test_users.py 20 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716
  1. import pytest
  2. from django.contrib.auth import get_user_model
  3. from django.urls import reverse
  4. from ....acl.models import Role
  5. from ....legal.models import Agreement
  6. from ....legal.utils import save_user_agreement_acceptance
  7. from ....test import assert_contains
  8. from ...models import Rank
  9. from ...utils import hash_email
  10. User = get_user_model()
  11. def test_link_is_registered_in_admin_nav(admin_client):
  12. response = admin_client.get(reverse("misago:admin:index"))
  13. assert_contains(response, reverse("misago:admin:users:accounts:index"))
  14. def test_list_renders_with_item(admin_client, users_admin_link, superuser):
  15. response = admin_client.get(users_admin_link)
  16. assert_contains(response, superuser.username)
  17. def test_new_user_form_renders(admin_client):
  18. response = admin_client.get(reverse("misago:admin:users:accounts:new"))
  19. assert response.status_code == 200
  20. def test_new_user_can_be_created(admin_client):
  21. default_rank = Rank.objects.get_default()
  22. authenticated_role = Role.objects.get(special_role="authenticated")
  23. admin_client.post(
  24. reverse("misago:admin:users:accounts:new"),
  25. data={
  26. "username": "User",
  27. "rank": str(default_rank.pk),
  28. "roles": str(authenticated_role.pk),
  29. "email": "user@example.com",
  30. "new_password": "pass123",
  31. "staff_level": "0",
  32. },
  33. )
  34. user = User.objects.get_by_email("user@example.com")
  35. assert user.username == "User"
  36. assert user.rank == default_rank
  37. assert authenticated_role in user.roles.all()
  38. assert user.check_password("pass123")
  39. assert not user.is_staff
  40. assert not user.is_superuser
  41. def test_new_user_can_be_created_with_whitespace_around_password(admin_client):
  42. default_rank = Rank.objects.get_default()
  43. authenticated_role = Role.objects.get(special_role="authenticated")
  44. admin_client.post(
  45. reverse("misago:admin:users:accounts:new"),
  46. data={
  47. "username": "User",
  48. "rank": str(default_rank.pk),
  49. "roles": str(authenticated_role.pk),
  50. "email": "user@example.com",
  51. "new_password": " pass123 ",
  52. "staff_level": "0",
  53. },
  54. )
  55. user = User.objects.get_by_email("user@example.com")
  56. assert user.check_password(" pass123 ")
  57. def test_new_user_creation_fails_because_user_was_not_given_authenticated_role(
  58. admin_client
  59. ):
  60. default_rank = Rank.objects.get_default()
  61. guest_role = Role.objects.get(special_role="anonymous")
  62. admin_client.post(
  63. reverse("misago:admin:users:accounts:new"),
  64. data={
  65. "username": "User",
  66. "rank": str(default_rank.pk),
  67. "roles": str(guest_role.pk),
  68. "email": "user@example.com",
  69. "new_password": "pass123",
  70. "staff_level": "0",
  71. },
  72. )
  73. with pytest.raises(User.DoesNotExist):
  74. User.objects.get_by_email("user@example.com")
  75. def test_edit_user_form_renders(admin_client, user):
  76. response = admin_client.get(
  77. reverse("misago:admin:users:accounts:edit", kwargs={"pk": user.pk})
  78. )
  79. assert response.status_code == 200
  80. def test_edit_user_form_renders_for_staff_user(staff_client, user):
  81. response = staff_client.get(
  82. reverse("misago:admin:users:accounts:edit", kwargs={"pk": user.pk})
  83. )
  84. assert response.status_code == 200
  85. def test_edit_staff_form_renders_for_staff_user(staff_client, other_staffuser):
  86. response = staff_client.get(
  87. reverse("misago:admin:users:accounts:edit", kwargs={"pk": other_staffuser.pk})
  88. )
  89. assert response.status_code == 200
  90. def test_edit_superuser_form_renders_for_staff_user(staff_client, superuser):
  91. response = staff_client.get(
  92. reverse("misago:admin:users:accounts:edit", kwargs={"pk": superuser.pk})
  93. )
  94. assert response.status_code == 200
  95. def get_default_edit_form_data(user):
  96. default_rank = Rank.objects.get_default()
  97. authenticated_role = Role.objects.get(special_role="authenticated")
  98. data = {
  99. "username": user.username,
  100. "rank": str(user.rank_id),
  101. "roles": str(user.roles.all()[0].id),
  102. "email": user.email,
  103. "new_password": "",
  104. "signature": user.signature,
  105. "is_signature_locked": str(user.is_signature_locked),
  106. "is_hiding_presence": str(user.is_hiding_presence),
  107. "limits_private_thread_invites_to": str(user.limits_private_thread_invites_to),
  108. "signature_lock_staff_message": str(user.signature_lock_staff_message or ""),
  109. "signature_lock_user_message": str(user.signature_lock_user_message or ""),
  110. "subscribe_to_started_threads": str(user.subscribe_to_started_threads),
  111. "subscribe_to_replied_threads": str(user.subscribe_to_replied_threads),
  112. "is_active": "1",
  113. }
  114. if user.is_staff:
  115. data["is_staff"] = "1"
  116. if user.is_superuser:
  117. data["is_superuser"] = "1"
  118. return data
  119. def test_edit_form_changes_user_username(admin_client, user):
  120. form_data = get_default_edit_form_data(user)
  121. form_data["username"] = "NewUsername"
  122. admin_client.post(
  123. reverse("misago:admin:users:accounts:edit", kwargs={"pk": user.pk}),
  124. data=form_data,
  125. )
  126. user.refresh_from_db()
  127. assert user.username == "NewUsername"
  128. assert user.slug == "newusername"
  129. def test_editing_user_username_creates_entry_in_username_history(admin_client, user):
  130. form_data = get_default_edit_form_data(user)
  131. form_data["username"] = "NewUsername"
  132. admin_client.post(
  133. reverse("misago:admin:users:accounts:edit", kwargs={"pk": user.pk}),
  134. data=form_data,
  135. )
  136. assert user.namechanges.exists()
  137. def test_not_editing_user_username_doesnt_create_entry_in_username_history(
  138. admin_client, user
  139. ):
  140. form_data = get_default_edit_form_data(user)
  141. admin_client.post(
  142. reverse("misago:admin:users:accounts:edit", kwargs={"pk": user.pk}),
  143. data=form_data,
  144. )
  145. assert not user.namechanges.exists()
  146. def test_edit_form_changes_user_email(admin_client, user):
  147. form_data = get_default_edit_form_data(user)
  148. form_data["email"] = "edited@example.com"
  149. admin_client.post(
  150. reverse("misago:admin:users:accounts:edit", kwargs={"pk": user.pk}),
  151. data=form_data,
  152. )
  153. user.refresh_from_db()
  154. assert user.email == "edited@example.com"
  155. assert user.email_hash == hash_email("edited@example.com")
  156. def test_edit_form_doesnt_remove_current_user_password_if_new_password_is_omitted(
  157. admin_client, user, user_password
  158. ):
  159. form_data = get_default_edit_form_data(user)
  160. admin_client.post(
  161. reverse("misago:admin:users:accounts:edit", kwargs={"pk": user.pk}),
  162. data=form_data,
  163. )
  164. user.refresh_from_db()
  165. assert user.check_password(user_password)
  166. def test_edit_form_displays_message_for_user_with_unusable_password(
  167. admin_client, user, user_password
  168. ):
  169. user.set_password(None)
  170. user.save()
  171. response = admin_client.get(
  172. reverse("misago:admin:users:accounts:edit", kwargs={"pk": user.pk})
  173. )
  174. assert_contains(response, "alert-has-unusable-password")
  175. def test_edit_form_doesnt_set_password_for_user_with_unusable_password_if_none_is_given(
  176. admin_client, user, user_password
  177. ):
  178. user.set_password(None)
  179. user.save()
  180. form_data = get_default_edit_form_data(user)
  181. admin_client.post(
  182. reverse("misago:admin:users:accounts:edit", kwargs={"pk": user.pk}),
  183. data=form_data,
  184. )
  185. user.refresh_from_db()
  186. assert not user.has_usable_password()
  187. def test_edit_form_sets_password_for_user_with_unusable_password(
  188. admin_client, user, user_password
  189. ):
  190. user.set_password(None)
  191. user.save()
  192. form_data = get_default_edit_form_data(user)
  193. form_data["new_password"] = user_password
  194. admin_client.post(
  195. reverse("misago:admin:users:accounts:edit", kwargs={"pk": user.pk}),
  196. data=form_data,
  197. )
  198. user.refresh_from_db()
  199. assert user.check_password(user_password)
  200. def test_edit_form_changes_user_password(admin_client, user):
  201. form_data = get_default_edit_form_data(user)
  202. form_data["new_password"] = "newpassword123"
  203. admin_client.post(
  204. reverse("misago:admin:users:accounts:edit", kwargs={"pk": user.pk}),
  205. data=form_data,
  206. )
  207. user.refresh_from_db()
  208. assert user.check_password("newpassword123")
  209. def test_edit_form_preserves_whitespace_in_new_user_password(admin_client, user):
  210. form_data = get_default_edit_form_data(user)
  211. form_data["new_password"] = " newpassword123 "
  212. admin_client.post(
  213. reverse("misago:admin:users:accounts:edit", kwargs={"pk": user.pk}),
  214. data=form_data,
  215. )
  216. user.refresh_from_db()
  217. assert user.check_password(" newpassword123 ")
  218. def test_admin_editing_their_own_password_is_not_logged_out(admin_client, superuser):
  219. form_data = get_default_edit_form_data(superuser)
  220. form_data["new_password"] = "newpassword123"
  221. admin_client.post(
  222. reverse("misago:admin:users:accounts:edit", kwargs={"pk": superuser.pk}),
  223. data=form_data,
  224. )
  225. user = admin_client.get("/api/auth/")
  226. assert user.json()["id"] == superuser.id
  227. def test_staff_user_cannot_degrade_superuser_to_staff_user(staff_client, superuser):
  228. form_data = get_default_edit_form_data(superuser)
  229. form_data["is_staff"] = "1"
  230. form_data.pop("is_superuser")
  231. staff_client.post(
  232. reverse("misago:admin:users:accounts:edit", kwargs={"pk": superuser.pk}),
  233. data=form_data,
  234. )
  235. superuser.refresh_from_db()
  236. assert superuser.is_staff
  237. assert superuser.is_superuser
  238. def test_staff_user_cannot_degrade_superuser_to_regular_user(staff_client, superuser):
  239. form_data = get_default_edit_form_data(superuser)
  240. form_data.pop("is_staff")
  241. form_data.pop("is_superuser")
  242. staff_client.post(
  243. reverse("misago:admin:users:accounts:edit", kwargs={"pk": superuser.pk}),
  244. data=form_data,
  245. )
  246. superuser.refresh_from_db()
  247. assert superuser.is_staff
  248. assert superuser.is_superuser
  249. def test_staff_user_cannot_promote_other_staff_user_to_superuser(
  250. staff_client, other_staffuser
  251. ):
  252. form_data = get_default_edit_form_data(other_staffuser)
  253. form_data["is_staff"] = "1"
  254. form_data["is_superuser"] = "1"
  255. staff_client.post(
  256. reverse("misago:admin:users:accounts:edit", kwargs={"pk": other_staffuser.pk}),
  257. data=form_data,
  258. )
  259. other_staffuser.refresh_from_db()
  260. assert other_staffuser.is_staff
  261. assert not other_staffuser.is_superuser
  262. def test_staff_user_cannot_promote_regular_user_to_staff(staff_client, user):
  263. form_data = get_default_edit_form_data(user)
  264. form_data["is_staff"] = "1"
  265. staff_client.post(
  266. reverse("misago:admin:users:accounts:edit", kwargs={"pk": user.pk}),
  267. data=form_data,
  268. )
  269. user.refresh_from_db()
  270. assert not user.is_staff
  271. def test_staff_user_cannot_promote_regular_user_to_superuser(staff_client, user):
  272. form_data = get_default_edit_form_data(user)
  273. form_data["is_superuser"] = "1"
  274. staff_client.post(
  275. reverse("misago:admin:users:accounts:edit", kwargs={"pk": user.pk}),
  276. data=form_data,
  277. )
  278. user.refresh_from_db()
  279. assert not user.is_superuser
  280. def test_staff_user_cannot_promote_themselves_to_superuser(staff_client, staffuser):
  281. form_data = get_default_edit_form_data(staffuser)
  282. form_data["is_superuser"] = "1"
  283. staff_client.post(
  284. reverse("misago:admin:users:accounts:edit", kwargs={"pk": staffuser.pk}),
  285. data=form_data,
  286. )
  287. staffuser.refresh_from_db()
  288. assert not staffuser.is_superuser
  289. def test_staff_user_cannot_degrade_themselves_to_regular_user(staff_client, staffuser):
  290. form_data = get_default_edit_form_data(staffuser)
  291. form_data.pop("is_staff")
  292. staff_client.post(
  293. reverse("misago:admin:users:accounts:edit", kwargs={"pk": staffuser.pk}),
  294. data=form_data,
  295. )
  296. staffuser.refresh_from_db()
  297. assert staffuser.is_staff
  298. def test_superuser_cannot_degrade_themselves_to_staff_user(admin_client, superuser):
  299. form_data = get_default_edit_form_data(superuser)
  300. form_data.pop("is_superuser")
  301. admin_client.post(
  302. reverse("misago:admin:users:accounts:edit", kwargs={"pk": superuser.pk}),
  303. data=form_data,
  304. )
  305. superuser.refresh_from_db()
  306. assert superuser.is_superuser
  307. def test_superuser_cannot_degrade_themselves_to_regular_user(admin_client, superuser):
  308. form_data = get_default_edit_form_data(superuser)
  309. form_data.pop("is_staff")
  310. form_data.pop("is_superuser")
  311. admin_client.post(
  312. reverse("misago:admin:users:accounts:edit", kwargs={"pk": superuser.pk}),
  313. data=form_data,
  314. )
  315. superuser.refresh_from_db()
  316. assert superuser.is_staff
  317. assert superuser.is_superuser
  318. def test_superuser_can_degrade_other_superuser_to_staff_user(
  319. admin_client, other_superuser
  320. ):
  321. form_data = get_default_edit_form_data(other_superuser)
  322. form_data.pop("is_superuser")
  323. admin_client.post(
  324. reverse("misago:admin:users:accounts:edit", kwargs={"pk": other_superuser.pk}),
  325. data=form_data,
  326. )
  327. other_superuser.refresh_from_db()
  328. assert other_superuser.is_staff
  329. assert not other_superuser.is_superuser
  330. def test_superuser_can_degrade_other_superuser_to_regular_user(
  331. admin_client, other_superuser
  332. ):
  333. form_data = get_default_edit_form_data(other_superuser)
  334. form_data.pop("is_staff")
  335. form_data.pop("is_superuser")
  336. admin_client.post(
  337. reverse("misago:admin:users:accounts:edit", kwargs={"pk": other_superuser.pk}),
  338. data=form_data,
  339. )
  340. other_superuser.refresh_from_db()
  341. assert not other_superuser.is_staff
  342. assert not other_superuser.is_superuser
  343. def test_superuser_can_promote_to_staff_user_to_superuser(admin_client, staffuser):
  344. form_data = get_default_edit_form_data(staffuser)
  345. form_data["is_superuser"] = "1"
  346. admin_client.post(
  347. reverse("misago:admin:users:accounts:edit", kwargs={"pk": staffuser.pk}),
  348. data=form_data,
  349. )
  350. staffuser.refresh_from_db()
  351. assert staffuser.is_staff
  352. assert staffuser.is_superuser
  353. def test_superuser_can_promote_to_regular_user_to_staff_user(admin_client, user):
  354. form_data = get_default_edit_form_data(user)
  355. form_data["is_staff"] = "1"
  356. admin_client.post(
  357. reverse("misago:admin:users:accounts:edit", kwargs={"pk": user.pk}),
  358. data=form_data,
  359. )
  360. user.refresh_from_db()
  361. assert user.is_staff
  362. assert not user.is_superuser
  363. def test_superuser_can_promote_to_regular_user_to_superuser(admin_client, user):
  364. form_data = get_default_edit_form_data(user)
  365. form_data["is_staff"] = "1"
  366. form_data["is_superuser"] = "1"
  367. admin_client.post(
  368. reverse("misago:admin:users:accounts:edit", kwargs={"pk": user.pk}),
  369. data=form_data,
  370. )
  371. user.refresh_from_db()
  372. assert user.is_staff
  373. assert user.is_superuser
  374. def test_superuser_can_disable_other_superuser_account(admin_client, other_superuser):
  375. form_data = get_default_edit_form_data(other_superuser)
  376. form_data["is_active"] = "0"
  377. form_data["is_active_staff_message"] = "Test message"
  378. admin_client.post(
  379. reverse("misago:admin:users:accounts:edit", kwargs={"pk": other_superuser.pk}),
  380. data=form_data,
  381. )
  382. other_superuser.refresh_from_db()
  383. assert not other_superuser.is_active
  384. assert other_superuser.is_active_staff_message == "Test message"
  385. def test_superuser_can_reactivate_other_superuser_account(
  386. admin_client, other_superuser
  387. ):
  388. other_superuser.is_active = False
  389. other_superuser.save()
  390. form_data = get_default_edit_form_data(other_superuser)
  391. form_data["is_active"] = "1"
  392. admin_client.post(
  393. reverse("misago:admin:users:accounts:edit", kwargs={"pk": other_superuser.pk}),
  394. data=form_data,
  395. )
  396. other_superuser.refresh_from_db()
  397. assert other_superuser.is_active
  398. def test_superuser_can_disable_staff_user_account(admin_client, staffuser):
  399. form_data = get_default_edit_form_data(staffuser)
  400. form_data["is_active"] = "0"
  401. form_data["is_active_staff_message"] = "Test message"
  402. admin_client.post(
  403. reverse("misago:admin:users:accounts:edit", kwargs={"pk": staffuser.pk}),
  404. data=form_data,
  405. )
  406. staffuser.refresh_from_db()
  407. assert not staffuser.is_active
  408. assert staffuser.is_active_staff_message == "Test message"
  409. def test_superuser_can_reactivate_staff_user_account(admin_client, staffuser):
  410. staffuser.is_active = False
  411. staffuser.save()
  412. form_data = get_default_edit_form_data(staffuser)
  413. form_data["is_active"] = "1"
  414. admin_client.post(
  415. reverse("misago:admin:users:accounts:edit", kwargs={"pk": staffuser.pk}),
  416. data=form_data,
  417. )
  418. staffuser.refresh_from_db()
  419. assert staffuser.is_active
  420. def test_superuser_can_disable_regular_user_account(admin_client, user):
  421. form_data = get_default_edit_form_data(user)
  422. form_data["is_active"] = "0"
  423. form_data["is_active_staff_message"] = "Test message"
  424. admin_client.post(
  425. reverse("misago:admin:users:accounts:edit", kwargs={"pk": user.pk}),
  426. data=form_data,
  427. )
  428. user.refresh_from_db()
  429. assert not user.is_active
  430. assert user.is_active_staff_message == "Test message"
  431. def test_superuser_can_reactivate_regular_user_account(admin_client, user):
  432. user.is_active = False
  433. user.save()
  434. form_data = get_default_edit_form_data(user)
  435. form_data["is_active"] = "1"
  436. admin_client.post(
  437. reverse("misago:admin:users:accounts:edit", kwargs={"pk": user.pk}),
  438. data=form_data,
  439. )
  440. user.refresh_from_db()
  441. assert user.is_active
  442. def test_staff_user_can_disable_regular_user_account(staff_client, user):
  443. form_data = get_default_edit_form_data(user)
  444. form_data["is_active"] = "0"
  445. staff_client.post(
  446. reverse("misago:admin:users:accounts:edit", kwargs={"pk": user.pk}),
  447. data=form_data,
  448. )
  449. user.refresh_from_db()
  450. assert not user.is_active
  451. def test_staff_user_can_reactivate_regular_user_account(staff_client, user):
  452. user.is_active = False
  453. user.save()
  454. form_data = get_default_edit_form_data(user)
  455. form_data["is_active"] = "1"
  456. staff_client.post(
  457. reverse("misago:admin:users:accounts:edit", kwargs={"pk": user.pk}),
  458. data=form_data,
  459. )
  460. user.refresh_from_db()
  461. assert user.is_active
  462. def test_superuser_cant_disable_their_own_account(admin_client, superuser):
  463. form_data = get_default_edit_form_data(superuser)
  464. form_data["is_active"] = "0"
  465. admin_client.post(
  466. reverse("misago:admin:users:accounts:edit", kwargs={"pk": superuser.pk}),
  467. data=form_data,
  468. )
  469. superuser.refresh_from_db()
  470. assert superuser.is_active
  471. def test_staff_user_cant_disable_their_own_account(staff_client, staffuser):
  472. form_data = get_default_edit_form_data(staffuser)
  473. form_data["is_active"] = "0"
  474. staff_client.post(
  475. reverse("misago:admin:users:accounts:edit", kwargs={"pk": staffuser.pk}),
  476. data=form_data,
  477. )
  478. staffuser.refresh_from_db()
  479. assert staffuser.is_active
  480. def test_staff_user_cant_disable_superuser_account(staff_client, superuser):
  481. form_data = get_default_edit_form_data(superuser)
  482. form_data["is_active"] = "0"
  483. staff_client.post(
  484. reverse("misago:admin:users:accounts:edit", kwargs={"pk": superuser.pk}),
  485. data=form_data,
  486. )
  487. superuser.refresh_from_db()
  488. assert superuser.is_active
  489. def test_staff_user_cant_disable_other_staff_user_account(
  490. staff_client, other_staffuser
  491. ):
  492. form_data = get_default_edit_form_data(other_staffuser)
  493. form_data["is_active"] = "0"
  494. staff_client.post(
  495. reverse("misago:admin:users:accounts:edit", kwargs={"pk": other_staffuser.pk}),
  496. data=form_data,
  497. )
  498. other_staffuser.refresh_from_db()
  499. assert other_staffuser.is_active
  500. def test_user_deleting_their_account_cant_be_reactivated(admin_client, user):
  501. user.mark_for_delete()
  502. form_data = get_default_edit_form_data(user)
  503. form_data["is_active"] = "1"
  504. admin_client.post(
  505. reverse("misago:admin:users:accounts:edit", kwargs={"pk": user.pk}),
  506. data=form_data,
  507. )
  508. user.refresh_from_db()
  509. assert not user.is_active
  510. def test_user_agreements_are_displayed_on_edit_form(admin_client, user):
  511. agreement = Agreement.objects.create(
  512. type=Agreement.TYPE_TOS,
  513. title="Test agreement!",
  514. text="Lorem ipsum!",
  515. is_active=True,
  516. )
  517. save_user_agreement_acceptance(user, agreement, commit=True)
  518. response = admin_client.get(
  519. reverse("misago:admin:users:accounts:edit", kwargs={"pk": user.pk})
  520. )
  521. assert_contains(response, agreement.title)