test_user_create_api.py 5.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165
  1. from django.contrib.auth import get_user_model
  2. from django.core import mail
  3. from django.urls import reverse
  4. from misago.conf import settings
  5. from misago.users.models import Online
  6. from misago.users.testutils import UserTestCase
  7. UserModel = get_user_model()
  8. class UserCreateTests(UserTestCase):
  9. """
  10. tests for new user registration (POST to /api/users/)
  11. """
  12. def setUp(self):
  13. super(UserCreateTests, self).setUp()
  14. self.api_link = '/api/users/'
  15. def test_empty_request(self):
  16. """empty request errors with code 400"""
  17. response = self.client.post(self.api_link)
  18. self.assertEqual(response.status_code, 400)
  19. def test_authenticated_request(self):
  20. """authentiated user request errors with code 403"""
  21. self.login_user(self.get_authenticated_user())
  22. response = self.client.post(self.api_link)
  23. self.assertEqual(response.status_code, 403)
  24. def test_registration_off_request(self):
  25. """registrations off request errors with code 403"""
  26. settings.override_setting('account_activation', 'closed')
  27. response = self.client.post(self.api_link)
  28. self.assertContains(response, 'closed', status_code=403)
  29. def test_registration_validates_username(self):
  30. """api validates usernames"""
  31. user = self.get_authenticated_user()
  32. response = self.client.post(self.api_link, data={
  33. 'username': user.username,
  34. 'email': 'loremipsum@dolor.met',
  35. 'password': 'LoremP4ssword'
  36. })
  37. self.assertEqual(response.status_code, 400)
  38. self.assertEqual(response.json(), {
  39. 'username': [
  40. "This username is not available."
  41. ]
  42. })
  43. def test_registration_validates_email(self):
  44. """api validates usernames"""
  45. user = self.get_authenticated_user()
  46. response = self.client.post(self.api_link, data={
  47. 'username': 'totallyNew',
  48. 'email': user.email,
  49. 'password': 'LoremP4ssword'
  50. })
  51. self.assertEqual(response.status_code, 400)
  52. self.assertEqual(response.json(), {
  53. 'email': [
  54. "This e-mail address is not available."
  55. ]
  56. })
  57. def test_registration_validates_password(self):
  58. """api uses django's validate_password to validate registrations"""
  59. response = self.client.post(self.api_link, data={
  60. 'username': 'Bob',
  61. 'email': 'l.o.r.e.m.i.p.s.u.m@gmail.com',
  62. 'password': '123'
  63. })
  64. self.assertContains(response, "password is too short", status_code=400)
  65. self.assertContains(response, "password is entirely numeric", status_code=400)
  66. self.assertContains(response, "email is not allowed", status_code=400)
  67. def test_registration_validates_password_similiarity(self):
  68. """api uses validate_password to validate registrations"""
  69. response = self.client.post(self.api_link, data={
  70. 'username': 'BobBoberson',
  71. 'email': 'l.o.r.e.m.i.p.s.u.m@gmail.com',
  72. 'password': 'BobBoberson'
  73. })
  74. self.assertContains(response, "password is too similar to the username", status_code=400)
  75. def test_registration_calls_validate_new_registration(self):
  76. """api uses validate_new_registration to validate registrations"""
  77. response = self.client.post(self.api_link, data={
  78. 'username': 'Bob',
  79. 'email': 'l.o.r.e.m.i.p.s.u.m@gmail.com',
  80. 'password': 'pas123'
  81. })
  82. self.assertContains(response, "email is not allowed", status_code=400)
  83. def test_registration_creates_active_user(self):
  84. """api creates active and signed in user on POST"""
  85. settings.override_setting('account_activation', 'none')
  86. response = self.client.post(self.api_link, data={
  87. 'username': 'Bob',
  88. 'email': 'bob@bob.com',
  89. 'password': 'pass123'
  90. })
  91. self.assertContains(response, 'active')
  92. self.assertContains(response, 'Bob')
  93. self.assertContains(response, 'bob@bob.com')
  94. UserModel.objects.get_by_username('Bob')
  95. test_user = UserModel.objects.get_by_email('bob@bob.com')
  96. self.assertEqual(Online.objects.filter(user=test_user).count(), 1)
  97. response = self.client.get(reverse('misago:index'))
  98. self.assertContains(response, 'Bob')
  99. self.assertIn('Welcome', mail.outbox[0].subject)
  100. def test_registration_creates_inactive_user(self):
  101. """api creates inactive user on POST"""
  102. settings.override_setting('account_activation', 'user')
  103. response = self.client.post(self.api_link, data={
  104. 'username': 'Bob',
  105. 'email': 'bob@bob.com',
  106. 'password': 'pass123'
  107. })
  108. self.assertContains(response, 'user')
  109. self.assertContains(response, 'Bob')
  110. self.assertContains(response, 'bob@bob.com')
  111. UserModel.objects.get_by_username('Bob')
  112. UserModel.objects.get_by_email('bob@bob.com')
  113. self.assertIn('Welcome', mail.outbox[0].subject)
  114. def test_registration_creates_admin_activated_user(self):
  115. """api creates admin activated user on POST"""
  116. settings.override_setting('account_activation', 'admin')
  117. response = self.client.post(self.api_link, data={
  118. 'username': 'Bob',
  119. 'email': 'bob@bob.com',
  120. 'password': 'pass123'
  121. })
  122. self.assertContains(response, 'admin')
  123. self.assertContains(response, 'Bob')
  124. self.assertContains(response, 'bob@bob.com')
  125. UserModel.objects.get_by_username('Bob')
  126. UserModel.objects.get_by_email('bob@bob.com')
  127. self.assertIn('Welcome', mail.outbox[0].subject)