diff options
| author | Mariusz Felisiak <felisiak.mariusz@gmail.com> | 2020-07-31 20:56:33 +0200 |
|---|---|---|
| committer | Mariusz Felisiak <felisiak.mariusz@gmail.com> | 2020-08-04 09:39:29 +0200 |
| commit | 985735265563d4bb0ff44cf6b823446e1813fa34 (patch) | |
| tree | 868c216cb98ead051b9e56fcaf49c862a3382127 /tests/auth_tests | |
| parent | acb7866b1fdda7592d9a16f0d0cc98f5d86a0a56 (diff) | |
[3.1.x] Fixed #31842 -- Added DEFAULT_HASHING_ALGORITHM transitional setting.
It's a transitional setting helpful in migrating multiple instance of
the same project to Django 3.1+.
Thanks Markus Holtermann for the report and review, Florian
Apolloner for the implementation idea and review, and Carlton Gibson
for the review.
Backport of d907371ef99a1e4ca6bc1660f57d81f265750984 from master.
Diffstat (limited to 'tests/auth_tests')
| -rw-r--r-- | tests/auth_tests/test_middleware.py | 10 | ||||
| -rw-r--r-- | tests/auth_tests/test_password_reset_timeout_days.py | 1 | ||||
| -rw-r--r-- | tests/auth_tests/test_tokens.py | 12 |
3 files changed, 22 insertions, 1 deletions
diff --git a/tests/auth_tests/test_middleware.py b/tests/auth_tests/test_middleware.py index 5538225acb..f86f8c6b27 100644 --- a/tests/auth_tests/test_middleware.py +++ b/tests/auth_tests/test_middleware.py @@ -2,7 +2,9 @@ from django.contrib.auth import HASH_SESSION_KEY from django.contrib.auth.middleware import AuthenticationMiddleware from django.contrib.auth.models import User from django.http import HttpRequest, HttpResponse -from django.test import TestCase +from django.test import TestCase, override_settings +from django.test.utils import ignore_warnings +from django.utils.deprecation import RemovedInDjango40Warning class TestAuthenticationMiddleware(TestCase): @@ -29,6 +31,12 @@ class TestAuthenticationMiddleware(TestCase): self.assertIsNotNone(self.request.user) self.assertFalse(self.request.user.is_anonymous) + @ignore_warnings(category=RemovedInDjango40Warning) + def test_session_default_hashing_algorithm(self): + hash_session = self.client.session[HASH_SESSION_KEY] + with override_settings(DEFAULT_HASHING_ALGORITHM='sha1'): + self.assertNotEqual(hash_session, self.user.get_session_auth_hash()) + def test_changed_password_invalidates_session(self): # After password change, user should be anonymous self.user.set_password('new_password') diff --git a/tests/auth_tests/test_password_reset_timeout_days.py b/tests/auth_tests/test_password_reset_timeout_days.py index 4bd5410f12..17aba80567 100644 --- a/tests/auth_tests/test_password_reset_timeout_days.py +++ b/tests/auth_tests/test_password_reset_timeout_days.py @@ -23,6 +23,7 @@ class DeprecationTests(TestCase): class Mocked(PasswordResetTokenGenerator): def __init__(self, now): self._now_val = now + super().__init__() def _now(self): return self._now_val diff --git a/tests/auth_tests/test_tokens.py b/tests/auth_tests/test_tokens.py index eaff78bd57..bba435be84 100644 --- a/tests/auth_tests/test_tokens.py +++ b/tests/auth_tests/test_tokens.py @@ -4,11 +4,14 @@ from django.conf import settings from django.contrib.auth.models import User from django.contrib.auth.tokens import PasswordResetTokenGenerator from django.test import TestCase +from django.test.utils import ignore_warnings +from django.utils.deprecation import RemovedInDjango40Warning class MockedPasswordResetTokenGenerator(PasswordResetTokenGenerator): def __init__(self, now): self._now_val = now + super().__init__() def _now(self): return self._now_val @@ -88,6 +91,15 @@ class TokenGeneratorTest(TestCase): self.assertIs(p0.check_token(user, tk1), False) self.assertIs(p1.check_token(user, tk0), False) + @ignore_warnings(category=RemovedInDjango40Warning) + def test_token_default_hashing_algorithm(self): + user = User.objects.create_user('tokentestuser', 'test2@example.com', 'testpw') + with self.settings(DEFAULT_HASHING_ALGORITHM='sha1'): + generator = PasswordResetTokenGenerator() + self.assertEqual(generator.algorithm, 'sha1') + token = generator.make_token(user) + self.assertIs(generator.check_token(user, token), True) + def test_legacy_token_validation(self): # RemovedInDjango40Warning: pre-Django 3.1 tokens will be invalid. user = User.objects.create_user('tokentestuser', 'test2@example.com', 'testpw') |
