test_jobs_visibility.py 1.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142
  1. from conftest import login_static
  2. def test_action_records_user_and_scoped_jobs(app_client):
  3. csrf = login_static(app_client)
  4. app_client._pps._records = [{"date": "2026-07-14 09:00:00", "from": "s@x",
  5. "rcpts": ["r@y"], "subject": "m", "guid": "g1",
  6. "localguid": "6:6:1", "size": "10"}]
  7. r = app_client.post("/api/actions", json={
  8. "action": "delete", "folder": "Quarantine",
  9. "messages": [{"localguid": "6:6:1", "guid": "g1"}],
  10. }, headers={"X-CSRF-Token": csrf})
  11. assert r.status_code == 202
  12. # /api/jobs is scoped to the caller (admin sees all, but the job IS the caller's).
  13. jobs = app_client.get("/api/jobs").get_json()["jobs"]
  14. assert jobs and jobs[0]["user"] == "dev@example.invalid"
  15. def test_move_targetfolder_validated(app_client):
  16. csrf = login_static(app_client)
  17. r = app_client.post("/api/actions", json={
  18. "action": "move", "folder": "Quarantine", "targetfolder": "Nonexistent",
  19. "messages": [{"localguid": "6:6:1"}],
  20. }, headers={"X-CSRF-Token": csrf})
  21. assert r.status_code == 400
  22. assert b"unknown target folder" in r.data
  23. def test_non_admin_sees_only_own_jobs(app_client, monkeypatch):
  24. # Two jobs by different users; a non-admin caller sees only theirs.
  25. q = app_client._queue
  26. q.enqueue("delete", "Quarantine", [{"localguid": "a"}], {}, user="alice@x.com")
  27. q.enqueue("delete", "Quarantine", [{"localguid": "b"}], {}, user="bob@x.com")
  28. login_static(app_client)
  29. # Force the current user to be a non-admin "bob" for the visibility check.
  30. import auth
  31. monkeypatch.setattr(auth, "current_user",
  32. lambda: {"email": "bob@x.com", "role": "user", "name": "bob"})
  33. jobs = app_client.get("/api/jobs").get_json()["jobs"]
  34. assert {j["user"] for j in jobs} == {"bob@x.com"}