Projet

Général

Profil

0002-users-api-unset-verified-flag-on-a-modified-email-ad.patch

Paul Marillonnet, 07 mars 2019 13:41

Télécharger (3,88 ko)

Voir les différences:

Subject: [PATCH 2/2] users api: unset verified flag on a modified email
 address (#30740)

 src/authentic2/api_views.py |  7 ++++++
 tests/test_api.py           | 49 +++++++++++++++++++++++++++++++++++++
 2 files changed, 56 insertions(+)
src/authentic2/api_views.py
429 429
        self.check_perm('custom_user.change_user', instance.ou)
430 430
        if 'ou' in validated_data:
431 431
            self.check_perm('custom_user.change_user', validated_data.get('ou'))
432
        if validated_data.get('email') != instance.email:
433
            instance.email_verified = False
432 434
        super(BaseUserSerializer, self).update(instance, validated_data)
433 435
        for key, value in attributes.iteritems():
434 436
            if is_verified.get(key):
......
482 484
            'uuid': {
483 485
                'read_only': False,
484 486
                'required': False,
487
            },
488
            'email_verified': {
489
                'read_only': True,
485 490
            }
486 491
        }
487 492
        exclude = ('date_joined', 'user_permissions', 'groups', 'last_login')
......
681 686
                'errors': serializer.errors
682 687
            }
683 688
            return Response(response, status.HTTP_400_BAD_REQUEST)
689
        user.email_verified = False
690
        user.save()
684 691
        utils.send_email_change_email(user, serializer.validated_data['email'], request=request)
685 692
        return Response({'result': 1})
686 693

  
tests/test_api.py
141 141
    assert resp.json['next'] is None
142 142

  
143 143

  
144
def test_api_users_email_verified(settings, app, admin, simple_user):
145
    from django.contrib.auth import get_user_model
146
    simple_user.email_verified = True
147
    simple_user.save()
148

  
149
    User = get_user_model()
150
    payload = {
151
        'username': simple_user.username,
152
        'id': simple_user.id,
153
        'email': 'john.doe@nowhere.null',
154
        'first_name': 'Johnny',
155
        'last_name': 'Doeny',
156
        'email_verified': True,
157
    }
158
    headers = basic_authorization_header(admin)
159
    resp = app.put_json('/api/users/{}/'.format(simple_user.uuid),
160
            params=payload, headers=headers, status=200)
161
    user = User.objects.get(id=simple_user.id)
162
    assert not user.email_verified
163
    assert not resp.json['email_verified']
164

  
165
    user.email_verified = True
166
    user.email = 'johnny.doeny@foo.bar'
167
    user.save()
168

  
169
    resp = app.patch_json('/api/users/{}/'.format(simple_user.uuid),
170
            params=payload, headers=headers, status=200)
171
    user = User.objects.get(id=simple_user.id)
172
    assert not user.email_verified
173
    assert not resp.json['email_verified']
174

  
175

  
176
def test_api_email_users_email_verified(settings, app, admin, simple_user):
177
    from django.contrib.auth import get_user_model
178
    simple_user.email_verified = True
179
    simple_user.save()
180

  
181
    User = get_user_model()
182
    payload = {
183
        'email': 'john.doe@nowhere.null',
184
        'email_verified': True,
185
    }
186
    headers = basic_authorization_header(admin)
187
    resp = app.post_json('/api/users/{}/email/'.format(simple_user.uuid),
188
            params=payload, headers=headers, status=200)
189
    user = User.objects.get(id=simple_user.id)
190
    assert not user.email_verified
191

  
192

  
144 193
def test_api_users_boolean_attribute(app, superuser):
145 194
    from authentic2.models import Attribute, AttributeValue
146 195
    at = Attribute.objects.create(
147
-