Files
PyRIGS/RIGS/tests/test_functional.py
AJ 08171767a0 Port to Django 5.2 (#635)
* Port to Django 5.2

* Pin pluggy to 1.2.0

Any newer and the mystery importlib metadata error appears. Weird! >_>

* Update for premailer changed default

* Update view logic for is_ajax being changed to a template context processor

* Port a few more tests to pytest proper

Having two distinct test flavours is giving me a headache

* Version 1 dockerfile

Makes a VERY big image, I suspect we can optimise this a lot...

* Optimise dockerfile a little lot a bit

* fix(users): change logout link to POST request

* fix(tests): fix some syntax errors in test code

still got lots of failed tests :(

* fix: replace deprecated Django APIs

* ci: update Dockerfile

* ci: update Dockerfile

* fix(dependencies+tests): update EoL/vulnerable dependencies and improve test stability

* Upgrade Python from 3.10 to 3.12
* Update frontend dependencies, replace node-sass with sass

* chore(logging): ignore dangling obj reference warning from pypdf

* ci: update compose.yml for prod deployment

- Add Nginx as a reverse proxy
- Add cert-selfsign.sh for generating self-signed certificates
- Add certbot-issue.sh for Let's Encrypt certificate issuance and renewal
- Add cron-install.sh and cron-uninstall.sh for system cron management
- Add .env.example as an environment variable template

* style: reformat code

* ci: add more sleep trying to pass tests

* ci: ignore browser-based tests during ci testing

* fix: create home for the new user during Dockerfile building

* chore: remove heroku conf file

* fix: RIGS not franken anymore

* fix: restore is_ajax as a boolean and split out the context processor

* test: remove Selenium interaction tests and their CI workarounds

* fix: harden production settings (CSRF origins, env casts, ADMINS) and drop dead debug toolbar code

* deploy: serve static files from nginx, pin PGDATA, and make cert scripts loud on failure

* build: switch .dockerignore to an allowlist

* build: drop unused dependencies, soft-pin the rest and target Python 3.14

* build: move image to Python 3.14 / Node 24 and force DEBUG off

* ci: add dependabot config for uv, npm, docker and actions

* build: narrow Sass deprecation silencing to @import and require Node 24

* build: provide placeholder env for collectstatic now that DEBUG is off in the image

* deploy: add plain-HTTP nginx config for local development and use it in compose

* deploy: remove self-signed cert script

* build: make the image multi-arch with official node and python base images

* ci: lint and test on PRs, build the image on PRs and push it to GHCR on master

* docs: add local running and sample data instructions

* fix: report a form error instead of crashing when big power has no Power MIC

* fix: upgrade pypdf and urllib3 to patched releases

* fix: apply non-breaking npm audit fixes

* fix: strip whitespace in ALLOWED_HOSTS and drop misleading HSTS preload

* deploy: add a pyrigs healthcheck and make nginx wait for it

* build: pin the uv image version

* fix: correct the check-in person picker condition and use BeautifulSoup's string argument

* refactor: replace unique_together with UniqueConstraint

* build: replace pycodestyle with ruff and fix what it found

Removes unused imports and variables, and fixes a few real problems it
surfaced:
- EventCheckIn.active() referenced an undefined name and raised NameError;
  it now returns whether the check-in has no end time
- RIGS.admin defined EventChecklistAdmin twice; the second is now
  PowerTestRecordAdmin
- RIGS/tests/conftest.py used date/timedelta without importing them
- the signal-registering imports in apps.py are kept with noqa

pycodestyle config in setup.cfg is dropped.

* style: format the codebase with ruff

* style: normalise line endings, trailing whitespace and end-of-file newlines

* ci: run ruff and file hygiene through prek, and document it

---------

Co-authored-by: Hang <me@hangxu.me>
Co-authored-by: Joe Banks <joe@jb3.dev>
2026-10-01 23:43:41 +01:00

168 lines
5.6 KiB
Python

import datetime
from datetime import date
import pytest
from django.conf import settings
from django.core import mail, signing
from django.http import HttpResponseBadRequest
from django.urls import reverse
from RIGS import models
from pytest_django.asserts import assertContains, assertNotContains, assertFormError
def setup_event():
venue = models.Venue.objects.create(name="Authorisation Test Venue")
client = models.Person.objects.create(name="Authorisation Test Person", email="authorisation@functional.test")
organisation = models.Organisation.objects.create(name="Authorisation Test Organisation", union_account=True)
return models.Event.objects.create(
name="Authorisation Test",
start_date=date.today(),
venue=venue,
person=client,
organisation=organisation,
)
def setup_mail(event, profile):
profile.email = "teccie@nottinghamtec.co.uk"
profile.save()
auth_data = {
"name": "Test ABC",
"po": "1234ABCZXY",
"account_code": "ABC TEST 12345",
"uni_id": 1234567890,
"tos": True,
}
hmac = signing.dumps({"pk": event.pk, "email": "authemail@function.test", "sent_by": profile.pk})
url = reverse("event_authorise", kwargs={"pk": event.pk, "hmac": hmac})
return auth_data, hmac, url
def test_create(admin_client):
url = reverse("event_create")
# end time before start access after start
response = admin_client.post(
url,
{
"start_date": datetime.date(2020, 1, 1),
"start_time": datetime.time(10, 00),
"end_time": datetime.time(9, 00),
"access_at": datetime.datetime(2020, 1, 5, 10),
},
)
assertFormError(
response.context["form"],
"end_time",
"Unless you've invented time travel, the event can't finish before it has started.",
)
assertFormError(
response.context["form"],
"access_at",
"Regardless of what some clients might think, access time cannot be after the event has started.",
)
def test_requires_valid_hmac(client, admin_user):
event = setup_event()
auth_data, hmac, url = setup_mail(event, admin_user)
bad_hmac = hmac[:-1]
url = reverse("event_authorise", kwargs={"pk": event.pk, "hmac": bad_hmac})
response = client.get(url)
assert isinstance(response, HttpResponseBadRequest)
# TODO: Add some form of sensible user facing error
# self.assertIn(response.content, "new URL") # check there is some level of sane instruction
# response = client.get(url)
# assertContains(response, event.organisation.name)
def test_validation(client, admin_user):
event = setup_event()
auth_data, hmac, url = setup_mail(event, admin_user)
response = client.get(url)
assertContains(response, "Terms of Hire")
assertContains(response, "Account code")
assertContains(response, "University ID")
response = client.post(url)
assertContains(response, "This field is required.", 5)
auth_data["amount"] = event.total + 1
response = client.post(url, auth_data)
assertContains(response, "The amount authorised must equal the total for the event")
assertNotContains(response, "This field is required.")
auth_data["amount"] = event.total
response = client.post(url, auth_data)
assertContains(response, "Your event has been authorised")
event.refresh_from_db()
assert event.authorised
assert str(event.authorisation.email) == "authemail@function.test"
def test_duplicate_warning(client, admin_user):
event = setup_event()
auth_data, hmac, url = setup_mail(event, admin_user)
auth = models.EventAuthorisation.objects.create(
event=event, name="Test ABC", email="dupe@functional.test", amount=event.total, sent_by=admin_user
)
response = client.get(url)
assertContains(response, "This event has already been authorised.")
auth.amount += 1
auth.save()
response = client.get(url)
assertContains(response, "amount has changed")
@pytest.mark.django_db
def test_email_sent(admin_client, admin_user, mailoutbox):
event = setup_event()
auth_data, hmac, url = setup_mail(event, admin_user)
data = auth_data
data["amount"] = event.total
response = admin_client.post(url, data)
assertContains(response, "Your event has been authorised.")
assert len(mailoutbox) == 2
assert mailoutbox[0].to == ["authemail@function.test"]
assert mailoutbox[1].to == [settings.AUTHORISATION_NOTIFICATION_ADDRESS]
def test_email_check(admin_client, admin_user):
event = setup_event()
url = reverse("event_authorise_request", kwargs={"pk": event.pk})
admin_user.email = "teccie@someotherdomain.com"
admin_user.save()
response = admin_client.post(url)
assertContains(response, "must have an @nottinghamtec.co.uk email address")
def test_request_send(admin_client, admin_user):
event = setup_event()
url = reverse("event_authorise_request", kwargs={"pk": event.pk})
admin_user.email = "teccie@nottinghamtec.co.uk"
admin_user.save()
response = admin_client.post(url)
assertContains(response, "This field is required.")
mail.outbox = []
response = admin_client.post(url, {"email": "client@functional.test"})
assert response.status_code == 302
assert len(mail.outbox) == 1
email = mail.outbox[0]
assert "client@functional.test" in email.to
assert "/event/%d/" % event.pk in email.body
# Check sent by details are populated
event.refresh_from_db()
assert event.auth_request_by == admin_user
assert event.auth_request_to == "client@functional.test"
assert event.auth_request_at is not None