| 123456789101112131415161718192021222324252627282930313233343536373839404142 |
- from conftest import login_static
- def test_action_records_user_and_scoped_jobs(app_client):
- csrf = login_static(app_client)
- app_client._pps._records = [{"date": "2026-07-14 09:00:00", "from": "s@x",
- "rcpts": ["r@y"], "subject": "m", "guid": "g1",
- "localguid": "6:6:1", "size": "10"}]
- r = app_client.post("/api/actions", json={
- "action": "delete", "folder": "Quarantine",
- "messages": [{"localguid": "6:6:1", "guid": "g1"}],
- }, headers={"X-CSRF-Token": csrf})
- assert r.status_code == 202
- # /api/jobs is scoped to the caller (admin sees all, but the job IS the caller's).
- jobs = app_client.get("/api/jobs").get_json()["jobs"]
- assert jobs and jobs[0]["user"] == "dev@example.invalid"
- def test_move_targetfolder_validated(app_client):
- csrf = login_static(app_client)
- r = app_client.post("/api/actions", json={
- "action": "move", "folder": "Quarantine", "targetfolder": "Nonexistent",
- "messages": [{"localguid": "6:6:1"}],
- }, headers={"X-CSRF-Token": csrf})
- assert r.status_code == 400
- assert b"unknown target folder" in r.data
- def test_non_admin_sees_only_own_jobs(app_client, monkeypatch):
- # Two jobs by different users; a non-admin caller sees only theirs.
- q = app_client._queue
- q.enqueue("delete", "Quarantine", [{"localguid": "a"}], {}, user="alice@x.com")
- q.enqueue("delete", "Quarantine", [{"localguid": "b"}], {}, user="bob@x.com")
- login_static(app_client)
- # Force the current user to be a non-admin "bob" for the visibility check.
- import auth
- monkeypatch.setattr(auth, "current_user",
- lambda: {"email": "bob@x.com", "role": "user", "name": "bob"})
- jobs = app_client.get("/api/jobs").get_json()["jobs"]
- assert {j["user"] for j in jobs} == {"bob@x.com"}
|