|
5 | 5 | import pytest
|
6 | 6 | from rest_framework.test import APIClient
|
7 | 7 |
|
8 |
| -from core import factories |
| 8 | +from core import factories, models |
9 | 9 |
|
10 | 10 | pytestmark = pytest.mark.django_db
|
11 | 11 |
|
@@ -34,9 +34,126 @@ def test_api_users_retrieve_me_authenticated():
|
34 | 34 | )
|
35 | 35 |
|
36 | 36 | assert response.status_code == 200
|
37 |
| - assert response.json() == { |
| 37 | + data = response.json() |
| 38 | + assert data == { |
38 | 39 | "id": str(user.id),
|
39 | 40 | "email": user.email,
|
40 | 41 | "full_name": user.full_name,
|
41 | 42 | "short_name": user.short_name,
|
| 43 | + "abilities": { |
| 44 | + "create_maildomains": False, |
| 45 | + "view_maildomains": False, |
| 46 | + }, |
42 | 47 | }
|
| 48 | + |
| 49 | + |
| 50 | +def test_api_users_retrieve_me_with_abilities_regular_user(): |
| 51 | + """Test abilities for regular user without mail domain access.""" |
| 52 | + user = factories.UserFactory() |
| 53 | + |
| 54 | + client = APIClient() |
| 55 | + client.force_login(user) |
| 56 | + |
| 57 | + response = client.get("/api/v1.0/users/me/") |
| 58 | + |
| 59 | + assert response.status_code == 200 |
| 60 | + data = response.json() |
| 61 | + abilities = data["abilities"] |
| 62 | + assert abilities["create_maildomains"] is False |
| 63 | + assert abilities["view_maildomains"] is False |
| 64 | + |
| 65 | + |
| 66 | +def test_api_users_retrieve_me_with_abilities_user_with_access(): |
| 67 | + """Test abilities for user with mail domain access.""" |
| 68 | + user = factories.UserFactory() |
| 69 | + maildomain = factories.MailDomainFactory() |
| 70 | + |
| 71 | + # Give user access to a mail domain |
| 72 | + models.MailDomainAccess.objects.create( |
| 73 | + maildomain=maildomain, |
| 74 | + user=user, |
| 75 | + role=models.MailDomainAccessRoleChoices.ADMIN, |
| 76 | + ) |
| 77 | + |
| 78 | + client = APIClient() |
| 79 | + client.force_login(user) |
| 80 | + |
| 81 | + response = client.get("/api/v1.0/users/me/") |
| 82 | + |
| 83 | + assert response.status_code == 200 |
| 84 | + data = response.json() |
| 85 | + abilities = data["abilities"] |
| 86 | + assert abilities["create_maildomains"] is False |
| 87 | + assert abilities["view_maildomains"] is True |
| 88 | + |
| 89 | + |
| 90 | +def test_api_users_retrieve_me_with_abilities_superuser_staff(): |
| 91 | + """Test abilities for superuser and staff user.""" |
| 92 | + user = factories.UserFactory(is_superuser=True, is_staff=True) |
| 93 | + |
| 94 | + client = APIClient() |
| 95 | + client.force_login(user) |
| 96 | + |
| 97 | + response = client.get("/api/v1.0/users/me/") |
| 98 | + |
| 99 | + assert response.status_code == 200 |
| 100 | + data = response.json() |
| 101 | + abilities = data["abilities"] |
| 102 | + assert abilities["create_maildomains"] is True |
| 103 | + assert abilities["view_maildomains"] is True |
| 104 | + |
| 105 | + |
| 106 | +def test_api_users_retrieve_me_with_abilities_superuser_not_staff(): |
| 107 | + """Test abilities for superuser without staff status.""" |
| 108 | + user = factories.UserFactory(is_superuser=True, is_staff=False) |
| 109 | + |
| 110 | + client = APIClient() |
| 111 | + client.force_login(user) |
| 112 | + |
| 113 | + response = client.get("/api/v1.0/users/me/") |
| 114 | + |
| 115 | + assert response.status_code == 200 |
| 116 | + data = response.json() |
| 117 | + abilities = data["abilities"] |
| 118 | + assert abilities["create_maildomains"] is False |
| 119 | + assert abilities["view_maildomains"] is False |
| 120 | + |
| 121 | + |
| 122 | +def test_api_users_retrieve_me_with_abilities_staff_not_superuser(): |
| 123 | + """Test abilities for staff user without superuser status.""" |
| 124 | + user = factories.UserFactory(is_superuser=False, is_staff=True) |
| 125 | + |
| 126 | + client = APIClient() |
| 127 | + client.force_login(user) |
| 128 | + |
| 129 | + response = client.get("/api/v1.0/users/me/") |
| 130 | + |
| 131 | + assert response.status_code == 200 |
| 132 | + data = response.json() |
| 133 | + abilities = data["abilities"] |
| 134 | + assert abilities["create_maildomains"] is False |
| 135 | + assert abilities["view_maildomains"] is False |
| 136 | + |
| 137 | + |
| 138 | +def test_api_users_retrieve_me_with_abilities_superuser_staff_with_access(): |
| 139 | + """Test abilities for superuser/staff with mail domain access.""" |
| 140 | + user = factories.UserFactory(is_superuser=True, is_staff=True) |
| 141 | + maildomain = factories.MailDomainFactory() |
| 142 | + |
| 143 | + # Give user access to a mail domain |
| 144 | + models.MailDomainAccess.objects.create( |
| 145 | + maildomain=maildomain, |
| 146 | + user=user, |
| 147 | + role=models.MailDomainAccessRoleChoices.ADMIN, |
| 148 | + ) |
| 149 | + |
| 150 | + client = APIClient() |
| 151 | + client.force_login(user) |
| 152 | + |
| 153 | + response = client.get("/api/v1.0/users/me/") |
| 154 | + |
| 155 | + assert response.status_code == 200 |
| 156 | + data = response.json() |
| 157 | + abilities = data["abilities"] |
| 158 | + assert abilities["create_maildomains"] is True |
| 159 | + assert abilities["view_maildomains"] is True |
0 commit comments