django-rest-framework/rest_framework/tests/test_testing.py

146 lines
5.1 KiB
Python
Raw Normal View History

2013-06-29 11:05:08 +04:00
# -- coding: utf-8 --
from __future__ import unicode_literals
2013-09-25 13:30:04 +04:00
from django.conf.urls import patterns, url
2013-06-30 00:02:58 +04:00
from django.contrib.auth.models import User
2013-06-29 11:05:08 +04:00
from django.test import TestCase
from rest_framework.decorators import api_view
from rest_framework.response import Response
2013-07-01 16:59:05 +04:00
from rest_framework.test import APIClient, APIRequestFactory, force_authenticate
2013-06-29 11:05:08 +04:00
2013-06-30 00:02:58 +04:00
@api_view(['GET', 'POST'])
2013-07-01 16:59:05 +04:00
def view(request):
2013-06-29 11:05:08 +04:00
return Response({
2013-06-30 00:02:58 +04:00
'auth': request.META.get('HTTP_AUTHORIZATION', b''),
'user': request.user.username
2013-06-29 11:05:08 +04:00
})
@api_view(['GET', 'POST'])
def session_view(request):
active_session = request.session.get('active_session', False)
request.session['active_session'] = True
return Response({
'active_session': active_session
})
2013-06-29 11:05:08 +04:00
urlpatterns = patterns('',
2013-07-01 16:59:05 +04:00
url(r'^view/$', view),
url(r'^session-view/$', session_view),
2013-06-29 11:05:08 +04:00
)
2013-07-01 16:59:05 +04:00
class TestAPITestClient(TestCase):
2013-06-29 11:05:08 +04:00
urls = 'rest_framework.tests.test_testing'
def setUp(self):
self.client = APIClient()
def test_credentials(self):
2013-06-30 00:02:58 +04:00
"""
Setting `.credentials()` adds the required headers to each request.
"""
2013-06-29 11:05:08 +04:00
self.client.credentials(HTTP_AUTHORIZATION='example')
2013-06-30 00:02:58 +04:00
for _ in range(0, 3):
response = self.client.get('/view/')
self.assertEqual(response.data['auth'], 'example')
2013-06-30 01:53:15 +04:00
def test_force_authenticate(self):
2013-06-30 00:02:58 +04:00
"""
2013-06-30 01:53:15 +04:00
Setting `.force_authenticate()` forcibly authenticates each request.
2013-06-30 00:02:58 +04:00
"""
user = User.objects.create_user('example', 'example@example.com')
2013-06-30 01:53:15 +04:00
self.client.force_authenticate(user)
2013-06-29 11:05:08 +04:00
response = self.client.get('/view/')
2013-06-30 00:02:58 +04:00
self.assertEqual(response.data['user'], 'example')
def test_force_authenticate_with_sessions(self):
"""
Setting `.force_authenticate()` forcibly authenticates each request.
"""
user = User.objects.create_user('example', 'example@example.com')
self.client.force_authenticate(user)
# First request does not yet have an active session
response = self.client.get('/session-view/')
self.assertEqual(response.data['active_session'], False)
# Subsequant requests have an active session
response = self.client.get('/session-view/')
self.assertEqual(response.data['active_session'], True)
# Force authenticating as `None` should also logout the user session.
self.client.force_authenticate(None)
response = self.client.get('/session-view/')
self.assertEqual(response.data['active_session'], False)
2013-06-30 00:02:58 +04:00
def test_csrf_exempt_by_default(self):
"""
By default, the test client is CSRF exempt.
"""
User.objects.create_user('example', 'example@example.com', 'password')
self.client.login(username='example', password='password')
response = self.client.post('/view/')
self.assertEqual(response.status_code, 200)
def test_explicitly_enforce_csrf_checks(self):
"""
The test client can enforce CSRF checks.
"""
client = APIClient(enforce_csrf_checks=True)
User.objects.create_user('example', 'example@example.com', 'password')
client.login(username='example', password='password')
response = client.post('/view/')
expected = {'detail': 'CSRF Failed: CSRF cookie not set.'}
self.assertEqual(response.status_code, 403)
self.assertEqual(response.data, expected)
2013-07-01 16:59:05 +04:00
class TestAPIRequestFactory(TestCase):
def test_csrf_exempt_by_default(self):
"""
By default, the test client is CSRF exempt.
"""
user = User.objects.create_user('example', 'example@example.com', 'password')
factory = APIRequestFactory()
request = factory.post('/view/')
request.user = user
response = view(request)
self.assertEqual(response.status_code, 200)
def test_explicitly_enforce_csrf_checks(self):
"""
The test client can enforce CSRF checks.
"""
user = User.objects.create_user('example', 'example@example.com', 'password')
factory = APIRequestFactory(enforce_csrf_checks=True)
request = factory.post('/view/')
request.user = user
response = view(request)
expected = {'detail': 'CSRF Failed: CSRF cookie not set.'}
self.assertEqual(response.status_code, 403)
self.assertEqual(response.data, expected)
def test_invalid_format(self):
"""
Attempting to use a format that is not configured will raise an
assertion error.
"""
factory = APIRequestFactory()
self.assertRaises(AssertionError, factory.post,
path='/view/', data={'example': 1}, format='xml'
)
def test_force_authenticate(self):
"""
Setting `force_authenticate()` forcibly authenticates the request.
"""
user = User.objects.create_user('example', 'example@example.com')
factory = APIRequestFactory()
request = factory.get('/view')
force_authenticate(request, user=user)
response = view(request)
self.assertEqual(response.data['user'], 'example')