2026-10-05 09:36:20 +02:00
|
|
|
# retoor <retoor@molodetz.nl>
|
|
|
|
|
JSON = {"Accept": "application/json"}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_join_request_is_stored_and_visible_to_admin(anon, admin):
|
2026-10-05 11:25:41 +02:00
|
|
|
response = anon.post("/join", data={"name": "Writer One", "contact": "schrijver@example.invalid", "repo_url": "https://example.com/repo", "message": "I want to write along.", "website": ""})
|
2026-10-05 09:36:20 +02:00
|
|
|
assert response.status_code in (302, 303)
|
|
|
|
|
assert "ok=1" in response.headers["location"]
|
|
|
|
|
rows = admin.get("/admin/joins", headers=JSON).json()["requests"]
|
2026-10-05 11:25:41 +02:00
|
|
|
row = next(row for row in rows if row["name"] == "Writer One")
|
2026-10-05 09:36:20 +02:00
|
|
|
assert row["contact"] == "schrijver@example.invalid"
|
|
|
|
|
assert row["repo_url"].startswith("https://example.com/repo")
|
|
|
|
|
status = admin.post(f"/admin/joins/{row['uid']}/status", json={"status": "contacted"}, headers=JSON)
|
|
|
|
|
assert status.status_code == 200
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_join_json_api(anon):
|
2026-10-05 11:25:41 +02:00
|
|
|
response = anon.post("/join", json={"name": "Writer Two", "contact": "@twee"}, headers=JSON)
|
2026-10-05 09:36:20 +02:00
|
|
|
assert response.status_code == 200
|
|
|
|
|
assert response.json()["ok"] is True
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_honeypot_is_not_stored(anon, admin):
|
2026-10-05 11:25:41 +02:00
|
|
|
anon.post("/join", data={"name": "Robot Bot", "contact": "bot@example.invalid", "website": "spam"})
|
2026-10-05 09:36:20 +02:00
|
|
|
rows = admin.get("/admin/joins", headers=JSON).json()["requests"]
|
|
|
|
|
assert not any(row["name"] == "Robot Bot" for row in rows)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_join_validation(anon):
|
2026-10-05 11:25:41 +02:00
|
|
|
response = anon.post("/join", json={"name": "x", "contact": ""}, headers=JSON)
|
2026-10-05 09:36:20 +02:00
|
|
|
assert response.status_code == 422
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_member_cannot_view_joins(member):
|
|
|
|
|
assert member.get("/admin/joins", headers=JSON).status_code == 403
|