about summary refs log tree commit diff
path: root/tests/unit/auth
diff options
context:
space:
mode:
Diffstat (limited to 'tests/unit/auth')
-rw-r--r--tests/unit/auth/test_admin_users.py36
1 files changed, 36 insertions, 0 deletions
diff --git a/tests/unit/auth/test_admin_users.py b/tests/unit/auth/test_admin_users.py
index f08bedd..9074581 100644
--- a/tests/unit/auth/test_admin_users.py
+++ b/tests/unit/auth/test_admin_users.py
@@ -4,6 +4,17 @@ import pytest
 from gn_auth.auth.db import sqlite3 as db
 from gn_auth.auth.authorisation.users.admin.models import create_verified_user
 
+# ---------------------------------------------------------------------------
+# Helpers
+# ---------------------------------------------------------------------------
+
+def _credential_count(conn, user_id: str) -> int:
+    with db.cursor(conn) as cursor:
+        cursor.execute(
+            "SELECT COUNT(*) AS cnt FROM user_credentials WHERE user_id=?",
+            (user_id,))
+        return cursor.fetchone()["cnt"]
+
 
 @pytest.mark.unit_test
 def test_create_verified_user_sets_verified_flag(conn_after_auth_migrations):
@@ -38,3 +49,28 @@ def test_create_verified_user_has_no_roles(conn_after_auth_migrations):
             (str(user.user_id),))
         row = cursor.fetchone()
     assert row["cnt"] == 0
+
+
+@pytest.mark.unit_test
+def test_create_verified_user_stores_credentials(conn_after_auth_migrations):
+    """
+    GIVEN: a database with migrations applied
+    WHEN: create_verified_user is called with valid email, name and password
+    THEN: a password credential row is stored for the new user
+    """
+    conn = conn_after_auth_migrations
+    user = create_verified_user(conn, "creds@example.org", "Creds User", "s3cr3t")
+    assert _credential_count(conn, str(user.user_id)) == 1
+
+
+@pytest.mark.unit_test
+def test_create_verified_user_raises_on_duplicate_email(conn_after_auth_migrations):
+    """
+    GIVEN: a user already exists with a given email
+    WHEN: create_verified_user is called with the same email
+    THEN: an exception is raised
+    """
+    conn = conn_after_auth_migrations
+    create_verified_user(conn, "dupe@example.org", "First User", "s3cr3t")
+    with pytest.raises(Exception):
+        create_verified_user(conn, "dupe@example.org", "Second User", "s3cr3t")