for readability, and adds unit test for expired token
This commit is contained in:
parent
65a8304794
commit
4bcaf9f32a
@ -224,7 +224,7 @@ def forgot_password(request):
|
|||||||
def verify_forgot_password(request):
|
def verify_forgot_password(request):
|
||||||
# get session variables, and specifically check for presence of token
|
# get session variables, and specifically check for presence of token
|
||||||
mysession = _process_for_token(request)
|
mysession = _process_for_token(request)
|
||||||
if not mysession['token_complete']:
|
if not mysession['has_userid_and_token']:
|
||||||
return render_404(request)
|
return render_404(request)
|
||||||
|
|
||||||
session_token = mysession['vars']['token']
|
session_token = mysession['vars']['token']
|
||||||
@ -275,6 +275,6 @@ def _process_for_token(request):
|
|||||||
session_vars = request.POST
|
session_vars = request.POST
|
||||||
|
|
||||||
mysession = {'vars': session_vars,
|
mysession = {'vars': session_vars,
|
||||||
'token_complete': session_vars.has_key('userid') and
|
'has_userid_and_token': session_vars.has_key('userid') and
|
||||||
session_vars.has_key('token')}
|
session_vars.has_key('token')}
|
||||||
return mysession
|
return mysession
|
||||||
|
@ -281,6 +281,16 @@ def test_register_views(test_app):
|
|||||||
new_user['_id']), status=400)
|
new_user['_id']), status=400)
|
||||||
assert response.status == '400 Bad Request'
|
assert response.status == '400 Bad Request'
|
||||||
|
|
||||||
|
## Try using an expired token to change password, shouldn't work
|
||||||
|
util.clear_test_template_context()
|
||||||
|
real_token_expiration = new_user['fp_token_expire']
|
||||||
|
new_user['fp_token_expire'] = datetime.datetime.now()
|
||||||
|
new_user.save()
|
||||||
|
response = test_app.get("%s?%s" % (path, get_params), status=400)
|
||||||
|
assert response.status == '400 Bad Request'
|
||||||
|
new_user['fp_token_expire'] = real_token_expiration
|
||||||
|
new_user.save()
|
||||||
|
|
||||||
## Verify step 1 of password-change works -- can see form to change password
|
## Verify step 1 of password-change works -- can see form to change password
|
||||||
util.clear_test_template_context()
|
util.clear_test_template_context()
|
||||||
response = test_app.get("%s?%s" % (path, get_params))
|
response = test_app.get("%s?%s" % (path, get_params))
|
||||||
|
Loading…
x
Reference in New Issue
Block a user