- Invite flow: admin issue/revoke on join requests, public single-use claim links (hash-only tokens, 7-day expiry, no state reveal), claim creates the Member account and marks the request accepted - Gallery: admin status page plus resync endpoint; sync refreshes thumbnails whose content changed; tools/gallery contract and checker - Docs: public content page, admin-only operator runbook, api.md invite/gallery sections, all routes in the live API docs, docs reachability gate test - Screenshots cover the new pages; version 1.0.18
33 lines
1.2 KiB
Python
33 lines
1.2 KiB
Python
# retoor <retoor@molodetz.nl>
|
|
JSON = {"Accept": "application/json"}
|
|
|
|
|
|
def test_gallery_status_requires_admin(anon, member):
|
|
assert anon.get("/admin/gallery", headers=JSON).status_code == 401
|
|
assert member.get("/admin/gallery", headers=JSON).status_code == 403
|
|
assert anon.post("/admin/gallery/resync", headers=JSON).status_code == 401
|
|
assert member.post("/admin/gallery/resync", headers=JSON).status_code == 403
|
|
|
|
|
|
def test_gallery_status_reports_counts(admin):
|
|
response = admin.get("/admin/gallery", headers=JSON)
|
|
assert response.status_code == 200
|
|
body = response.json()
|
|
assert body["flyers"] >= 1
|
|
assert body["memes"] >= 1
|
|
assert body["missing"] == []
|
|
page = admin.get("/admin/gallery")
|
|
assert page.status_code == 200
|
|
assert "Resync gallery" in page.text
|
|
|
|
|
|
def test_gallery_resync_reconciles(admin):
|
|
response = admin.post("/admin/gallery/resync", headers=JSON)
|
|
assert response.status_code == 200
|
|
data = response.json()["data"]
|
|
assert data["synced"] == data["flyers"] + data["memes"]
|
|
assert data["missing"] == []
|
|
form = admin.post("/admin/gallery/resync")
|
|
assert form.status_code in (302, 303)
|
|
assert form.headers["location"] == "/admin/gallery"
|