36 lines
1.6 KiB
Python
36 lines
1.6 KiB
Python
# retoor <retoor@molodetz.nl>
|
|||
|
|
from tests.conftest import ADMIN_PASSWORD, ADMIN_USERNAME
|
||
|
|
|
||
|
|
|
||
|
|
def test_login_wrong_password(anon):
|
||
|
|
response = anon.post("/auth/login", data={"username": ADMIN_USERNAME, "password": "verkeerd-wachtwoord"})
|
||
|
|
assert response.status_code in (400, 401, 200)
|
||
|
|
assert "session" not in "".join(response.cookies.keys()).lower() or response.status_code != 302
|
||
|
|
|
||
|
|
|
||
|
|
def test_login_and_logout(anon):
|
||
|
|
response = anon.post("/auth/login", data={"username": ADMIN_USERNAME, "password": ADMIN_PASSWORD})
|
||
|
|
assert response.status_code in (302, 303)
|
||
|
|
assert anon.get("/admin").status_code == 200
|
||
|
|
cookie = response.headers.get("set-cookie", "").lower()
|
||
|
|
assert "httponly" in cookie and "samesite=lax" in cookie
|
||
|
|
assert anon.post("/auth/logout").status_code in (302, 303)
|
||
|
|
assert anon.get("/admin").status_code in (302, 303, 401)
|
||
|
|
|
||
|
|
|
||
|
|
def test_admin_redirects_anonymous(anon):
|
||
|
|
response = anon.get("/admin")
|
||
|
|
assert response.status_code in (302, 303)
|
||
|
|
assert "/auth/login" in response.headers["location"]
|
||
|
|
|
||
|
|
|
||
|
|
def test_api_key_header(admin, anon):
|
||
|
|
key = admin.get("/profile/api-key", headers={"Accept": "application/json"}).json()["api_key"]
|
||
|
|
assert anon.get("/admin", headers={"X-API-KEY": key, "Accept": "application/json"}).status_code == 200
|
||
|
|
assert anon.get("/admin", headers={"Authorization": f"Bearer {key}", "Accept": "application/json"}).status_code == 200
|
||
|
|
|
||
|
|
|
||
|
|
def test_no_jwt_anywhere(admin):
|
||
|
|
response = admin.get("/profile/api-key", headers={"Accept": "application/json"})
|
||
|
|
assert response.json()["api_key"].count(".") == 0
|