 'juste a super comment', True) # nopep8
- content_workspace_2 = api.create(ContentType.Page, workspace2,main_folder_workspace2, 'content_workspace_2', '',True) # nopep8
- dbsession.flush()
- transaction.commit()
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'admin@admin.admin',
- 'admin@admin.admin'
- )
- )
- selected_contents_id = [
- firstly_created_but_recently_commented.content_id,
- firstly_created_but_recently_updated.content_id,
- firstly_created.content_id,
- main_folder.content_id,
- ]
- url = '/api/v2/users/1/workspaces/{workspace_id}/contents/read_status?contents_ids={cid1}&contents_ids={cid2}&contents_ids={cid3}&contents_ids={cid4}'.format( # nopep8
- workspace_id=workspace.workspace_id,
- cid1=selected_contents_id[0],
- cid2=selected_contents_id[1],
- cid3=selected_contents_id[2],
- cid4=selected_contents_id[3],
- )
- res = self.testapp.get(
- url=url,
- status=200,
- )
- res = res.json_body
- assert len(res) == 4
- for elem in res:
- assert isinstance(elem['content_id'], int)
- assert isinstance(elem['read_by_user'], bool)
- # comment is newest than page2
- assert res[0]['content_id'] == firstly_created_but_recently_commented.content_id
- # last updated content is newer than other one despite creation
- # of the other is more recent
- assert res[1]['content_id'] == firstly_created_but_recently_updated.content_id
- # creation order is inverted here as last created is last active
- assert res[2]['content_id'] == firstly_created.content_id
- # folder subcontent modification does not change folder order
- assert res[3]['content_id'] == main_folder.content_id
-
-
- class TestUserSetContentAsRead(FunctionalTest):
- """
- Tests for /api/v2/users/{user_id}/workspaces/{workspace_id}/contents/{content_id}/read # nopep8
- """
- def test_api_set_content_as_read__ok__200__nominal_case(self):
- # init DB
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- workspace_api = WorkspaceApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config
-
- )
- workspace = WorkspaceApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- ).create_workspace(
- 'test workspace',
- save_now=True
- )
- api = ContentApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- main_folder = api.create(ContentType.Folder, workspace, None, 'this is randomized folder', '', True) # nopep8
- # creation order test
- firstly_created = api.create(ContentType.Page, workspace, main_folder, 'creation_order_test', '', True) # nopep8
- api.mark_unread(firstly_created)
- dbsession.flush()
- transaction.commit()
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'admin@admin.admin',
- 'admin@admin.admin'
- )
- )
- res = self.testapp.get('/api/v2/users/1/workspaces/{}/contents/read_status'.format(workspace.workspace_id), status=200) # nopep8
- assert res.json_body[0]['content_id'] == firstly_created.content_id
- assert res.json_body[0]['read_by_user'] is False
- self.testapp.put(
- '/api/v2/users/{user_id}/workspaces/{workspace_id}/contents/{content_id}/read'.format( # nopep8
- workspace_id=workspace.workspace_id,
- content_id=firstly_created.content_id,
- user_id=admin.user_id,
- )
- )
- res = self.testapp.get('/api/v2/users/1/workspaces/{}/contents/read_status'.format(workspace.workspace_id), status=200) # nopep8
- assert res.json_body[0]['content_id'] == firstly_created.content_id
- assert res.json_body[0]['read_by_user'] is True
-
- def test_api_set_content_as_read__ok__200__with_comments(self):
- # init DB
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- workspace_api = WorkspaceApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config
-
- )
- workspace = WorkspaceApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- ).create_workspace(
- 'test workspace',
- save_now=True
- )
- api = ContentApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- main_folder = api.create(ContentType.Folder, workspace, None, 'this is randomized folder', '', True) # nopep8
- # creation order test
- firstly_created = api.create(ContentType.Page, workspace, main_folder, 'creation_order_test', '', True) # nopep8
- comments = api.create_comment(workspace, firstly_created, 'juste a super comment', True) # nopep8
- api.mark_unread(firstly_created)
- api.mark_unread(comments)
- dbsession.flush()
- transaction.commit()
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'admin@admin.admin',
- 'admin@admin.admin'
- )
- )
- res = self.testapp.get('/api/v2/users/1/workspaces/{}/contents/read_status'.format(workspace.workspace_id), status=200) # nopep8
- assert res.json_body[0]['content_id'] == firstly_created.content_id
- assert res.json_body[0]['read_by_user'] is False
- self.testapp.put(
- '/api/v2/users/{user_id}/workspaces/{workspace_id}/contents/{content_id}/read'.format( # nopep8
- workspace_id=workspace.workspace_id,
- content_id=firstly_created.content_id,
- user_id=admin.user_id,
- )
- )
- res = self.testapp.get('/api/v2/users/1/workspaces/{}/contents/read_status'.format(workspace.workspace_id), status=200) # nopep8
- assert res.json_body[0]['content_id'] == firstly_created.content_id
- assert res.json_body[0]['read_by_user'] is True
-
- # comment is also set as read
- assert comments.has_new_information_for(admin) is False
-
-
- class TestUserSetContentAsUnread(FunctionalTest):
- """
- Tests for /api/v2/users/{user_id}/workspaces/{workspace_id}/contents/{content_id}/unread # nopep8
- """
- def test_api_set_content_as_unread__ok__200__nominal_case(self):
- # init DB
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- workspace_api = WorkspaceApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config
-
- )
- workspace = WorkspaceApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- ).create_workspace(
- 'test workspace',
- save_now=True
- )
- api = ContentApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- main_folder = api.create(ContentType.Folder, workspace, None, 'this is randomized folder', '', True) # nopep8
- # creation order test
- firstly_created = api.create(ContentType.Page, workspace, main_folder, 'creation_order_test', '', True) # nopep8
- api.mark_read(firstly_created)
- dbsession.flush()
- transaction.commit()
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'admin@admin.admin',
- 'admin@admin.admin'
- )
- )
- res = self.testapp.get('/api/v2/users/1/workspaces/{}/contents/read_status'.format(workspace.workspace_id), status=200) # nopep8
- assert res.json_body[0]['content_id'] == firstly_created.content_id
- assert res.json_body[0]['read_by_user'] is True
- self.testapp.put(
- '/api/v2/users/{user_id}/workspaces/{workspace_id}/contents/{content_id}/unread'.format( # nopep8
- workspace_id=workspace.workspace_id,
- content_id=firstly_created.content_id,
- user_id=admin.user_id,
- )
- )
- res = self.testapp.get('/api/v2/users/1/workspaces/{}/contents/read_status'.format(workspace.workspace_id), status=200) # nopep8
- assert res.json_body[0]['content_id'] == firstly_created.content_id
- assert res.json_body[0]['read_by_user'] is False
-
- def test_api_set_content_as_unread__ok__200__with_comments(self):
- # init DB
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- workspace_api = WorkspaceApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config
-
- )
- workspace = WorkspaceApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- ).create_workspace(
- 'test workspace',
- save_now=True
- )
- api = ContentApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- main_folder = api.create(ContentType.Folder, workspace, None, 'this is randomized folder', '', True) # nopep8
- # creation order test
- firstly_created = api.create(ContentType.Page, workspace, main_folder, 'creation_order_test', '', True) # nopep8
- comments = api.create_comment(workspace, firstly_created, 'juste a super comment', True) # nopep8
- api.mark_read(firstly_created)
- api.mark_read(comments)
- dbsession.flush()
- transaction.commit()
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'admin@admin.admin',
- 'admin@admin.admin'
- )
- )
- res = self.testapp.get('/api/v2/users/1/workspaces/{}/contents/read_status'.format(workspace.workspace_id), status=200) # nopep8
- assert res.json_body[0]['content_id'] == firstly_created.content_id
- assert res.json_body[0]['read_by_user'] is True
- self.testapp.put(
- '/api/v2/users/{user_id}/workspaces/{workspace_id}/contents/{content_id}/unread'.format( # nopep8
- workspace_id=workspace.workspace_id,
- content_id=firstly_created.content_id,
- user_id=admin.user_id,
- )
- )
- res = self.testapp.get('/api/v2/users/1/workspaces/{}/contents/read_status'.format(workspace.workspace_id), status=200) # nopep8
- assert res.json_body[0]['content_id'] == firstly_created.content_id
- assert res.json_body[0]['read_by_user'] is False
-
- assert comments.has_new_information_for(admin) is True
-
-
- class TestUserSetWorkspaceAsRead(FunctionalTest):
- """
- Tests for /api/v2/users/{user_id}/workspaces/{workspace_id}/read
- """
- def test_api_set_content_as_read__ok__200__nominal_case(self):
- # init DB
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- workspace_api = WorkspaceApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config
-
- )
- workspace = WorkspaceApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- ).create_workspace(
- 'test workspace',
- save_now=True
- )
- api = ContentApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- main_folder = api.create(ContentType.Folder, workspace, None, 'this is randomized folder', '', True) # nopep8
- # creation order test
- firstly_created = api.create(ContentType.Page, workspace, main_folder, 'creation_order_test', '', True) # nopep8
- api.mark_unread(main_folder)
- api.mark_unread(firstly_created)
- dbsession.flush()
- transaction.commit()
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'admin@admin.admin',
- 'admin@admin.admin'
- )
- )
- res = self.testapp.get('/api/v2/users/1/workspaces/{}/contents/read_status'.format(workspace.workspace_id), status=200) # nopep8
- assert res.json_body[0]['content_id'] == firstly_created.content_id
- assert res.json_body[0]['read_by_user'] is False
- assert res.json_body[1]['content_id'] == main_folder.content_id
- assert res.json_body[1]['read_by_user'] is False
- self.testapp.put(
- '/api/v2/users/{user_id}/workspaces/{workspace_id}/read'.format( # nopep8
- workspace_id=workspace.workspace_id,
- content_id=firstly_created.content_id,
- user_id=admin.user_id,
- )
- )
- res = self.testapp.get('/api/v2/users/1/workspaces/{}/contents/read_status'.format(workspace.workspace_id), status=200) # nopep8
- assert res.json_body[0]['content_id'] == firstly_created.content_id
- assert res.json_body[0]['read_by_user'] is True
- assert res.json_body[1]['content_id'] == main_folder.content_id
- assert res.json_body[1]['read_by_user'] is True
-
-
- class TestUserWorkspaceEndpoint(FunctionalTest):
- """
- Tests for /api/v2/users/{user_id}/workspaces
- """
- fixtures = [BaseFixture, ContentFixtures]
-
- def test_api__get_user_workspaces__ok_200__nominal_case(self):
- """
- Check obtain all workspaces reachables for user with user auth.
- """
- self.testapp.authorization = (
- 'Basic',
- (
- 'admin@admin.admin',
- 'admin@admin.admin'
- )
- )
- res = self.testapp.get('/api/v2/users/1/workspaces', status=200)
- res = res.json_body
- workspace = res[0]
- assert workspace['workspace_id'] == 1
- assert workspace['label'] == 'Business'
- assert workspace['slug'] == 'business'
- assert len(workspace['sidebar_entries']) == 7
-
- sidebar_entry = workspace['sidebar_entries'][0]
- assert sidebar_entry['slug'] == 'dashboard'
- assert sidebar_entry['label'] == 'Dashboard'
- assert sidebar_entry['route'] == '/#/workspaces/1/dashboard' # nopep8
- assert sidebar_entry['hexcolor'] == "#252525"
- assert sidebar_entry['fa_icon'] == "signal"
-
- sidebar_entry = workspace['sidebar_entries'][1]
- assert sidebar_entry['slug'] == 'contents/all'
- assert sidebar_entry['label'] == 'All Contents'
- assert sidebar_entry['route'] == "/#/workspaces/1/contents" # nopep8
- assert sidebar_entry['hexcolor'] == "#fdfdfd"
- assert sidebar_entry['fa_icon'] == "th"
-
- sidebar_entry = workspace['sidebar_entries'][2]
- assert sidebar_entry['slug'] == 'contents/html-documents'
- assert sidebar_entry['label'] == 'Text Documents'
- assert sidebar_entry['route'] == '/#/workspaces/1/contents?type=html-documents' # nopep8
- assert sidebar_entry['hexcolor'] == "#3f52e3"
- assert sidebar_entry['fa_icon'] == "file-text-o"
-
- sidebar_entry = workspace['sidebar_entries'][3]
- assert sidebar_entry['slug'] == 'contents/markdownpluspage'
- assert sidebar_entry['label'] == 'Markdown Plus Documents'
- assert sidebar_entry['route'] == "/#/workspaces/1/contents?type=markdownpluspage" # nopep8
- assert sidebar_entry['hexcolor'] == "#f12d2d"
- assert sidebar_entry['fa_icon'] == "file-code-o"
-
- sidebar_entry = workspace['sidebar_entries'][4]
- assert sidebar_entry['slug'] == 'contents/files'
- assert sidebar_entry['label'] == 'Files'
- assert sidebar_entry['route'] == "/#/workspaces/1/contents?type=file" # nopep8
- assert sidebar_entry['hexcolor'] == "#FF9900"
- assert sidebar_entry['fa_icon'] == "paperclip"
-
- sidebar_entry = workspace['sidebar_entries'][5]
- assert sidebar_entry['slug'] == 'contents/threads'
- assert sidebar_entry['label'] == 'Threads'
- assert sidebar_entry['route'] == "/#/workspaces/1/contents?type=thread" # nopep8
- assert sidebar_entry['hexcolor'] == "#ad4cf9"
- assert sidebar_entry['fa_icon'] == "comments-o"
-
- sidebar_entry = workspace['sidebar_entries'][6]
- assert sidebar_entry['slug'] == 'calendar'
- assert sidebar_entry['label'] == 'Calendar'
- assert sidebar_entry['route'] == "/#/workspaces/1/calendar" # nopep8
- assert sidebar_entry['hexcolor'] == "#757575"
- assert sidebar_entry['fa_icon'] == "calendar"
-
- def test_api__get_user_workspaces__err_403__unallowed_user(self):
- """
- Check obtain all workspaces reachables for one user
- with another non-admin user auth.
- """
- self.testapp.authorization = (
- 'Basic',
- (
- 'lawrence-not-real-email@fsf.local',
- 'foobarbaz'
- )
- )
- res = self.testapp.get('/api/v2/users/1/workspaces', status=403)
- assert isinstance(res.json, dict)
- assert 'code' in res.json.keys()
- assert 'message' in res.json.keys()
- assert 'details' in res.json.keys()
-
- def test_api__get_user_workspaces__err_401__unregistered_user(self):
- """
- Check obtain all workspaces reachables for one user
- without correct user auth (user unregistered).
- """
- self.testapp.authorization = (
- 'Basic',
- (
- 'john@doe.doe',
- 'lapin'
- )
- )
- res = self.testapp.get('/api/v2/users/1/workspaces', status=401)
- assert isinstance(res.json, dict)
- assert 'code' in res.json.keys()
- assert 'message' in res.json.keys()
- assert 'details' in res.json.keys()
-
- def test_api__get_user_workspaces__err_400__user_does_not_exist(self):
- """
- Check obtain all workspaces reachables for one user who does
- not exist
- with a correct user auth.
- """
- self.testapp.authorization = (
- 'Basic',
- (
- 'admin@admin.admin',
- 'admin@admin.admin'
- )
- )
- res = self.testapp.get('/api/v2/users/5/workspaces', status=400)
- assert isinstance(res.json, dict)
- assert 'code' in res.json.keys()
- assert 'message' in res.json.keys()
- assert 'details' in res.json.keys()
-
-
- class TestUserEndpoint(FunctionalTest):
- # -*- coding: utf-8 -*-
- """
- Tests for GET /api/v2/users/{user_id}
- """
- fixtures = [BaseFixture]
-
- def test_api__get_user__ok_200__admin(self):
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- uapi = UserApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- gapi = GroupApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- groups = [gapi.get_one_with_name('users')]
- test_user = uapi.create_user(
- email='test@test.test',
- password='pass',
- name='bob',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- uapi.save(test_user)
- transaction.commit()
- user_id = int(test_user.user_id)
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'admin@admin.admin',
- 'admin@admin.admin'
- )
- )
- res = self.testapp.get(
- '/api/v2/users/{}'.format(user_id),
- status=200
- )
- res = res.json_body
- assert res['user_id'] == user_id
- assert res['created']
- assert res['is_active'] is True
- assert res['profile'] == 'users'
- assert res['email'] == 'test@test.test'
- assert res['public_name'] == 'bob'
- assert res['timezone'] == 'Europe/Paris'
-
- def test_api__get_user__ok_200__user_itself(self):
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- uapi = UserApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- gapi = GroupApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- groups = [gapi.get_one_with_name('users')]
- test_user = uapi.create_user(
- email='test@test.test',
- password='pass',
- name='bob',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- uapi.save(test_user)
- transaction.commit()
- user_id = int(test_user.user_id)
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'test@test.test',
- 'pass'
- )
- )
- res = self.testapp.get(
- '/api/v2/users/{}'.format(user_id),
- status=200
- )
- res = res.json_body
- assert res['user_id'] == user_id
- assert res['created']
- assert res['is_active'] is True
- assert res['profile'] == 'users'
- assert res['email'] == 'test@test.test'
- assert res['public_name'] == 'bob'
- assert res['timezone'] == 'Europe/Paris'
-
- def test_api__get_user__err_403__other_normal_user(self):
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- uapi = UserApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- gapi = GroupApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- groups = [gapi.get_one_with_name('users')]
- test_user = uapi.create_user(
- email='test@test.test',
- password='pass',
- name='bob',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- test_user2 = uapi.create_user(
- email='test2@test2.test2',
- password='pass',
- name='bob2',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- uapi.save(test_user2)
- uapi.save(test_user)
- transaction.commit()
- user_id = int(test_user.user_id)
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'test2@test2.test2',
- 'pass'
- )
- )
- self.testapp.get(
- '/api/v2/users/{}'.format(user_id),
- status=403
- )
-
-
- class TestSetEmailEndpoint(FunctionalTest):
- # -*- coding: utf-8 -*-
- """
- Tests for PUT /api/v2/users/{user_id}/email
- """
- fixtures = [BaseFixture]
-
- def test_api__set_user_email__ok_200__admin(self):
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- uapi = UserApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- gapi = GroupApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- groups = [gapi.get_one_with_name('users')]
- test_user = uapi.create_user(
- email='test@test.test',
- password='pass',
- name='bob',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- uapi.save(test_user)
- transaction.commit()
- user_id = int(test_user.user_id)
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'admin@admin.admin',
- 'admin@admin.admin'
- )
- )
- # check before
- res = self.testapp.get(
- '/api/v2/users/{}'.format(user_id),
- status=200
- )
- res = res.json_body
- assert res['email'] == 'test@test.test'
-
- # Set password
- params = {
- 'email': 'mysuperemail@email.fr',
- 'loggedin_user_password': 'admin@admin.admin',
- }
- self.testapp.put_json(
- '/api/v2/users/{}/email'.format(user_id),
- params=params,
- status=200,
- )
- # Check After
- res = self.testapp.get(
- '/api/v2/users/{}'.format(user_id),
- status=200
- )
- res = res.json_body
- assert res['email'] == 'mysuperemail@email.fr'
-
- def test_api__set_user_email__err_403__admin_wrong_password(self):
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- uapi = UserApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- gapi = GroupApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- groups = [gapi.get_one_with_name('users')]
- test_user = uapi.create_user(
- email='test@test.test',
- password='pass',
- name='bob',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- uapi.save(test_user)
- transaction.commit()
- user_id = int(test_user.user_id)
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'admin@admin.admin',
- 'admin@admin.admin'
- )
- )
- # check before
- res = self.testapp.get(
- '/api/v2/users/{}'.format(user_id),
- status=200
- )
- res = res.json_body
- assert res['email'] == 'test@test.test'
-
- # Set password
- params = {
- 'email': 'mysuperemail@email.fr',
- 'loggedin_user_password': 'badpassword',
- }
- self.testapp.put_json(
- '/api/v2/users/{}/email'.format(user_id),
- params=params,
- status=403,
- )
- # Check After
- res = self.testapp.get(
- '/api/v2/users/{}'.format(user_id),
- status=200
- )
- res = res.json_body
- assert res['email'] == 'test@test.test'
-
- def test_api__set_user_email__err_400__admin_string_is_not_email(self):
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- uapi = UserApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- gapi = GroupApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- groups = [gapi.get_one_with_name('users')]
- test_user = uapi.create_user(
- email='test@test.test',
- password='pass',
- name='bob',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- uapi.save(test_user)
- transaction.commit()
- user_id = int(test_user.user_id)
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'admin@admin.admin',
- 'admin@admin.admin'
- )
- )
- # check before
- res = self.testapp.get(
- '/api/v2/users/{}'.format(user_id),
- status=200
- )
- res = res.json_body
- assert res['email'] == 'test@test.test'
-
- # Set password
- params = {
- 'email': 'thatisnotandemail',
- 'loggedin_user_password': 'admin@admin.admin',
- }
- self.testapp.put_json(
- '/api/v2/users/{}/email'.format(user_id),
- params=params,
- status=400,
- )
- # Check After
- res = self.testapp.get(
- '/api/v2/users/{}'.format(user_id),
- status=200
- )
- res = res.json_body
- assert res['email'] == 'test@test.test'
-
- def test_api__set_user_email__ok_200__user_itself(self):
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- uapi = UserApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- gapi = GroupApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- groups = [gapi.get_one_with_name('users')]
- test_user = uapi.create_user(
- email='test@test.test',
- password='pass',
- name='bob',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- uapi.save(test_user)
- transaction.commit()
- user_id = int(test_user.user_id)
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'test@test.test',
- 'pass'
- )
- )
- # check before
- res = self.testapp.get(
- '/api/v2/users/{}'.format(user_id),
- status=200
- )
- res = res.json_body
- assert res['email'] == 'test@test.test'
-
- # Set password
- params = {
- 'email': 'mysuperemail@email.fr',
- 'loggedin_user_password': 'pass',
- }
- self.testapp.put_json(
- '/api/v2/users/{}/email'.format(user_id),
- params=params,
- status=200,
- )
- self.testapp.authorization = (
- 'Basic',
- (
- 'mysuperemail@email.fr',
- 'pass'
- )
- )
- # Check After
- res = self.testapp.get(
- '/api/v2/users/{}'.format(user_id),
- status=200
- )
- res = res.json_body
- assert res['email'] == 'mysuperemail@email.fr'
-
- def test_api__set_user_email__err_403__other_normal_user(self):
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- uapi = UserApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- gapi = GroupApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- groups = [gapi.get_one_with_name('users')]
- test_user = uapi.create_user(
- email='test@test.test',
- password='pass',
- name='bob',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- test_user2 = uapi.create_user(
- email='test2@test2.test2',
- password='pass',
- name='bob2',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- uapi.save(test_user2)
- uapi.save(test_user)
- transaction.commit()
- user_id = int(test_user.user_id)
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'test@test.test',
- 'pass'
- )
- )
- # Set password
- params = {
- 'email': 'mysuperemail@email.fr',
- 'loggedin_user_password': 'test2@test2.test2',
- }
- self.testapp.put_json(
- '/api/v2/users/{}/email'.format(user_id),
- params=params,
- status=403,
- )
-
-
- class TestSetPasswordEndpoint(FunctionalTest):
- # -*- coding: utf-8 -*-
- """
- Tests for PUT /api/v2/users/{user_id}/password
- """
- fixtures = [BaseFixture]
-
- def test_api__set_user_password__ok_200__admin(self):
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- uapi = UserApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- gapi = GroupApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- groups = [gapi.get_one_with_name('users')]
- test_user = uapi.create_user(
- email='test@test.test',
- password='pass',
- name='bob',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- uapi.save(test_user)
- transaction.commit()
- user_id = int(test_user.user_id)
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'admin@admin.admin',
- 'admin@admin.admin'
- )
- )
- # check before
- user = uapi.get_one(user_id)
- assert user.validate_password('pass')
- assert not user.validate_password('mynewpassword')
- # Set password
- params = {
- 'new_password': 'mynewpassword',
- 'new_password2': 'mynewpassword',
- 'loggedin_user_password': 'admin@admin.admin',
- }
- self.testapp.put_json(
- '/api/v2/users/{}/password'.format(user_id),
- params=params,
- status=204,
- )
- # Check After
- user = uapi.get_one(user_id)
- assert not user.validate_password('pass')
- assert user.validate_password('mynewpassword')
-
- def test_api__set_user_password__err_403__admin_wrong_password(self):
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- uapi = UserApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- gapi = GroupApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- groups = [gapi.get_one_with_name('users')]
- test_user = uapi.create_user(
- email='test@test.test',
- password='pass',
- name='bob',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- uapi.save(test_user)
- transaction.commit()
- user_id = int(test_user.user_id)
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'admin@admin.admin',
- 'admin@admin.admin'
- )
- )
- # check before
- user = uapi.get_one(user_id)
- assert user.validate_password('pass')
- assert not user.validate_password('mynewpassword')
- # Set password
- params = {
- 'new_password': 'mynewpassword',
- 'new_password2': 'mynewpassword',
- 'loggedin_user_password': 'wrongpassword',
- }
- self.testapp.put_json(
- '/api/v2/users/{}/password'.format(user_id),
- params=params,
- status=403,
- )
- # Check After
- user = uapi.get_one(user_id)
- assert user.validate_password('pass')
- assert not user.validate_password('mynewpassword')
-
- def test_api__set_user_password__err_400__admin_passwords_do_not_match(self): # nopep8
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- uapi = UserApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- gapi = GroupApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- groups = [gapi.get_one_with_name('users')]
- test_user = uapi.create_user(
- email='test@test.test',
- password='pass',
- name='bob',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- uapi.save(test_user)
- transaction.commit()
- user_id = int(test_user.user_id)
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'admin@admin.admin',
- 'admin@admin.admin'
- )
- )
- # check before
- user = uapi.get_one(user_id)
- assert user.validate_password('pass')
- assert not user.validate_password('mynewpassword')
- assert not user.validate_password('mynewpassword2')
- # Set password
- params = {
- 'new_password': 'mynewpassword',
- 'new_password2': 'mynewpassword2',
- 'loggedin_user_password': 'admin@admin.admin',
- }
- self.testapp.put_json(
- '/api/v2/users/{}/password'.format(user_id),
- params=params,
- status=400,
- )
- # Check After
- user = uapi.get_one(user_id)
- assert user.validate_password('pass')
- assert not user.validate_password('mynewpassword')
- assert not user.validate_password('mynewpassword2')
-
- def test_api__set_user_password__ok_200__user_itself(self):
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- uapi = UserApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- gapi = GroupApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- groups = [gapi.get_one_with_name('users')]
- test_user = uapi.create_user(
- email='test@test.test',
- password='pass',
- name='bob',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- uapi.save(test_user)
- transaction.commit()
- user_id = int(test_user.user_id)
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'test@test.test',
- 'pass'
- )
- )
- # check before
- user = uapi.get_one(user_id)
- assert user.validate_password('pass')
- assert not user.validate_password('mynewpassword')
- # Set password
- params = {
- 'new_password': 'mynewpassword',
- 'new_password2': 'mynewpassword',
- 'loggedin_user_password': 'pass',
- }
- self.testapp.put_json(
- '/api/v2/users/{}/password'.format(user_id),
- params=params,
- status=204,
- )
- # Check After
- user = uapi.get_one(user_id)
- assert not user.validate_password('pass')
- assert user.validate_password('mynewpassword')
-
- def test_api__set_user_email__err_403__other_normal_user(self):
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- uapi = UserApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- gapi = GroupApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- groups = [gapi.get_one_with_name('users')]
- test_user = uapi.create_user(
- email='test@test.test',
- password='pass',
- name='bob',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- test_user2 = uapi.create_user(
- email='test2@test2.test2',
- password='pass',
- name='bob2',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- uapi.save(test_user2)
- uapi.save(test_user)
- transaction.commit()
- user_id = int(test_user.user_id)
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'test@test.test',
- 'pass'
- )
- )
- # Set password
- params = {
- 'email': 'mysuperemail@email.fr',
- 'loggedin_user_password': 'test2@test2.test2',
- }
- self.testapp.put_json(
- '/api/v2/users/{}/email'.format(user_id),
- params=params,
- status=403,
- )
-
-
- class TestSetUserInfoEndpoint(FunctionalTest):
- # -*- coding: utf-8 -*-
- """
- Tests for PUT /api/v2/users/{user_id}
- """
- fixtures = [BaseFixture]
-
- def test_api__set_user_info__ok_200__admin(self):
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- uapi = UserApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- gapi = GroupApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- groups = [gapi.get_one_with_name('users')]
- test_user = uapi.create_user(
- email='test@test.test',
- password='pass',
- name='bob',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- uapi.save(test_user)
- transaction.commit()
- user_id = int(test_user.user_id)
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'admin@admin.admin',
- 'admin@admin.admin'
- )
- )
- # check before
- res = self.testapp.get(
- '/api/v2/users/{}'.format(user_id),
- status=200
- )
- res = res.json_body
- assert res['user_id'] == user_id
- assert res['public_name'] == 'bob'
- assert res['timezone'] == 'Europe/Paris'
- # Set params
- params = {
- 'public_name': 'updated',
- 'timezone': 'Europe/London',
- }
- self.testapp.put_json(
- '/api/v2/users/{}'.format(user_id),
- params=params,
- status=200,
- )
- # Check After
- res = self.testapp.get(
- '/api/v2/users/{}'.format(user_id),
- status=200
- )
- res = res.json_body
- assert res['user_id'] == user_id
- assert res['public_name'] == 'updated'
- assert res['timezone'] == 'Europe/London'
-
- def test_api__set_user_info__ok_200__user_itself(self):
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- uapi = UserApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- gapi = GroupApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- groups = [gapi.get_one_with_name('users')]
- test_user = uapi.create_user(
- email='test@test.test',
- password='pass',
- name='bob',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- uapi.save(test_user)
- transaction.commit()
- user_id = int(test_user.user_id)
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'test@test.test',
- 'pass',
- )
- )
- # check before
- res = self.testapp.get(
- '/api/v2/users/{}'.format(user_id),
- status=200
- )
- res = res.json_body
- assert res['user_id'] == user_id
- assert res['public_name'] == 'bob'
- assert res['timezone'] == 'Europe/Paris'
- # Set params
- params = {
- 'public_name': 'updated',
- 'timezone': 'Europe/London',
- }
- self.testapp.put_json(
- '/api/v2/users/{}'.format(user_id),
- params=params,
- status=200,
- )
- # Check After
- res = self.testapp.get(
- '/api/v2/users/{}'.format(user_id),
- status=200
- )
- res = res.json_body
- assert res['user_id'] == user_id
- assert res['public_name'] == 'updated'
- assert res['timezone'] == 'Europe/London'
-
- def test_api__set_user_email__err_403__other_normal_user(self):
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- uapi = UserApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- gapi = GroupApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- groups = [gapi.get_one_with_name('users')]
- test_user = uapi.create_user(
- email='test@test.test',
- password='pass',
- name='bob',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- test_user2 = uapi.create_user(
- email='test2@test2.test2',
- password='pass',
- name='test',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- uapi.save(test_user2)
- uapi.save(test_user)
- transaction.commit()
- user_id = int(test_user.user_id)
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'test2@test2.test2',
- 'pass',
- )
- )
- # Set params
- params = {
- 'public_name': 'updated',
- 'timezone': 'Europe/London',
- }
- self.testapp.put_json(
- '/api/v2/users/{}'.format(user_id),
- params=params,
- status=403,
- )
-
-
- class TestSetUserProfilEndpoint(FunctionalTest):
- # -*- coding: utf-8 -*-
- """
- Tests for PUT /api/v2/users/{user_id}/profile
- """
- fixtures = [BaseFixture]
-
- def test_api__set_user_info__ok_200__admin(self):
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- uapi = UserApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- gapi = GroupApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- groups = [gapi.get_one_with_name('users')]
- test_user = uapi.create_user(
- email='test@test.test',
- password='pass',
- name='bob',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- uapi.save(test_user)
- transaction.commit()
- user_id = int(test_user.user_id)
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'admin@admin.admin',
- 'admin@admin.admin'
- )
- )
- # check before
- res = self.testapp.get(
- '/api/v2/users/{}'.format(user_id),
- status=200
- )
- res = res.json_body
- assert res['user_id'] == user_id
- assert res['profile'] == 'users'
- # Set params
- params = {
- 'profile': 'administrators',
- }
- self.testapp.put_json(
- '/api/v2/users/{}/profile'.format(user_id),
- params=params,
- status=204,
- )
- # Check After
- res = self.testapp.get(
- '/api/v2/users/{}'.format(user_id),
- status=200
- )
- res = res.json_body
- assert res['user_id'] == user_id
- assert res['profile'] == 'administrators'
-
- def test_api__set_user_info__err_403__user_itself(self):
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- uapi = UserApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- gapi = GroupApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- groups = [gapi.get_one_with_name('users')]
- test_user = uapi.create_user(
- email='test@test.test',
- password='pass',
- name='bob',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- uapi.save(test_user)
- transaction.commit()
- user_id = int(test_user.user_id)
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'test@test.test',
- 'pass',
- )
- )
- # check before
- res = self.testapp.get(
- '/api/v2/users/{}'.format(user_id),
- status=200
- )
- res = res.json_body
- assert res['user_id'] == user_id
- assert res['profile'] == 'users'
- # Set params
- params = {
- 'profile': 'administrators',
- }
- self.testapp.put_json(
- '/api/v2/users/{}/profile'.format(user_id),
- params=params,
- status=403,
- )
- # Check After
- res = self.testapp.get(
- '/api/v2/users/{}'.format(user_id),
- status=200
- )
- res = res.json_body
- assert res['user_id'] == user_id
- assert res['profile'] == 'users'
-
- def test_api__set_user_email__err_403__other_normal_user(self):
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- uapi = UserApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- gapi = GroupApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- groups = [gapi.get_one_with_name('users')]
- test_user = uapi.create_user(
- email='test@test.test',
- password='pass',
- name='bob',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- test_user2 = uapi.create_user(
- email='test2@test2.test2',
- password='pass',
- name='test',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- uapi.save(test_user2)
- uapi.save(test_user)
- transaction.commit()
- user_id = int(test_user.user_id)
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'test2@test2.test2',
- 'pass',
- )
- )
- # Set params
- params = {
- 'profile': 'administrators',
- }
- self.testapp.put_json(
- '/api/v2/users/{}/profile'.format(user_id),
- params=params,
- status=403,
- )
-
-
- class TestSetUserEnableDisableEndpoints(FunctionalTest):
- # -*- coding: utf-8 -*-
- """
- Tests for PUT /api/v2/users/{user_id}/enable
- and PUT /api/v2/users/{user_id}/disable
- """
- fixtures = [BaseFixture]
-
- def test_api_enable_user__ok_200__admin(self):
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- uapi = UserApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- gapi = GroupApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- groups = [gapi.get_one_with_name('users')]
- test_user = uapi.create_user(
- email='test@test.test',
- password='pass',
- name='bob',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- uapi.disable(test_user, do_save=True)
- uapi.save(test_user)
- transaction.commit()
- user_id = int(test_user.user_id)
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'admin@admin.admin',
- 'admin@admin.admin'
- )
- )
- # check before
- res = self.testapp.get(
- '/api/v2/users/{}'.format(user_id),
- status=200
- )
- res = res.json_body
- assert res['user_id'] == user_id
- assert res['is_active'] is False
- self.testapp.put_json(
- '/api/v2/users/{}/enable'.format(user_id),
- status=204,
- )
- # Check After
- res = self.testapp.get(
- '/api/v2/users/{}'.format(user_id),
- status=200
- )
- res = res.json_body
- assert res['user_id'] == user_id
- assert res['is_active'] is True
-
- def test_api_disable_user__ok_200__admin(self):
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- uapi = UserApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- gapi = GroupApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- groups = [gapi.get_one_with_name('users')]
- test_user = uapi.create_user(
- email='test@test.test',
- password='pass',
- name='bob',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- uapi.enable(test_user, do_save=True)
- uapi.save(test_user)
- transaction.commit()
- user_id = int(test_user.user_id)
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'admin@admin.admin',
- 'admin@admin.admin'
- )
- )
- # check before
- res = self.testapp.get(
- '/api/v2/users/{}'.format(user_id),
- status=200
- )
- res = res.json_body
- assert res['user_id'] == user_id
- assert res['is_active'] is True
- self.testapp.put_json(
- '/api/v2/users/{}/disable'.format(user_id),
- status=204,
- )
- # Check After
- res = self.testapp.get(
- '/api/v2/users/{}'.format(user_id),
- status=200
- )
- res = res.json_body
- assert res['user_id'] == user_id
- assert res['is_active'] is False
-
- def test_api_enable_user__err_403__other_account(self):
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- uapi = UserApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- gapi = GroupApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- groups = [gapi.get_one_with_name('users')]
- test_user = uapi.create_user(
- email='test@test.test',
- password='pass',
- name='bob',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- test_user2 = uapi.create_user(
- email='test2@test2.test2',
- password='pass',
- name='test2',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- uapi.disable(test_user, do_save=True)
- uapi.save(test_user2)
- uapi.save(test_user)
- transaction.commit()
- user_id = int(test_user.user_id)
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'test2@test2.test2',
- 'pass'
- )
- )
- self.testapp.put_json(
- '/api/v2/users/{}/enable'.format(user_id),
- status=403,
- )
-
- def test_api_disable_user__err_403__other_account(self):
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- uapi = UserApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- gapi = GroupApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- groups = [gapi.get_one_with_name('users')]
- test_user = uapi.create_user(
- email='test@test.test',
- password='pass',
- name='bob',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- test_user2 = uapi.create_user(
- email='test2@test2.test2',
- password='pass',
- name='test2',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- uapi.enable(test_user, do_save=True)
- uapi.save(test_user2)
- uapi.save(test_user)
- transaction.commit()
- user_id = int(test_user.user_id)
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'test2@test2.test2',
- 'pass'
- )
- )
- self.testapp.put_json(
- '/api/v2/users/{}/disable'.format(user_id),
- status=403,
- )
-
- def test_api_disable_user__ok_200__user_itself(self):
- dbsession = get_tm_session(self.session_factory, transaction.manager)
- admin = dbsession.query(models.User) \
- .filter(models.User.email == 'admin@admin.admin') \
- .one()
- uapi = UserApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- gapi = GroupApi(
- current_user=admin,
- session=dbsession,
- config=self.app_config,
- )
- groups = [gapi.get_one_with_name('users')]
- test_user = uapi.create_user(
- email='test@test.test',
- password='pass',
- name='bob',
- groups=groups,
- timezone='Europe/Paris',
- do_save=True,
- do_notify=False,
- )
- uapi.enable(test_user, do_save=True)
- uapi.save(test_user)
- transaction.commit()
- user_id = int(test_user.user_id)
-
- self.testapp.authorization = (
- 'Basic',
- (
- 'test@test.test',
- 'pass'
- )
- )
- # check before
- res = self.testapp.get(
- '/api/v2/users/{}'.format(user_id),
- status=200
- )
- res = res.json_body
- assert res['user_id'] == user_id
- assert res['is_active'] is True
- self.testapp.put_json(
- '/api/v2/users/{}/disable'.format(user_id),
- status=403,
- )
- # Check After
- res = self.testapp.get(
- '/api/v2/users/{}'.format(user_id),
- status=200
- )
- res = res.json_body
- assert res['user_id'] == user_id
- assert res['is_active'] is True
|