Compare commits

..

No commits in common. "67953ac42e5c78751a398dea932978cdfe9b4f69" and "daed360fb6f8f9b2282c73d7ba1c72fbd745676f" have entirely different histories.

6 changed files with 6 additions and 12 deletions

View file

@ -8,7 +8,6 @@ def create_app(test_config=None):
app.config.from_mapping( app.config.from_mapping(
SECRET_KEY='dev', SECRET_KEY='dev',
DATABASE=os.path.join(app.instance_path, 'flaskr.sqlite'), DATABASE=os.path.join(app.instance_path, 'flaskr.sqlite'),
ALLOW_REGISTER=False,
) )
app.wsgi_app = ProxyFix( app.wsgi_app = ProxyFix(

View file

@ -1,7 +1,7 @@
import functools import functools
from flask import ( from flask import (
Blueprint, flash, g, redirect, render_template, request, session, url_for, current_app Blueprint, flash, g, redirect, render_template, request, session, url_for
) )
from werkzeug.security import check_password_hash, generate_password_hash from werkzeug.security import check_password_hash, generate_password_hash
@ -11,8 +11,7 @@ bp = Blueprint('auth', __name__, url_prefix='/auth')
@bp.route('/register', methods=('GET', 'POST')) @bp.route('/register', methods=('GET', 'POST'))
def register(): def register():
if not current_app.config["ALLOW_REGISTER"]: return "Admin only", 403
return "Admin only", 403
if request.method == 'POST': if request.method == 'POST':
username = request.form['username'] username = request.form['username']
password = request.form['password'] password = request.form['password']

View file

@ -9,6 +9,7 @@
<li><span>{{ g.user['username'] }}</span> <li><span>{{ g.user['username'] }}</span>
<li><a href="{{ url_for('auth.logout') }}">Log Out</a> <li><a href="{{ url_for('auth.logout') }}">Log Out</a>
{% else %} {% else %}
<li><a href="{{ url_for('auth.register') }}">Register</a>
<li><a href="{{ url_for('auth.login') }}">Log In</a> <li><a href="{{ url_for('auth.login') }}">Log In</a>
{% endif %} {% endif %}
</ul> </ul>

View file

@ -15,7 +15,6 @@ def app():
app = create_app({ app = create_app({
'TESTING': True, 'TESTING': True,
'DATABASE': db_path, 'DATABASE': db_path,
'ALLOW_REGISTER': True,
}) })
with app.app_context(): with app.app_context():

View file

@ -14,10 +14,6 @@ def test_register(client, app):
"SELECT * FROM user WHERE USERNAME = 'a'", "SELECT * FROM user WHERE USERNAME = 'a'",
).fetchone() is not None ).fetchone() is not None
app.config["ALLOW_REGISTER"] = False
response = client.get('/auth/register')
assert b"Admin only" in response.data
@pytest.mark.parametrize(('username', 'password', 'message'), ( @pytest.mark.parametrize(('username', 'password', 'message'), (
('', '', b'Username is required.'), ('', '', b'Username is required.'),
('a', '', b'Password is required.'), ('a', '', b'Password is required.'),

View file

@ -4,7 +4,7 @@ from flaskr.db import get_db
def test_index(client, auth): def test_index(client, auth):
response = client.get('/') response = client.get('/')
assert b"Log In" in response.data assert b"Log In" in response.data
assert b"Register" not in response.data assert b"Register" in response.data
auth.login() auth.login()
response = client.get('/') response = client.get('/')
@ -58,7 +58,7 @@ def test_create(client, auth, app):
def test_update(client, auth, app): def test_update(client, auth, app):
auth.login() auth.login()
assert client.get('/1/update').status_code == 200 assert client.get('/1/update').status_code == 200
client.post('/1/update', data={'title': 'updated', 'body': '', 'created': '1970-01-01 00:00:00'}) client.post('/1/update', data={'title': 'updated', 'body': ''})
with app.app_context(): with app.app_context():
db = get_db() db = get_db()
@ -71,7 +71,7 @@ def test_update(client, auth, app):
)) ))
def test_create_update_validate(client, auth, path): def test_create_update_validate(client, auth, path):
auth.login() auth.login()
response = client.post(path, data={'title': '', 'body': '', 'created': '1970-01-01 00:00:00'}) response = client.post(path, data={'title': '', 'body': ''})
assert b'Title is required.' in response.data assert b'Title is required.' in response.data
def test_delete(client, auth, app): def test_delete(client, auth, app):