|
3 | 3 | from responses import matchers |
4 | 4 |
|
5 | 5 | from users.authBackend import CasRequestError, UlbCasBackend |
6 | | -from users.models import User |
| 6 | +from users.models import CasFailure, User |
7 | 7 |
|
8 | 8 | pytestmark = pytest.mark.django_db |
9 | 9 |
|
@@ -70,3 +70,122 @@ def test_server_error(fake_base_url): |
70 | 70 | UlbCasBackend().authenticate(None, ticket=ticket) |
71 | 71 |
|
72 | 72 | assert e.value.args[0].status_code == 500 |
| 73 | + |
| 74 | + |
| 75 | +CAS_XML_TEMPLATE = """\ |
| 76 | +<cas:serviceResponse xmlns:cas='http://www.yale.edu/tp/cas'> |
| 77 | + <cas:authenticationSuccess> |
| 78 | + <cas:user>{netid}</cas:user> |
| 79 | + <cas:attributes> |
| 80 | + <cas:mail>{email}</cas:mail> |
| 81 | + <cas:sn>{last_name}</cas:sn> |
| 82 | + <cas:givenName>{first_name}</cas:givenName> |
| 83 | + </cas:attributes> |
| 84 | + </cas:authenticationSuccess> |
| 85 | +</cas:serviceResponse>""" |
| 86 | + |
| 87 | +TICKET = "test-ticket" |
| 88 | +SERVICE_MATCHER = matchers.query_string_matcher( |
| 89 | + f"ticket={TICKET}&service=http%3A%2F%2Fexample.com%2Fauth-ulb" |
| 90 | +) |
| 91 | + |
| 92 | + |
| 93 | +def _mock_cas_response(netid, email, first_name="Test", last_name="User"): |
| 94 | + xml = CAS_XML_TEMPLATE.format( |
| 95 | + netid=netid, email=email, first_name=first_name, last_name=last_name |
| 96 | + ) |
| 97 | + responses.add( |
| 98 | + responses.GET, |
| 99 | + "https://auth.ulb.be/proxyValidate", |
| 100 | + body=xml, |
| 101 | + status=200, |
| 102 | + match=[SERVICE_MATCHER], |
| 103 | + ) |
| 104 | + |
| 105 | + |
| 106 | +@responses.activate |
| 107 | +def test_netid_match_updates_email(fake_base_url): |
| 108 | + """When netid matches an existing user, reuse it and update email.""" |
| 109 | + User.objects.create_user( |
| 110 | + netid="glagaff", email="gaston.lagaffe@ulb.ac.be", first_name="Gaston" |
| 111 | + ) |
| 112 | + |
| 113 | + _mock_cas_response("glagaff", "gaston.lagaffe@ulb.be") |
| 114 | + user = UlbCasBackend().authenticate(None, ticket=TICKET) |
| 115 | + |
| 116 | + assert user.netid == "glagaff" |
| 117 | + assert user.email == "gaston.lagaffe@ulb.be" |
| 118 | + assert User.objects.count() == 1 |
| 119 | + |
| 120 | + |
| 121 | +@responses.activate |
| 122 | +def test_email_fallback_updates_netid(fake_base_url): |
| 123 | + """When netid doesn't match but email does, reuse the user and update netid.""" |
| 124 | + User.objects.create_user( |
| 125 | + netid="fantasio", email="fantasio@ulb.be", first_name="Fantasio" |
| 126 | + ) |
| 127 | + |
| 128 | + _mock_cas_response("fant0001", "fantasio@ulb.be") |
| 129 | + user = UlbCasBackend().authenticate(None, ticket=TICKET) |
| 130 | + |
| 131 | + assert user.netid == "fant0001" |
| 132 | + assert user.email == "fantasio@ulb.be" |
| 133 | + assert User.objects.count() == 1 |
| 134 | + |
| 135 | + |
| 136 | +@responses.activate |
| 137 | +def test_no_match_creates_user(fake_base_url): |
| 138 | + """When neither netid nor email match, create a new user.""" |
| 139 | + _mock_cas_response("mleblanc", "modeste.leblanc@ulb.be", "Modeste", "Leblanc") |
| 140 | + user = UlbCasBackend().authenticate(None, ticket=TICKET) |
| 141 | + |
| 142 | + assert user.netid == "mleblanc" |
| 143 | + assert user.email == "modeste.leblanc@ulb.be" |
| 144 | + assert user.first_name == "Modeste" |
| 145 | + assert user.last_name == "Leblanc" |
| 146 | + assert User.objects.count() == 1 |
| 147 | + |
| 148 | + |
| 149 | +@responses.activate |
| 150 | +def test_fields_synced_on_login(fake_base_url): |
| 151 | + """All CAS fields are updated on every login.""" |
| 152 | + User.objects.create_user( |
| 153 | + netid="pdemousk", |
| 154 | + email="prunelle.de.mouskinson@ulb.ac.be", |
| 155 | + first_name="Leon", |
| 156 | + last_name="Prunelle", |
| 157 | + ) |
| 158 | + |
| 159 | + _mock_cas_response( |
| 160 | + "pdemousk", "prunelle.de.mouskinson@ulb.be", "Leon", "De Mouskinson" |
| 161 | + ) |
| 162 | + user = UlbCasBackend().authenticate(None, ticket=TICKET) |
| 163 | + |
| 164 | + assert user.email == "prunelle.de.mouskinson@ulb.be" |
| 165 | + assert user.first_name == "Leon" |
| 166 | + assert user.last_name == "De Mouskinson" |
| 167 | + |
| 168 | + |
| 169 | +@responses.activate |
| 170 | +def test_no_duplicate_when_netid_and_email_match_different_users(fake_base_url): |
| 171 | + """When netid matches user A and email matches user B, prefer user A (netid).""" |
| 172 | + User.objects.create_user( |
| 173 | + netid="glagaff", email="gaston.lagaffe@ulb.ac.be", first_name="Gaston" |
| 174 | + ) |
| 175 | + User.objects.create_user( |
| 176 | + netid="lechat", email="gaston.lagaffe@ulb.be", first_name="Le Chat" |
| 177 | + ) |
| 178 | + |
| 179 | + _mock_cas_response("glagaff", "gaston.lagaffe@ulb.be") |
| 180 | + user = UlbCasBackend().authenticate(None, ticket=TICKET) |
| 181 | + |
| 182 | + assert user.netid == "glagaff" |
| 183 | + # Email not updated because Le Chat already has it |
| 184 | + assert user.email == "gaston.lagaffe@ulb.ac.be" |
| 185 | + assert User.objects.count() == 2 |
| 186 | + |
| 187 | + # An EMAIL_CONFLICT failure should be logged |
| 188 | + failure = CasFailure.objects.get() |
| 189 | + assert failure.code == "EMAIL_CONFLICT" |
| 190 | + assert "glagaff" in failure.details |
| 191 | + assert "lechat" in failure.details |
0 commit comments