mirror of
https://github.com/sudoxnym/habitica.git
synced 2026-08-04 09:39:23 +00:00
local login test
This commit is contained in:
parent
1d3c67af40
commit
5426d63a36
2 changed files with 71 additions and 3 deletions
69
test/api/v3/integration/user/auth/POST-login-local.test.js
Normal file
69
test/api/v3/integration/user/auth/POST-login-local.test.js
Normal file
|
|
@ -0,0 +1,69 @@
|
|||
import {
|
||||
generateUser,
|
||||
requester,
|
||||
translate as t,
|
||||
} from '../../../../../helpers/api-integration/v3';
|
||||
|
||||
describe('POST /user/auth/local/login', () => {
|
||||
let api;
|
||||
let user;
|
||||
let endpoint = '/user/auth/local/login';
|
||||
let password = 'password';
|
||||
beforeEach(async () => {
|
||||
api = requester();
|
||||
user = await generateUser();
|
||||
});
|
||||
it('success with username', async () => {
|
||||
let response = await api.post(endpoint, {
|
||||
username: user.auth.local.username,
|
||||
password,
|
||||
});
|
||||
expect(response.apiToken).to.eql(user.apiToken);
|
||||
});
|
||||
it('success with email', async () => {
|
||||
let response = await api.post(endpoint, {
|
||||
username: user.auth.local.email,
|
||||
password,
|
||||
});
|
||||
expect(response.apiToken).to.eql(user.apiToken);
|
||||
});
|
||||
it('user is blocked', async () => {
|
||||
await user.update({ 'auth.blocked': 1 });
|
||||
expect(api.post(endpoint, {
|
||||
username: user.auth.local.username,
|
||||
password,
|
||||
})).to.eventually.be.rejected.and.eql({
|
||||
code: 400,
|
||||
error: 'NotAuthorized',
|
||||
message: t('accountSuspended', { userId: user._id }),
|
||||
});
|
||||
});
|
||||
it('wrong password', async () => {
|
||||
expect(api.post(endpoint, {
|
||||
username: user.auth.local.username,
|
||||
password: 'wrong-password',
|
||||
})).to.eventually.be.rejected.and.eql({
|
||||
code: 400,
|
||||
error: 'NotAuthorized',
|
||||
message: t('wrongPassword'),
|
||||
});
|
||||
});
|
||||
it('missing username', async () => {
|
||||
expect(api.post(endpoint, {
|
||||
password: 'wrong-password',
|
||||
})).to.eventually.be.rejected.and.eql({
|
||||
code: 400,
|
||||
error: 'NotAuthorized',
|
||||
message: t('missingUsername'),
|
||||
});
|
||||
});
|
||||
it('missing password', async () => {
|
||||
expect(api.post(endpoint, {
|
||||
username: user.auth.local.username,
|
||||
})).to.eventually.be.rejected.and.eql({
|
||||
code: 400,
|
||||
error: 'NotAuthorized',
|
||||
message: t('missingPassword'),
|
||||
});
|
||||
});
|
||||
});
|
||||
|
|
@ -180,7 +180,7 @@ function _loginRes (user, req, res) {
|
|||
api.loginLocal = {
|
||||
method: 'POST',
|
||||
url: '/user/auth/local/login',
|
||||
middlewares: [cron],
|
||||
middlewares: [],
|
||||
async handler (req, res) {
|
||||
req.checkBody({
|
||||
username: {
|
||||
|
|
@ -192,7 +192,6 @@ api.loginLocal = {
|
|||
errorMessage: res.t('missingPassword'),
|
||||
},
|
||||
});
|
||||
|
||||
let validationErrors = req.validationErrors();
|
||||
if (validationErrors) throw validationErrors;
|
||||
|
||||
|
|
@ -211,7 +210,7 @@ api.loginLocal = {
|
|||
let user = await User.findOne(login, {auth: 1, apiToken: 1}).exec();
|
||||
|
||||
// TODO place back long error message return res.json(401, {err:"Uh-oh - your username or password is incorrect.\n- Make sure your username or email is typed correctly.\n- You may have signed up with Facebook, not email. Double-check by trying Facebook login.\n- If you forgot your password, click \"Forgot Password\"."});
|
||||
let isValidPassword = user && user.auth.local.hashed_password !== passwordUtils.encrypt(req.body.password, user.auth.local.salt);
|
||||
let isValidPassword = user && user.auth.local.hashed_password === passwordUtils.encrypt(req.body.password, user.auth.local.salt);
|
||||
|
||||
if (!isValidPassword) throw new NotAuthorized(res.t('invalidLoginCredentials'));
|
||||
_loginRes(user, ...arguments);
|
||||
|
|
|
|||
Loading…
Reference in a new issue