mirror of
https://github.com/nottinghamtec/PyRIGS.git
synced 2026-10-05 03:55:37 +00:00
* Port to Django 5.2 * Pin pluggy to 1.2.0 Any newer and the mystery importlib metadata error appears. Weird! >_> * Update for premailer changed default * Update view logic for is_ajax being changed to a template context processor * Port a few more tests to pytest proper Having two distinct test flavours is giving me a headache * Version 1 dockerfile Makes a VERY big image, I suspect we can optimise this a lot... * Optimise dockerfile a little lot a bit * fix(users): change logout link to POST request * fix(tests): fix some syntax errors in test code still got lots of failed tests :( * fix: replace deprecated Django APIs * ci: update Dockerfile * ci: update Dockerfile * fix(dependencies+tests): update EoL/vulnerable dependencies and improve test stability * Upgrade Python from 3.10 to 3.12 * Update frontend dependencies, replace node-sass with sass * chore(logging): ignore dangling obj reference warning from pypdf * ci: update compose.yml for prod deployment - Add Nginx as a reverse proxy - Add cert-selfsign.sh for generating self-signed certificates - Add certbot-issue.sh for Let's Encrypt certificate issuance and renewal - Add cron-install.sh and cron-uninstall.sh for system cron management - Add .env.example as an environment variable template * style: reformat code * ci: add more sleep trying to pass tests * ci: ignore browser-based tests during ci testing * fix: create home for the new user during Dockerfile building * chore: remove heroku conf file * fix: RIGS not franken anymore * fix: restore is_ajax as a boolean and split out the context processor * test: remove Selenium interaction tests and their CI workarounds * fix: harden production settings (CSRF origins, env casts, ADMINS) and drop dead debug toolbar code * deploy: serve static files from nginx, pin PGDATA, and make cert scripts loud on failure * build: switch .dockerignore to an allowlist * build: drop unused dependencies, soft-pin the rest and target Python 3.14 * build: move image to Python 3.14 / Node 24 and force DEBUG off * ci: add dependabot config for uv, npm, docker and actions * build: narrow Sass deprecation silencing to @import and require Node 24 * build: provide placeholder env for collectstatic now that DEBUG is off in the image * deploy: add plain-HTTP nginx config for local development and use it in compose * deploy: remove self-signed cert script * build: make the image multi-arch with official node and python base images * ci: lint and test on PRs, build the image on PRs and push it to GHCR on master * docs: add local running and sample data instructions * fix: report a form error instead of crashing when big power has no Power MIC * fix: upgrade pypdf and urllib3 to patched releases * fix: apply non-breaking npm audit fixes * fix: strip whitespace in ALLOWED_HOSTS and drop misleading HSTS preload * deploy: add a pyrigs healthcheck and make nginx wait for it * build: pin the uv image version * fix: correct the check-in person picker condition and use BeautifulSoup's string argument * refactor: replace unique_together with UniqueConstraint * build: replace pycodestyle with ruff and fix what it found Removes unused imports and variables, and fixes a few real problems it surfaced: - EventCheckIn.active() referenced an undefined name and raised NameError; it now returns whether the check-in has no end time - RIGS.admin defined EventChecklistAdmin twice; the second is now PowerTestRecordAdmin - RIGS/tests/conftest.py used date/timedelta without importing them - the signal-registering imports in apps.py are kept with noqa pycodestyle config in setup.cfg is dropped. * style: format the codebase with ruff * style: normalise line endings, trailing whitespace and end-of-file newlines * ci: run ruff and file hygiene through prek, and document it --------- Co-authored-by: Hang <me@hangxu.me> Co-authored-by: Joe Banks <joe@jb3.dev>
168 lines
5.6 KiB
Python
168 lines
5.6 KiB
Python
import datetime
|
|
from datetime import date
|
|
|
|
import pytest
|
|
from django.conf import settings
|
|
from django.core import mail, signing
|
|
from django.http import HttpResponseBadRequest
|
|
from django.urls import reverse
|
|
|
|
from RIGS import models
|
|
from pytest_django.asserts import assertContains, assertNotContains, assertFormError
|
|
|
|
|
|
def setup_event():
|
|
venue = models.Venue.objects.create(name="Authorisation Test Venue")
|
|
client = models.Person.objects.create(name="Authorisation Test Person", email="authorisation@functional.test")
|
|
organisation = models.Organisation.objects.create(name="Authorisation Test Organisation", union_account=True)
|
|
return models.Event.objects.create(
|
|
name="Authorisation Test",
|
|
start_date=date.today(),
|
|
venue=venue,
|
|
person=client,
|
|
organisation=organisation,
|
|
)
|
|
|
|
|
|
def setup_mail(event, profile):
|
|
profile.email = "teccie@nottinghamtec.co.uk"
|
|
profile.save()
|
|
auth_data = {
|
|
"name": "Test ABC",
|
|
"po": "1234ABCZXY",
|
|
"account_code": "ABC TEST 12345",
|
|
"uni_id": 1234567890,
|
|
"tos": True,
|
|
}
|
|
hmac = signing.dumps({"pk": event.pk, "email": "authemail@function.test", "sent_by": profile.pk})
|
|
url = reverse("event_authorise", kwargs={"pk": event.pk, "hmac": hmac})
|
|
return auth_data, hmac, url
|
|
|
|
|
|
def test_create(admin_client):
|
|
url = reverse("event_create")
|
|
# end time before start access after start
|
|
response = admin_client.post(
|
|
url,
|
|
{
|
|
"start_date": datetime.date(2020, 1, 1),
|
|
"start_time": datetime.time(10, 00),
|
|
"end_time": datetime.time(9, 00),
|
|
"access_at": datetime.datetime(2020, 1, 5, 10),
|
|
},
|
|
)
|
|
assertFormError(
|
|
response.context["form"],
|
|
"end_time",
|
|
"Unless you've invented time travel, the event can't finish before it has started.",
|
|
)
|
|
assertFormError(
|
|
response.context["form"],
|
|
"access_at",
|
|
"Regardless of what some clients might think, access time cannot be after the event has started.",
|
|
)
|
|
|
|
|
|
def test_requires_valid_hmac(client, admin_user):
|
|
event = setup_event()
|
|
auth_data, hmac, url = setup_mail(event, admin_user)
|
|
bad_hmac = hmac[:-1]
|
|
url = reverse("event_authorise", kwargs={"pk": event.pk, "hmac": bad_hmac})
|
|
response = client.get(url)
|
|
assert isinstance(response, HttpResponseBadRequest)
|
|
# TODO: Add some form of sensible user facing error
|
|
# self.assertIn(response.content, "new URL") # check there is some level of sane instruction
|
|
# response = client.get(url)
|
|
# assertContains(response, event.organisation.name)
|
|
|
|
|
|
def test_validation(client, admin_user):
|
|
event = setup_event()
|
|
auth_data, hmac, url = setup_mail(event, admin_user)
|
|
response = client.get(url)
|
|
assertContains(response, "Terms of Hire")
|
|
assertContains(response, "Account code")
|
|
assertContains(response, "University ID")
|
|
|
|
response = client.post(url)
|
|
assertContains(response, "This field is required.", 5)
|
|
|
|
auth_data["amount"] = event.total + 1
|
|
|
|
response = client.post(url, auth_data)
|
|
assertContains(response, "The amount authorised must equal the total for the event")
|
|
assertNotContains(response, "This field is required.")
|
|
|
|
auth_data["amount"] = event.total
|
|
response = client.post(url, auth_data)
|
|
assertContains(response, "Your event has been authorised")
|
|
|
|
event.refresh_from_db()
|
|
assert event.authorised
|
|
assert str(event.authorisation.email) == "authemail@function.test"
|
|
|
|
|
|
def test_duplicate_warning(client, admin_user):
|
|
event = setup_event()
|
|
auth_data, hmac, url = setup_mail(event, admin_user)
|
|
auth = models.EventAuthorisation.objects.create(
|
|
event=event, name="Test ABC", email="dupe@functional.test", amount=event.total, sent_by=admin_user
|
|
)
|
|
response = client.get(url)
|
|
assertContains(response, "This event has already been authorised.")
|
|
|
|
auth.amount += 1
|
|
auth.save()
|
|
|
|
response = client.get(url)
|
|
assertContains(response, "amount has changed")
|
|
|
|
|
|
@pytest.mark.django_db
|
|
def test_email_sent(admin_client, admin_user, mailoutbox):
|
|
event = setup_event()
|
|
auth_data, hmac, url = setup_mail(event, admin_user)
|
|
|
|
data = auth_data
|
|
data["amount"] = event.total
|
|
response = admin_client.post(url, data)
|
|
assertContains(response, "Your event has been authorised.")
|
|
assert len(mailoutbox) == 2
|
|
assert mailoutbox[0].to == ["authemail@function.test"]
|
|
assert mailoutbox[1].to == [settings.AUTHORISATION_NOTIFICATION_ADDRESS]
|
|
|
|
|
|
def test_email_check(admin_client, admin_user):
|
|
event = setup_event()
|
|
url = reverse("event_authorise_request", kwargs={"pk": event.pk})
|
|
admin_user.email = "teccie@someotherdomain.com"
|
|
admin_user.save()
|
|
|
|
response = admin_client.post(url)
|
|
|
|
assertContains(response, "must have an @nottinghamtec.co.uk email address")
|
|
|
|
|
|
def test_request_send(admin_client, admin_user):
|
|
event = setup_event()
|
|
url = reverse("event_authorise_request", kwargs={"pk": event.pk})
|
|
admin_user.email = "teccie@nottinghamtec.co.uk"
|
|
admin_user.save()
|
|
response = admin_client.post(url)
|
|
assertContains(response, "This field is required.")
|
|
|
|
mail.outbox = []
|
|
|
|
response = admin_client.post(url, {"email": "client@functional.test"})
|
|
assert response.status_code == 302
|
|
assert len(mail.outbox) == 1
|
|
email = mail.outbox[0]
|
|
assert "client@functional.test" in email.to
|
|
assert "/event/%d/" % event.pk in email.body
|
|
|
|
# Check sent by details are populated
|
|
event.refresh_from_db()
|
|
assert event.auth_request_by == admin_user
|
|
assert event.auth_request_to == "client@functional.test"
|
|
assert event.auth_request_at is not None
|