test_user_avatar_api.py 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477
  1. import json
  2. import os
  3. from pathlib import Path
  4. from django.contrib.auth import get_user_model
  5. from misago.acl.test import patch_user_acl
  6. from misago.conf import settings
  7. from misago.conf.test import override_dynamic_settings
  8. from misago.users.avatars import gallery, store
  9. from misago.users.models import AvatarGallery
  10. from misago.users.testutils import AuthenticatedUserTestCase
  11. TESTFILES_DIR = os.path.join(os.path.dirname(os.path.abspath(__file__)), 'testfiles')
  12. TEST_AVATAR_PATH = os.path.join(TESTFILES_DIR, 'avatar.png')
  13. User = get_user_model()
  14. class UserAvatarTests(AuthenticatedUserTestCase):
  15. """tests for user avatar RPC (/api/users/1/avatar/)"""
  16. def setUp(self):
  17. super().setUp()
  18. self.link = '/api/users/%s/avatar/' % self.user.pk
  19. self.client.post(self.link, data={'avatar': 'generated'})
  20. def get_current_user(self):
  21. return User.objects.get(pk=self.user.pk)
  22. def assertOldAvatarsAreDeleted(self, user):
  23. self.assertEqual(
  24. user.avatar_set.count(), len(settings.MISAGO_AVATARS_SIZES)
  25. )
  26. @override_dynamic_settings(allow_custom_avatars=False)
  27. def test_avatars_off(self):
  28. """custom avatars are not allowed"""
  29. response = self.client.get(self.link)
  30. self.assertEqual(response.status_code, 200)
  31. options = response.json()
  32. self.assertTrue(options['generated'])
  33. self.assertFalse(options['gravatar'])
  34. self.assertFalse(options['crop_src'])
  35. self.assertFalse(options['crop_tmp'])
  36. self.assertFalse(options['upload'])
  37. self.assertFalse(options['galleries'])
  38. @override_dynamic_settings(allow_custom_avatars=True)
  39. def test_avatars_on(self):
  40. """custom avatars are allowed"""
  41. response = self.client.get(self.link)
  42. self.assertEqual(response.status_code, 200)
  43. options = response.json()
  44. self.assertTrue(options['generated'])
  45. self.assertTrue(options['gravatar'])
  46. self.assertFalse(options['crop_src'])
  47. self.assertFalse(options['crop_tmp'])
  48. self.assertTrue(options['upload'])
  49. self.assertFalse(options['galleries'])
  50. def test_gallery_exists(self):
  51. """api returns gallery"""
  52. gallery.load_avatar_galleries()
  53. response = self.client.get(self.link)
  54. self.assertEqual(response.status_code, 200)
  55. options = response.json()
  56. self.assertTrue(options['galleries'])
  57. def test_avatar_locked(self):
  58. """requests to api error if user's avatar is locked"""
  59. self.user.is_avatar_locked = True
  60. self.user.avatar_lock_user_message = "Your avatar is pwnt."
  61. self.user.save()
  62. response = self.client.get(self.link)
  63. self.assertEqual(response.status_code, 403)
  64. self.assertEqual(response.json(), {
  65. "detail": "Your avatar is locked. You can't change it.",
  66. "reason": "<p>Your avatar is pwnt.</p>",
  67. })
  68. def test_other_user_avatar(self):
  69. """requests to api error if user tries to access other user"""
  70. self.logout_user()
  71. response = self.client.get(self.link)
  72. self.assertEqual(response.status_code, 403)
  73. self.assertEqual(response.json(), {
  74. "detail": "You have to sign in to perform this action.",
  75. })
  76. self.login_user(
  77. User.objects.create_user("BobUser", "bob@bob.com", self.USER_PASSWORD)
  78. )
  79. response = self.client.get(self.link)
  80. self.assertEqual(response.status_code, 403)
  81. self.assertEqual(response.json(), {
  82. "detail": "You can't change other users avatars.",
  83. })
  84. def test_empty_requests(self):
  85. """empty request errors with code 400"""
  86. response = self.client.post(self.link)
  87. self.assertEqual(response.status_code, 400)
  88. self.assertEqual(response.json(), {
  89. "detail": "Unknown avatar type.",
  90. })
  91. def test_failed_gravatar_request(self):
  92. """no gravatar RPC fails"""
  93. self.user.email_hash = 'wolololo'
  94. self.user.save()
  95. response = self.client.post(self.link, data={'avatar': 'gravatar'})
  96. self.assertEqual(response.status_code, 400)
  97. self.assertEqual(response.json(), {
  98. "detail": "No Gravatar is associated with your e-mail address.",
  99. })
  100. def test_successful_gravatar_request(self):
  101. """gravatar RPC passes"""
  102. self.user.set_email('rafio.xudb@gmail.com')
  103. self.user.save()
  104. response = self.client.post(self.link, data={'avatar': 'gravatar'})
  105. self.assertEqual(response.status_code, 200)
  106. self.assertEqual(
  107. response.json()["detail"], "Gravatar was downloaded and set as new avatar."
  108. )
  109. self.assertOldAvatarsAreDeleted(self.user)
  110. def test_generation_request(self):
  111. """generated avatar is set"""
  112. response = self.client.post(self.link, data={'avatar': 'generated'})
  113. self.assertEqual(response.status_code, 200)
  114. self.assertEqual(
  115. response.json()["detail"], "New avatar based on your account was set."
  116. )
  117. self.assertOldAvatarsAreDeleted(self.user)
  118. def test_avatar_upload_and_crop(self):
  119. """avatar can be uploaded and cropped"""
  120. response = self.client.post(self.link, data={'avatar': 'upload'})
  121. self.assertEqual(response.status_code, 400)
  122. self.assertEqual(response.json(), {
  123. "detail": "No file was sent.",
  124. })
  125. with open(TEST_AVATAR_PATH, 'rb') as avatar:
  126. response = self.client.post(self.link, data={'avatar': 'upload', 'image': avatar})
  127. self.assertEqual(response.status_code, 200)
  128. response_json = response.json()
  129. self.assertTrue(response_json['crop_tmp'])
  130. self.assertEqual(
  131. self.get_current_user().avatar_tmp.url, response_json['crop_tmp']['url']
  132. )
  133. avatar = Path(self.get_current_user().avatar_tmp.path)
  134. self.assertTrue(avatar.exists())
  135. self.assertTrue(avatar.is_file())
  136. response = self.client.post(
  137. self.link,
  138. json.dumps({
  139. 'avatar': 'crop_tmp',
  140. 'crop': {
  141. 'offset': {
  142. 'x': 0,
  143. 'y': 0
  144. },
  145. 'zoom': 1,
  146. },
  147. }),
  148. content_type="application/json",
  149. )
  150. response_json = response.json()
  151. self.assertEqual(response.status_code, 200)
  152. self.assertEqual(
  153. response.json()["detail"], "Uploaded avatar was set."
  154. )
  155. self.assertFalse(self.get_current_user().avatar_tmp)
  156. self.assertOldAvatarsAreDeleted(self.user)
  157. avatar = Path(self.get_current_user().avatar_src.path)
  158. self.assertTrue(avatar.exists())
  159. self.assertTrue(avatar.is_file())
  160. response = self.client.post(
  161. self.link,
  162. json.dumps({
  163. 'avatar': 'crop_tmp',
  164. 'crop': {
  165. 'offset': {
  166. 'x': 0,
  167. 'y': 0
  168. },
  169. 'zoom': 1,
  170. },
  171. }),
  172. content_type="application/json",
  173. )
  174. self.assertEqual(response.status_code, 400)
  175. self.assertEqual(response.json(), {
  176. "detail": "This avatar type is not allowed.",
  177. })
  178. response = self.client.post(
  179. self.link,
  180. json.dumps({
  181. 'avatar': 'crop_src',
  182. 'crop': {
  183. 'offset': {
  184. 'x': 0,
  185. 'y': 0
  186. },
  187. 'zoom': 1,
  188. },
  189. }),
  190. content_type="application/json",
  191. )
  192. self.assertEqual(response.status_code, 200)
  193. self.assertEqual(
  194. response.json()["detail"], "Avatar was re-cropped."
  195. )
  196. self.assertOldAvatarsAreDeleted(self.user)
  197. # delete user avatars, test if it deletes src and tmp
  198. store.delete_avatar(self.get_current_user())
  199. self.assertTrue(self.get_current_user().avatar_src.path)
  200. avatar = Path(self.get_current_user().avatar_src.path)
  201. self.assertFalse(avatar.exists())
  202. self.assertFalse(avatar.is_file())
  203. def test_gallery_set_empty_gallery(self):
  204. """gallery handles set avatar on empty gallery"""
  205. response = self.client.get(self.link)
  206. self.assertEqual(response.status_code, 200)
  207. response = self.client.post(self.link, data={'avatar': 'galleries', 'image': 123})
  208. self.assertEqual(response.status_code, 400)
  209. self.assertEqual(response.json(), {
  210. "detail": "This avatar type is not allowed.",
  211. })
  212. def test_gallery_image_validation(self):
  213. """gallery validates image to set"""
  214. gallery.load_avatar_galleries()
  215. response = self.client.get(self.link)
  216. self.assertEqual(response.status_code, 200)
  217. # no image id is handled
  218. response = self.client.post(
  219. self.link,
  220. data={
  221. 'avatar': 'galleries',
  222. },
  223. )
  224. self.assertEqual(response.status_code, 400)
  225. self.assertEqual(response.json(), {
  226. "detail": "Incorrect image.",
  227. })
  228. # invalid id is handled
  229. response = self.client.post(
  230. self.link,
  231. data={
  232. 'avatar': 'galleries',
  233. 'image': 'asdsadsadsa',
  234. },
  235. )
  236. self.assertEqual(response.status_code, 400)
  237. self.assertEqual(response.json(), {
  238. "detail": "Incorrect image.",
  239. })
  240. # nonexistant image is handled
  241. response = self.client.get(self.link)
  242. self.assertEqual(response.status_code, 200)
  243. options = response.json()
  244. self.assertTrue(options['galleries'])
  245. test_avatar = options['galleries'][0]['images'][0]['id']
  246. response = self.client.post(
  247. self.link,
  248. data={
  249. 'avatar': 'galleries',
  250. 'image': test_avatar + 5000,
  251. },
  252. )
  253. self.assertEqual(response.status_code, 400)
  254. self.assertEqual(response.json(), {
  255. "detail": "Incorrect image.",
  256. })
  257. # default gallery image is handled
  258. AvatarGallery.objects.filter(pk=test_avatar).update(gallery=gallery.DEFAULT_GALLERY)
  259. response = self.client.post(self.link, data={'avatar': 'galleries', 'image': test_avatar})
  260. self.assertEqual(response.status_code, 400)
  261. self.assertEqual(response.json(), {
  262. "detail": "Incorrect image.",
  263. })
  264. def test_gallery_set_valid_avatar(self):
  265. """its possible to set avatar from gallery"""
  266. gallery.load_avatar_galleries()
  267. response = self.client.get(self.link)
  268. self.assertEqual(response.status_code, 200)
  269. options = response.json()
  270. self.assertTrue(options['galleries'])
  271. test_avatar = options['galleries'][0]['images'][0]['id']
  272. response = self.client.post(
  273. self.link,
  274. data={
  275. 'avatar': 'galleries',
  276. 'image': test_avatar,
  277. },
  278. )
  279. self.assertEqual(response.status_code, 200)
  280. self.assertEqual(
  281. response.json()["detail"], "Avatar from gallery was set."
  282. )
  283. self.assertOldAvatarsAreDeleted(self.user)
  284. class UserAvatarModerationTests(AuthenticatedUserTestCase):
  285. """tests for moderate user avatar RPC (/api/users/1/moderate-avatar/)"""
  286. def setUp(self):
  287. super().setUp()
  288. self.other_user = User.objects.create_user("OtherUser", "other@user.com", "pass123")
  289. self.link = '/api/users/%s/moderate-avatar/' % self.other_user.pk
  290. @patch_user_acl({'can_moderate_avatars': 0})
  291. def test_no_permission(self):
  292. """no permission to moderate avatar"""
  293. response = self.client.get(self.link)
  294. self.assertEqual(response.status_code, 403)
  295. self.assertEqual(response.json(), {
  296. "detail": "You can't moderate avatars.",
  297. })
  298. @patch_user_acl({'can_moderate_avatars': 1})
  299. def test_moderate_avatar(self):
  300. """moderate avatar"""
  301. response = self.client.get(self.link)
  302. self.assertEqual(response.status_code, 200)
  303. options = response.json()
  304. self.assertEqual(options['is_avatar_locked'], self.other_user.is_avatar_locked)
  305. self.assertEqual(
  306. options['avatar_lock_user_message'], self.other_user.avatar_lock_user_message
  307. )
  308. self.assertEqual(
  309. options['avatar_lock_staff_message'], self.other_user.avatar_lock_staff_message
  310. )
  311. response = self.client.post(
  312. self.link,
  313. json.dumps({
  314. 'is_avatar_locked': True,
  315. 'avatar_lock_user_message': "Test user message.",
  316. 'avatar_lock_staff_message': "Test staff message.",
  317. }),
  318. content_type="application/json",
  319. )
  320. self.assertEqual(response.status_code, 200)
  321. other_user = User.objects.get(pk=self.other_user.pk)
  322. options = response.json()
  323. self.assertEqual(other_user.is_avatar_locked, True)
  324. self.assertEqual(other_user.avatar_lock_user_message, "Test user message.")
  325. self.assertEqual(other_user.avatar_lock_staff_message, "Test staff message.")
  326. self.assertEqual(options['avatars'], other_user.avatars)
  327. self.assertEqual(options['is_avatar_locked'], other_user.is_avatar_locked)
  328. self.assertEqual(options['avatar_lock_user_message'], other_user.avatar_lock_user_message)
  329. self.assertEqual(
  330. options['avatar_lock_staff_message'], other_user.avatar_lock_staff_message
  331. )
  332. response = self.client.post(
  333. self.link,
  334. json.dumps({
  335. 'is_avatar_locked': False,
  336. 'avatar_lock_user_message': None,
  337. 'avatar_lock_staff_message': None,
  338. }),
  339. content_type="application/json",
  340. )
  341. self.assertEqual(response.status_code, 200)
  342. other_user = User.objects.get(pk=self.other_user.pk)
  343. self.assertFalse(other_user.is_avatar_locked)
  344. self.assertIsNone(other_user.avatar_lock_user_message)
  345. self.assertIsNone(other_user.avatar_lock_staff_message)
  346. options = response.json()
  347. self.assertEqual(options['avatars'], other_user.avatars)
  348. self.assertEqual(options['is_avatar_locked'], other_user.is_avatar_locked)
  349. self.assertEqual(options['avatar_lock_user_message'], other_user.avatar_lock_user_message)
  350. self.assertEqual(
  351. options['avatar_lock_staff_message'], other_user.avatar_lock_staff_message
  352. )
  353. response = self.client.post(
  354. self.link,
  355. json.dumps({
  356. 'is_avatar_locked': True,
  357. 'avatar_lock_user_message': '',
  358. 'avatar_lock_staff_message': '',
  359. }),
  360. content_type="application/json",
  361. )
  362. self.assertEqual(response.status_code, 200)
  363. other_user = User.objects.get(pk=self.other_user.pk)
  364. self.assertTrue(other_user.is_avatar_locked)
  365. self.assertEqual(other_user.avatar_lock_user_message, '')
  366. self.assertEqual(other_user.avatar_lock_staff_message, '')
  367. options = response.json()
  368. self.assertEqual(options['avatars'], other_user.avatars)
  369. self.assertEqual(options['is_avatar_locked'], other_user.is_avatar_locked)
  370. self.assertEqual(options['avatar_lock_user_message'], other_user.avatar_lock_user_message)
  371. self.assertEqual(
  372. options['avatar_lock_staff_message'], other_user.avatar_lock_staff_message
  373. )
  374. response = self.client.post(
  375. self.link,
  376. json.dumps({
  377. 'is_avatar_locked': False,
  378. }),
  379. content_type="application/json",
  380. )
  381. self.assertEqual(response.status_code, 200)
  382. other_user = User.objects.get(pk=self.other_user.pk)
  383. self.assertFalse(other_user.is_avatar_locked)
  384. self.assertEqual(other_user.avatar_lock_user_message, '')
  385. self.assertEqual(other_user.avatar_lock_staff_message, '')
  386. options = response.json()
  387. self.assertEqual(options['avatars'], other_user.avatars)
  388. self.assertEqual(options['is_avatar_locked'], other_user.is_avatar_locked)
  389. self.assertEqual(options['avatar_lock_user_message'], other_user.avatar_lock_user_message)
  390. self.assertEqual(
  391. options['avatar_lock_staff_message'], other_user.avatar_lock_staff_message
  392. )
  393. @patch_user_acl({'can_moderate_avatars': 1})
  394. def test_moderate_own_avatar(self):
  395. """moderate own avatar"""
  396. response = self.client.get('/api/users/%s/moderate-avatar/' % self.user.pk)
  397. self.assertEqual(response.status_code, 200)