def login(): form = LoginForm(next=request.args.get('next')) if form.validate_on_submit(): u = User.find_by_identity(request.form.get('identity')) if u and u.authenticated(password=request.form.get('password')): # As you can see remember me is always enabled, this was a design # decision I made because more often than not users want this # enabled. This allows for a less complicated login form. # # If however you want them to be able to select whether or not they # should remain logged in then perform the following 3 steps: # 1) Replace 'True' below with: request.form.get('remember', False) # 2) Uncomment the 'remember' field in user/forms.py#LoginForm # 3) Add a checkbox to the login form with the id/name 'remember' if login_user(u, remember=True): u.update_activity_tracking(request.remote_addr) # Handle optionally redirecting to the next URL safely. next_url = request.form.get('next') if next_url: return redirect(safe_next_url(next_url)) return redirect(url_for('user.settings')) else: flash(_('This account has been disabled.'), 'error') else: flash(_('Identity or password is incorrect.'), 'error') return render_template('user/login.jinja2', form=form)
def test_deliver_password_reset_email(self, token): """ Deliver a password reset email. """ with mail.record_messages() as outbox: user = User.find_by_identity('*****@*****.**') deliver_password_reset_email(user.id, token) assert len(outbox) == 1 assert token in outbox[0].body
def test_is_last_admin_yes(self, users, token): """ Last admin should not be able to change himself. """ user = User.find_by_identity('*****@*****.**') assert User.is_last_admin(user, 'member', 'y') is True assert User.is_last_admin(user, 'admin', 'y') is False assert User.is_last_admin(user, 'admin', None) is True assert User.is_last_admin(user, 'member', None) is True
def token(db): """ Serialize a JWS token. :param db: Pytest fixture :return: JWS token """ user = User.find_by_identity('*****@*****.**') return user.serialize_token()
def test_login_activity(self, users): """ Login successfully and update the activity stats. """ user = User.find_by_identity('*****@*****.**') old_sign_in_count = user.sign_in_count response = self.login() new_sign_in_count = user.sign_in_count assert response.status_code == 200 assert (old_sign_in_count + 1) == new_sign_in_count
def test_password_reset(self, users, token): """ Reset successful. """ reset = {'password': '******', 'reset_token': token} response = self.client.post(url_for('user.password_reset'), data=reset, follow_redirects=True) assert_status_with_message(200, response, _('Your password has been reset.')) admin = User.find_by_identity('*****@*****.**') assert admin.password != 'newpassword'
def test_begin_update_credentials_email_change(self): """ Update credentials but only the e-mail address. """ self.login() user = { 'current_password': '******', 'email': '*****@*****.**' } response = self.client.post(url_for('user.update_credentials'), data=user, follow_redirects=True) assert_status_with_message(200, response, _('Your sign in settings have been ' 'updated.')) old_user = User.find_by_identity('*****@*****.**') assert old_user is None new_user = User.find_by_identity('*****@*****.**') assert new_user is not None
def ensure_identity_exists(form, field): """ Ensure an identity exists. :param form: wtforms Instance :param field: Field being passed in. :return: None """ user = User.find_by_identity(field.data) if not user: raise ValidationError(_('Unable to locate account.'))
def test_begin_update_credentials_email_change(self): """ Update credentials but only the e-mail address. """ self.login() user = { 'current_password': '******', 'email': '*****@*****.**' } response = self.client.post(url_for('user.update_credentials'), data=user, follow_redirects=True) assert_status_with_message( 200, response, _('Your sign in settings have been ' 'updated.')) old_user = User.find_by_identity('*****@*****.**') assert old_user is None new_user = User.find_by_identity('*****@*****.**') assert new_user is not None
def test_welcome_with_existing_username(self, users): """ Create username failure due to username already existing. """ self.login() u = User.find_by_identity('*****@*****.**') u.username = '******' u.save() user = {'username': '******'} response = self.client.post(url_for('user.welcome'), data=user, follow_redirects=True) assert_status_with_message(200, response, 'Already exists.')
def test_cancel_subscription(self, subscriptions, mock_stripe): """ User subscription gets cancelled.. """ user = User.find_by_identity('*****@*****.**') params = { 'id': user.id } self.login() response = self.client.post(url_for('admin.users_cancel_subscription'), data=params, follow_redirects=True) assert_status_with_message(200, response, _('Subscription has been cancelled for ' '%(user)s', user='******')) assert user.cancelled_subscription_on is not None
def test_welcome_with_existing_username(self, users): """ Create username failure due to username already existing. """ self.login() u = User.find_by_identity('*****@*****.**') u.username = '******' u.save() user = {'username': '******'} response = self.client.post(url_for('user.welcome'), data=user, follow_redirects=True) assert_status_with_message(200, response, _('You already picked a username.'))
def test_signup(self, users): """ Signup successfully. """ old_user_count = User.query.count() user = {'email': '*****@*****.**', 'password': '******'} response = self.client.post(url_for('user.signup'), data=user, follow_redirects=True) assert_status_with_message(200, response, _('Awesome, thanks for signing up!')) new_user_count = User.query.count() assert (old_user_count + 1) == new_user_count new_user = User.find_by_identity('*****@*****.**') assert new_user.password != 'password'
def test_is_last_admin_no(self, users, token): """ Not the last admin should be able to change himself. """ user = User.find_by_identity('*****@*****.**') params = { 'role': 'admin', 'email': '*****@*****.**', 'password': '******' } new_user = User(**params) new_user.save() assert User.is_last_admin(user, 'member', 'y') is False assert User.is_last_admin(user, 'admin', None) is False assert User.is_last_admin(user, 'member', None) is False
def create_admin(): """ Create an admin account. :return: User instance """ if User.find_by_identity(SEED_ADMIN_EMAIL) is not None: return None params = { 'role': 'admin', 'email': SEED_ADMIN_EMAIL, 'password': '******' } return User(**params).save()
def subscriptions(db): """ Create subscription fixtures. They reset per test. :param db: Pytest fixture :return: SQLAlchemy database session """ subscriber = User.find_by_identity('*****@*****.**') if subscriber: subscriber.delete() db.session.query(Subscription).delete() params = { 'role': 'admin', 'email': '*****@*****.**', 'name': 'Subby', 'password': '******', 'payment_id': 'cus_000' } admin = User(**params) # The account needs to be commit before we can assign a subscription to it. db.session.add(admin) db.session.commit() # Create a subscription. params = { 'user_id': admin.id, 'plan': 'gold' } subscription = Subscription(**params) db.session.add(subscription) # Create a credit card. params = { 'user_id': admin.id, 'brand': 'Visa', 'last4': '4242', 'exp_date': datetime.date(2015, 06, 01) } credit_card = CreditCard(**params) db.session.add(credit_card) db.session.commit() return db