from conftest import login_static def test_action_records_user_and_scoped_jobs(app_client): csrf = login_static(app_client) app_client._pps._records = [{"date": "2026-07-14 09:00:00", "from": "s@x", "rcpts": ["r@y"], "subject": "m", "guid": "g1", "localguid": "6:6:1", "size": "10"}] r = app_client.post("/api/actions", json={ "action": "delete", "folder": "Quarantine", "messages": [{"localguid": "6:6:1", "guid": "g1"}], }, headers={"X-CSRF-Token": csrf}) assert r.status_code == 202 # /api/jobs is scoped to the caller (admin sees all, but the job IS the caller's). jobs = app_client.get("/api/jobs").get_json()["jobs"] assert jobs and jobs[0]["user"] == "dev@example.invalid" def test_move_targetfolder_validated(app_client): csrf = login_static(app_client) r = app_client.post("/api/actions", json={ "action": "move", "folder": "Quarantine", "targetfolder": "Nonexistent", "messages": [{"localguid": "6:6:1"}], }, headers={"X-CSRF-Token": csrf}) assert r.status_code == 400 assert b"unknown target folder" in r.data def test_non_admin_sees_only_own_jobs(app_client, monkeypatch): # Two jobs by different users; a non-admin caller sees only theirs. q = app_client._queue q.enqueue("delete", "Quarantine", [{"localguid": "a"}], {}, user="alice@x.com") q.enqueue("delete", "Quarantine", [{"localguid": "b"}], {}, user="bob@x.com") login_static(app_client) # Force the current user to be a non-admin "bob" for the visibility check. import auth monkeypatch.setattr(auth, "current_user", lambda: {"email": "bob@x.com", "role": "user", "name": "bob"}) jobs = app_client.get("/api/jobs").get_json()["jobs"] assert {j["user"] for j in jobs} == {"bob@x.com"}