"""Unit tests for admin user-management model functions.""" import pytest from gn_auth.auth.db import sqlite3 as db from gn_auth.auth.authorisation.users.admin.models import create_verified_user # --------------------------------------------------------------------------- # Helpers # --------------------------------------------------------------------------- def _credential_count(conn, user_id: str) -> int: with db.cursor(conn) as cursor: cursor.execute( "SELECT COUNT(*) AS cnt FROM user_credentials WHERE user_id=?", (user_id,)) return cursor.fetchone()["cnt"] @pytest.mark.unit_test def test_create_verified_user_sets_verified_flag(conn_after_auth_migrations): """ GIVEN: a database with migrations applied WHEN: create_verified_user is called with valid email, name and password THEN: the returned user has verified=True and the flag is persisted in the DB """ conn = conn_after_auth_migrations user = create_verified_user(conn, "new@example.org", "New User", "s3cr3t") assert user.verified is True with db.cursor(conn) as cursor: cursor.execute( "SELECT verified FROM users WHERE user_id=?", (str(user.user_id),)) row = cursor.fetchone() assert row is not None assert bool(row["verified"]) is True @pytest.mark.unit_test def test_create_verified_user_has_no_roles(conn_after_auth_migrations): """ GIVEN: a database with migrations applied WHEN: create_verified_user is called with valid email, name and password THEN: the new user is assigned no roles """ conn = conn_after_auth_migrations user = create_verified_user(conn, "noroles@example.org", "No Roles User", "s3cr3t") with db.cursor(conn) as cursor: cursor.execute( "SELECT COUNT(*) AS cnt FROM user_roles WHERE user_id=?", (str(user.user_id),)) row = cursor.fetchone() assert row["cnt"] == 0 @pytest.mark.unit_test def test_create_verified_user_stores_credentials(conn_after_auth_migrations): """ GIVEN: a database with migrations applied WHEN: create_verified_user is called with valid email, name and password THEN: a password credential row is stored for the new user """ conn = conn_after_auth_migrations user = create_verified_user(conn, "creds@example.org", "Creds User", "s3cr3t") assert _credential_count(conn, str(user.user_id)) == 1 @pytest.mark.unit_test def test_create_verified_user_raises_on_duplicate_email(conn_after_auth_migrations): """ GIVEN: a user already exists with a given email WHEN: create_verified_user is called with the same email THEN: an exception is raised """ conn = conn_after_auth_migrations create_verified_user(conn, "dupe@example.org", "First User", "s3cr3t") with pytest.raises(Exception): create_verified_user(conn, "dupe@example.org", "Second User", "s3cr3t")