tests.py 45 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081
  1. """
  2. Testing using the Test Client
  3. The test client is a class that can act like a simple
  4. browser for testing purposes.
  5. It allows the user to compose GET and POST requests, and
  6. obtain the response that the server gave to those requests.
  7. The server Response objects are annotated with the details
  8. of the contexts and templates that were rendered during the
  9. process of serving the request.
  10. ``Client`` objects are stateful - they will retain cookie (and
  11. thus session) details for the lifetime of the ``Client`` instance.
  12. This is not intended as a replacement for Twill, Selenium, or
  13. other browser automation frameworks - it is here to allow
  14. testing against the contexts and templates produced by a view,
  15. rather than the HTML rendered to the end-user.
  16. """
  17. import itertools
  18. import tempfile
  19. from unittest import mock
  20. from django.contrib.auth.models import User
  21. from django.core import mail
  22. from django.http import HttpResponse, HttpResponseNotAllowed
  23. from django.test import (
  24. AsyncRequestFactory, Client, RequestFactory, SimpleTestCase, TestCase,
  25. modify_settings, override_settings,
  26. )
  27. from django.urls import reverse_lazy
  28. from django.utils.decorators import async_only_middleware
  29. from .views import TwoArgException, get_view, post_view, trace_view
  30. def middleware_urlconf(get_response):
  31. def middleware(request):
  32. request.urlconf = 'tests.test_client.urls_middleware_urlconf'
  33. return get_response(request)
  34. return middleware
  35. @async_only_middleware
  36. def async_middleware_urlconf(get_response):
  37. async def middleware(request):
  38. request.urlconf = 'tests.test_client.urls_middleware_urlconf'
  39. return await get_response(request)
  40. return middleware
  41. @override_settings(ROOT_URLCONF='test_client.urls')
  42. class ClientTest(TestCase):
  43. @classmethod
  44. def setUpTestData(cls):
  45. cls.u1 = User.objects.create_user(username='testclient', password='password')
  46. cls.u2 = User.objects.create_user(username='inactive', password='password', is_active=False)
  47. def test_get_view(self):
  48. "GET a view"
  49. # The data is ignored, but let's check it doesn't crash the system
  50. # anyway.
  51. data = {'var': '\xf2'}
  52. response = self.client.get('/get_view/', data)
  53. # Check some response details
  54. self.assertContains(response, 'This is a test')
  55. self.assertEqual(response.context['var'], '\xf2')
  56. self.assertEqual(response.templates[0].name, 'GET Template')
  57. def test_query_string_encoding(self):
  58. # WSGI requires latin-1 encoded strings.
  59. response = self.client.get('/get_view/?var=1\ufffd')
  60. self.assertEqual(response.context['var'], '1\ufffd')
  61. def test_get_data_none(self):
  62. msg = (
  63. "Cannot encode None for key 'value' in a query string. Did you "
  64. "mean to pass an empty string or omit the value?"
  65. )
  66. with self.assertRaisesMessage(TypeError, msg):
  67. self.client.get('/get_view/', {'value': None})
  68. def test_get_post_view(self):
  69. "GET a view that normally expects POSTs"
  70. response = self.client.get('/post_view/', {})
  71. # Check some response details
  72. self.assertEqual(response.status_code, 200)
  73. self.assertEqual(response.templates[0].name, 'Empty GET Template')
  74. self.assertTemplateUsed(response, 'Empty GET Template')
  75. self.assertTemplateNotUsed(response, 'Empty POST Template')
  76. def test_empty_post(self):
  77. "POST an empty dictionary to a view"
  78. response = self.client.post('/post_view/', {})
  79. # Check some response details
  80. self.assertEqual(response.status_code, 200)
  81. self.assertEqual(response.templates[0].name, 'Empty POST Template')
  82. self.assertTemplateNotUsed(response, 'Empty GET Template')
  83. self.assertTemplateUsed(response, 'Empty POST Template')
  84. def test_post(self):
  85. "POST some data to a view"
  86. post_data = {
  87. 'value': 37
  88. }
  89. response = self.client.post('/post_view/', post_data)
  90. # Check some response details
  91. self.assertContains(response, 'Data received')
  92. self.assertEqual(response.context['data'], '37')
  93. self.assertEqual(response.templates[0].name, 'POST Template')
  94. def test_post_data_none(self):
  95. msg = (
  96. "Cannot encode None for key 'value' as POST data. Did you mean "
  97. "to pass an empty string or omit the value?"
  98. )
  99. with self.assertRaisesMessage(TypeError, msg):
  100. self.client.post('/post_view/', {'value': None})
  101. def test_json_serialization(self):
  102. """The test client serializes JSON data."""
  103. methods = ('post', 'put', 'patch', 'delete')
  104. tests = (
  105. ({'value': 37}, {'value': 37}),
  106. ([37, True], [37, True]),
  107. ((37, False), [37, False]),
  108. )
  109. for method in methods:
  110. with self.subTest(method=method):
  111. for data, expected in tests:
  112. with self.subTest(data):
  113. client_method = getattr(self.client, method)
  114. method_name = method.upper()
  115. response = client_method('/json_view/', data, content_type='application/json')
  116. self.assertContains(response, 'Viewing %s page.' % method_name)
  117. self.assertEqual(response.context['data'], expected)
  118. def test_json_encoder_argument(self):
  119. """The test Client accepts a json_encoder."""
  120. mock_encoder = mock.MagicMock()
  121. mock_encoding = mock.MagicMock()
  122. mock_encoder.return_value = mock_encoding
  123. mock_encoding.encode.return_value = '{"value": 37}'
  124. client = self.client_class(json_encoder=mock_encoder)
  125. # Vendored tree JSON content types are accepted.
  126. client.post('/json_view/', {'value': 37}, content_type='application/vnd.api+json')
  127. self.assertTrue(mock_encoder.called)
  128. self.assertTrue(mock_encoding.encode.called)
  129. def test_put(self):
  130. response = self.client.put('/put_view/', {'foo': 'bar'})
  131. self.assertEqual(response.status_code, 200)
  132. self.assertEqual(response.templates[0].name, 'PUT Template')
  133. self.assertEqual(response.context['data'], "{'foo': 'bar'}")
  134. self.assertEqual(response.context['Content-Length'], '14')
  135. def test_trace(self):
  136. """TRACE a view"""
  137. response = self.client.trace('/trace_view/')
  138. self.assertEqual(response.status_code, 200)
  139. self.assertEqual(response.context['method'], 'TRACE')
  140. self.assertEqual(response.templates[0].name, 'TRACE Template')
  141. def test_response_headers(self):
  142. "Check the value of HTTP headers returned in a response"
  143. response = self.client.get("/header_view/")
  144. self.assertEqual(response.headers['X-DJANGO-TEST'], 'Slartibartfast')
  145. def test_response_attached_request(self):
  146. """
  147. The returned response has a ``request`` attribute with the originating
  148. environ dict and a ``wsgi_request`` with the originating WSGIRequest.
  149. """
  150. response = self.client.get("/header_view/")
  151. self.assertTrue(hasattr(response, 'request'))
  152. self.assertTrue(hasattr(response, 'wsgi_request'))
  153. for key, value in response.request.items():
  154. self.assertIn(key, response.wsgi_request.environ)
  155. self.assertEqual(response.wsgi_request.environ[key], value)
  156. def test_response_resolver_match(self):
  157. """
  158. The response contains a ResolverMatch instance.
  159. """
  160. response = self.client.get('/header_view/')
  161. self.assertTrue(hasattr(response, 'resolver_match'))
  162. def test_response_resolver_match_redirect_follow(self):
  163. """
  164. The response ResolverMatch instance contains the correct
  165. information when following redirects.
  166. """
  167. response = self.client.get('/redirect_view/', follow=True)
  168. self.assertEqual(response.resolver_match.url_name, 'get_view')
  169. def test_response_resolver_match_regular_view(self):
  170. """
  171. The response ResolverMatch instance contains the correct
  172. information when accessing a regular view.
  173. """
  174. response = self.client.get('/get_view/')
  175. self.assertEqual(response.resolver_match.url_name, 'get_view')
  176. @modify_settings(MIDDLEWARE={'prepend': 'test_client.tests.middleware_urlconf'})
  177. def test_response_resolver_match_middleware_urlconf(self):
  178. response = self.client.get('/middleware_urlconf_view/')
  179. self.assertEqual(response.resolver_match.url_name, 'middleware_urlconf_view')
  180. def test_raw_post(self):
  181. "POST raw data (with a content type) to a view"
  182. test_doc = """<?xml version="1.0" encoding="utf-8"?>
  183. <library><book><title>Blink</title><author>Malcolm Gladwell</author></book></library>
  184. """
  185. response = self.client.post('/raw_post_view/', test_doc, content_type='text/xml')
  186. self.assertEqual(response.status_code, 200)
  187. self.assertEqual(response.templates[0].name, "Book template")
  188. self.assertEqual(response.content, b"Blink - Malcolm Gladwell")
  189. def test_insecure(self):
  190. "GET a URL through http"
  191. response = self.client.get('/secure_view/', secure=False)
  192. self.assertFalse(response.test_was_secure_request)
  193. self.assertEqual(response.test_server_port, '80')
  194. def test_secure(self):
  195. "GET a URL through https"
  196. response = self.client.get('/secure_view/', secure=True)
  197. self.assertTrue(response.test_was_secure_request)
  198. self.assertEqual(response.test_server_port, '443')
  199. def test_redirect(self):
  200. "GET a URL that redirects elsewhere"
  201. response = self.client.get('/redirect_view/')
  202. self.assertRedirects(response, '/get_view/')
  203. def test_redirect_with_query(self):
  204. "GET a URL that redirects with given GET parameters"
  205. response = self.client.get('/redirect_view/', {'var': 'value'})
  206. self.assertRedirects(response, '/get_view/?var=value')
  207. def test_redirect_with_query_ordering(self):
  208. """assertRedirects() ignores the order of query string parameters."""
  209. response = self.client.get('/redirect_view/', {'var': 'value', 'foo': 'bar'})
  210. self.assertRedirects(response, '/get_view/?var=value&foo=bar')
  211. self.assertRedirects(response, '/get_view/?foo=bar&var=value')
  212. def test_permanent_redirect(self):
  213. "GET a URL that redirects permanently elsewhere"
  214. response = self.client.get('/permanent_redirect_view/')
  215. self.assertRedirects(response, '/get_view/', status_code=301)
  216. def test_temporary_redirect(self):
  217. "GET a URL that does a non-permanent redirect"
  218. response = self.client.get('/temporary_redirect_view/')
  219. self.assertRedirects(response, '/get_view/', status_code=302)
  220. def test_redirect_to_strange_location(self):
  221. "GET a URL that redirects to a non-200 page"
  222. response = self.client.get('/double_redirect_view/')
  223. # The response was a 302, and that the attempt to get the redirection
  224. # location returned 301 when retrieved
  225. self.assertRedirects(response, '/permanent_redirect_view/', target_status_code=301)
  226. def test_follow_redirect(self):
  227. "A URL that redirects can be followed to termination."
  228. response = self.client.get('/double_redirect_view/', follow=True)
  229. self.assertRedirects(response, '/get_view/', status_code=302, target_status_code=200)
  230. self.assertEqual(len(response.redirect_chain), 2)
  231. def test_follow_relative_redirect(self):
  232. "A URL with a relative redirect can be followed."
  233. response = self.client.get('/accounts/', follow=True)
  234. self.assertEqual(response.status_code, 200)
  235. self.assertEqual(response.request['PATH_INFO'], '/accounts/login/')
  236. def test_follow_relative_redirect_no_trailing_slash(self):
  237. "A URL with a relative redirect with no trailing slash can be followed."
  238. response = self.client.get('/accounts/no_trailing_slash', follow=True)
  239. self.assertEqual(response.status_code, 200)
  240. self.assertEqual(response.request['PATH_INFO'], '/accounts/login/')
  241. def test_redirect_to_querystring_only(self):
  242. """A URL that consists of a querystring only can be followed"""
  243. response = self.client.post('/post_then_get_view/', follow=True)
  244. self.assertEqual(response.status_code, 200)
  245. self.assertEqual(response.request['PATH_INFO'], '/post_then_get_view/')
  246. self.assertEqual(response.content, b'The value of success is true.')
  247. def test_follow_307_and_308_redirect(self):
  248. """
  249. A 307 or 308 redirect preserves the request method after the redirect.
  250. """
  251. methods = ('get', 'post', 'head', 'options', 'put', 'patch', 'delete', 'trace')
  252. codes = (307, 308)
  253. for method, code in itertools.product(methods, codes):
  254. with self.subTest(method=method, code=code):
  255. req_method = getattr(self.client, method)
  256. response = req_method('/redirect_view_%s/' % code, data={'value': 'test'}, follow=True)
  257. self.assertEqual(response.status_code, 200)
  258. self.assertEqual(response.request['PATH_INFO'], '/post_view/')
  259. self.assertEqual(response.request['REQUEST_METHOD'], method.upper())
  260. def test_follow_307_and_308_preserves_query_string(self):
  261. methods = ('post', 'options', 'put', 'patch', 'delete', 'trace')
  262. codes = (307, 308)
  263. for method, code in itertools.product(methods, codes):
  264. with self.subTest(method=method, code=code):
  265. req_method = getattr(self.client, method)
  266. response = req_method(
  267. '/redirect_view_%s_query_string/' % code,
  268. data={'value': 'test'},
  269. follow=True,
  270. )
  271. self.assertRedirects(response, '/post_view/?hello=world', status_code=code)
  272. self.assertEqual(response.request['QUERY_STRING'], 'hello=world')
  273. def test_follow_307_and_308_get_head_query_string(self):
  274. methods = ('get', 'head')
  275. codes = (307, 308)
  276. for method, code in itertools.product(methods, codes):
  277. with self.subTest(method=method, code=code):
  278. req_method = getattr(self.client, method)
  279. response = req_method(
  280. '/redirect_view_%s_query_string/' % code,
  281. data={'value': 'test'},
  282. follow=True,
  283. )
  284. self.assertRedirects(response, '/post_view/?hello=world', status_code=code)
  285. self.assertEqual(response.request['QUERY_STRING'], 'value=test')
  286. def test_follow_307_and_308_preserves_post_data(self):
  287. for code in (307, 308):
  288. with self.subTest(code=code):
  289. response = self.client.post('/redirect_view_%s/' % code, data={'value': 'test'}, follow=True)
  290. self.assertContains(response, 'test is the value')
  291. def test_follow_307_and_308_preserves_put_body(self):
  292. for code in (307, 308):
  293. with self.subTest(code=code):
  294. response = self.client.put('/redirect_view_%s/?to=/put_view/' % code, data='a=b', follow=True)
  295. self.assertContains(response, 'a=b is the body')
  296. def test_follow_307_and_308_preserves_get_params(self):
  297. data = {'var': 30, 'to': '/get_view/'}
  298. for code in (307, 308):
  299. with self.subTest(code=code):
  300. response = self.client.get('/redirect_view_%s/' % code, data=data, follow=True)
  301. self.assertContains(response, '30 is the value')
  302. def test_redirect_http(self):
  303. """GET a URL that redirects to an HTTP URI."""
  304. response = self.client.get('/http_redirect_view/', follow=True)
  305. self.assertFalse(response.test_was_secure_request)
  306. def test_redirect_https(self):
  307. """GET a URL that redirects to an HTTPS URI."""
  308. response = self.client.get('/https_redirect_view/', follow=True)
  309. self.assertTrue(response.test_was_secure_request)
  310. def test_notfound_response(self):
  311. "GET a URL that responds as '404:Not Found'"
  312. response = self.client.get('/bad_view/')
  313. self.assertContains(response, 'MAGIC', status_code=404)
  314. def test_valid_form(self):
  315. "POST valid data to a form"
  316. post_data = {
  317. 'text': 'Hello World',
  318. 'email': 'foo@example.com',
  319. 'value': 37,
  320. 'single': 'b',
  321. 'multi': ('b', 'c', 'e')
  322. }
  323. response = self.client.post('/form_view/', post_data)
  324. self.assertEqual(response.status_code, 200)
  325. self.assertTemplateUsed(response, "Valid POST Template")
  326. def test_valid_form_with_hints(self):
  327. "GET a form, providing hints in the GET data"
  328. hints = {
  329. 'text': 'Hello World',
  330. 'multi': ('b', 'c', 'e')
  331. }
  332. response = self.client.get('/form_view/', data=hints)
  333. # The multi-value data has been rolled out ok
  334. self.assertContains(response, 'Select a valid choice.', 0)
  335. self.assertTemplateUsed(response, "Form GET Template")
  336. def test_incomplete_data_form(self):
  337. "POST incomplete data to a form"
  338. post_data = {
  339. 'text': 'Hello World',
  340. 'value': 37
  341. }
  342. response = self.client.post('/form_view/', post_data)
  343. self.assertContains(response, 'This field is required.', 3)
  344. self.assertTemplateUsed(response, "Invalid POST Template")
  345. self.assertFormError(response, 'form', 'email', 'This field is required.')
  346. self.assertFormError(response, 'form', 'single', 'This field is required.')
  347. self.assertFormError(response, 'form', 'multi', 'This field is required.')
  348. def test_form_error(self):
  349. "POST erroneous data to a form"
  350. post_data = {
  351. 'text': 'Hello World',
  352. 'email': 'not an email address',
  353. 'value': 37,
  354. 'single': 'b',
  355. 'multi': ('b', 'c', 'e')
  356. }
  357. response = self.client.post('/form_view/', post_data)
  358. self.assertEqual(response.status_code, 200)
  359. self.assertTemplateUsed(response, "Invalid POST Template")
  360. self.assertFormError(response, 'form', 'email', 'Enter a valid email address.')
  361. def test_valid_form_with_template(self):
  362. "POST valid data to a form using multiple templates"
  363. post_data = {
  364. 'text': 'Hello World',
  365. 'email': 'foo@example.com',
  366. 'value': 37,
  367. 'single': 'b',
  368. 'multi': ('b', 'c', 'e')
  369. }
  370. response = self.client.post('/form_view_with_template/', post_data)
  371. self.assertContains(response, 'POST data OK')
  372. self.assertTemplateUsed(response, "form_view.html")
  373. self.assertTemplateUsed(response, 'base.html')
  374. self.assertTemplateNotUsed(response, "Valid POST Template")
  375. def test_incomplete_data_form_with_template(self):
  376. "POST incomplete data to a form using multiple templates"
  377. post_data = {
  378. 'text': 'Hello World',
  379. 'value': 37
  380. }
  381. response = self.client.post('/form_view_with_template/', post_data)
  382. self.assertContains(response, 'POST data has errors')
  383. self.assertTemplateUsed(response, 'form_view.html')
  384. self.assertTemplateUsed(response, 'base.html')
  385. self.assertTemplateNotUsed(response, "Invalid POST Template")
  386. self.assertFormError(response, 'form', 'email', 'This field is required.')
  387. self.assertFormError(response, 'form', 'single', 'This field is required.')
  388. self.assertFormError(response, 'form', 'multi', 'This field is required.')
  389. def test_form_error_with_template(self):
  390. "POST erroneous data to a form using multiple templates"
  391. post_data = {
  392. 'text': 'Hello World',
  393. 'email': 'not an email address',
  394. 'value': 37,
  395. 'single': 'b',
  396. 'multi': ('b', 'c', 'e')
  397. }
  398. response = self.client.post('/form_view_with_template/', post_data)
  399. self.assertContains(response, 'POST data has errors')
  400. self.assertTemplateUsed(response, "form_view.html")
  401. self.assertTemplateUsed(response, 'base.html')
  402. self.assertTemplateNotUsed(response, "Invalid POST Template")
  403. self.assertFormError(response, 'form', 'email', 'Enter a valid email address.')
  404. def test_unknown_page(self):
  405. "GET an invalid URL"
  406. response = self.client.get('/unknown_view/')
  407. # The response was a 404
  408. self.assertEqual(response.status_code, 404)
  409. def test_url_parameters(self):
  410. "Make sure that URL ;-parameters are not stripped."
  411. response = self.client.get('/unknown_view/;some-parameter')
  412. # The path in the response includes it (ignore that it's a 404)
  413. self.assertEqual(response.request['PATH_INFO'], '/unknown_view/;some-parameter')
  414. def test_view_with_login(self):
  415. "Request a page that is protected with @login_required"
  416. # Get the page without logging in. Should result in 302.
  417. response = self.client.get('/login_protected_view/')
  418. self.assertRedirects(response, '/accounts/login/?next=/login_protected_view/')
  419. # Log in
  420. login = self.client.login(username='testclient', password='password')
  421. self.assertTrue(login, 'Could not log in')
  422. # Request a page that requires a login
  423. response = self.client.get('/login_protected_view/')
  424. self.assertEqual(response.status_code, 200)
  425. self.assertEqual(response.context['user'].username, 'testclient')
  426. @override_settings(
  427. INSTALLED_APPS=['django.contrib.auth'],
  428. SESSION_ENGINE='django.contrib.sessions.backends.file',
  429. )
  430. def test_view_with_login_when_sessions_app_is_not_installed(self):
  431. self.test_view_with_login()
  432. def test_view_with_force_login(self):
  433. "Request a page that is protected with @login_required"
  434. # Get the page without logging in. Should result in 302.
  435. response = self.client.get('/login_protected_view/')
  436. self.assertRedirects(response, '/accounts/login/?next=/login_protected_view/')
  437. # Log in
  438. self.client.force_login(self.u1)
  439. # Request a page that requires a login
  440. response = self.client.get('/login_protected_view/')
  441. self.assertEqual(response.status_code, 200)
  442. self.assertEqual(response.context['user'].username, 'testclient')
  443. def test_view_with_method_login(self):
  444. "Request a page that is protected with a @login_required method"
  445. # Get the page without logging in. Should result in 302.
  446. response = self.client.get('/login_protected_method_view/')
  447. self.assertRedirects(response, '/accounts/login/?next=/login_protected_method_view/')
  448. # Log in
  449. login = self.client.login(username='testclient', password='password')
  450. self.assertTrue(login, 'Could not log in')
  451. # Request a page that requires a login
  452. response = self.client.get('/login_protected_method_view/')
  453. self.assertEqual(response.status_code, 200)
  454. self.assertEqual(response.context['user'].username, 'testclient')
  455. def test_view_with_method_force_login(self):
  456. "Request a page that is protected with a @login_required method"
  457. # Get the page without logging in. Should result in 302.
  458. response = self.client.get('/login_protected_method_view/')
  459. self.assertRedirects(response, '/accounts/login/?next=/login_protected_method_view/')
  460. # Log in
  461. self.client.force_login(self.u1)
  462. # Request a page that requires a login
  463. response = self.client.get('/login_protected_method_view/')
  464. self.assertEqual(response.status_code, 200)
  465. self.assertEqual(response.context['user'].username, 'testclient')
  466. def test_view_with_login_and_custom_redirect(self):
  467. "Request a page that is protected with @login_required(redirect_field_name='redirect_to')"
  468. # Get the page without logging in. Should result in 302.
  469. response = self.client.get('/login_protected_view_custom_redirect/')
  470. self.assertRedirects(response, '/accounts/login/?redirect_to=/login_protected_view_custom_redirect/')
  471. # Log in
  472. login = self.client.login(username='testclient', password='password')
  473. self.assertTrue(login, 'Could not log in')
  474. # Request a page that requires a login
  475. response = self.client.get('/login_protected_view_custom_redirect/')
  476. self.assertEqual(response.status_code, 200)
  477. self.assertEqual(response.context['user'].username, 'testclient')
  478. def test_view_with_force_login_and_custom_redirect(self):
  479. """
  480. Request a page that is protected with
  481. @login_required(redirect_field_name='redirect_to')
  482. """
  483. # Get the page without logging in. Should result in 302.
  484. response = self.client.get('/login_protected_view_custom_redirect/')
  485. self.assertRedirects(response, '/accounts/login/?redirect_to=/login_protected_view_custom_redirect/')
  486. # Log in
  487. self.client.force_login(self.u1)
  488. # Request a page that requires a login
  489. response = self.client.get('/login_protected_view_custom_redirect/')
  490. self.assertEqual(response.status_code, 200)
  491. self.assertEqual(response.context['user'].username, 'testclient')
  492. def test_view_with_bad_login(self):
  493. "Request a page that is protected with @login, but use bad credentials"
  494. login = self.client.login(username='otheruser', password='nopassword')
  495. self.assertFalse(login)
  496. def test_view_with_inactive_login(self):
  497. """
  498. An inactive user may login if the authenticate backend allows it.
  499. """
  500. credentials = {'username': 'inactive', 'password': 'password'}
  501. self.assertFalse(self.client.login(**credentials))
  502. with self.settings(AUTHENTICATION_BACKENDS=['django.contrib.auth.backends.AllowAllUsersModelBackend']):
  503. self.assertTrue(self.client.login(**credentials))
  504. @override_settings(
  505. AUTHENTICATION_BACKENDS=[
  506. 'django.contrib.auth.backends.ModelBackend',
  507. 'django.contrib.auth.backends.AllowAllUsersModelBackend',
  508. ]
  509. )
  510. def test_view_with_inactive_force_login(self):
  511. "Request a page that is protected with @login, but use an inactive login"
  512. # Get the page without logging in. Should result in 302.
  513. response = self.client.get('/login_protected_view/')
  514. self.assertRedirects(response, '/accounts/login/?next=/login_protected_view/')
  515. # Log in
  516. self.client.force_login(self.u2, backend='django.contrib.auth.backends.AllowAllUsersModelBackend')
  517. # Request a page that requires a login
  518. response = self.client.get('/login_protected_view/')
  519. self.assertEqual(response.status_code, 200)
  520. self.assertEqual(response.context['user'].username, 'inactive')
  521. def test_logout(self):
  522. "Request a logout after logging in"
  523. # Log in
  524. self.client.login(username='testclient', password='password')
  525. # Request a page that requires a login
  526. response = self.client.get('/login_protected_view/')
  527. self.assertEqual(response.status_code, 200)
  528. self.assertEqual(response.context['user'].username, 'testclient')
  529. # Log out
  530. self.client.logout()
  531. # Request a page that requires a login
  532. response = self.client.get('/login_protected_view/')
  533. self.assertRedirects(response, '/accounts/login/?next=/login_protected_view/')
  534. def test_logout_with_force_login(self):
  535. "Request a logout after logging in"
  536. # Log in
  537. self.client.force_login(self.u1)
  538. # Request a page that requires a login
  539. response = self.client.get('/login_protected_view/')
  540. self.assertEqual(response.status_code, 200)
  541. self.assertEqual(response.context['user'].username, 'testclient')
  542. # Log out
  543. self.client.logout()
  544. # Request a page that requires a login
  545. response = self.client.get('/login_protected_view/')
  546. self.assertRedirects(response, '/accounts/login/?next=/login_protected_view/')
  547. @override_settings(
  548. AUTHENTICATION_BACKENDS=[
  549. 'django.contrib.auth.backends.ModelBackend',
  550. 'test_client.auth_backends.TestClientBackend',
  551. ],
  552. )
  553. def test_force_login_with_backend(self):
  554. """
  555. Request a page that is protected with @login_required when using
  556. force_login() and passing a backend.
  557. """
  558. # Get the page without logging in. Should result in 302.
  559. response = self.client.get('/login_protected_view/')
  560. self.assertRedirects(response, '/accounts/login/?next=/login_protected_view/')
  561. # Log in
  562. self.client.force_login(self.u1, backend='test_client.auth_backends.TestClientBackend')
  563. self.assertEqual(self.u1.backend, 'test_client.auth_backends.TestClientBackend')
  564. # Request a page that requires a login
  565. response = self.client.get('/login_protected_view/')
  566. self.assertEqual(response.status_code, 200)
  567. self.assertEqual(response.context['user'].username, 'testclient')
  568. @override_settings(
  569. AUTHENTICATION_BACKENDS=[
  570. 'django.contrib.auth.backends.ModelBackend',
  571. 'test_client.auth_backends.TestClientBackend',
  572. ],
  573. )
  574. def test_force_login_without_backend(self):
  575. """
  576. force_login() without passing a backend and with multiple backends
  577. configured should automatically use the first backend.
  578. """
  579. self.client.force_login(self.u1)
  580. response = self.client.get('/login_protected_view/')
  581. self.assertEqual(response.status_code, 200)
  582. self.assertEqual(response.context['user'].username, 'testclient')
  583. self.assertEqual(self.u1.backend, 'django.contrib.auth.backends.ModelBackend')
  584. @override_settings(AUTHENTICATION_BACKENDS=[
  585. 'test_client.auth_backends.BackendWithoutGetUserMethod',
  586. 'django.contrib.auth.backends.ModelBackend',
  587. ])
  588. def test_force_login_with_backend_missing_get_user(self):
  589. """
  590. force_login() skips auth backends without a get_user() method.
  591. """
  592. self.client.force_login(self.u1)
  593. self.assertEqual(self.u1.backend, 'django.contrib.auth.backends.ModelBackend')
  594. @override_settings(SESSION_ENGINE="django.contrib.sessions.backends.signed_cookies")
  595. def test_logout_cookie_sessions(self):
  596. self.test_logout()
  597. def test_view_with_permissions(self):
  598. "Request a page that is protected with @permission_required"
  599. # Get the page without logging in. Should result in 302.
  600. response = self.client.get('/permission_protected_view/')
  601. self.assertRedirects(response, '/accounts/login/?next=/permission_protected_view/')
  602. # Log in
  603. login = self.client.login(username='testclient', password='password')
  604. self.assertTrue(login, 'Could not log in')
  605. # Log in with wrong permissions. Should result in 302.
  606. response = self.client.get('/permission_protected_view/')
  607. self.assertRedirects(response, '/accounts/login/?next=/permission_protected_view/')
  608. # TODO: Log in with right permissions and request the page again
  609. def test_view_with_permissions_exception(self):
  610. "Request a page that is protected with @permission_required but raises an exception"
  611. # Get the page without logging in. Should result in 403.
  612. response = self.client.get('/permission_protected_view_exception/')
  613. self.assertEqual(response.status_code, 403)
  614. # Log in
  615. login = self.client.login(username='testclient', password='password')
  616. self.assertTrue(login, 'Could not log in')
  617. # Log in with wrong permissions. Should result in 403.
  618. response = self.client.get('/permission_protected_view_exception/')
  619. self.assertEqual(response.status_code, 403)
  620. def test_view_with_method_permissions(self):
  621. "Request a page that is protected with a @permission_required method"
  622. # Get the page without logging in. Should result in 302.
  623. response = self.client.get('/permission_protected_method_view/')
  624. self.assertRedirects(response, '/accounts/login/?next=/permission_protected_method_view/')
  625. # Log in
  626. login = self.client.login(username='testclient', password='password')
  627. self.assertTrue(login, 'Could not log in')
  628. # Log in with wrong permissions. Should result in 302.
  629. response = self.client.get('/permission_protected_method_view/')
  630. self.assertRedirects(response, '/accounts/login/?next=/permission_protected_method_view/')
  631. # TODO: Log in with right permissions and request the page again
  632. def test_external_redirect(self):
  633. response = self.client.get('/django_project_redirect/')
  634. self.assertRedirects(response, 'https://www.djangoproject.com/', fetch_redirect_response=False)
  635. def test_external_redirect_without_trailing_slash(self):
  636. """
  637. Client._handle_redirects() with an empty path.
  638. """
  639. response = self.client.get('/no_trailing_slash_external_redirect/', follow=True)
  640. self.assertRedirects(response, 'https://testserver')
  641. def test_external_redirect_with_fetch_error_msg(self):
  642. """
  643. assertRedirects without fetch_redirect_response=False raises
  644. a relevant ValueError rather than a non-descript AssertionError.
  645. """
  646. response = self.client.get('/django_project_redirect/')
  647. msg = (
  648. "The test client is unable to fetch remote URLs (got "
  649. "https://www.djangoproject.com/). If the host is served by Django, "
  650. "add 'www.djangoproject.com' to ALLOWED_HOSTS. "
  651. "Otherwise, use assertRedirects(..., fetch_redirect_response=False)."
  652. )
  653. with self.assertRaisesMessage(ValueError, msg):
  654. self.assertRedirects(response, 'https://www.djangoproject.com/')
  655. def test_session_modifying_view(self):
  656. "Request a page that modifies the session"
  657. # Session value isn't set initially
  658. with self.assertRaises(KeyError):
  659. self.client.session['tobacconist']
  660. self.client.post('/session_view/')
  661. # The session was modified
  662. self.assertEqual(self.client.session['tobacconist'], 'hovercraft')
  663. @override_settings(
  664. INSTALLED_APPS=[],
  665. SESSION_ENGINE='django.contrib.sessions.backends.file',
  666. )
  667. def test_sessions_app_is_not_installed(self):
  668. self.test_session_modifying_view()
  669. @override_settings(
  670. INSTALLED_APPS=[],
  671. SESSION_ENGINE='django.contrib.sessions.backends.nonexistent',
  672. )
  673. def test_session_engine_is_invalid(self):
  674. with self.assertRaisesMessage(ImportError, 'nonexistent'):
  675. self.test_session_modifying_view()
  676. def test_view_with_exception(self):
  677. "Request a page that is known to throw an error"
  678. with self.assertRaises(KeyError):
  679. self.client.get("/broken_view/")
  680. def test_exc_info(self):
  681. client = Client(raise_request_exception=False)
  682. response = client.get("/broken_view/")
  683. self.assertEqual(response.status_code, 500)
  684. exc_type, exc_value, exc_traceback = response.exc_info
  685. self.assertIs(exc_type, KeyError)
  686. self.assertIsInstance(exc_value, KeyError)
  687. self.assertEqual(str(exc_value), "'Oops! Looks like you wrote some bad code.'")
  688. self.assertIsNotNone(exc_traceback)
  689. def test_exc_info_none(self):
  690. response = self.client.get("/get_view/")
  691. self.assertIsNone(response.exc_info)
  692. def test_mail_sending(self):
  693. "Mail is redirected to a dummy outbox during test setup"
  694. response = self.client.get('/mail_sending_view/')
  695. self.assertEqual(response.status_code, 200)
  696. self.assertEqual(len(mail.outbox), 1)
  697. self.assertEqual(mail.outbox[0].subject, 'Test message')
  698. self.assertEqual(mail.outbox[0].body, 'This is a test email')
  699. self.assertEqual(mail.outbox[0].from_email, 'from@example.com')
  700. self.assertEqual(mail.outbox[0].to[0], 'first@example.com')
  701. self.assertEqual(mail.outbox[0].to[1], 'second@example.com')
  702. def test_reverse_lazy_decodes(self):
  703. "reverse_lazy() works in the test client"
  704. data = {'var': 'data'}
  705. response = self.client.get(reverse_lazy('get_view'), data)
  706. # Check some response details
  707. self.assertContains(response, 'This is a test')
  708. def test_relative_redirect(self):
  709. response = self.client.get('/accounts/')
  710. self.assertRedirects(response, '/accounts/login/')
  711. def test_relative_redirect_no_trailing_slash(self):
  712. response = self.client.get('/accounts/no_trailing_slash')
  713. self.assertRedirects(response, '/accounts/login/')
  714. def test_mass_mail_sending(self):
  715. "Mass mail is redirected to a dummy outbox during test setup"
  716. response = self.client.get('/mass_mail_sending_view/')
  717. self.assertEqual(response.status_code, 200)
  718. self.assertEqual(len(mail.outbox), 2)
  719. self.assertEqual(mail.outbox[0].subject, 'First Test message')
  720. self.assertEqual(mail.outbox[0].body, 'This is the first test email')
  721. self.assertEqual(mail.outbox[0].from_email, 'from@example.com')
  722. self.assertEqual(mail.outbox[0].to[0], 'first@example.com')
  723. self.assertEqual(mail.outbox[0].to[1], 'second@example.com')
  724. self.assertEqual(mail.outbox[1].subject, 'Second Test message')
  725. self.assertEqual(mail.outbox[1].body, 'This is the second test email')
  726. self.assertEqual(mail.outbox[1].from_email, 'from@example.com')
  727. self.assertEqual(mail.outbox[1].to[0], 'second@example.com')
  728. self.assertEqual(mail.outbox[1].to[1], 'third@example.com')
  729. def test_exception_following_nested_client_request(self):
  730. """
  731. A nested test client request shouldn't clobber exception signals from
  732. the outer client request.
  733. """
  734. with self.assertRaisesMessage(Exception, 'exception message'):
  735. self.client.get('/nesting_exception_view/')
  736. def test_response_raises_multi_arg_exception(self):
  737. """A request may raise an exception with more than one required arg."""
  738. with self.assertRaises(TwoArgException) as cm:
  739. self.client.get('/two_arg_exception/')
  740. self.assertEqual(cm.exception.args, ('one', 'two'))
  741. def test_uploading_temp_file(self):
  742. with tempfile.TemporaryFile() as test_file:
  743. response = self.client.post('/upload_view/', data={'temp_file': test_file})
  744. self.assertEqual(response.content, b'temp_file')
  745. def test_uploading_named_temp_file(self):
  746. with tempfile.NamedTemporaryFile() as test_file:
  747. response = self.client.post(
  748. '/upload_view/',
  749. data={'named_temp_file': test_file},
  750. )
  751. self.assertEqual(response.content, b'named_temp_file')
  752. @override_settings(
  753. MIDDLEWARE=['django.middleware.csrf.CsrfViewMiddleware'],
  754. ROOT_URLCONF='test_client.urls',
  755. )
  756. class CSRFEnabledClientTests(SimpleTestCase):
  757. def test_csrf_enabled_client(self):
  758. "A client can be instantiated with CSRF checks enabled"
  759. csrf_client = Client(enforce_csrf_checks=True)
  760. # The normal client allows the post
  761. response = self.client.post('/post_view/', {})
  762. self.assertEqual(response.status_code, 200)
  763. # The CSRF-enabled client rejects it
  764. response = csrf_client.post('/post_view/', {})
  765. self.assertEqual(response.status_code, 403)
  766. class CustomTestClient(Client):
  767. i_am_customized = "Yes"
  768. class CustomTestClientTest(SimpleTestCase):
  769. client_class = CustomTestClient
  770. def test_custom_test_client(self):
  771. """A test case can specify a custom class for self.client."""
  772. self.assertIs(hasattr(self.client, "i_am_customized"), True)
  773. def _generic_view(request):
  774. return HttpResponse(status=200)
  775. @override_settings(ROOT_URLCONF='test_client.urls')
  776. class RequestFactoryTest(SimpleTestCase):
  777. """Tests for the request factory."""
  778. # A mapping between names of HTTP/1.1 methods and their test views.
  779. http_methods_and_views = (
  780. ('get', get_view),
  781. ('post', post_view),
  782. ('put', _generic_view),
  783. ('patch', _generic_view),
  784. ('delete', _generic_view),
  785. ('head', _generic_view),
  786. ('options', _generic_view),
  787. ('trace', trace_view),
  788. )
  789. request_factory = RequestFactory()
  790. def test_request_factory(self):
  791. """The request factory implements all the HTTP/1.1 methods."""
  792. for method_name, view in self.http_methods_and_views:
  793. method = getattr(self.request_factory, method_name)
  794. request = method('/somewhere/')
  795. response = view(request)
  796. self.assertEqual(response.status_code, 200)
  797. def test_get_request_from_factory(self):
  798. """
  799. The request factory returns a templated response for a GET request.
  800. """
  801. request = self.request_factory.get('/somewhere/')
  802. response = get_view(request)
  803. self.assertContains(response, 'This is a test')
  804. def test_trace_request_from_factory(self):
  805. """The request factory returns an echo response for a TRACE request."""
  806. url_path = '/somewhere/'
  807. request = self.request_factory.trace(url_path)
  808. response = trace_view(request)
  809. protocol = request.META["SERVER_PROTOCOL"]
  810. echoed_request_line = "TRACE {} {}".format(url_path, protocol)
  811. self.assertContains(response, echoed_request_line)
  812. @override_settings(ROOT_URLCONF='test_client.urls')
  813. class AsyncClientTest(TestCase):
  814. async def test_response_resolver_match(self):
  815. response = await self.async_client.get('/async_get_view/')
  816. self.assertTrue(hasattr(response, 'resolver_match'))
  817. self.assertEqual(response.resolver_match.url_name, 'async_get_view')
  818. @modify_settings(
  819. MIDDLEWARE={'prepend': 'test_client.tests.async_middleware_urlconf'},
  820. )
  821. async def test_response_resolver_match_middleware_urlconf(self):
  822. response = await self.async_client.get('/middleware_urlconf_view/')
  823. self.assertEqual(response.resolver_match.url_name, 'middleware_urlconf_view')
  824. async def test_follow_parameter_not_implemented(self):
  825. msg = 'AsyncClient request methods do not accept the follow parameter.'
  826. tests = (
  827. 'get',
  828. 'post',
  829. 'put',
  830. 'patch',
  831. 'delete',
  832. 'head',
  833. 'options',
  834. 'trace',
  835. )
  836. for method_name in tests:
  837. with self.subTest(method=method_name):
  838. method = getattr(self.async_client, method_name)
  839. with self.assertRaisesMessage(NotImplementedError, msg):
  840. await method('/redirect_view/', follow=True)
  841. async def test_get_data(self):
  842. response = await self.async_client.get('/get_view/', {'var': 'val'})
  843. self.assertContains(response, 'This is a test. val is the value.')
  844. @override_settings(ROOT_URLCONF='test_client.urls')
  845. class AsyncRequestFactoryTest(SimpleTestCase):
  846. request_factory = AsyncRequestFactory()
  847. async def test_request_factory(self):
  848. tests = (
  849. 'get',
  850. 'post',
  851. 'put',
  852. 'patch',
  853. 'delete',
  854. 'head',
  855. 'options',
  856. 'trace',
  857. )
  858. for method_name in tests:
  859. with self.subTest(method=method_name):
  860. async def async_generic_view(request):
  861. if request.method.lower() != method_name:
  862. return HttpResponseNotAllowed(method_name)
  863. return HttpResponse(status=200)
  864. method = getattr(self.request_factory, method_name)
  865. request = method('/somewhere/')
  866. response = await async_generic_view(request)
  867. self.assertEqual(response.status_code, 200)
  868. async def test_request_factory_data(self):
  869. async def async_generic_view(request):
  870. return HttpResponse(status=200, content=request.body)
  871. request = self.request_factory.post(
  872. '/somewhere/',
  873. data={'example': 'data'},
  874. content_type='application/json',
  875. )
  876. self.assertEqual(request.headers['content-length'], '19')
  877. self.assertEqual(request.headers['content-type'], 'application/json')
  878. response = await async_generic_view(request)
  879. self.assertEqual(response.status_code, 200)
  880. self.assertEqual(response.content, b'{"example": "data"}')
  881. def test_request_factory_sets_headers(self):
  882. request = self.request_factory.get(
  883. '/somewhere/',
  884. AUTHORIZATION='Bearer faketoken',
  885. X_ANOTHER_HEADER='some other value',
  886. )
  887. self.assertEqual(request.headers['authorization'], 'Bearer faketoken')
  888. self.assertIn('HTTP_AUTHORIZATION', request.META)
  889. self.assertEqual(request.headers['x-another-header'], 'some other value')
  890. self.assertIn('HTTP_X_ANOTHER_HEADER', request.META)
  891. def test_request_factory_query_string(self):
  892. request = self.request_factory.get('/somewhere/', {'example': 'data'})
  893. self.assertNotIn('Query-String', request.headers)
  894. self.assertEqual(request.GET['example'], 'data')