summaryrefslogtreecommitdiff
path: root/tests/auth_tests
diff options
context:
space:
mode:
authorMariusz Felisiak <felisiak.mariusz@gmail.com>2020-07-31 20:56:33 +0200
committerMariusz Felisiak <felisiak.mariusz@gmail.com>2020-08-04 09:39:29 +0200
commit985735265563d4bb0ff44cf6b823446e1813fa34 (patch)
tree868c216cb98ead051b9e56fcaf49c862a3382127 /tests/auth_tests
parentacb7866b1fdda7592d9a16f0d0cc98f5d86a0a56 (diff)
[3.1.x] Fixed #31842 -- Added DEFAULT_HASHING_ALGORITHM transitional setting.
It's a transitional setting helpful in migrating multiple instance of the same project to Django 3.1+. Thanks Markus Holtermann for the report and review, Florian Apolloner for the implementation idea and review, and Carlton Gibson for the review. Backport of d907371ef99a1e4ca6bc1660f57d81f265750984 from master.
Diffstat (limited to 'tests/auth_tests')
-rw-r--r--tests/auth_tests/test_middleware.py10
-rw-r--r--tests/auth_tests/test_password_reset_timeout_days.py1
-rw-r--r--tests/auth_tests/test_tokens.py12
3 files changed, 22 insertions, 1 deletions
diff --git a/tests/auth_tests/test_middleware.py b/tests/auth_tests/test_middleware.py
index 5538225acb..f86f8c6b27 100644
--- a/tests/auth_tests/test_middleware.py
+++ b/tests/auth_tests/test_middleware.py
@@ -2,7 +2,9 @@ from django.contrib.auth import HASH_SESSION_KEY
from django.contrib.auth.middleware import AuthenticationMiddleware
from django.contrib.auth.models import User
from django.http import HttpRequest, HttpResponse
-from django.test import TestCase
+from django.test import TestCase, override_settings
+from django.test.utils import ignore_warnings
+from django.utils.deprecation import RemovedInDjango40Warning
class TestAuthenticationMiddleware(TestCase):
@@ -29,6 +31,12 @@ class TestAuthenticationMiddleware(TestCase):
self.assertIsNotNone(self.request.user)
self.assertFalse(self.request.user.is_anonymous)
+ @ignore_warnings(category=RemovedInDjango40Warning)
+ def test_session_default_hashing_algorithm(self):
+ hash_session = self.client.session[HASH_SESSION_KEY]
+ with override_settings(DEFAULT_HASHING_ALGORITHM='sha1'):
+ self.assertNotEqual(hash_session, self.user.get_session_auth_hash())
+
def test_changed_password_invalidates_session(self):
# After password change, user should be anonymous
self.user.set_password('new_password')
diff --git a/tests/auth_tests/test_password_reset_timeout_days.py b/tests/auth_tests/test_password_reset_timeout_days.py
index 4bd5410f12..17aba80567 100644
--- a/tests/auth_tests/test_password_reset_timeout_days.py
+++ b/tests/auth_tests/test_password_reset_timeout_days.py
@@ -23,6 +23,7 @@ class DeprecationTests(TestCase):
class Mocked(PasswordResetTokenGenerator):
def __init__(self, now):
self._now_val = now
+ super().__init__()
def _now(self):
return self._now_val
diff --git a/tests/auth_tests/test_tokens.py b/tests/auth_tests/test_tokens.py
index eaff78bd57..bba435be84 100644
--- a/tests/auth_tests/test_tokens.py
+++ b/tests/auth_tests/test_tokens.py
@@ -4,11 +4,14 @@ from django.conf import settings
from django.contrib.auth.models import User
from django.contrib.auth.tokens import PasswordResetTokenGenerator
from django.test import TestCase
+from django.test.utils import ignore_warnings
+from django.utils.deprecation import RemovedInDjango40Warning
class MockedPasswordResetTokenGenerator(PasswordResetTokenGenerator):
def __init__(self, now):
self._now_val = now
+ super().__init__()
def _now(self):
return self._now_val
@@ -88,6 +91,15 @@ class TokenGeneratorTest(TestCase):
self.assertIs(p0.check_token(user, tk1), False)
self.assertIs(p1.check_token(user, tk0), False)
+ @ignore_warnings(category=RemovedInDjango40Warning)
+ def test_token_default_hashing_algorithm(self):
+ user = User.objects.create_user('tokentestuser', 'test2@example.com', 'testpw')
+ with self.settings(DEFAULT_HASHING_ALGORITHM='sha1'):
+ generator = PasswordResetTokenGenerator()
+ self.assertEqual(generator.algorithm, 'sha1')
+ token = generator.make_token(user)
+ self.assertIs(generator.check_token(user, token), True)
+
def test_legacy_token_validation(self):
# RemovedInDjango40Warning: pre-Django 3.1 tokens will be invalid.
user = User.objects.create_user('tokentestuser', 'test2@example.com', 'testpw')