tests.py 366 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248224922502251225222532254225522562257225822592260226122622263226422652266226722682269227022712272227322742275227622772278227922802281228222832284228522862287228822892290229122922293229422952296229722982299230023012302230323042305230623072308230923102311231223132314231523162317231823192320232123222323232423252326232723282329233023312332233323342335233623372338233923402341234223432344234523462347234823492350235123522353235423552356235723582359236023612362236323642365236623672368236923702371237223732374237523762377237823792380238123822383238423852386238723882389239023912392239323942395239623972398239924002401240224032404240524062407240824092410241124122413241424152416241724182419242024212422242324242425242624272428242924302431243224332434243524362437243824392440244124422443244424452446244724482449245024512452245324542455245624572458245924602461246224632464246524662467246824692470247124722473247424752476247724782479248024812482248324842485248624872488248924902491249224932494249524962497249824992500250125022503250425052506250725082509251025112512251325142515251625172518251925202521252225232524252525262527252825292530253125322533253425352536253725382539254025412542254325442545254625472548254925502551255225532554255525562557255825592560256125622563256425652566256725682569257025712572257325742575257625772578257925802581258225832584258525862587258825892590259125922593259425952596259725982599260026012602260326042605260626072608260926102611261226132614261526162617261826192620262126222623262426252626262726282629263026312632263326342635263626372638263926402641264226432644264526462647264826492650265126522653265426552656265726582659266026612662266326642665266626672668266926702671267226732674267526762677267826792680268126822683268426852686268726882689269026912692269326942695269626972698269927002701270227032704270527062707270827092710271127122713271427152716271727182719272027212722272327242725272627272728272927302731273227332734273527362737273827392740274127422743274427452746274727482749275027512752275327542755275627572758275927602761276227632764276527662767276827692770277127722773277427752776277727782779278027812782278327842785278627872788278927902791279227932794279527962797279827992800280128022803280428052806280728082809281028112812281328142815281628172818281928202821282228232824282528262827282828292830283128322833283428352836283728382839284028412842284328442845284628472848284928502851285228532854285528562857285828592860286128622863286428652866286728682869287028712872287328742875287628772878287928802881288228832884288528862887288828892890289128922893289428952896289728982899290029012902290329042905290629072908290929102911291229132914291529162917291829192920292129222923292429252926292729282929293029312932293329342935293629372938293929402941294229432944294529462947294829492950295129522953295429552956295729582959296029612962296329642965296629672968296929702971297229732974297529762977297829792980298129822983298429852986298729882989299029912992299329942995299629972998299930003001300230033004300530063007300830093010301130123013301430153016301730183019302030213022302330243025302630273028302930303031303230333034303530363037303830393040304130423043304430453046304730483049305030513052305330543055305630573058305930603061306230633064306530663067306830693070307130723073307430753076307730783079308030813082308330843085308630873088308930903091309230933094309530963097309830993100310131023103310431053106310731083109311031113112311331143115311631173118311931203121312231233124312531263127312831293130313131323133313431353136313731383139314031413142314331443145314631473148314931503151315231533154315531563157315831593160316131623163316431653166316731683169317031713172317331743175317631773178317931803181318231833184318531863187318831893190319131923193319431953196319731983199320032013202320332043205320632073208320932103211321232133214321532163217321832193220322132223223322432253226322732283229323032313232323332343235323632373238323932403241324232433244324532463247324832493250325132523253325432553256325732583259326032613262326332643265326632673268326932703271327232733274327532763277327832793280328132823283328432853286328732883289329032913292329332943295329632973298329933003301330233033304330533063307330833093310331133123313331433153316331733183319332033213322332333243325332633273328332933303331333233333334333533363337333833393340334133423343334433453346334733483349335033513352335333543355335633573358335933603361336233633364336533663367336833693370337133723373337433753376337733783379338033813382338333843385338633873388338933903391339233933394339533963397339833993400340134023403340434053406340734083409341034113412341334143415341634173418341934203421342234233424342534263427342834293430343134323433343434353436343734383439344034413442344334443445344634473448344934503451345234533454345534563457345834593460346134623463346434653466346734683469347034713472347334743475347634773478347934803481348234833484348534863487348834893490349134923493349434953496349734983499350035013502350335043505350635073508350935103511351235133514351535163517351835193520352135223523352435253526352735283529353035313532353335343535353635373538353935403541354235433544354535463547354835493550355135523553355435553556355735583559356035613562356335643565356635673568356935703571357235733574357535763577357835793580358135823583358435853586358735883589359035913592359335943595359635973598359936003601360236033604360536063607360836093610361136123613361436153616361736183619362036213622362336243625362636273628362936303631363236333634363536363637363836393640364136423643364436453646364736483649365036513652365336543655365636573658365936603661366236633664366536663667366836693670367136723673367436753676367736783679368036813682368336843685368636873688368936903691369236933694369536963697369836993700370137023703370437053706370737083709371037113712371337143715371637173718371937203721372237233724372537263727372837293730373137323733373437353736373737383739374037413742374337443745374637473748374937503751375237533754375537563757375837593760376137623763376437653766376737683769377037713772377337743775377637773778377937803781378237833784378537863787378837893790379137923793379437953796379737983799380038013802380338043805380638073808380938103811381238133814381538163817381838193820382138223823382438253826382738283829383038313832383338343835383638373838383938403841384238433844384538463847384838493850385138523853385438553856385738583859386038613862386338643865386638673868386938703871387238733874387538763877387838793880388138823883388438853886388738883889389038913892389338943895389638973898389939003901390239033904390539063907390839093910391139123913391439153916391739183919392039213922392339243925392639273928392939303931393239333934393539363937393839393940394139423943394439453946394739483949395039513952395339543955395639573958395939603961396239633964396539663967396839693970397139723973397439753976397739783979398039813982398339843985398639873988398939903991399239933994399539963997399839994000400140024003400440054006400740084009401040114012401340144015401640174018401940204021402240234024402540264027402840294030403140324033403440354036403740384039404040414042404340444045404640474048404940504051405240534054405540564057405840594060406140624063406440654066406740684069407040714072407340744075407640774078407940804081408240834084408540864087408840894090409140924093409440954096409740984099410041014102410341044105410641074108410941104111411241134114411541164117411841194120412141224123412441254126412741284129413041314132413341344135413641374138413941404141414241434144414541464147414841494150415141524153415441554156415741584159416041614162416341644165416641674168416941704171417241734174417541764177417841794180418141824183418441854186418741884189419041914192419341944195419641974198419942004201420242034204420542064207420842094210421142124213421442154216421742184219422042214222422342244225422642274228422942304231423242334234423542364237423842394240424142424243424442454246424742484249425042514252425342544255425642574258425942604261426242634264426542664267426842694270427142724273427442754276427742784279428042814282428342844285428642874288428942904291429242934294429542964297429842994300430143024303430443054306430743084309431043114312431343144315431643174318431943204321432243234324432543264327432843294330433143324333433443354336433743384339434043414342434343444345434643474348434943504351435243534354435543564357435843594360436143624363436443654366436743684369437043714372437343744375437643774378437943804381438243834384438543864387438843894390439143924393439443954396439743984399440044014402440344044405440644074408440944104411441244134414441544164417441844194420442144224423442444254426442744284429443044314432443344344435443644374438443944404441444244434444444544464447444844494450445144524453445444554456445744584459446044614462446344644465446644674468446944704471447244734474447544764477447844794480448144824483448444854486448744884489449044914492449344944495449644974498449945004501450245034504450545064507450845094510451145124513451445154516451745184519452045214522452345244525452645274528452945304531453245334534453545364537453845394540454145424543454445454546454745484549455045514552455345544555455645574558455945604561456245634564456545664567456845694570457145724573457445754576457745784579458045814582458345844585458645874588458945904591459245934594459545964597459845994600460146024603460446054606460746084609461046114612461346144615461646174618461946204621462246234624462546264627462846294630463146324633463446354636463746384639464046414642464346444645464646474648464946504651465246534654465546564657465846594660466146624663466446654666466746684669467046714672467346744675467646774678467946804681468246834684468546864687468846894690469146924693469446954696469746984699470047014702470347044705470647074708470947104711471247134714471547164717471847194720472147224723472447254726472747284729473047314732473347344735473647374738473947404741474247434744474547464747474847494750475147524753475447554756475747584759476047614762476347644765476647674768476947704771477247734774477547764777477847794780478147824783478447854786478747884789479047914792479347944795479647974798479948004801480248034804480548064807480848094810481148124813481448154816481748184819482048214822482348244825482648274828482948304831483248334834483548364837483848394840484148424843484448454846484748484849485048514852485348544855485648574858485948604861486248634864486548664867486848694870487148724873487448754876487748784879488048814882488348844885488648874888488948904891489248934894489548964897489848994900490149024903490449054906490749084909491049114912491349144915491649174918491949204921492249234924492549264927492849294930493149324933493449354936493749384939494049414942494349444945494649474948494949504951495249534954495549564957495849594960496149624963496449654966496749684969497049714972497349744975497649774978497949804981498249834984498549864987498849894990499149924993499449954996499749984999500050015002500350045005500650075008500950105011501250135014501550165017501850195020502150225023502450255026502750285029503050315032503350345035503650375038503950405041504250435044504550465047504850495050505150525053505450555056505750585059506050615062506350645065506650675068506950705071507250735074507550765077507850795080508150825083508450855086508750885089509050915092509350945095509650975098509951005101510251035104510551065107510851095110511151125113511451155116511751185119512051215122512351245125512651275128512951305131513251335134513551365137513851395140514151425143514451455146514751485149515051515152515351545155515651575158515951605161516251635164516551665167516851695170517151725173517451755176517751785179518051815182518351845185518651875188518951905191519251935194519551965197519851995200520152025203520452055206520752085209521052115212521352145215521652175218521952205221522252235224522552265227522852295230523152325233523452355236523752385239524052415242524352445245524652475248524952505251525252535254525552565257525852595260526152625263526452655266526752685269527052715272527352745275527652775278527952805281528252835284528552865287528852895290529152925293529452955296529752985299530053015302530353045305530653075308530953105311531253135314531553165317531853195320532153225323532453255326532753285329533053315332533353345335533653375338533953405341534253435344534553465347534853495350535153525353535453555356535753585359536053615362536353645365536653675368536953705371537253735374537553765377537853795380538153825383538453855386538753885389539053915392539353945395539653975398539954005401540254035404540554065407540854095410541154125413541454155416541754185419542054215422542354245425542654275428542954305431543254335434543554365437543854395440544154425443544454455446544754485449545054515452545354545455545654575458545954605461546254635464546554665467546854695470547154725473547454755476547754785479548054815482548354845485548654875488548954905491549254935494549554965497549854995500550155025503550455055506550755085509551055115512551355145515551655175518551955205521552255235524552555265527552855295530553155325533553455355536553755385539554055415542554355445545554655475548554955505551555255535554555555565557555855595560556155625563556455655566556755685569557055715572557355745575557655775578557955805581558255835584558555865587558855895590559155925593559455955596559755985599560056015602560356045605560656075608560956105611561256135614561556165617561856195620562156225623562456255626562756285629563056315632563356345635563656375638563956405641564256435644564556465647564856495650565156525653565456555656565756585659566056615662566356645665566656675668566956705671567256735674567556765677567856795680568156825683568456855686568756885689569056915692569356945695569656975698569957005701570257035704570557065707570857095710571157125713571457155716571757185719572057215722572357245725572657275728572957305731573257335734573557365737573857395740574157425743574457455746574757485749575057515752575357545755575657575758575957605761576257635764576557665767576857695770577157725773577457755776577757785779578057815782578357845785578657875788578957905791579257935794579557965797579857995800580158025803580458055806580758085809581058115812581358145815581658175818581958205821582258235824582558265827582858295830583158325833583458355836583758385839584058415842584358445845584658475848584958505851585258535854585558565857585858595860586158625863586458655866586758685869587058715872587358745875587658775878587958805881588258835884588558865887588858895890589158925893589458955896589758985899590059015902590359045905590659075908590959105911591259135914591559165917591859195920592159225923592459255926592759285929593059315932593359345935593659375938593959405941594259435944594559465947594859495950595159525953595459555956595759585959596059615962596359645965596659675968596959705971597259735974597559765977597859795980598159825983598459855986598759885989599059915992599359945995599659975998599960006001600260036004600560066007600860096010601160126013601460156016601760186019602060216022602360246025602660276028602960306031603260336034603560366037603860396040604160426043604460456046604760486049605060516052605360546055605660576058605960606061606260636064606560666067606860696070607160726073607460756076607760786079608060816082608360846085608660876088608960906091609260936094609560966097609860996100610161026103610461056106610761086109611061116112611361146115611661176118611961206121612261236124612561266127612861296130613161326133613461356136613761386139614061416142614361446145614661476148614961506151615261536154615561566157615861596160616161626163616461656166616761686169617061716172617361746175617661776178617961806181618261836184618561866187618861896190619161926193619461956196619761986199620062016202620362046205620662076208620962106211621262136214621562166217621862196220622162226223622462256226622762286229623062316232623362346235623662376238623962406241624262436244624562466247624862496250625162526253625462556256625762586259626062616262626362646265626662676268626962706271627262736274627562766277627862796280628162826283628462856286628762886289629062916292629362946295629662976298629963006301630263036304630563066307630863096310631163126313631463156316631763186319632063216322632363246325632663276328632963306331633263336334633563366337633863396340634163426343634463456346634763486349635063516352635363546355635663576358635963606361636263636364636563666367636863696370637163726373637463756376637763786379638063816382638363846385638663876388638963906391639263936394639563966397639863996400640164026403640464056406640764086409641064116412641364146415641664176418641964206421642264236424642564266427642864296430643164326433643464356436643764386439644064416442644364446445644664476448644964506451645264536454645564566457645864596460646164626463646464656466646764686469647064716472647364746475647664776478647964806481648264836484648564866487648864896490649164926493649464956496649764986499650065016502650365046505650665076508650965106511651265136514651565166517651865196520652165226523652465256526652765286529653065316532653365346535653665376538653965406541654265436544654565466547654865496550655165526553655465556556655765586559656065616562656365646565656665676568656965706571657265736574657565766577657865796580658165826583658465856586658765886589659065916592659365946595659665976598659966006601660266036604660566066607660866096610661166126613661466156616661766186619662066216622662366246625662666276628662966306631663266336634663566366637663866396640664166426643664466456646664766486649665066516652665366546655665666576658665966606661666266636664666566666667666866696670667166726673667466756676667766786679668066816682668366846685668666876688668966906691669266936694669566966697669866996700670167026703670467056706670767086709671067116712671367146715671667176718671967206721672267236724672567266727672867296730673167326733673467356736673767386739674067416742674367446745674667476748674967506751675267536754675567566757675867596760676167626763676467656766676767686769677067716772677367746775677667776778677967806781678267836784678567866787678867896790679167926793679467956796679767986799680068016802680368046805680668076808680968106811681268136814681568166817681868196820682168226823682468256826682768286829683068316832683368346835683668376838683968406841684268436844684568466847684868496850685168526853685468556856685768586859686068616862686368646865686668676868686968706871687268736874687568766877687868796880688168826883688468856886688768886889689068916892689368946895689668976898689969006901690269036904690569066907690869096910691169126913691469156916691769186919692069216922692369246925692669276928692969306931693269336934693569366937693869396940694169426943694469456946694769486949695069516952695369546955695669576958695969606961696269636964696569666967696869696970697169726973697469756976697769786979698069816982698369846985698669876988698969906991699269936994699569966997699869997000700170027003700470057006700770087009701070117012701370147015701670177018701970207021702270237024702570267027702870297030703170327033703470357036703770387039704070417042704370447045704670477048704970507051705270537054705570567057705870597060706170627063706470657066706770687069707070717072707370747075707670777078707970807081708270837084708570867087708870897090709170927093709470957096709770987099710071017102710371047105710671077108710971107111711271137114711571167117711871197120712171227123712471257126712771287129713071317132713371347135713671377138713971407141714271437144714571467147714871497150715171527153715471557156715771587159716071617162716371647165716671677168716971707171717271737174717571767177717871797180718171827183718471857186718771887189719071917192719371947195719671977198719972007201720272037204720572067207720872097210721172127213721472157216721772187219722072217222722372247225722672277228722972307231723272337234723572367237723872397240724172427243724472457246724772487249725072517252725372547255725672577258725972607261726272637264726572667267726872697270727172727273727472757276727772787279728072817282728372847285728672877288728972907291729272937294729572967297729872997300730173027303730473057306730773087309731073117312731373147315731673177318731973207321732273237324732573267327732873297330733173327333733473357336733773387339734073417342734373447345734673477348734973507351735273537354735573567357735873597360736173627363736473657366736773687369737073717372737373747375737673777378737973807381738273837384738573867387738873897390739173927393739473957396739773987399740074017402740374047405740674077408740974107411741274137414741574167417741874197420742174227423742474257426742774287429743074317432743374347435743674377438743974407441744274437444744574467447744874497450745174527453745474557456745774587459746074617462746374647465746674677468746974707471747274737474747574767477747874797480748174827483748474857486748774887489749074917492749374947495749674977498749975007501750275037504750575067507750875097510751175127513751475157516751775187519752075217522752375247525752675277528752975307531753275337534753575367537753875397540754175427543754475457546754775487549755075517552755375547555755675577558755975607561756275637564756575667567756875697570757175727573757475757576757775787579758075817582758375847585758675877588758975907591759275937594759575967597759875997600760176027603760476057606760776087609761076117612761376147615761676177618761976207621762276237624762576267627762876297630763176327633763476357636763776387639764076417642764376447645764676477648764976507651765276537654765576567657765876597660766176627663766476657666766776687669767076717672767376747675767676777678767976807681768276837684768576867687768876897690769176927693769476957696769776987699770077017702770377047705770677077708770977107711771277137714771577167717771877197720772177227723772477257726772777287729773077317732773377347735773677377738773977407741774277437744774577467747774877497750775177527753775477557756775777587759776077617762776377647765776677677768776977707771777277737774777577767777777877797780778177827783778477857786778777887789779077917792779377947795779677977798779978007801780278037804780578067807780878097810781178127813781478157816781778187819782078217822782378247825782678277828782978307831783278337834783578367837783878397840784178427843784478457846784778487849785078517852785378547855785678577858785978607861786278637864786578667867786878697870787178727873787478757876787778787879788078817882788378847885788678877888788978907891789278937894789578967897789878997900790179027903790479057906790779087909791079117912791379147915791679177918791979207921792279237924792579267927792879297930793179327933793479357936793779387939794079417942794379447945794679477948794979507951795279537954795579567957795879597960796179627963796479657966796779687969797079717972797379747975797679777978797979807981798279837984798579867987798879897990799179927993799479957996799779987999800080018002800380048005800680078008800980108011801280138014801580168017801880198020802180228023802480258026802780288029803080318032803380348035803680378038803980408041804280438044804580468047804880498050805180528053805480558056805780588059806080618062806380648065806680678068806980708071807280738074807580768077807880798080808180828083808480858086808780888089809080918092809380948095809680978098809981008101810281038104810581068107810881098110811181128113811481158116811781188119812081218122812381248125812681278128812981308131813281338134813581368137813881398140814181428143814481458146814781488149815081518152815381548155815681578158815981608161816281638164816581668167816881698170817181728173817481758176817781788179818081818182818381848185818681878188818981908191819281938194819581968197819881998200820182028203820482058206820782088209821082118212821382148215821682178218821982208221822282238224822582268227822882298230823182328233823482358236823782388239824082418242824382448245824682478248824982508251825282538254825582568257825882598260826182628263826482658266826782688269827082718272827382748275827682778278827982808281828282838284828582868287828882898290829182928293829482958296829782988299830083018302830383048305830683078308830983108311831283138314831583168317831883198320832183228323832483258326832783288329833083318332833383348335833683378338833983408341834283438344834583468347834883498350835183528353835483558356835783588359836083618362836383648365836683678368836983708371837283738374837583768377837883798380838183828383838483858386838783888389839083918392839383948395839683978398839984008401840284038404840584068407840884098410841184128413841484158416841784188419842084218422842384248425842684278428842984308431843284338434843584368437843884398440844184428443844484458446844784488449845084518452845384548455845684578458845984608461846284638464846584668467846884698470847184728473847484758476847784788479848084818482848384848485848684878488848984908491849284938494849584968497849884998500850185028503850485058506850785088509851085118512851385148515851685178518851985208521852285238524852585268527852885298530853185328533853485358536853785388539854085418542854385448545854685478548854985508551855285538554855585568557855885598560856185628563856485658566856785688569857085718572857385748575857685778578857985808581858285838584858585868587858885898590859185928593859485958596859785988599860086018602860386048605860686078608860986108611861286138614861586168617861886198620862186228623862486258626862786288629863086318632863386348635863686378638863986408641864286438644864586468647864886498650865186528653865486558656865786588659866086618662866386648665866686678668866986708671867286738674867586768677867886798680868186828683868486858686868786888689869086918692869386948695869686978698869987008701870287038704870587068707870887098710871187128713871487158716871787188719872087218722872387248725872687278728872987308731873287338734873587368737873887398740874187428743874487458746874787488749875087518752875387548755875687578758875987608761876287638764876587668767876887698770877187728773877487758776877787788779878087818782878387848785878687878788878987908791879287938794879587968797879887998800880188028803880488058806880788088809881088118812881388148815881688178818881988208821882288238824882588268827882888298830883188328833883488358836883788388839884088418842884388448845884688478848884988508851885288538854885588568857885888598860886188628863886488658866886788688869887088718872887388748875887688778878887988808881888288838884888588868887888888898890889188928893889488958896889788988899890089018902890389048905890689078908890989108911891289138914891589168917891889198920892189228923892489258926892789288929893089318932893389348935893689378938893989408941894289438944894589468947894889498950895189528953895489558956895789588959896089618962896389648965896689678968896989708971897289738974897589768977897889798980898189828983898489858986898789888989899089918992899389948995899689978998899990009001900290039004900590069007900890099010901190129013901490159016901790189019902090219022902390249025902690279028902990309031903290339034903590369037903890399040904190429043904490459046904790489049905090519052
  1. import datetime
  2. import os
  3. import re
  4. import unittest
  5. import zoneinfo
  6. from unittest import mock
  7. from urllib.parse import parse_qsl, urljoin, urlsplit
  8. from django import forms
  9. from django.contrib import admin
  10. from django.contrib.admin import AdminSite, ModelAdmin
  11. from django.contrib.admin.helpers import ACTION_CHECKBOX_NAME
  12. from django.contrib.admin.models import ADDITION, DELETION, LogEntry
  13. from django.contrib.admin.options import TO_FIELD_VAR
  14. from django.contrib.admin.templatetags.admin_urls import add_preserved_filters
  15. from django.contrib.admin.tests import AdminSeleniumTestCase
  16. from django.contrib.admin.utils import quote
  17. from django.contrib.admin.views.main import IS_POPUP_VAR
  18. from django.contrib.auth import REDIRECT_FIELD_NAME, get_permission_codename
  19. from django.contrib.auth.admin import UserAdmin
  20. from django.contrib.auth.forms import AdminPasswordChangeForm
  21. from django.contrib.auth.models import Group, Permission, User
  22. from django.contrib.contenttypes.models import ContentType
  23. from django.core import mail
  24. from django.core.checks import Error
  25. from django.core.files import temp as tempfile
  26. from django.db import connection
  27. from django.forms.utils import ErrorList
  28. from django.template.response import TemplateResponse
  29. from django.test import (
  30. RequestFactory,
  31. TestCase,
  32. ignore_warnings,
  33. modify_settings,
  34. override_settings,
  35. skipUnlessDBFeature,
  36. )
  37. from django.test.selenium import screenshot_cases
  38. from django.test.utils import override_script_prefix
  39. from django.urls import NoReverseMatch, resolve, reverse
  40. from django.utils import formats, translation
  41. from django.utils.cache import get_max_age
  42. from django.utils.deprecation import RemovedInDjango60Warning
  43. from django.utils.encoding import iri_to_uri
  44. from django.utils.html import escape
  45. from django.utils.http import urlencode
  46. from . import customadmin
  47. from .admin import CityAdmin, site, site2
  48. from .models import (
  49. Actor,
  50. AdminOrderedAdminMethod,
  51. AdminOrderedCallable,
  52. AdminOrderedField,
  53. AdminOrderedModelMethod,
  54. Album,
  55. Answer,
  56. Answer2,
  57. Article,
  58. BarAccount,
  59. Book,
  60. Bookmark,
  61. Box,
  62. Category,
  63. Chapter,
  64. ChapterXtra1,
  65. ChapterXtra2,
  66. Character,
  67. Child,
  68. Choice,
  69. City,
  70. Collector,
  71. Color,
  72. ComplexSortedPerson,
  73. CoverLetter,
  74. CustomArticle,
  75. CyclicOne,
  76. CyclicTwo,
  77. DooHickey,
  78. Employee,
  79. EmptyModel,
  80. Fabric,
  81. FancyDoodad,
  82. FieldOverridePost,
  83. FilteredManager,
  84. FooAccount,
  85. FoodDelivery,
  86. FunkyTag,
  87. Gallery,
  88. Grommet,
  89. Inquisition,
  90. Language,
  91. Link,
  92. MainPrepopulated,
  93. Media,
  94. ModelWithStringPrimaryKey,
  95. OtherStory,
  96. Paper,
  97. Parent,
  98. ParentWithDependentChildren,
  99. ParentWithUUIDPK,
  100. Person,
  101. Persona,
  102. Picture,
  103. Pizza,
  104. Plot,
  105. PlotDetails,
  106. PluggableSearchPerson,
  107. Podcast,
  108. Post,
  109. PrePopulatedPost,
  110. Promo,
  111. Question,
  112. ReadablePizza,
  113. ReadOnlyPizza,
  114. ReadOnlyRelatedField,
  115. Recommendation,
  116. Recommender,
  117. RelatedPrepopulated,
  118. RelatedWithUUIDPKModel,
  119. Report,
  120. Restaurant,
  121. RowLevelChangePermissionModel,
  122. SecretHideout,
  123. Section,
  124. ShortMessage,
  125. Simple,
  126. Song,
  127. State,
  128. Story,
  129. SuperSecretHideout,
  130. SuperVillain,
  131. Telegram,
  132. TitleTranslation,
  133. Topping,
  134. Traveler,
  135. UnchangeableObject,
  136. UndeletableObject,
  137. UnorderedObject,
  138. UserProxy,
  139. Villain,
  140. Vodcast,
  141. Whatsit,
  142. Widget,
  143. Worker,
  144. WorkHour,
  145. )
  146. ERROR_MESSAGE = "Please enter the correct username and password \
  147. for a staff account. Note that both fields may be case-sensitive."
  148. MULTIPART_ENCTYPE = 'enctype="multipart/form-data"'
  149. def make_aware_datetimes(dt, iana_key):
  150. """Makes one aware datetime for each supported time zone provider."""
  151. yield dt.replace(tzinfo=zoneinfo.ZoneInfo(iana_key))
  152. class AdminFieldExtractionMixin:
  153. """
  154. Helper methods for extracting data from AdminForm.
  155. """
  156. def get_admin_form_fields(self, response):
  157. """
  158. Return a list of AdminFields for the AdminForm in the response.
  159. """
  160. fields = []
  161. for fieldset in response.context["adminform"]:
  162. for field_line in fieldset:
  163. fields.extend(field_line)
  164. return fields
  165. def get_admin_readonly_fields(self, response):
  166. """
  167. Return the readonly fields for the response's AdminForm.
  168. """
  169. return [f for f in self.get_admin_form_fields(response) if f.is_readonly]
  170. def get_admin_readonly_field(self, response, field_name):
  171. """
  172. Return the readonly field for the given field_name.
  173. """
  174. admin_readonly_fields = self.get_admin_readonly_fields(response)
  175. for field in admin_readonly_fields:
  176. if field.field["name"] == field_name:
  177. return field
  178. @override_settings(ROOT_URLCONF="admin_views.urls", USE_I18N=True, LANGUAGE_CODE="en")
  179. class AdminViewBasicTestCase(TestCase):
  180. @classmethod
  181. def setUpTestData(cls):
  182. cls.superuser = User.objects.create_superuser(
  183. username="super", password="secret", email="super@example.com"
  184. )
  185. cls.s1 = Section.objects.create(name="Test section")
  186. cls.a1 = Article.objects.create(
  187. content="<p>Middle content</p>",
  188. date=datetime.datetime(2008, 3, 18, 11, 54, 58),
  189. section=cls.s1,
  190. title="Article 1",
  191. )
  192. cls.a2 = Article.objects.create(
  193. content="<p>Oldest content</p>",
  194. date=datetime.datetime(2000, 3, 18, 11, 54, 58),
  195. section=cls.s1,
  196. title="Article 2",
  197. )
  198. cls.a3 = Article.objects.create(
  199. content="<p>Newest content</p>",
  200. date=datetime.datetime(2009, 3, 18, 11, 54, 58),
  201. section=cls.s1,
  202. )
  203. cls.p1 = PrePopulatedPost.objects.create(
  204. title="A Long Title", published=True, slug="a-long-title"
  205. )
  206. cls.color1 = Color.objects.create(value="Red", warm=True)
  207. cls.color2 = Color.objects.create(value="Orange", warm=True)
  208. cls.color3 = Color.objects.create(value="Blue", warm=False)
  209. cls.color4 = Color.objects.create(value="Green", warm=False)
  210. cls.fab1 = Fabric.objects.create(surface="x")
  211. cls.fab2 = Fabric.objects.create(surface="y")
  212. cls.fab3 = Fabric.objects.create(surface="plain")
  213. cls.b1 = Book.objects.create(name="Book 1")
  214. cls.b2 = Book.objects.create(name="Book 2")
  215. cls.pro1 = Promo.objects.create(name="Promo 1", book=cls.b1)
  216. cls.pro1 = Promo.objects.create(name="Promo 2", book=cls.b2)
  217. cls.chap1 = Chapter.objects.create(
  218. title="Chapter 1", content="[ insert contents here ]", book=cls.b1
  219. )
  220. cls.chap2 = Chapter.objects.create(
  221. title="Chapter 2", content="[ insert contents here ]", book=cls.b1
  222. )
  223. cls.chap3 = Chapter.objects.create(
  224. title="Chapter 1", content="[ insert contents here ]", book=cls.b2
  225. )
  226. cls.chap4 = Chapter.objects.create(
  227. title="Chapter 2", content="[ insert contents here ]", book=cls.b2
  228. )
  229. cls.cx1 = ChapterXtra1.objects.create(chap=cls.chap1, xtra="ChapterXtra1 1")
  230. cls.cx2 = ChapterXtra1.objects.create(chap=cls.chap3, xtra="ChapterXtra1 2")
  231. Actor.objects.create(name="Palin", age=27)
  232. # Post data for edit inline
  233. cls.inline_post_data = {
  234. "name": "Test section",
  235. # inline data
  236. "article_set-TOTAL_FORMS": "6",
  237. "article_set-INITIAL_FORMS": "3",
  238. "article_set-MAX_NUM_FORMS": "0",
  239. "article_set-0-id": cls.a1.pk,
  240. # there is no title in database, give one here or formset will fail.
  241. "article_set-0-title": "Norske bostaver æøå skaper problemer",
  242. "article_set-0-content": "&lt;p&gt;Middle content&lt;/p&gt;",
  243. "article_set-0-date_0": "2008-03-18",
  244. "article_set-0-date_1": "11:54:58",
  245. "article_set-0-section": cls.s1.pk,
  246. "article_set-1-id": cls.a2.pk,
  247. "article_set-1-title": "Need a title.",
  248. "article_set-1-content": "&lt;p&gt;Oldest content&lt;/p&gt;",
  249. "article_set-1-date_0": "2000-03-18",
  250. "article_set-1-date_1": "11:54:58",
  251. "article_set-2-id": cls.a3.pk,
  252. "article_set-2-title": "Need a title.",
  253. "article_set-2-content": "&lt;p&gt;Newest content&lt;/p&gt;",
  254. "article_set-2-date_0": "2009-03-18",
  255. "article_set-2-date_1": "11:54:58",
  256. "article_set-3-id": "",
  257. "article_set-3-title": "",
  258. "article_set-3-content": "",
  259. "article_set-3-date_0": "",
  260. "article_set-3-date_1": "",
  261. "article_set-4-id": "",
  262. "article_set-4-title": "",
  263. "article_set-4-content": "",
  264. "article_set-4-date_0": "",
  265. "article_set-4-date_1": "",
  266. "article_set-5-id": "",
  267. "article_set-5-title": "",
  268. "article_set-5-content": "",
  269. "article_set-5-date_0": "",
  270. "article_set-5-date_1": "",
  271. }
  272. def setUp(self):
  273. self.client.force_login(self.superuser)
  274. def assertContentBefore(self, response, text1, text2, failing_msg=None):
  275. """
  276. Testing utility asserting that text1 appears before text2 in response
  277. content.
  278. """
  279. self.assertEqual(response.status_code, 200)
  280. self.assertLess(
  281. response.content.index(text1.encode()),
  282. response.content.index(text2.encode()),
  283. (failing_msg or "") + "\nResponse:\n" + response.text,
  284. )
  285. class AdminViewBasicTest(AdminViewBasicTestCase):
  286. def test_trailing_slash_required(self):
  287. """
  288. If you leave off the trailing slash, app should redirect and add it.
  289. """
  290. add_url = reverse("admin:admin_views_article_add")
  291. response = self.client.get(add_url[:-1])
  292. self.assertRedirects(response, add_url, status_code=301)
  293. def test_basic_add_GET(self):
  294. """
  295. A smoke test to ensure GET on the add_view works.
  296. """
  297. response = self.client.get(reverse("admin:admin_views_section_add"))
  298. self.assertIsInstance(response, TemplateResponse)
  299. self.assertEqual(response.status_code, 200)
  300. def test_add_with_GET_args(self):
  301. response = self.client.get(
  302. reverse("admin:admin_views_section_add"), {"name": "My Section"}
  303. )
  304. self.assertContains(
  305. response,
  306. 'value="My Section"',
  307. msg_prefix="Couldn't find an input with the right value in the response",
  308. )
  309. def test_add_query_string_persists(self):
  310. save_options = [
  311. {"_addanother": "1"}, # "Save and add another".
  312. {"_continue": "1"}, # "Save and continue editing".
  313. {"_saveasnew": "1"}, # "Save as new".
  314. ]
  315. other_options = [
  316. "",
  317. "_changelist_filters=is_staff__exact%3D0",
  318. f"{IS_POPUP_VAR}=1",
  319. f"{TO_FIELD_VAR}=id",
  320. ]
  321. url = reverse("admin:auth_user_add")
  322. for i, save_option in enumerate(save_options):
  323. for j, other_option in enumerate(other_options):
  324. with self.subTest(save_option=save_option, other_option=other_option):
  325. qsl = "username=newuser"
  326. if other_option:
  327. qsl = f"{qsl}&{other_option}"
  328. response = self.client.post(
  329. f"{url}?{qsl}",
  330. {
  331. "username": f"newuser{i}{j}",
  332. "password1": "newpassword",
  333. "password2": "newpassword",
  334. **save_option,
  335. },
  336. )
  337. parsed_url = urlsplit(response.url)
  338. self.assertEqual(parsed_url.query, qsl)
  339. def test_change_query_string_persists(self):
  340. save_options = [
  341. {"_addanother": "1"}, # "Save and add another".
  342. {"_continue": "1"}, # "Save and continue editing".
  343. ]
  344. other_options = [
  345. "",
  346. "_changelist_filters=warm%3D1",
  347. f"{IS_POPUP_VAR}=1",
  348. f"{TO_FIELD_VAR}=id",
  349. ]
  350. url = reverse("admin:admin_views_color_change", args=(self.color1.pk,))
  351. for save_option in save_options:
  352. for other_option in other_options:
  353. with self.subTest(save_option=save_option, other_option=other_option):
  354. qsl = "value=blue"
  355. if other_option:
  356. qsl = f"{qsl}&{other_option}"
  357. response = self.client.post(
  358. f"{url}?{qsl}",
  359. {
  360. "value": "gold",
  361. "warm": True,
  362. **save_option,
  363. },
  364. )
  365. parsed_url = urlsplit(response.url)
  366. self.assertEqual(parsed_url.query, qsl)
  367. def test_basic_edit_GET(self):
  368. """
  369. A smoke test to ensure GET on the change_view works.
  370. """
  371. response = self.client.get(
  372. reverse("admin:admin_views_section_change", args=(self.s1.pk,))
  373. )
  374. self.assertIsInstance(response, TemplateResponse)
  375. self.assertEqual(response.status_code, 200)
  376. def test_basic_edit_GET_string_PK(self):
  377. """
  378. GET on the change_view (when passing a string as the PK argument for a
  379. model with an integer PK field) redirects to the index page with a
  380. message saying the object doesn't exist.
  381. """
  382. response = self.client.get(
  383. reverse("admin:admin_views_section_change", args=(quote("abc/<b>"),)),
  384. follow=True,
  385. )
  386. self.assertRedirects(response, reverse("admin:index"))
  387. self.assertEqual(
  388. [m.message for m in response.context["messages"]],
  389. ["section with ID “abc/<b>” doesn’t exist. Perhaps it was deleted?"],
  390. )
  391. def test_basic_edit_GET_old_url_redirect(self):
  392. """
  393. The change URL changed in Django 1.9, but the old one still redirects.
  394. """
  395. response = self.client.get(
  396. reverse("admin:admin_views_section_change", args=(self.s1.pk,)).replace(
  397. "change/", ""
  398. )
  399. )
  400. self.assertRedirects(
  401. response, reverse("admin:admin_views_section_change", args=(self.s1.pk,))
  402. )
  403. def test_basic_inheritance_GET_string_PK(self):
  404. """
  405. GET on the change_view (for inherited models) redirects to the index
  406. page with a message saying the object doesn't exist.
  407. """
  408. response = self.client.get(
  409. reverse("admin:admin_views_supervillain_change", args=("abc",)), follow=True
  410. )
  411. self.assertRedirects(response, reverse("admin:index"))
  412. self.assertEqual(
  413. [m.message for m in response.context["messages"]],
  414. ["super villain with ID “abc” doesn’t exist. Perhaps it was deleted?"],
  415. )
  416. def test_basic_add_POST(self):
  417. """
  418. A smoke test to ensure POST on add_view works.
  419. """
  420. post_data = {
  421. "name": "Another Section",
  422. # inline data
  423. "article_set-TOTAL_FORMS": "3",
  424. "article_set-INITIAL_FORMS": "0",
  425. "article_set-MAX_NUM_FORMS": "0",
  426. }
  427. response = self.client.post(reverse("admin:admin_views_section_add"), post_data)
  428. self.assertEqual(response.status_code, 302) # redirect somewhere
  429. def test_popup_add_POST(self):
  430. """HTTP response from a popup is properly escaped."""
  431. post_data = {
  432. IS_POPUP_VAR: "1",
  433. "title": "title with a new\nline",
  434. "content": "some content",
  435. "date_0": "2010-09-10",
  436. "date_1": "14:55:39",
  437. }
  438. response = self.client.post(reverse("admin:admin_views_article_add"), post_data)
  439. self.assertContains(response, "title with a new\\nline")
  440. def test_basic_edit_POST(self):
  441. """
  442. A smoke test to ensure POST on edit_view works.
  443. """
  444. url = reverse("admin:admin_views_section_change", args=(self.s1.pk,))
  445. response = self.client.post(url, self.inline_post_data)
  446. self.assertEqual(response.status_code, 302) # redirect somewhere
  447. def test_edit_save_as(self):
  448. """
  449. Test "save as".
  450. """
  451. post_data = self.inline_post_data.copy()
  452. post_data.update(
  453. {
  454. "_saveasnew": "Save+as+new",
  455. "article_set-1-section": "1",
  456. "article_set-2-section": "1",
  457. "article_set-3-section": "1",
  458. "article_set-4-section": "1",
  459. "article_set-5-section": "1",
  460. }
  461. )
  462. response = self.client.post(
  463. reverse("admin:admin_views_section_change", args=(self.s1.pk,)), post_data
  464. )
  465. self.assertEqual(response.status_code, 302) # redirect somewhere
  466. def test_edit_save_as_delete_inline(self):
  467. """
  468. Should be able to "Save as new" while also deleting an inline.
  469. """
  470. post_data = self.inline_post_data.copy()
  471. post_data.update(
  472. {
  473. "_saveasnew": "Save+as+new",
  474. "article_set-1-section": "1",
  475. "article_set-2-section": "1",
  476. "article_set-2-DELETE": "1",
  477. "article_set-3-section": "1",
  478. }
  479. )
  480. response = self.client.post(
  481. reverse("admin:admin_views_section_change", args=(self.s1.pk,)), post_data
  482. )
  483. self.assertEqual(response.status_code, 302)
  484. # started with 3 articles, one was deleted.
  485. self.assertEqual(Section.objects.latest("id").article_set.count(), 2)
  486. def test_change_list_column_field_classes(self):
  487. response = self.client.get(reverse("admin:admin_views_article_changelist"))
  488. # callables display the callable name.
  489. self.assertContains(response, "column-callable_year")
  490. self.assertContains(response, "field-callable_year")
  491. # lambdas display as "lambda" + index that they appear in list_display.
  492. self.assertContains(response, "column-lambda8")
  493. self.assertContains(response, "field-lambda8")
  494. def test_change_list_sorting_callable(self):
  495. """
  496. Ensure we can sort on a list_display field that is a callable
  497. (column 2 is callable_year in ArticleAdmin)
  498. """
  499. response = self.client.get(
  500. reverse("admin:admin_views_article_changelist"), {"o": 2}
  501. )
  502. self.assertContentBefore(
  503. response,
  504. "Oldest content",
  505. "Middle content",
  506. "Results of sorting on callable are out of order.",
  507. )
  508. self.assertContentBefore(
  509. response,
  510. "Middle content",
  511. "Newest content",
  512. "Results of sorting on callable are out of order.",
  513. )
  514. def test_change_list_boolean_display_property(self):
  515. response = self.client.get(reverse("admin:admin_views_article_changelist"))
  516. self.assertContains(
  517. response,
  518. '<td class="field-model_property_is_from_past">'
  519. '<img src="/static/admin/img/icon-yes.svg" alt="True"></td>',
  520. )
  521. def test_change_list_sorting_property(self):
  522. """
  523. Sort on a list_display field that is a property (column 10 is
  524. a property in Article model).
  525. """
  526. response = self.client.get(
  527. reverse("admin:admin_views_article_changelist"), {"o": 10}
  528. )
  529. self.assertContentBefore(
  530. response,
  531. "Oldest content",
  532. "Middle content",
  533. "Results of sorting on property are out of order.",
  534. )
  535. self.assertContentBefore(
  536. response,
  537. "Middle content",
  538. "Newest content",
  539. "Results of sorting on property are out of order.",
  540. )
  541. def test_change_list_sorting_callable_query_expression(self):
  542. """Query expressions may be used for admin_order_field."""
  543. tests = [
  544. ("order_by_expression", 9),
  545. ("order_by_f_expression", 12),
  546. ("order_by_orderby_expression", 13),
  547. ]
  548. for admin_order_field, index in tests:
  549. with self.subTest(admin_order_field):
  550. response = self.client.get(
  551. reverse("admin:admin_views_article_changelist"),
  552. {"o": index},
  553. )
  554. self.assertContentBefore(
  555. response,
  556. "Oldest content",
  557. "Middle content",
  558. "Results of sorting on callable are out of order.",
  559. )
  560. self.assertContentBefore(
  561. response,
  562. "Middle content",
  563. "Newest content",
  564. "Results of sorting on callable are out of order.",
  565. )
  566. def test_change_list_sorting_callable_query_expression_reverse(self):
  567. tests = [
  568. ("order_by_expression", -9),
  569. ("order_by_f_expression", -12),
  570. ("order_by_orderby_expression", -13),
  571. ]
  572. for admin_order_field, index in tests:
  573. with self.subTest(admin_order_field):
  574. response = self.client.get(
  575. reverse("admin:admin_views_article_changelist"),
  576. {"o": index},
  577. )
  578. self.assertContentBefore(
  579. response,
  580. "Middle content",
  581. "Oldest content",
  582. "Results of sorting on callable are out of order.",
  583. )
  584. self.assertContentBefore(
  585. response,
  586. "Newest content",
  587. "Middle content",
  588. "Results of sorting on callable are out of order.",
  589. )
  590. def test_change_list_sorting_model(self):
  591. """
  592. Ensure we can sort on a list_display field that is a Model method
  593. (column 3 is 'model_year' in ArticleAdmin)
  594. """
  595. response = self.client.get(
  596. reverse("admin:admin_views_article_changelist"), {"o": "-3"}
  597. )
  598. self.assertContentBefore(
  599. response,
  600. "Newest content",
  601. "Middle content",
  602. "Results of sorting on Model method are out of order.",
  603. )
  604. self.assertContentBefore(
  605. response,
  606. "Middle content",
  607. "Oldest content",
  608. "Results of sorting on Model method are out of order.",
  609. )
  610. def test_change_list_sorting_model_admin(self):
  611. """
  612. Ensure we can sort on a list_display field that is a ModelAdmin method
  613. (column 4 is 'modeladmin_year' in ArticleAdmin)
  614. """
  615. response = self.client.get(
  616. reverse("admin:admin_views_article_changelist"), {"o": "4"}
  617. )
  618. self.assertContentBefore(
  619. response,
  620. "Oldest content",
  621. "Middle content",
  622. "Results of sorting on ModelAdmin method are out of order.",
  623. )
  624. self.assertContentBefore(
  625. response,
  626. "Middle content",
  627. "Newest content",
  628. "Results of sorting on ModelAdmin method are out of order.",
  629. )
  630. def test_change_list_sorting_model_admin_reverse(self):
  631. """
  632. Ensure we can sort on a list_display field that is a ModelAdmin
  633. method in reverse order (i.e. admin_order_field uses the '-' prefix)
  634. (column 6 is 'model_year_reverse' in ArticleAdmin)
  635. """
  636. td = '<td class="field-model_property_year">%s</td>'
  637. td_2000, td_2008, td_2009 = td % 2000, td % 2008, td % 2009
  638. response = self.client.get(
  639. reverse("admin:admin_views_article_changelist"), {"o": "6"}
  640. )
  641. self.assertContentBefore(
  642. response,
  643. td_2009,
  644. td_2008,
  645. "Results of sorting on ModelAdmin method are out of order.",
  646. )
  647. self.assertContentBefore(
  648. response,
  649. td_2008,
  650. td_2000,
  651. "Results of sorting on ModelAdmin method are out of order.",
  652. )
  653. # Let's make sure the ordering is right and that we don't get a
  654. # FieldError when we change to descending order
  655. response = self.client.get(
  656. reverse("admin:admin_views_article_changelist"), {"o": "-6"}
  657. )
  658. self.assertContentBefore(
  659. response,
  660. td_2000,
  661. td_2008,
  662. "Results of sorting on ModelAdmin method are out of order.",
  663. )
  664. self.assertContentBefore(
  665. response,
  666. td_2008,
  667. td_2009,
  668. "Results of sorting on ModelAdmin method are out of order.",
  669. )
  670. def test_change_list_sorting_multiple(self):
  671. p1 = Person.objects.create(name="Chris", gender=1, alive=True)
  672. p2 = Person.objects.create(name="Chris", gender=2, alive=True)
  673. p3 = Person.objects.create(name="Bob", gender=1, alive=True)
  674. link1 = reverse("admin:admin_views_person_change", args=(p1.pk,))
  675. link2 = reverse("admin:admin_views_person_change", args=(p2.pk,))
  676. link3 = reverse("admin:admin_views_person_change", args=(p3.pk,))
  677. # Sort by name, gender
  678. response = self.client.get(
  679. reverse("admin:admin_views_person_changelist"), {"o": "1.2"}
  680. )
  681. self.assertContentBefore(response, link3, link1)
  682. self.assertContentBefore(response, link1, link2)
  683. # Sort by gender descending, name
  684. response = self.client.get(
  685. reverse("admin:admin_views_person_changelist"), {"o": "-2.1"}
  686. )
  687. self.assertContentBefore(response, link2, link3)
  688. self.assertContentBefore(response, link3, link1)
  689. def test_change_list_sorting_preserve_queryset_ordering(self):
  690. """
  691. If no ordering is defined in `ModelAdmin.ordering` or in the query
  692. string, then the underlying order of the queryset should not be
  693. changed, even if it is defined in `Modeladmin.get_queryset()`.
  694. Refs #11868, #7309.
  695. """
  696. p1 = Person.objects.create(name="Amy", gender=1, alive=True, age=80)
  697. p2 = Person.objects.create(name="Bob", gender=1, alive=True, age=70)
  698. p3 = Person.objects.create(name="Chris", gender=2, alive=False, age=60)
  699. link1 = reverse("admin:admin_views_person_change", args=(p1.pk,))
  700. link2 = reverse("admin:admin_views_person_change", args=(p2.pk,))
  701. link3 = reverse("admin:admin_views_person_change", args=(p3.pk,))
  702. response = self.client.get(reverse("admin:admin_views_person_changelist"), {})
  703. self.assertContentBefore(response, link3, link2)
  704. self.assertContentBefore(response, link2, link1)
  705. def test_change_list_sorting_model_meta(self):
  706. # Test ordering on Model Meta is respected
  707. l1 = Language.objects.create(iso="ur", name="Urdu")
  708. l2 = Language.objects.create(iso="ar", name="Arabic")
  709. link1 = reverse("admin:admin_views_language_change", args=(quote(l1.pk),))
  710. link2 = reverse("admin:admin_views_language_change", args=(quote(l2.pk),))
  711. response = self.client.get(reverse("admin:admin_views_language_changelist"), {})
  712. self.assertContentBefore(response, link2, link1)
  713. # Test we can override with query string
  714. response = self.client.get(
  715. reverse("admin:admin_views_language_changelist"), {"o": "-1"}
  716. )
  717. self.assertContentBefore(response, link1, link2)
  718. def test_change_list_sorting_override_model_admin(self):
  719. # Test ordering on Model Admin is respected, and overrides Model Meta
  720. dt = datetime.datetime.now()
  721. p1 = Podcast.objects.create(name="A", release_date=dt)
  722. p2 = Podcast.objects.create(name="B", release_date=dt - datetime.timedelta(10))
  723. link1 = reverse("admin:admin_views_podcast_change", args=(p1.pk,))
  724. link2 = reverse("admin:admin_views_podcast_change", args=(p2.pk,))
  725. response = self.client.get(reverse("admin:admin_views_podcast_changelist"), {})
  726. self.assertContentBefore(response, link1, link2)
  727. def test_multiple_sort_same_field(self):
  728. # The changelist displays the correct columns if two columns correspond
  729. # to the same ordering field.
  730. dt = datetime.datetime.now()
  731. p1 = Podcast.objects.create(name="A", release_date=dt)
  732. p2 = Podcast.objects.create(name="B", release_date=dt - datetime.timedelta(10))
  733. link1 = reverse("admin:admin_views_podcast_change", args=(quote(p1.pk),))
  734. link2 = reverse("admin:admin_views_podcast_change", args=(quote(p2.pk),))
  735. response = self.client.get(reverse("admin:admin_views_podcast_changelist"), {})
  736. self.assertContentBefore(response, link1, link2)
  737. p1 = ComplexSortedPerson.objects.create(name="Bob", age=10)
  738. p2 = ComplexSortedPerson.objects.create(name="Amy", age=20)
  739. link1 = reverse("admin:admin_views_complexsortedperson_change", args=(p1.pk,))
  740. link2 = reverse("admin:admin_views_complexsortedperson_change", args=(p2.pk,))
  741. response = self.client.get(
  742. reverse("admin:admin_views_complexsortedperson_changelist"), {}
  743. )
  744. # Should have 5 columns (including action checkbox col)
  745. result_list_table_re = re.compile('<table id="result_list">(.*?)</thead>')
  746. result_list_table_head = result_list_table_re.search(str(response.content))[0]
  747. self.assertEqual(result_list_table_head.count('<th scope="col"'), 5)
  748. self.assertContains(response, "Name")
  749. self.assertContains(response, "Colored name")
  750. # Check order
  751. self.assertContentBefore(response, "Name", "Colored name")
  752. # Check sorting - should be by name
  753. self.assertContentBefore(response, link2, link1)
  754. def test_sort_indicators_admin_order(self):
  755. """
  756. The admin shows default sort indicators for all kinds of 'ordering'
  757. fields: field names, method on the model admin and model itself, and
  758. other callables. See #17252.
  759. """
  760. models = [
  761. (AdminOrderedField, "adminorderedfield"),
  762. (AdminOrderedModelMethod, "adminorderedmodelmethod"),
  763. (AdminOrderedAdminMethod, "adminorderedadminmethod"),
  764. (AdminOrderedCallable, "adminorderedcallable"),
  765. ]
  766. for model, url in models:
  767. model.objects.create(stuff="The Last Item", order=3)
  768. model.objects.create(stuff="The First Item", order=1)
  769. model.objects.create(stuff="The Middle Item", order=2)
  770. response = self.client.get(
  771. reverse("admin:admin_views_%s_changelist" % url), {}
  772. )
  773. # Should have 3 columns including action checkbox col.
  774. result_list_table_re = re.compile('<table id="result_list">(.*?)</thead>')
  775. result_list_table_head = result_list_table_re.search(str(response.content))[
  776. 0
  777. ]
  778. self.assertEqual(result_list_table_head.count('<th scope="col"'), 3)
  779. # Check if the correct column was selected. 2 is the index of the
  780. # 'order' column in the model admin's 'list_display' with 0 being
  781. # the implicit 'action_checkbox' and 1 being the column 'stuff'.
  782. self.assertEqual(
  783. response.context["cl"].get_ordering_field_columns(), {2: "asc"}
  784. )
  785. # Check order of records.
  786. self.assertContentBefore(response, "The First Item", "The Middle Item")
  787. self.assertContentBefore(response, "The Middle Item", "The Last Item")
  788. def test_has_related_field_in_list_display_fk(self):
  789. """Joins shouldn't be performed for <FK>_id fields in list display."""
  790. state = State.objects.create(name="Karnataka")
  791. City.objects.create(state=state, name="Bangalore")
  792. response = self.client.get(reverse("admin:admin_views_city_changelist"), {})
  793. response.context["cl"].list_display = ["id", "name", "state"]
  794. self.assertIs(response.context["cl"].has_related_field_in_list_display(), True)
  795. response.context["cl"].list_display = ["id", "name", "state_id"]
  796. self.assertIs(response.context["cl"].has_related_field_in_list_display(), False)
  797. def test_has_related_field_in_list_display_o2o(self):
  798. """Joins shouldn't be performed for <O2O>_id fields in list display."""
  799. media = Media.objects.create(name="Foo")
  800. Vodcast.objects.create(media=media)
  801. response = self.client.get(reverse("admin:admin_views_vodcast_changelist"), {})
  802. response.context["cl"].list_display = ["media"]
  803. self.assertIs(response.context["cl"].has_related_field_in_list_display(), True)
  804. response.context["cl"].list_display = ["media_id"]
  805. self.assertIs(response.context["cl"].has_related_field_in_list_display(), False)
  806. def test_limited_filter(self):
  807. """
  808. Admin changelist filters do not contain objects excluded via
  809. limit_choices_to.
  810. """
  811. response = self.client.get(reverse("admin:admin_views_thing_changelist"))
  812. self.assertContains(
  813. response,
  814. '<nav id="changelist-filter" aria-labelledby="changelist-filter-header">',
  815. msg_prefix="Expected filter not found in changelist view",
  816. )
  817. self.assertNotContains(
  818. response,
  819. '<a href="?color__id__exact=3">Blue</a>',
  820. msg_prefix="Changelist filter not correctly limited by limit_choices_to",
  821. )
  822. def test_change_list_facet_toggle(self):
  823. # Toggle is visible when show_facet is the default of
  824. # admin.ShowFacets.ALLOW.
  825. admin_url = reverse("admin:admin_views_album_changelist")
  826. response = self.client.get(admin_url)
  827. self.assertContains(
  828. response,
  829. '<a href="?_facets=True" class="viewlink">Show counts</a>',
  830. msg_prefix="Expected facet filter toggle not found in changelist view",
  831. )
  832. response = self.client.get(f"{admin_url}?_facets=True")
  833. self.assertContains(
  834. response,
  835. '<a href="?" class="hidelink">Hide counts</a>',
  836. msg_prefix="Expected facet filter toggle not found in changelist view",
  837. )
  838. # Toggle is not visible when show_facet is admin.ShowFacets.ALWAYS.
  839. response = self.client.get(reverse("admin:admin_views_workhour_changelist"))
  840. self.assertNotContains(
  841. response,
  842. "Show counts",
  843. msg_prefix="Expected not to find facet filter toggle in changelist view",
  844. )
  845. self.assertNotContains(
  846. response,
  847. "Hide counts",
  848. msg_prefix="Expected not to find facet filter toggle in changelist view",
  849. )
  850. # Toggle is not visible when show_facet is admin.ShowFacets.NEVER.
  851. response = self.client.get(reverse("admin:admin_views_fooddelivery_changelist"))
  852. self.assertNotContains(
  853. response,
  854. "Show counts",
  855. msg_prefix="Expected not to find facet filter toggle in changelist view",
  856. )
  857. self.assertNotContains(
  858. response,
  859. "Hide counts",
  860. msg_prefix="Expected not to find facet filter toggle in changelist view",
  861. )
  862. def test_relation_spanning_filters(self):
  863. changelist_url = reverse("admin:admin_views_chapterxtra1_changelist")
  864. response = self.client.get(changelist_url)
  865. self.assertContains(
  866. response,
  867. '<nav id="changelist-filter" aria-labelledby="changelist-filter-header">',
  868. )
  869. filters = {
  870. "chap__id__exact": {
  871. "values": [c.id for c in Chapter.objects.all()],
  872. "test": lambda obj, value: obj.chap.id == value,
  873. },
  874. "chap__title": {
  875. "values": [c.title for c in Chapter.objects.all()],
  876. "test": lambda obj, value: obj.chap.title == value,
  877. },
  878. "chap__book__id__exact": {
  879. "values": [b.id for b in Book.objects.all()],
  880. "test": lambda obj, value: obj.chap.book.id == value,
  881. },
  882. "chap__book__name": {
  883. "values": [b.name for b in Book.objects.all()],
  884. "test": lambda obj, value: obj.chap.book.name == value,
  885. },
  886. "chap__book__promo__id__exact": {
  887. "values": [p.id for p in Promo.objects.all()],
  888. "test": lambda obj, value: obj.chap.book.promo_set.filter(
  889. id=value
  890. ).exists(),
  891. },
  892. "chap__book__promo__name": {
  893. "values": [p.name for p in Promo.objects.all()],
  894. "test": lambda obj, value: obj.chap.book.promo_set.filter(
  895. name=value
  896. ).exists(),
  897. },
  898. # A forward relation (book) after a reverse relation (promo).
  899. "guest_author__promo__book__id__exact": {
  900. "values": [p.id for p in Book.objects.all()],
  901. "test": lambda obj, value: obj.guest_author.promo_set.filter(
  902. book=value
  903. ).exists(),
  904. },
  905. }
  906. for filter_path, params in filters.items():
  907. for value in params["values"]:
  908. query_string = urlencode({filter_path: value})
  909. # ensure filter link exists
  910. self.assertContains(response, '<a href="?%s"' % query_string)
  911. # ensure link works
  912. filtered_response = self.client.get(
  913. "%s?%s" % (changelist_url, query_string)
  914. )
  915. self.assertEqual(filtered_response.status_code, 200)
  916. # ensure changelist contains only valid objects
  917. for obj in filtered_response.context["cl"].queryset.all():
  918. self.assertTrue(params["test"](obj, value))
  919. def test_incorrect_lookup_parameters(self):
  920. """Ensure incorrect lookup parameters are handled gracefully."""
  921. changelist_url = reverse("admin:admin_views_thing_changelist")
  922. response = self.client.get(changelist_url, {"notarealfield": "5"})
  923. self.assertRedirects(response, "%s?e=1" % changelist_url)
  924. # Spanning relationships through a nonexistent related object (Refs #16716)
  925. response = self.client.get(changelist_url, {"notarealfield__whatever": "5"})
  926. self.assertRedirects(response, "%s?e=1" % changelist_url)
  927. response = self.client.get(
  928. changelist_url, {"color__id__exact": "StringNotInteger!"}
  929. )
  930. self.assertRedirects(response, "%s?e=1" % changelist_url)
  931. # Regression test for #18530
  932. response = self.client.get(changelist_url, {"pub_date__gte": "foo"})
  933. self.assertRedirects(response, "%s?e=1" % changelist_url)
  934. def test_isnull_lookups(self):
  935. """Ensure is_null is handled correctly."""
  936. Article.objects.create(
  937. title="I Could Go Anywhere",
  938. content="Versatile",
  939. date=datetime.datetime.now(),
  940. )
  941. changelist_url = reverse("admin:admin_views_article_changelist")
  942. response = self.client.get(changelist_url)
  943. self.assertContains(response, "4 articles")
  944. response = self.client.get(changelist_url, {"section__isnull": "false"})
  945. self.assertContains(response, "3 articles")
  946. response = self.client.get(changelist_url, {"section__isnull": "0"})
  947. self.assertContains(response, "3 articles")
  948. response = self.client.get(changelist_url, {"section__isnull": "true"})
  949. self.assertContains(response, "1 article")
  950. response = self.client.get(changelist_url, {"section__isnull": "1"})
  951. self.assertContains(response, "1 article")
  952. def test_logout_and_password_change_URLs(self):
  953. response = self.client.get(reverse("admin:admin_views_article_changelist"))
  954. self.assertContains(
  955. response,
  956. '<form id="logout-form" method="post" action="%s">'
  957. % reverse("admin:logout"),
  958. )
  959. self.assertContains(
  960. response, '<a href="%s">' % reverse("admin:password_change")
  961. )
  962. def test_named_group_field_choices_change_list(self):
  963. """
  964. Ensures the admin changelist shows correct values in the relevant column
  965. for rows corresponding to instances of a model in which a named group
  966. has been used in the choices option of a field.
  967. """
  968. link1 = reverse("admin:admin_views_fabric_change", args=(self.fab1.pk,))
  969. link2 = reverse("admin:admin_views_fabric_change", args=(self.fab2.pk,))
  970. response = self.client.get(reverse("admin:admin_views_fabric_changelist"))
  971. fail_msg = (
  972. "Changelist table isn't showing the right human-readable values "
  973. "set by a model field 'choices' option named group."
  974. )
  975. self.assertContains(
  976. response,
  977. '<a href="%s">Horizontal</a>' % link1,
  978. msg_prefix=fail_msg,
  979. html=True,
  980. )
  981. self.assertContains(
  982. response,
  983. '<a href="%s">Vertical</a>' % link2,
  984. msg_prefix=fail_msg,
  985. html=True,
  986. )
  987. def test_named_group_field_choices_filter(self):
  988. """
  989. Ensures the filter UI shows correctly when at least one named group has
  990. been used in the choices option of a model field.
  991. """
  992. response = self.client.get(reverse("admin:admin_views_fabric_changelist"))
  993. fail_msg = (
  994. "Changelist filter isn't showing options contained inside a model "
  995. "field 'choices' option named group."
  996. )
  997. self.assertContains(
  998. response,
  999. '<nav id="changelist-filter" aria-labelledby="changelist-filter-header">',
  1000. )
  1001. self.assertContains(
  1002. response,
  1003. '<a href="?surface__exact=x">Horizontal</a>',
  1004. msg_prefix=fail_msg,
  1005. html=True,
  1006. )
  1007. self.assertContains(
  1008. response,
  1009. '<a href="?surface__exact=y">Vertical</a>',
  1010. msg_prefix=fail_msg,
  1011. html=True,
  1012. )
  1013. def test_change_list_null_boolean_display(self):
  1014. Post.objects.create(public=None)
  1015. response = self.client.get(reverse("admin:admin_views_post_changelist"))
  1016. self.assertContains(response, "icon-unknown.svg")
  1017. def test_display_decorator_with_boolean_and_empty_value(self):
  1018. msg = (
  1019. "The boolean and empty_value arguments to the @display decorator "
  1020. "are mutually exclusive."
  1021. )
  1022. with self.assertRaisesMessage(ValueError, msg):
  1023. class BookAdmin(admin.ModelAdmin):
  1024. @admin.display(boolean=True, empty_value="(Missing)")
  1025. def is_published(self, obj):
  1026. return obj.publish_date is not None
  1027. def test_i18n_language_non_english_default(self):
  1028. """
  1029. Check if the JavaScript i18n view returns an empty language catalog
  1030. if the default language is non-English but the selected language
  1031. is English. See #13388 and #3594 for more details.
  1032. """
  1033. with self.settings(LANGUAGE_CODE="fr"), translation.override("en-us"):
  1034. response = self.client.get(reverse("admin:jsi18n"))
  1035. self.assertNotContains(response, "Choisir une heure")
  1036. def test_i18n_language_non_english_fallback(self):
  1037. """
  1038. Makes sure that the fallback language is still working properly
  1039. in cases where the selected language cannot be found.
  1040. """
  1041. with self.settings(LANGUAGE_CODE="fr"), translation.override("none"):
  1042. response = self.client.get(reverse("admin:jsi18n"))
  1043. self.assertContains(response, "Choisir une heure")
  1044. def test_jsi18n_with_context(self):
  1045. response = self.client.get(reverse("admin-extra-context:jsi18n"))
  1046. self.assertEqual(response.status_code, 200)
  1047. def test_jsi18n_format_fallback(self):
  1048. """
  1049. The JavaScript i18n view doesn't return localized date/time formats
  1050. when the selected language cannot be found.
  1051. """
  1052. with self.settings(LANGUAGE_CODE="ru"), translation.override("none"):
  1053. response = self.client.get(reverse("admin:jsi18n"))
  1054. self.assertNotContains(response, "%d.%m.%Y %H:%M:%S")
  1055. self.assertContains(response, "%Y-%m-%d %H:%M:%S")
  1056. def test_disallowed_filtering(self):
  1057. with self.assertLogs("django.security.DisallowedModelAdminLookup", "ERROR"):
  1058. response = self.client.get(
  1059. "%s?owner__email__startswith=fuzzy"
  1060. % reverse("admin:admin_views_album_changelist")
  1061. )
  1062. self.assertEqual(response.status_code, 400)
  1063. # Filters are allowed if explicitly included in list_filter
  1064. response = self.client.get(
  1065. "%s?color__value__startswith=red"
  1066. % reverse("admin:admin_views_thing_changelist")
  1067. )
  1068. self.assertEqual(response.status_code, 200)
  1069. response = self.client.get(
  1070. "%s?color__value=red" % reverse("admin:admin_views_thing_changelist")
  1071. )
  1072. self.assertEqual(response.status_code, 200)
  1073. # Filters should be allowed if they involve a local field without the
  1074. # need to allow them in list_filter or date_hierarchy.
  1075. response = self.client.get(
  1076. "%s?age__gt=30" % reverse("admin:admin_views_person_changelist")
  1077. )
  1078. self.assertEqual(response.status_code, 200)
  1079. e1 = Employee.objects.create(
  1080. name="Anonymous", gender=1, age=22, alive=True, code="123"
  1081. )
  1082. e2 = Employee.objects.create(
  1083. name="Visitor", gender=2, age=19, alive=True, code="124"
  1084. )
  1085. WorkHour.objects.create(datum=datetime.datetime.now(), employee=e1)
  1086. WorkHour.objects.create(datum=datetime.datetime.now(), employee=e2)
  1087. response = self.client.get(reverse("admin:admin_views_workhour_changelist"))
  1088. self.assertContains(response, "employee__person_ptr__exact")
  1089. response = self.client.get(
  1090. "%s?employee__person_ptr__exact=%d"
  1091. % (reverse("admin:admin_views_workhour_changelist"), e1.pk)
  1092. )
  1093. self.assertEqual(response.status_code, 200)
  1094. def test_disallowed_to_field(self):
  1095. url = reverse("admin:admin_views_section_changelist")
  1096. with self.assertLogs("django.security.DisallowedModelAdminToField", "ERROR"):
  1097. response = self.client.get(url, {TO_FIELD_VAR: "missing_field"})
  1098. self.assertEqual(response.status_code, 400)
  1099. # Specifying a field that is not referred by any other model registered
  1100. # to this admin site should raise an exception.
  1101. with self.assertLogs("django.security.DisallowedModelAdminToField", "ERROR"):
  1102. response = self.client.get(
  1103. reverse("admin:admin_views_section_changelist"), {TO_FIELD_VAR: "name"}
  1104. )
  1105. self.assertEqual(response.status_code, 400)
  1106. # Primary key should always be allowed, even if the referenced model
  1107. # isn't registered.
  1108. response = self.client.get(
  1109. reverse("admin:admin_views_notreferenced_changelist"), {TO_FIELD_VAR: "id"}
  1110. )
  1111. self.assertEqual(response.status_code, 200)
  1112. # Specifying a field referenced by another model though a m2m should be
  1113. # allowed.
  1114. response = self.client.get(
  1115. reverse("admin:admin_views_recipe_changelist"), {TO_FIELD_VAR: "rname"}
  1116. )
  1117. self.assertEqual(response.status_code, 200)
  1118. # Specifying a field referenced through a reverse m2m relationship
  1119. # should be allowed.
  1120. response = self.client.get(
  1121. reverse("admin:admin_views_ingredient_changelist"), {TO_FIELD_VAR: "iname"}
  1122. )
  1123. self.assertEqual(response.status_code, 200)
  1124. # Specifying a field that is not referred by any other model directly
  1125. # registered to this admin site but registered through inheritance
  1126. # should be allowed.
  1127. response = self.client.get(
  1128. reverse("admin:admin_views_referencedbyparent_changelist"),
  1129. {TO_FIELD_VAR: "name"},
  1130. )
  1131. self.assertEqual(response.status_code, 200)
  1132. # Specifying a field that is only referred to by a inline of a
  1133. # registered model should be allowed.
  1134. response = self.client.get(
  1135. reverse("admin:admin_views_referencedbyinline_changelist"),
  1136. {TO_FIELD_VAR: "name"},
  1137. )
  1138. self.assertEqual(response.status_code, 200)
  1139. # #25622 - Specifying a field of a model only referred by a generic
  1140. # relation should raise DisallowedModelAdminToField.
  1141. url = reverse("admin:admin_views_referencedbygenrel_changelist")
  1142. with self.assertLogs("django.security.DisallowedModelAdminToField", "ERROR"):
  1143. response = self.client.get(url, {TO_FIELD_VAR: "object_id"})
  1144. self.assertEqual(response.status_code, 400)
  1145. # We also want to prevent the add, change, and delete views from
  1146. # leaking a disallowed field value.
  1147. with self.assertLogs("django.security.DisallowedModelAdminToField", "ERROR"):
  1148. response = self.client.post(
  1149. reverse("admin:admin_views_section_add"), {TO_FIELD_VAR: "name"}
  1150. )
  1151. self.assertEqual(response.status_code, 400)
  1152. section = Section.objects.create()
  1153. url = reverse("admin:admin_views_section_change", args=(section.pk,))
  1154. with self.assertLogs("django.security.DisallowedModelAdminToField", "ERROR"):
  1155. response = self.client.post(url, {TO_FIELD_VAR: "name"})
  1156. self.assertEqual(response.status_code, 400)
  1157. url = reverse("admin:admin_views_section_delete", args=(section.pk,))
  1158. with self.assertLogs("django.security.DisallowedModelAdminToField", "ERROR"):
  1159. response = self.client.post(url, {TO_FIELD_VAR: "name"})
  1160. self.assertEqual(response.status_code, 400)
  1161. def test_allowed_filtering_15103(self):
  1162. """
  1163. Regressions test for ticket 15103 - filtering on fields defined in a
  1164. ForeignKey 'limit_choices_to' should be allowed, otherwise raw_id_fields
  1165. can break.
  1166. """
  1167. # Filters should be allowed if they are defined on a ForeignKey
  1168. # pointing to this model.
  1169. url = "%s?leader__name=Palin&leader__age=27" % reverse(
  1170. "admin:admin_views_inquisition_changelist"
  1171. )
  1172. response = self.client.get(url)
  1173. self.assertEqual(response.status_code, 200)
  1174. def test_popup_dismiss_related(self):
  1175. """
  1176. Regression test for ticket 20664 - ensure the pk is properly quoted.
  1177. """
  1178. actor = Actor.objects.create(name="Palin", age=27)
  1179. response = self.client.get(
  1180. "%s?%s" % (reverse("admin:admin_views_actor_changelist"), IS_POPUP_VAR)
  1181. )
  1182. self.assertContains(response, 'data-popup-opener="%s"' % actor.pk)
  1183. def test_hide_change_password(self):
  1184. """
  1185. Tests if the "change password" link in the admin is hidden if the User
  1186. does not have a usable password set.
  1187. (against 9bea85795705d015cdadc82c68b99196a8554f5c)
  1188. """
  1189. user = User.objects.get(username="super")
  1190. user.set_unusable_password()
  1191. user.save()
  1192. self.client.force_login(user)
  1193. response = self.client.get(reverse("admin:index"))
  1194. self.assertNotContains(
  1195. response,
  1196. reverse("admin:password_change"),
  1197. msg_prefix=(
  1198. 'The "change password" link should not be displayed if a user does not '
  1199. "have a usable password."
  1200. ),
  1201. )
  1202. def test_change_view_with_show_delete_extra_context(self):
  1203. """
  1204. The 'show_delete' context variable in the admin's change view controls
  1205. the display of the delete button.
  1206. """
  1207. instance = UndeletableObject.objects.create(name="foo")
  1208. response = self.client.get(
  1209. reverse("admin:admin_views_undeletableobject_change", args=(instance.pk,))
  1210. )
  1211. self.assertNotContains(response, "deletelink")
  1212. def test_change_view_logs_m2m_field_changes(self):
  1213. """Changes to ManyToManyFields are included in the object's history."""
  1214. pizza = ReadablePizza.objects.create(name="Cheese")
  1215. cheese = Topping.objects.create(name="cheese")
  1216. post_data = {"name": pizza.name, "toppings": [cheese.pk]}
  1217. response = self.client.post(
  1218. reverse("admin:admin_views_readablepizza_change", args=(pizza.pk,)),
  1219. post_data,
  1220. )
  1221. self.assertRedirects(
  1222. response, reverse("admin:admin_views_readablepizza_changelist")
  1223. )
  1224. pizza_ctype = ContentType.objects.get_for_model(
  1225. ReadablePizza, for_concrete_model=False
  1226. )
  1227. log = LogEntry.objects.filter(
  1228. content_type=pizza_ctype, object_id=pizza.pk
  1229. ).first()
  1230. self.assertEqual(log.get_change_message(), "Changed Toppings.")
  1231. def test_allows_attributeerror_to_bubble_up(self):
  1232. """
  1233. AttributeErrors are allowed to bubble when raised inside a change list
  1234. view. Requires a model to be created so there's something to display.
  1235. Refs: #16655, #18593, and #18747
  1236. """
  1237. Simple.objects.create()
  1238. with self.assertRaises(AttributeError):
  1239. self.client.get(reverse("admin:admin_views_simple_changelist"))
  1240. def test_changelist_with_no_change_url(self):
  1241. """
  1242. ModelAdmin.changelist_view shouldn't result in a NoReverseMatch if url
  1243. for change_view is removed from get_urls (#20934).
  1244. """
  1245. o = UnchangeableObject.objects.create()
  1246. response = self.client.get(
  1247. reverse("admin:admin_views_unchangeableobject_changelist")
  1248. )
  1249. # Check the format of the shown object -- shouldn't contain a change link
  1250. self.assertContains(
  1251. response, '<th class="field-__str__">%s</th>' % o, html=True
  1252. )
  1253. def test_invalid_appindex_url(self):
  1254. """
  1255. #21056 -- URL reversing shouldn't work for nonexistent apps.
  1256. """
  1257. good_url = "/test_admin/admin/admin_views/"
  1258. confirm_good_url = reverse(
  1259. "admin:app_list", kwargs={"app_label": "admin_views"}
  1260. )
  1261. self.assertEqual(good_url, confirm_good_url)
  1262. with self.assertRaises(NoReverseMatch):
  1263. reverse("admin:app_list", kwargs={"app_label": "this_should_fail"})
  1264. with self.assertRaises(NoReverseMatch):
  1265. reverse("admin:app_list", args=("admin_views2",))
  1266. def test_resolve_admin_views(self):
  1267. index_match = resolve("/test_admin/admin4/")
  1268. list_match = resolve("/test_admin/admin4/auth/user/")
  1269. self.assertIs(index_match.func.admin_site, customadmin.simple_site)
  1270. self.assertIsInstance(
  1271. list_match.func.model_admin, customadmin.CustomPwdTemplateUserAdmin
  1272. )
  1273. def test_adminsite_display_site_url(self):
  1274. """
  1275. #13749 - Admin should display link to front-end site 'View site'
  1276. """
  1277. url = reverse("admin:index")
  1278. response = self.client.get(url)
  1279. self.assertEqual(response.context["site_url"], "/my-site-url/")
  1280. self.assertContains(response, '<a href="/my-site-url/">View site</a>')
  1281. def test_date_hierarchy_empty_queryset(self):
  1282. self.assertIs(Question.objects.exists(), False)
  1283. response = self.client.get(reverse("admin:admin_views_answer2_changelist"))
  1284. self.assertEqual(response.status_code, 200)
  1285. @override_settings(TIME_ZONE="America/Sao_Paulo", USE_TZ=True)
  1286. def test_date_hierarchy_timezone_dst(self):
  1287. # This datetime doesn't exist in this timezone due to DST.
  1288. for date in make_aware_datetimes(
  1289. datetime.datetime(2016, 10, 16, 15), "America/Sao_Paulo"
  1290. ):
  1291. with self.subTest(repr(date.tzinfo)):
  1292. q = Question.objects.create(question="Why?", expires=date)
  1293. Answer2.objects.create(question=q, answer="Because.")
  1294. response = self.client.get(
  1295. reverse("admin:admin_views_answer2_changelist")
  1296. )
  1297. self.assertContains(response, "question__expires__day=16")
  1298. self.assertContains(response, "question__expires__month=10")
  1299. self.assertContains(response, "question__expires__year=2016")
  1300. @override_settings(TIME_ZONE="America/Los_Angeles", USE_TZ=True)
  1301. def test_date_hierarchy_local_date_differ_from_utc(self):
  1302. # This datetime is 2017-01-01 in UTC.
  1303. for date in make_aware_datetimes(
  1304. datetime.datetime(2016, 12, 31, 16), "America/Los_Angeles"
  1305. ):
  1306. with self.subTest(repr(date.tzinfo)):
  1307. q = Question.objects.create(question="Why?", expires=date)
  1308. Answer2.objects.create(question=q, answer="Because.")
  1309. response = self.client.get(
  1310. reverse("admin:admin_views_answer2_changelist")
  1311. )
  1312. self.assertContains(response, "question__expires__day=31")
  1313. self.assertContains(response, "question__expires__month=12")
  1314. self.assertContains(response, "question__expires__year=2016")
  1315. def test_sortable_by_columns_subset(self):
  1316. expected_sortable_fields = ("date", "callable_year")
  1317. expected_not_sortable_fields = (
  1318. "content",
  1319. "model_year",
  1320. "modeladmin_year",
  1321. "model_year_reversed",
  1322. "section",
  1323. )
  1324. response = self.client.get(reverse("admin6:admin_views_article_changelist"))
  1325. for field_name in expected_sortable_fields:
  1326. self.assertContains(
  1327. response, '<th scope="col" class="sortable column-%s">' % field_name
  1328. )
  1329. for field_name in expected_not_sortable_fields:
  1330. self.assertContains(
  1331. response, '<th scope="col" class="column-%s">' % field_name
  1332. )
  1333. def test_get_sortable_by_columns_subset(self):
  1334. response = self.client.get(reverse("admin6:admin_views_actor_changelist"))
  1335. self.assertContains(response, '<th scope="col" class="sortable column-age">')
  1336. self.assertContains(response, '<th scope="col" class="column-name">')
  1337. def test_sortable_by_no_column(self):
  1338. expected_not_sortable_fields = ("title", "book")
  1339. response = self.client.get(reverse("admin6:admin_views_chapter_changelist"))
  1340. for field_name in expected_not_sortable_fields:
  1341. self.assertContains(
  1342. response, '<th scope="col" class="column-%s">' % field_name
  1343. )
  1344. self.assertNotContains(response, '<th scope="col" class="sortable column')
  1345. def test_get_sortable_by_no_column(self):
  1346. response = self.client.get(reverse("admin6:admin_views_color_changelist"))
  1347. self.assertContains(response, '<th scope="col" class="column-value">')
  1348. self.assertNotContains(response, '<th scope="col" class="sortable column')
  1349. def test_app_index_context(self):
  1350. response = self.client.get(reverse("admin:app_list", args=("admin_views",)))
  1351. self.assertContains(
  1352. response,
  1353. "<title>Admin_Views administration | Django site admin</title>",
  1354. )
  1355. self.assertEqual(response.context["title"], "Admin_Views administration")
  1356. self.assertEqual(response.context["app_label"], "admin_views")
  1357. # Models are sorted alphabetically by default.
  1358. models = [model["name"] for model in response.context["app_list"][0]["models"]]
  1359. self.assertSequenceEqual(models, sorted(models))
  1360. def test_app_index_context_reordered(self):
  1361. self.client.force_login(self.superuser)
  1362. response = self.client.get(reverse("admin2:app_list", args=("admin_views",)))
  1363. self.assertContains(
  1364. response,
  1365. "<title>Admin_Views administration | Django site admin</title>",
  1366. )
  1367. # Models are in reverse order.
  1368. models = [model["name"] for model in response.context["app_list"][0]["models"]]
  1369. self.assertSequenceEqual(models, sorted(models, reverse=True))
  1370. def test_change_view_subtitle_per_object(self):
  1371. response = self.client.get(
  1372. reverse("admin:admin_views_article_change", args=(self.a1.pk,)),
  1373. )
  1374. self.assertContains(
  1375. response,
  1376. "<title>Article 1 | Change article | Django site admin</title>",
  1377. )
  1378. self.assertContains(response, "<h1>Change article</h1>")
  1379. self.assertContains(response, "<h2>Article 1</h2>")
  1380. response = self.client.get(
  1381. reverse("admin:admin_views_article_change", args=(self.a2.pk,)),
  1382. )
  1383. self.assertContains(
  1384. response,
  1385. "<title>Article 2 | Change article | Django site admin</title>",
  1386. )
  1387. self.assertContains(response, "<h1>Change article</h1>")
  1388. self.assertContains(response, "<h2>Article 2</h2>")
  1389. def test_error_in_titles(self):
  1390. for url, subtitle in [
  1391. (
  1392. reverse("admin:admin_views_article_change", args=(self.a1.pk,)),
  1393. "Article 1 | Change article",
  1394. ),
  1395. (reverse("admin:admin_views_article_add"), "Add article"),
  1396. (reverse("admin:login"), "Log in"),
  1397. (reverse("admin:password_change"), "Password change"),
  1398. (
  1399. reverse("admin:auth_user_password_change", args=(self.superuser.id,)),
  1400. "Change password: super",
  1401. ),
  1402. ]:
  1403. with self.subTest(url=url, subtitle=subtitle):
  1404. response = self.client.post(url, {})
  1405. self.assertContains(response, f"<title>Error: {subtitle}")
  1406. def test_view_subtitle_per_object(self):
  1407. viewuser = User.objects.create_user(
  1408. username="viewuser",
  1409. password="secret",
  1410. is_staff=True,
  1411. )
  1412. viewuser.user_permissions.add(
  1413. get_perm(Article, get_permission_codename("view", Article._meta)),
  1414. )
  1415. self.client.force_login(viewuser)
  1416. response = self.client.get(
  1417. reverse("admin:admin_views_article_change", args=(self.a1.pk,)),
  1418. )
  1419. self.assertContains(
  1420. response,
  1421. "<title>Article 1 | View article | Django site admin</title>",
  1422. )
  1423. self.assertContains(response, "<h1>View article</h1>")
  1424. self.assertContains(response, "<h2>Article 1</h2>")
  1425. response = self.client.get(
  1426. reverse("admin:admin_views_article_change", args=(self.a2.pk,)),
  1427. )
  1428. self.assertContains(
  1429. response,
  1430. "<title>Article 2 | View article | Django site admin</title>",
  1431. )
  1432. self.assertContains(response, "<h1>View article</h1>")
  1433. self.assertContains(response, "<h2>Article 2</h2>")
  1434. def test_formset_kwargs_can_be_overridden(self):
  1435. response = self.client.get(reverse("admin:admin_views_city_add"))
  1436. self.assertContains(response, "overridden_name")
  1437. def test_render_views_no_subtitle(self):
  1438. tests = [
  1439. reverse("admin:index"),
  1440. reverse("admin:password_change"),
  1441. reverse("admin:app_list", args=("admin_views",)),
  1442. reverse("admin:admin_views_article_delete", args=(self.a1.pk,)),
  1443. reverse("admin:admin_views_article_history", args=(self.a1.pk,)),
  1444. ]
  1445. for url in tests:
  1446. with self.subTest(url=url):
  1447. with self.assertNoLogs("django.template", "DEBUG"):
  1448. self.client.get(url)
  1449. # Login must be after logout.
  1450. with self.assertNoLogs("django.template", "DEBUG"):
  1451. self.client.post(reverse("admin:logout"))
  1452. self.client.get(reverse("admin:login"))
  1453. def test_render_delete_selected_confirmation_no_subtitle(self):
  1454. post_data = {
  1455. "action": "delete_selected",
  1456. "selected_across": "0",
  1457. "index": "0",
  1458. "_selected_action": self.a1.pk,
  1459. }
  1460. with self.assertNoLogs("django.template", "DEBUG"):
  1461. self.client.post(reverse("admin:admin_views_article_changelist"), post_data)
  1462. @override_settings(
  1463. AUTH_PASSWORD_VALIDATORS=[
  1464. {
  1465. "NAME": (
  1466. "django.contrib.auth.password_validation."
  1467. "UserAttributeSimilarityValidator"
  1468. )
  1469. },
  1470. {
  1471. "NAME": (
  1472. "django.contrib.auth.password_validation."
  1473. "NumericPasswordValidator"
  1474. )
  1475. },
  1476. ]
  1477. )
  1478. def test_password_change_helptext(self):
  1479. response = self.client.get(reverse("admin:password_change"))
  1480. self.assertContains(
  1481. response, '<div class="help" id="id_new_password1_helptext">'
  1482. )
  1483. def test_enable_zooming_on_mobile(self):
  1484. response = self.client.get(reverse("admin:index"))
  1485. self.assertContains(
  1486. response,
  1487. '<meta name="viewport" content="width=device-width, initial-scale=1.0">',
  1488. )
  1489. def test_header(self):
  1490. response = self.client.get(reverse("admin:index"))
  1491. self.assertContains(response, '<header id="header">')
  1492. self.client.logout()
  1493. response = self.client.get(reverse("admin:login"))
  1494. self.assertContains(response, '<header id="header">')
  1495. def test_main_content(self):
  1496. response = self.client.get(reverse("admin:index"))
  1497. self.assertContains(
  1498. response,
  1499. '<main id="content-start" class="content" tabindex="-1">',
  1500. )
  1501. def test_footer(self):
  1502. response = self.client.get(reverse("admin:index"))
  1503. self.assertContains(response, '<footer id="footer">')
  1504. self.client.logout()
  1505. response = self.client.get(reverse("admin:login"))
  1506. self.assertContains(response, '<footer id="footer">')
  1507. def test_aria_describedby_for_add_and_change_links(self):
  1508. response = self.client.get(reverse("admin:index"))
  1509. tests = [
  1510. ("admin_views", "actor"),
  1511. ("admin_views", "worker"),
  1512. ("auth", "group"),
  1513. ("auth", "user"),
  1514. ]
  1515. for app_label, model_name in tests:
  1516. with self.subTest(app_label=app_label, model_name=model_name):
  1517. row_id = f"{app_label}-{model_name}"
  1518. self.assertContains(response, f'<th scope="row" id="{row_id}">')
  1519. self.assertContains(
  1520. response,
  1521. f'<a href="/test_admin/admin/{app_label}/{model_name}/" '
  1522. f'class="changelink" aria-describedby="{row_id}">Change</a>',
  1523. )
  1524. self.assertContains(
  1525. response,
  1526. f'<a href="/test_admin/admin/{app_label}/{model_name}/add/" '
  1527. f'class="addlink" aria-describedby="{row_id}">Add</a>',
  1528. )
  1529. @override_settings(
  1530. AUTH_PASSWORD_VALIDATORS=[
  1531. {
  1532. "NAME": (
  1533. "django.contrib.auth.password_validation."
  1534. "UserAttributeSimilarityValidator"
  1535. )
  1536. },
  1537. {
  1538. "NAME": (
  1539. "django.contrib.auth.password_validation." "NumericPasswordValidator"
  1540. )
  1541. },
  1542. ],
  1543. TEMPLATES=[
  1544. {
  1545. "BACKEND": "django.template.backends.django.DjangoTemplates",
  1546. # Put this app's and the shared tests templates dirs in DIRS to
  1547. # take precedence over the admin's templates dir.
  1548. "DIRS": [
  1549. os.path.join(os.path.dirname(__file__), "templates"),
  1550. os.path.join(os.path.dirname(os.path.dirname(__file__)), "templates"),
  1551. ],
  1552. "APP_DIRS": True,
  1553. "OPTIONS": {
  1554. "context_processors": [
  1555. "django.template.context_processors.request",
  1556. "django.contrib.auth.context_processors.auth",
  1557. "django.contrib.messages.context_processors.messages",
  1558. ],
  1559. },
  1560. }
  1561. ],
  1562. )
  1563. class AdminCustomTemplateTests(AdminViewBasicTestCase):
  1564. def test_custom_model_admin_templates(self):
  1565. # Test custom change list template with custom extra context
  1566. response = self.client.get(
  1567. reverse("admin:admin_views_customarticle_changelist")
  1568. )
  1569. self.assertContains(response, "var hello = 'Hello!';")
  1570. self.assertTemplateUsed(response, "custom_admin/change_list.html")
  1571. # Test custom add form template
  1572. response = self.client.get(reverse("admin:admin_views_customarticle_add"))
  1573. self.assertTemplateUsed(response, "custom_admin/add_form.html")
  1574. # Add an article so we can test delete, change, and history views
  1575. post = self.client.post(
  1576. reverse("admin:admin_views_customarticle_add"),
  1577. {
  1578. "content": "<p>great article</p>",
  1579. "date_0": "2008-03-18",
  1580. "date_1": "10:54:39",
  1581. },
  1582. )
  1583. self.assertRedirects(
  1584. post, reverse("admin:admin_views_customarticle_changelist")
  1585. )
  1586. self.assertEqual(CustomArticle.objects.count(), 1)
  1587. article_pk = CustomArticle.objects.all()[0].pk
  1588. # Test custom delete, change, and object history templates
  1589. # Test custom change form template
  1590. response = self.client.get(
  1591. reverse("admin:admin_views_customarticle_change", args=(article_pk,))
  1592. )
  1593. self.assertTemplateUsed(response, "custom_admin/change_form.html")
  1594. response = self.client.get(
  1595. reverse("admin:admin_views_customarticle_delete", args=(article_pk,))
  1596. )
  1597. self.assertTemplateUsed(response, "custom_admin/delete_confirmation.html")
  1598. response = self.client.post(
  1599. reverse("admin:admin_views_customarticle_changelist"),
  1600. data={
  1601. "index": 0,
  1602. "action": ["delete_selected"],
  1603. "_selected_action": ["1"],
  1604. },
  1605. )
  1606. self.assertTemplateUsed(
  1607. response, "custom_admin/delete_selected_confirmation.html"
  1608. )
  1609. response = self.client.get(
  1610. reverse("admin:admin_views_customarticle_history", args=(article_pk,))
  1611. )
  1612. self.assertTemplateUsed(response, "custom_admin/object_history.html")
  1613. # A custom popup response template may be specified by
  1614. # ModelAdmin.popup_response_template.
  1615. response = self.client.post(
  1616. reverse("admin:admin_views_customarticle_add") + "?%s=1" % IS_POPUP_VAR,
  1617. {
  1618. "content": "<p>great article</p>",
  1619. "date_0": "2008-03-18",
  1620. "date_1": "10:54:39",
  1621. IS_POPUP_VAR: "1",
  1622. },
  1623. )
  1624. self.assertEqual(response.template_name, "custom_admin/popup_response.html")
  1625. def test_extended_bodyclass_template_change_form(self):
  1626. """
  1627. The admin/change_form.html template uses block.super in the
  1628. bodyclass block.
  1629. """
  1630. response = self.client.get(reverse("admin:admin_views_section_add"))
  1631. self.assertContains(response, "bodyclass_consistency_check ")
  1632. def test_extended_extrabody(self):
  1633. response = self.client.get(reverse("admin:admin_views_section_add"))
  1634. self.assertContains(response, "extrabody_check\n</body>")
  1635. def test_change_password_template(self):
  1636. user = User.objects.get(username="super")
  1637. response = self.client.get(
  1638. reverse("admin:auth_user_password_change", args=(user.id,))
  1639. )
  1640. # The auth/user/change_password.html template uses super in the
  1641. # bodyclass block.
  1642. self.assertContains(response, "bodyclass_consistency_check ")
  1643. # When a site has multiple passwords in the browser's password manager,
  1644. # a browser pop up asks which user the new password is for. To prevent
  1645. # this, the username is added to the change password form.
  1646. self.assertContains(
  1647. response, '<input type="text" name="username" value="super" class="hidden">'
  1648. )
  1649. # help text for passwords has an id.
  1650. self.assertContains(
  1651. response,
  1652. '<div class="help" id="id_password1_helptext"><ul><li>'
  1653. "Your password can’t be too similar to your other personal information."
  1654. "</li><li>Your password can’t be entirely numeric.</li></ul></div>",
  1655. )
  1656. self.assertContains(
  1657. response,
  1658. '<div class="help" id="id_password2_helptext">'
  1659. "Enter the same password as before, for verification.</div>",
  1660. )
  1661. def test_change_password_template_helptext_no_id(self):
  1662. user = User.objects.get(username="super")
  1663. class EmptyIdForLabelTextInput(forms.TextInput):
  1664. def id_for_label(self, id):
  1665. return None
  1666. class EmptyIdForLabelHelpTextPasswordChangeForm(AdminPasswordChangeForm):
  1667. password1 = forms.CharField(
  1668. help_text="Your new password", widget=EmptyIdForLabelTextInput()
  1669. )
  1670. class CustomUserAdmin(UserAdmin):
  1671. change_password_form = EmptyIdForLabelHelpTextPasswordChangeForm
  1672. request = RequestFactory().get(
  1673. reverse("admin:auth_user_password_change", args=(user.id,))
  1674. )
  1675. request.user = user
  1676. user_admin = CustomUserAdmin(User, site)
  1677. response = user_admin.user_change_password(request, str(user.pk))
  1678. self.assertContains(response, '<div class="help">')
  1679. def test_extended_bodyclass_template_index(self):
  1680. """
  1681. The admin/index.html template uses block.super in the bodyclass block.
  1682. """
  1683. response = self.client.get(reverse("admin:index"))
  1684. self.assertContains(response, "bodyclass_consistency_check ")
  1685. def test_extended_bodyclass_change_list(self):
  1686. """
  1687. The admin/change_list.html' template uses block.super
  1688. in the bodyclass block.
  1689. """
  1690. response = self.client.get(reverse("admin:admin_views_article_changelist"))
  1691. self.assertContains(response, "bodyclass_consistency_check ")
  1692. def test_extended_bodyclass_template_login(self):
  1693. """
  1694. The admin/login.html template uses block.super in the
  1695. bodyclass block.
  1696. """
  1697. self.client.logout()
  1698. response = self.client.get(reverse("admin:login"))
  1699. self.assertContains(response, "bodyclass_consistency_check ")
  1700. def test_extended_bodyclass_template_delete_confirmation(self):
  1701. """
  1702. The admin/delete_confirmation.html template uses
  1703. block.super in the bodyclass block.
  1704. """
  1705. group = Group.objects.create(name="foogroup")
  1706. response = self.client.get(reverse("admin:auth_group_delete", args=(group.id,)))
  1707. self.assertContains(response, "bodyclass_consistency_check ")
  1708. def test_extended_bodyclass_template_delete_selected_confirmation(self):
  1709. """
  1710. The admin/delete_selected_confirmation.html template uses
  1711. block.super in bodyclass block.
  1712. """
  1713. group = Group.objects.create(name="foogroup")
  1714. post_data = {
  1715. "action": "delete_selected",
  1716. "selected_across": "0",
  1717. "index": "0",
  1718. "_selected_action": group.id,
  1719. }
  1720. response = self.client.post(reverse("admin:auth_group_changelist"), post_data)
  1721. self.assertEqual(response.context["site_header"], "Django administration")
  1722. self.assertContains(response, "bodyclass_consistency_check ")
  1723. def test_filter_with_custom_template(self):
  1724. """
  1725. A custom template can be used to render an admin filter.
  1726. """
  1727. response = self.client.get(reverse("admin:admin_views_color2_changelist"))
  1728. self.assertTemplateUsed(response, "custom_filter_template.html")
  1729. @override_settings(ROOT_URLCONF="admin_views.urls")
  1730. class AdminViewFormUrlTest(TestCase):
  1731. current_app = "admin3"
  1732. @classmethod
  1733. def setUpTestData(cls):
  1734. cls.superuser = User.objects.create_superuser(
  1735. username="super", password="secret", email="super@example.com"
  1736. )
  1737. cls.s1 = Section.objects.create(name="Test section")
  1738. cls.a1 = Article.objects.create(
  1739. content="<p>Middle content</p>",
  1740. date=datetime.datetime(2008, 3, 18, 11, 54, 58),
  1741. section=cls.s1,
  1742. )
  1743. cls.a2 = Article.objects.create(
  1744. content="<p>Oldest content</p>",
  1745. date=datetime.datetime(2000, 3, 18, 11, 54, 58),
  1746. section=cls.s1,
  1747. )
  1748. cls.a3 = Article.objects.create(
  1749. content="<p>Newest content</p>",
  1750. date=datetime.datetime(2009, 3, 18, 11, 54, 58),
  1751. section=cls.s1,
  1752. )
  1753. cls.p1 = PrePopulatedPost.objects.create(
  1754. title="A Long Title", published=True, slug="a-long-title"
  1755. )
  1756. def setUp(self):
  1757. self.client.force_login(self.superuser)
  1758. def test_change_form_URL_has_correct_value(self):
  1759. """
  1760. change_view has form_url in response.context
  1761. """
  1762. response = self.client.get(
  1763. reverse(
  1764. "admin:admin_views_section_change",
  1765. args=(self.s1.pk,),
  1766. current_app=self.current_app,
  1767. )
  1768. )
  1769. self.assertIn(
  1770. "form_url", response.context, msg="form_url not present in response.context"
  1771. )
  1772. self.assertEqual(response.context["form_url"], "pony")
  1773. def test_initial_data_can_be_overridden(self):
  1774. """
  1775. The behavior for setting initial form data can be overridden in the
  1776. ModelAdmin class. Usually, the initial value is set via the GET params.
  1777. """
  1778. response = self.client.get(
  1779. reverse("admin:admin_views_restaurant_add", current_app=self.current_app),
  1780. {"name": "test_value"},
  1781. )
  1782. # this would be the usual behaviour
  1783. self.assertNotContains(response, 'value="test_value"')
  1784. # this is the overridden behaviour
  1785. self.assertContains(response, 'value="overridden_value"')
  1786. @override_settings(ROOT_URLCONF="admin_views.urls")
  1787. class AdminJavaScriptTest(TestCase):
  1788. @classmethod
  1789. def setUpTestData(cls):
  1790. cls.superuser = User.objects.create_superuser(
  1791. username="super", password="secret", email="super@example.com"
  1792. )
  1793. def setUp(self):
  1794. self.client.force_login(self.superuser)
  1795. def test_js_minified_only_if_debug_is_false(self):
  1796. """
  1797. The minified versions of the JS files are only used when DEBUG is False.
  1798. """
  1799. with override_settings(DEBUG=False):
  1800. response = self.client.get(reverse("admin:admin_views_section_add"))
  1801. self.assertNotContains(response, "vendor/jquery/jquery.js")
  1802. self.assertContains(response, "vendor/jquery/jquery.min.js")
  1803. self.assertContains(response, "prepopulate.js")
  1804. self.assertContains(response, "actions.js")
  1805. self.assertContains(response, "inlines.js")
  1806. with override_settings(DEBUG=True):
  1807. response = self.client.get(reverse("admin:admin_views_section_add"))
  1808. self.assertContains(response, "vendor/jquery/jquery.js")
  1809. self.assertNotContains(response, "vendor/jquery/jquery.min.js")
  1810. self.assertContains(response, "prepopulate.js")
  1811. self.assertContains(response, "actions.js")
  1812. self.assertContains(response, "inlines.js")
  1813. @override_settings(ROOT_URLCONF="admin_views.urls")
  1814. class SaveAsTests(TestCase):
  1815. @classmethod
  1816. def setUpTestData(cls):
  1817. cls.superuser = User.objects.create_superuser(
  1818. username="super", password="secret", email="super@example.com"
  1819. )
  1820. cls.per1 = Person.objects.create(name="John Mauchly", gender=1, alive=True)
  1821. def setUp(self):
  1822. self.client.force_login(self.superuser)
  1823. def test_save_as_duplication(self):
  1824. """'save as' creates a new person"""
  1825. post_data = {"_saveasnew": "", "name": "John M", "gender": 1, "age": 42}
  1826. response = self.client.post(
  1827. reverse("admin:admin_views_person_change", args=(self.per1.pk,)), post_data
  1828. )
  1829. self.assertEqual(len(Person.objects.filter(name="John M")), 1)
  1830. self.assertEqual(len(Person.objects.filter(id=self.per1.pk)), 1)
  1831. new_person = Person.objects.latest("id")
  1832. self.assertRedirects(
  1833. response, reverse("admin:admin_views_person_change", args=(new_person.pk,))
  1834. )
  1835. def test_save_as_continue_false(self):
  1836. """
  1837. Saving a new object using "Save as new" redirects to the changelist
  1838. instead of the change view when ModelAdmin.save_as_continue=False.
  1839. """
  1840. post_data = {"_saveasnew": "", "name": "John M", "gender": 1, "age": 42}
  1841. url = reverse(
  1842. "admin:admin_views_person_change",
  1843. args=(self.per1.pk,),
  1844. current_app=site2.name,
  1845. )
  1846. response = self.client.post(url, post_data)
  1847. self.assertEqual(len(Person.objects.filter(name="John M")), 1)
  1848. self.assertEqual(len(Person.objects.filter(id=self.per1.pk)), 1)
  1849. self.assertRedirects(
  1850. response,
  1851. reverse("admin:admin_views_person_changelist", current_app=site2.name),
  1852. )
  1853. def test_save_as_new_with_validation_errors(self):
  1854. """
  1855. When you click "Save as new" and have a validation error,
  1856. you only see the "Save as new" button and not the other save buttons,
  1857. and that only the "Save as" button is visible.
  1858. """
  1859. response = self.client.post(
  1860. reverse("admin:admin_views_person_change", args=(self.per1.pk,)),
  1861. {
  1862. "_saveasnew": "",
  1863. "gender": "invalid",
  1864. "_addanother": "fail",
  1865. },
  1866. )
  1867. self.assertContains(response, "Please correct the errors below.")
  1868. self.assertFalse(response.context["show_save_and_add_another"])
  1869. self.assertFalse(response.context["show_save_and_continue"])
  1870. self.assertTrue(response.context["show_save_as_new"])
  1871. def test_save_as_new_with_validation_errors_with_inlines(self):
  1872. parent = Parent.objects.create(name="Father")
  1873. child = Child.objects.create(parent=parent, name="Child")
  1874. response = self.client.post(
  1875. reverse("admin:admin_views_parent_change", args=(parent.pk,)),
  1876. {
  1877. "_saveasnew": "Save as new",
  1878. "child_set-0-parent": parent.pk,
  1879. "child_set-0-id": child.pk,
  1880. "child_set-0-name": "Child",
  1881. "child_set-INITIAL_FORMS": 1,
  1882. "child_set-MAX_NUM_FORMS": 1000,
  1883. "child_set-MIN_NUM_FORMS": 0,
  1884. "child_set-TOTAL_FORMS": 4,
  1885. "name": "_invalid",
  1886. },
  1887. )
  1888. self.assertContains(response, "Please correct the error below.")
  1889. self.assertFalse(response.context["show_save_and_add_another"])
  1890. self.assertFalse(response.context["show_save_and_continue"])
  1891. self.assertTrue(response.context["show_save_as_new"])
  1892. def test_save_as_new_with_inlines_with_validation_errors(self):
  1893. parent = Parent.objects.create(name="Father")
  1894. child = Child.objects.create(parent=parent, name="Child")
  1895. response = self.client.post(
  1896. reverse("admin:admin_views_parent_change", args=(parent.pk,)),
  1897. {
  1898. "_saveasnew": "Save as new",
  1899. "child_set-0-parent": parent.pk,
  1900. "child_set-0-id": child.pk,
  1901. "child_set-0-name": "_invalid",
  1902. "child_set-INITIAL_FORMS": 1,
  1903. "child_set-MAX_NUM_FORMS": 1000,
  1904. "child_set-MIN_NUM_FORMS": 0,
  1905. "child_set-TOTAL_FORMS": 4,
  1906. "name": "Father",
  1907. },
  1908. )
  1909. self.assertContains(response, "Please correct the error below.")
  1910. self.assertFalse(response.context["show_save_and_add_another"])
  1911. self.assertFalse(response.context["show_save_and_continue"])
  1912. self.assertTrue(response.context["show_save_as_new"])
  1913. @override_settings(ROOT_URLCONF="admin_views.urls")
  1914. class CustomModelAdminTest(AdminViewBasicTestCase):
  1915. def test_custom_admin_site_login_form(self):
  1916. self.client.logout()
  1917. response = self.client.get(reverse("admin2:index"), follow=True)
  1918. self.assertIsInstance(response, TemplateResponse)
  1919. self.assertEqual(response.status_code, 200)
  1920. login = self.client.post(
  1921. reverse("admin2:login"),
  1922. {
  1923. REDIRECT_FIELD_NAME: reverse("admin2:index"),
  1924. "username": "customform",
  1925. "password": "secret",
  1926. },
  1927. follow=True,
  1928. )
  1929. self.assertIsInstance(login, TemplateResponse)
  1930. self.assertContains(login, "custom form error")
  1931. self.assertContains(login, "path/to/media.css")
  1932. def test_custom_admin_site_login_template(self):
  1933. self.client.logout()
  1934. response = self.client.get(reverse("admin2:index"), follow=True)
  1935. self.assertIsInstance(response, TemplateResponse)
  1936. self.assertTemplateUsed(response, "custom_admin/login.html")
  1937. self.assertContains(response, "Hello from a custom login template")
  1938. def test_custom_admin_site_logout_template(self):
  1939. response = self.client.post(reverse("admin2:logout"))
  1940. self.assertIsInstance(response, TemplateResponse)
  1941. self.assertTemplateUsed(response, "custom_admin/logout.html")
  1942. self.assertContains(response, "Hello from a custom logout template")
  1943. def test_custom_admin_site_index_view_and_template(self):
  1944. response = self.client.get(reverse("admin2:index"))
  1945. self.assertIsInstance(response, TemplateResponse)
  1946. self.assertTemplateUsed(response, "custom_admin/index.html")
  1947. self.assertContains(response, "Hello from a custom index template *bar*")
  1948. def test_custom_admin_site_app_index_view_and_template(self):
  1949. response = self.client.get(reverse("admin2:app_list", args=("admin_views",)))
  1950. self.assertIsInstance(response, TemplateResponse)
  1951. self.assertTemplateUsed(response, "custom_admin/app_index.html")
  1952. self.assertContains(response, "Hello from a custom app_index template")
  1953. def test_custom_admin_site_password_change_template(self):
  1954. response = self.client.get(reverse("admin2:password_change"))
  1955. self.assertIsInstance(response, TemplateResponse)
  1956. self.assertTemplateUsed(response, "custom_admin/password_change_form.html")
  1957. self.assertContains(
  1958. response, "Hello from a custom password change form template"
  1959. )
  1960. def test_custom_admin_site_password_change_with_extra_context(self):
  1961. response = self.client.get(reverse("admin2:password_change"))
  1962. self.assertIsInstance(response, TemplateResponse)
  1963. self.assertTemplateUsed(response, "custom_admin/password_change_form.html")
  1964. self.assertContains(response, "eggs")
  1965. def test_custom_admin_site_password_change_done_template(self):
  1966. response = self.client.get(reverse("admin2:password_change_done"))
  1967. self.assertIsInstance(response, TemplateResponse)
  1968. self.assertTemplateUsed(response, "custom_admin/password_change_done.html")
  1969. self.assertContains(
  1970. response, "Hello from a custom password change done template"
  1971. )
  1972. def test_custom_admin_site_view(self):
  1973. self.client.force_login(self.superuser)
  1974. response = self.client.get(reverse("admin2:my_view"))
  1975. self.assertEqual(response.content, b"Django is a magical pony!")
  1976. def test_pwd_change_custom_template(self):
  1977. self.client.force_login(self.superuser)
  1978. su = User.objects.get(username="super")
  1979. response = self.client.get(
  1980. reverse("admin4:auth_user_password_change", args=(su.pk,))
  1981. )
  1982. self.assertEqual(response.status_code, 200)
  1983. def get_perm(Model, codename):
  1984. """Return the permission object, for the Model"""
  1985. ct = ContentType.objects.get_for_model(Model, for_concrete_model=False)
  1986. return Permission.objects.get(content_type=ct, codename=codename)
  1987. @override_settings(
  1988. ROOT_URLCONF="admin_views.urls",
  1989. # Test with the admin's documented list of required context processors.
  1990. TEMPLATES=[
  1991. {
  1992. "BACKEND": "django.template.backends.django.DjangoTemplates",
  1993. "APP_DIRS": True,
  1994. "OPTIONS": {
  1995. "context_processors": [
  1996. "django.template.context_processors.request",
  1997. "django.contrib.auth.context_processors.auth",
  1998. "django.contrib.messages.context_processors.messages",
  1999. ],
  2000. },
  2001. }
  2002. ],
  2003. )
  2004. class AdminViewPermissionsTest(TestCase):
  2005. """Tests for Admin Views Permissions."""
  2006. @classmethod
  2007. def setUpTestData(cls):
  2008. cls.superuser = User.objects.create_superuser(
  2009. username="super", password="secret", email="super@example.com"
  2010. )
  2011. cls.viewuser = User.objects.create_user(
  2012. username="viewuser", password="secret", is_staff=True
  2013. )
  2014. cls.adduser = User.objects.create_user(
  2015. username="adduser", password="secret", is_staff=True
  2016. )
  2017. cls.changeuser = User.objects.create_user(
  2018. username="changeuser", password="secret", is_staff=True
  2019. )
  2020. cls.deleteuser = User.objects.create_user(
  2021. username="deleteuser", password="secret", is_staff=True
  2022. )
  2023. cls.joepublicuser = User.objects.create_user(
  2024. username="joepublic", password="secret"
  2025. )
  2026. cls.nostaffuser = User.objects.create_user(
  2027. username="nostaff", password="secret"
  2028. )
  2029. cls.s1 = Section.objects.create(name="Test section")
  2030. cls.a1 = Article.objects.create(
  2031. content="<p>Middle content</p>",
  2032. date=datetime.datetime(2008, 3, 18, 11, 54, 58),
  2033. section=cls.s1,
  2034. another_section=cls.s1,
  2035. )
  2036. cls.a2 = Article.objects.create(
  2037. content="<p>Oldest content</p>",
  2038. date=datetime.datetime(2000, 3, 18, 11, 54, 58),
  2039. section=cls.s1,
  2040. )
  2041. cls.a3 = Article.objects.create(
  2042. content="<p>Newest content</p>",
  2043. date=datetime.datetime(2009, 3, 18, 11, 54, 58),
  2044. section=cls.s1,
  2045. )
  2046. cls.p1 = PrePopulatedPost.objects.create(
  2047. title="A Long Title", published=True, slug="a-long-title"
  2048. )
  2049. # Setup permissions, for our users who can add, change, and delete.
  2050. opts = Article._meta
  2051. # User who can view Articles
  2052. cls.viewuser.user_permissions.add(
  2053. get_perm(Article, get_permission_codename("view", opts))
  2054. )
  2055. # User who can add Articles
  2056. cls.adduser.user_permissions.add(
  2057. get_perm(Article, get_permission_codename("add", opts))
  2058. )
  2059. # User who can change Articles
  2060. cls.changeuser.user_permissions.add(
  2061. get_perm(Article, get_permission_codename("change", opts))
  2062. )
  2063. cls.nostaffuser.user_permissions.add(
  2064. get_perm(Article, get_permission_codename("change", opts))
  2065. )
  2066. # User who can delete Articles
  2067. cls.deleteuser.user_permissions.add(
  2068. get_perm(Article, get_permission_codename("delete", opts))
  2069. )
  2070. cls.deleteuser.user_permissions.add(
  2071. get_perm(Section, get_permission_codename("delete", Section._meta))
  2072. )
  2073. # login POST dicts
  2074. cls.index_url = reverse("admin:index")
  2075. cls.super_login = {
  2076. REDIRECT_FIELD_NAME: cls.index_url,
  2077. "username": "super",
  2078. "password": "secret",
  2079. }
  2080. cls.super_email_login = {
  2081. REDIRECT_FIELD_NAME: cls.index_url,
  2082. "username": "super@example.com",
  2083. "password": "secret",
  2084. }
  2085. cls.super_email_bad_login = {
  2086. REDIRECT_FIELD_NAME: cls.index_url,
  2087. "username": "super@example.com",
  2088. "password": "notsecret",
  2089. }
  2090. cls.adduser_login = {
  2091. REDIRECT_FIELD_NAME: cls.index_url,
  2092. "username": "adduser",
  2093. "password": "secret",
  2094. }
  2095. cls.changeuser_login = {
  2096. REDIRECT_FIELD_NAME: cls.index_url,
  2097. "username": "changeuser",
  2098. "password": "secret",
  2099. }
  2100. cls.deleteuser_login = {
  2101. REDIRECT_FIELD_NAME: cls.index_url,
  2102. "username": "deleteuser",
  2103. "password": "secret",
  2104. }
  2105. cls.nostaff_login = {
  2106. REDIRECT_FIELD_NAME: reverse("has_permission_admin:index"),
  2107. "username": "nostaff",
  2108. "password": "secret",
  2109. }
  2110. cls.joepublic_login = {
  2111. REDIRECT_FIELD_NAME: cls.index_url,
  2112. "username": "joepublic",
  2113. "password": "secret",
  2114. }
  2115. cls.viewuser_login = {
  2116. REDIRECT_FIELD_NAME: cls.index_url,
  2117. "username": "viewuser",
  2118. "password": "secret",
  2119. }
  2120. cls.no_username_login = {
  2121. REDIRECT_FIELD_NAME: cls.index_url,
  2122. "password": "secret",
  2123. }
  2124. def test_login(self):
  2125. """
  2126. Make sure only staff members can log in.
  2127. Successful posts to the login page will redirect to the original url.
  2128. Unsuccessful attempts will continue to render the login page with
  2129. a 200 status code.
  2130. """
  2131. login_url = "%s?next=%s" % (reverse("admin:login"), reverse("admin:index"))
  2132. # Super User
  2133. response = self.client.get(self.index_url)
  2134. self.assertRedirects(response, login_url)
  2135. login = self.client.post(login_url, self.super_login)
  2136. self.assertRedirects(login, self.index_url)
  2137. self.assertFalse(login.context)
  2138. self.client.post(reverse("admin:logout"))
  2139. # Test if user enters email address
  2140. response = self.client.get(self.index_url)
  2141. self.assertEqual(response.status_code, 302)
  2142. login = self.client.post(login_url, self.super_email_login)
  2143. self.assertContains(login, ERROR_MESSAGE)
  2144. # only correct passwords get a username hint
  2145. login = self.client.post(login_url, self.super_email_bad_login)
  2146. self.assertContains(login, ERROR_MESSAGE)
  2147. new_user = User(username="jondoe", password="secret", email="super@example.com")
  2148. new_user.save()
  2149. # check to ensure if there are multiple email addresses a user doesn't get a 500
  2150. login = self.client.post(login_url, self.super_email_login)
  2151. self.assertContains(login, ERROR_MESSAGE)
  2152. # View User
  2153. response = self.client.get(self.index_url)
  2154. self.assertEqual(response.status_code, 302)
  2155. login = self.client.post(login_url, self.viewuser_login)
  2156. self.assertRedirects(login, self.index_url)
  2157. self.assertFalse(login.context)
  2158. self.client.post(reverse("admin:logout"))
  2159. # Add User
  2160. response = self.client.get(self.index_url)
  2161. self.assertEqual(response.status_code, 302)
  2162. login = self.client.post(login_url, self.adduser_login)
  2163. self.assertRedirects(login, self.index_url)
  2164. self.assertFalse(login.context)
  2165. self.client.post(reverse("admin:logout"))
  2166. # Change User
  2167. response = self.client.get(self.index_url)
  2168. self.assertEqual(response.status_code, 302)
  2169. login = self.client.post(login_url, self.changeuser_login)
  2170. self.assertRedirects(login, self.index_url)
  2171. self.assertFalse(login.context)
  2172. self.client.post(reverse("admin:logout"))
  2173. # Delete User
  2174. response = self.client.get(self.index_url)
  2175. self.assertEqual(response.status_code, 302)
  2176. login = self.client.post(login_url, self.deleteuser_login)
  2177. self.assertRedirects(login, self.index_url)
  2178. self.assertFalse(login.context)
  2179. self.client.post(reverse("admin:logout"))
  2180. # Regular User should not be able to login.
  2181. response = self.client.get(self.index_url)
  2182. self.assertEqual(response.status_code, 302)
  2183. login = self.client.post(login_url, self.joepublic_login)
  2184. self.assertContains(login, ERROR_MESSAGE)
  2185. # Requests without username should not return 500 errors.
  2186. response = self.client.get(self.index_url)
  2187. self.assertEqual(response.status_code, 302)
  2188. login = self.client.post(login_url, self.no_username_login)
  2189. self.assertEqual(login.status_code, 200)
  2190. self.assertFormError(
  2191. login.context["form"], "username", ["This field is required."]
  2192. )
  2193. def test_login_redirect_for_direct_get(self):
  2194. """
  2195. Login redirect should be to the admin index page when going directly to
  2196. /admin/login/.
  2197. """
  2198. response = self.client.get(reverse("admin:login"))
  2199. self.assertEqual(response.status_code, 200)
  2200. self.assertEqual(response.context[REDIRECT_FIELD_NAME], reverse("admin:index"))
  2201. def test_login_has_permission(self):
  2202. # Regular User should not be able to login.
  2203. response = self.client.get(reverse("has_permission_admin:index"))
  2204. self.assertEqual(response.status_code, 302)
  2205. login = self.client.post(
  2206. reverse("has_permission_admin:login"), self.joepublic_login
  2207. )
  2208. self.assertContains(login, "permission denied")
  2209. # User with permissions should be able to login.
  2210. response = self.client.get(reverse("has_permission_admin:index"))
  2211. self.assertEqual(response.status_code, 302)
  2212. login = self.client.post(
  2213. reverse("has_permission_admin:login"), self.nostaff_login
  2214. )
  2215. self.assertRedirects(login, reverse("has_permission_admin:index"))
  2216. self.assertFalse(login.context)
  2217. self.client.post(reverse("has_permission_admin:logout"))
  2218. # Staff should be able to login.
  2219. response = self.client.get(reverse("has_permission_admin:index"))
  2220. self.assertEqual(response.status_code, 302)
  2221. login = self.client.post(
  2222. reverse("has_permission_admin:login"),
  2223. {
  2224. REDIRECT_FIELD_NAME: reverse("has_permission_admin:index"),
  2225. "username": "deleteuser",
  2226. "password": "secret",
  2227. },
  2228. )
  2229. self.assertRedirects(login, reverse("has_permission_admin:index"))
  2230. self.assertFalse(login.context)
  2231. self.client.post(reverse("has_permission_admin:logout"))
  2232. def test_login_successfully_redirects_to_original_URL(self):
  2233. response = self.client.get(self.index_url)
  2234. self.assertEqual(response.status_code, 302)
  2235. query_string = "the-answer=42"
  2236. redirect_url = "%s?%s" % (self.index_url, query_string)
  2237. new_next = {REDIRECT_FIELD_NAME: redirect_url}
  2238. post_data = self.super_login.copy()
  2239. post_data.pop(REDIRECT_FIELD_NAME)
  2240. login = self.client.post(
  2241. "%s?%s" % (reverse("admin:login"), urlencode(new_next)), post_data
  2242. )
  2243. self.assertRedirects(login, redirect_url)
  2244. def test_double_login_is_not_allowed(self):
  2245. """Regression test for #19327"""
  2246. login_url = "%s?next=%s" % (reverse("admin:login"), reverse("admin:index"))
  2247. response = self.client.get(self.index_url)
  2248. self.assertEqual(response.status_code, 302)
  2249. # Establish a valid admin session
  2250. login = self.client.post(login_url, self.super_login)
  2251. self.assertRedirects(login, self.index_url)
  2252. self.assertFalse(login.context)
  2253. # Logging in with non-admin user fails
  2254. login = self.client.post(login_url, self.joepublic_login)
  2255. self.assertContains(login, ERROR_MESSAGE)
  2256. # Establish a valid admin session
  2257. login = self.client.post(login_url, self.super_login)
  2258. self.assertRedirects(login, self.index_url)
  2259. self.assertFalse(login.context)
  2260. # Logging in with admin user while already logged in
  2261. login = self.client.post(login_url, self.super_login)
  2262. self.assertRedirects(login, self.index_url)
  2263. self.assertFalse(login.context)
  2264. self.client.post(reverse("admin:logout"))
  2265. def test_login_page_notice_for_non_staff_users(self):
  2266. """
  2267. A logged-in non-staff user trying to access the admin index should be
  2268. presented with the login page and a hint indicating that the current
  2269. user doesn't have access to it.
  2270. """
  2271. hint_template = "You are authenticated as {}"
  2272. # Anonymous user should not be shown the hint
  2273. response = self.client.get(self.index_url, follow=True)
  2274. self.assertContains(response, "login-form")
  2275. self.assertNotContains(response, hint_template.format(""), status_code=200)
  2276. # Non-staff user should be shown the hint
  2277. self.client.force_login(self.nostaffuser)
  2278. response = self.client.get(self.index_url, follow=True)
  2279. self.assertContains(response, "login-form")
  2280. self.assertContains(
  2281. response, hint_template.format(self.nostaffuser.username), status_code=200
  2282. )
  2283. def test_add_view(self):
  2284. """Test add view restricts access and actually adds items."""
  2285. add_dict = {
  2286. "title": "Døm ikke",
  2287. "content": "<p>great article</p>",
  2288. "date_0": "2008-03-18",
  2289. "date_1": "10:54:39",
  2290. "section": self.s1.pk,
  2291. }
  2292. # Change User should not have access to add articles
  2293. self.client.force_login(self.changeuser)
  2294. # make sure the view removes test cookie
  2295. self.assertIs(self.client.session.test_cookie_worked(), False)
  2296. response = self.client.get(reverse("admin:admin_views_article_add"))
  2297. self.assertEqual(response.status_code, 403)
  2298. # Try POST just to make sure
  2299. post = self.client.post(reverse("admin:admin_views_article_add"), add_dict)
  2300. self.assertEqual(post.status_code, 403)
  2301. self.assertEqual(Article.objects.count(), 3)
  2302. self.client.post(reverse("admin:logout"))
  2303. # View User should not have access to add articles
  2304. self.client.force_login(self.viewuser)
  2305. response = self.client.get(reverse("admin:admin_views_article_add"))
  2306. self.assertEqual(response.status_code, 403)
  2307. # Try POST just to make sure
  2308. post = self.client.post(reverse("admin:admin_views_article_add"), add_dict)
  2309. self.assertEqual(post.status_code, 403)
  2310. self.assertEqual(Article.objects.count(), 3)
  2311. # Now give the user permission to add but not change.
  2312. self.viewuser.user_permissions.add(
  2313. get_perm(Article, get_permission_codename("add", Article._meta))
  2314. )
  2315. response = self.client.get(reverse("admin:admin_views_article_add"))
  2316. self.assertEqual(response.context["title"], "Add article")
  2317. self.assertContains(response, "<title>Add article | Django site admin</title>")
  2318. self.assertContains(
  2319. response, '<input type="submit" value="Save and view" name="_continue">'
  2320. )
  2321. self.assertContains(
  2322. response,
  2323. '<h2 id="fieldset-0-0-heading" class="fieldset-heading">Some fields</h2>',
  2324. )
  2325. self.assertContains(
  2326. response,
  2327. '<h2 id="fieldset-0-1-heading" class="fieldset-heading">'
  2328. "Some other fields</h2>",
  2329. )
  2330. self.assertContains(
  2331. response,
  2332. '<h2 id="fieldset-0-2-heading" class="fieldset-heading">이름</h2>',
  2333. )
  2334. post = self.client.post(
  2335. reverse("admin:admin_views_article_add"), add_dict, follow=False
  2336. )
  2337. self.assertEqual(post.status_code, 302)
  2338. self.assertEqual(Article.objects.count(), 4)
  2339. article = Article.objects.latest("pk")
  2340. response = self.client.get(
  2341. reverse("admin:admin_views_article_change", args=(article.pk,))
  2342. )
  2343. self.assertContains(
  2344. response,
  2345. '<li class="success">The article “Døm ikke” was added successfully.</li>',
  2346. )
  2347. article.delete()
  2348. self.client.post(reverse("admin:logout"))
  2349. # Add user may login and POST to add view, then redirect to admin root
  2350. self.client.force_login(self.adduser)
  2351. addpage = self.client.get(reverse("admin:admin_views_article_add"))
  2352. change_list_link = '&rsaquo; <a href="%s">Articles</a>' % reverse(
  2353. "admin:admin_views_article_changelist"
  2354. )
  2355. self.assertNotContains(
  2356. addpage,
  2357. change_list_link,
  2358. msg_prefix=(
  2359. "User restricted to add permission is given link to change list view "
  2360. "in breadcrumbs."
  2361. ),
  2362. )
  2363. post = self.client.post(reverse("admin:admin_views_article_add"), add_dict)
  2364. self.assertRedirects(post, self.index_url)
  2365. self.assertEqual(Article.objects.count(), 4)
  2366. self.assertEqual(len(mail.outbox), 2)
  2367. self.assertEqual(mail.outbox[0].subject, "Greetings from a created object")
  2368. self.client.post(reverse("admin:logout"))
  2369. # The addition was logged correctly
  2370. addition_log = LogEntry.objects.all()[0]
  2371. new_article = Article.objects.last()
  2372. article_ct = ContentType.objects.get_for_model(Article)
  2373. self.assertEqual(addition_log.user_id, self.adduser.pk)
  2374. self.assertEqual(addition_log.content_type_id, article_ct.pk)
  2375. self.assertEqual(addition_log.object_id, str(new_article.pk))
  2376. self.assertEqual(addition_log.object_repr, "Døm ikke")
  2377. self.assertEqual(addition_log.action_flag, ADDITION)
  2378. self.assertEqual(addition_log.get_change_message(), "Added.")
  2379. # Super can add too, but is redirected to the change list view
  2380. self.client.force_login(self.superuser)
  2381. addpage = self.client.get(reverse("admin:admin_views_article_add"))
  2382. self.assertContains(
  2383. addpage,
  2384. change_list_link,
  2385. msg_prefix=(
  2386. "Unrestricted user is not given link to change list view in "
  2387. "breadcrumbs."
  2388. ),
  2389. )
  2390. post = self.client.post(reverse("admin:admin_views_article_add"), add_dict)
  2391. self.assertRedirects(post, reverse("admin:admin_views_article_changelist"))
  2392. self.assertEqual(Article.objects.count(), 5)
  2393. self.client.post(reverse("admin:logout"))
  2394. # 8509 - if a normal user is already logged in, it is possible
  2395. # to change user into the superuser without error
  2396. self.client.force_login(self.joepublicuser)
  2397. # Check and make sure that if user expires, data still persists
  2398. self.client.force_login(self.superuser)
  2399. # make sure the view removes test cookie
  2400. self.assertIs(self.client.session.test_cookie_worked(), False)
  2401. @mock.patch("django.contrib.admin.options.InlineModelAdmin.has_change_permission")
  2402. def test_add_view_with_view_only_inlines(self, has_change_permission):
  2403. """User with add permission to a section but view-only for inlines."""
  2404. self.viewuser.user_permissions.add(
  2405. get_perm(Section, get_permission_codename("add", Section._meta))
  2406. )
  2407. self.client.force_login(self.viewuser)
  2408. # Valid POST creates a new section.
  2409. data = {
  2410. "name": "New obj",
  2411. "article_set-TOTAL_FORMS": 0,
  2412. "article_set-INITIAL_FORMS": 0,
  2413. }
  2414. response = self.client.post(reverse("admin:admin_views_section_add"), data)
  2415. self.assertRedirects(response, reverse("admin:index"))
  2416. self.assertEqual(Section.objects.latest("id").name, data["name"])
  2417. # InlineModelAdmin.has_change_permission()'s obj argument is always
  2418. # None during object add.
  2419. self.assertEqual(
  2420. [obj for (request, obj), _ in has_change_permission.call_args_list],
  2421. [None, None],
  2422. )
  2423. def test_change_view(self):
  2424. """Change view should restrict access and allow users to edit items."""
  2425. change_dict = {
  2426. "title": "Ikke fordømt",
  2427. "content": "<p>edited article</p>",
  2428. "date_0": "2008-03-18",
  2429. "date_1": "10:54:39",
  2430. "section": self.s1.pk,
  2431. }
  2432. article_change_url = reverse(
  2433. "admin:admin_views_article_change", args=(self.a1.pk,)
  2434. )
  2435. article_changelist_url = reverse("admin:admin_views_article_changelist")
  2436. # add user should not be able to view the list of article or change any of them
  2437. self.client.force_login(self.adduser)
  2438. response = self.client.get(article_changelist_url)
  2439. self.assertEqual(response.status_code, 403)
  2440. response = self.client.get(article_change_url)
  2441. self.assertEqual(response.status_code, 403)
  2442. post = self.client.post(article_change_url, change_dict)
  2443. self.assertEqual(post.status_code, 403)
  2444. self.client.post(reverse("admin:logout"))
  2445. # view user can view articles but not make changes.
  2446. self.client.force_login(self.viewuser)
  2447. response = self.client.get(article_changelist_url)
  2448. self.assertContains(
  2449. response,
  2450. "<title>Select article to view | Django site admin</title>",
  2451. )
  2452. self.assertContains(response, "<h1>Select article to view</h1>")
  2453. self.assertEqual(response.context["title"], "Select article to view")
  2454. response = self.client.get(article_change_url)
  2455. self.assertContains(response, "<title>View article | Django site admin</title>")
  2456. self.assertContains(response, "<h1>View article</h1>")
  2457. self.assertContains(response, "<label>Extra form field:</label>")
  2458. self.assertContains(
  2459. response,
  2460. '<a href="/test_admin/admin/admin_views/article/" class="closelink">Close'
  2461. "</a>",
  2462. )
  2463. self.assertEqual(response.context["title"], "View article")
  2464. post = self.client.post(article_change_url, change_dict)
  2465. self.assertEqual(post.status_code, 403)
  2466. self.assertEqual(
  2467. Article.objects.get(pk=self.a1.pk).content, "<p>Middle content</p>"
  2468. )
  2469. self.client.post(reverse("admin:logout"))
  2470. # change user can view all items and edit them
  2471. self.client.force_login(self.changeuser)
  2472. response = self.client.get(article_changelist_url)
  2473. self.assertEqual(response.context["title"], "Select article to change")
  2474. self.assertContains(
  2475. response,
  2476. "<title>Select article to change | Django site admin</title>",
  2477. )
  2478. self.assertContains(response, "<h1>Select article to change</h1>")
  2479. response = self.client.get(article_change_url)
  2480. self.assertEqual(response.context["title"], "Change article")
  2481. self.assertContains(
  2482. response,
  2483. "<title>Change article | Django site admin</title>",
  2484. )
  2485. self.assertContains(response, "<h1>Change article</h1>")
  2486. post = self.client.post(article_change_url, change_dict)
  2487. self.assertRedirects(post, article_changelist_url)
  2488. self.assertEqual(
  2489. Article.objects.get(pk=self.a1.pk).content, "<p>edited article</p>"
  2490. )
  2491. # one error in form should produce singular error message, multiple
  2492. # errors plural.
  2493. change_dict["title"] = ""
  2494. post = self.client.post(article_change_url, change_dict)
  2495. self.assertContains(
  2496. post,
  2497. "Please correct the error below.",
  2498. msg_prefix=(
  2499. "Singular error message not found in response to post with one error"
  2500. ),
  2501. )
  2502. change_dict["content"] = ""
  2503. post = self.client.post(article_change_url, change_dict)
  2504. self.assertContains(
  2505. post,
  2506. "Please correct the errors below.",
  2507. msg_prefix=(
  2508. "Plural error message not found in response to post with multiple "
  2509. "errors"
  2510. ),
  2511. )
  2512. self.client.post(reverse("admin:logout"))
  2513. # Test redirection when using row-level change permissions. Refs #11513.
  2514. r1 = RowLevelChangePermissionModel.objects.create(id=1, name="odd id")
  2515. r2 = RowLevelChangePermissionModel.objects.create(id=2, name="even id")
  2516. r3 = RowLevelChangePermissionModel.objects.create(id=3, name="odd id mult 3")
  2517. r6 = RowLevelChangePermissionModel.objects.create(id=6, name="even id mult 3")
  2518. change_url_1 = reverse(
  2519. "admin:admin_views_rowlevelchangepermissionmodel_change", args=(r1.pk,)
  2520. )
  2521. change_url_2 = reverse(
  2522. "admin:admin_views_rowlevelchangepermissionmodel_change", args=(r2.pk,)
  2523. )
  2524. change_url_3 = reverse(
  2525. "admin:admin_views_rowlevelchangepermissionmodel_change", args=(r3.pk,)
  2526. )
  2527. change_url_6 = reverse(
  2528. "admin:admin_views_rowlevelchangepermissionmodel_change", args=(r6.pk,)
  2529. )
  2530. logins = [
  2531. self.superuser,
  2532. self.viewuser,
  2533. self.adduser,
  2534. self.changeuser,
  2535. self.deleteuser,
  2536. ]
  2537. for login_user in logins:
  2538. with self.subTest(login_user.username):
  2539. self.client.force_login(login_user)
  2540. response = self.client.get(change_url_1)
  2541. self.assertEqual(response.status_code, 403)
  2542. response = self.client.post(change_url_1, {"name": "changed"})
  2543. self.assertEqual(
  2544. RowLevelChangePermissionModel.objects.get(id=1).name, "odd id"
  2545. )
  2546. self.assertEqual(response.status_code, 403)
  2547. response = self.client.get(change_url_2)
  2548. self.assertEqual(response.status_code, 200)
  2549. response = self.client.post(change_url_2, {"name": "changed"})
  2550. self.assertEqual(
  2551. RowLevelChangePermissionModel.objects.get(id=2).name, "changed"
  2552. )
  2553. self.assertRedirects(response, self.index_url)
  2554. response = self.client.get(change_url_3)
  2555. self.assertEqual(response.status_code, 200)
  2556. response = self.client.post(change_url_3, {"name": "changed"})
  2557. self.assertEqual(response.status_code, 403)
  2558. self.assertEqual(
  2559. RowLevelChangePermissionModel.objects.get(id=3).name,
  2560. "odd id mult 3",
  2561. )
  2562. response = self.client.get(change_url_6)
  2563. self.assertEqual(response.status_code, 200)
  2564. response = self.client.post(change_url_6, {"name": "changed"})
  2565. self.assertEqual(
  2566. RowLevelChangePermissionModel.objects.get(id=6).name, "changed"
  2567. )
  2568. self.assertRedirects(response, self.index_url)
  2569. self.client.post(reverse("admin:logout"))
  2570. for login_user in [self.joepublicuser, self.nostaffuser]:
  2571. with self.subTest(login_user.username):
  2572. self.client.force_login(login_user)
  2573. response = self.client.get(change_url_1, follow=True)
  2574. self.assertContains(response, "login-form")
  2575. response = self.client.post(
  2576. change_url_1, {"name": "changed"}, follow=True
  2577. )
  2578. self.assertEqual(
  2579. RowLevelChangePermissionModel.objects.get(id=1).name, "odd id"
  2580. )
  2581. self.assertContains(response, "login-form")
  2582. response = self.client.get(change_url_2, follow=True)
  2583. self.assertContains(response, "login-form")
  2584. response = self.client.post(
  2585. change_url_2, {"name": "changed again"}, follow=True
  2586. )
  2587. self.assertEqual(
  2588. RowLevelChangePermissionModel.objects.get(id=2).name, "changed"
  2589. )
  2590. self.assertContains(response, "login-form")
  2591. self.client.post(reverse("admin:logout"))
  2592. def test_change_view_without_object_change_permission(self):
  2593. """
  2594. The object should be read-only if the user has permission to view it
  2595. and change objects of that type but not to change the current object.
  2596. """
  2597. change_url = reverse("admin9:admin_views_article_change", args=(self.a1.pk,))
  2598. self.client.force_login(self.viewuser)
  2599. response = self.client.get(change_url)
  2600. self.assertEqual(response.context["title"], "View article")
  2601. self.assertContains(response, "<title>View article | Django site admin</title>")
  2602. self.assertContains(response, "<h1>View article</h1>")
  2603. self.assertContains(
  2604. response,
  2605. '<a href="/test_admin/admin9/admin_views/article/" class="closelink">Close'
  2606. "</a>",
  2607. )
  2608. def test_change_view_save_as_new(self):
  2609. """
  2610. 'Save as new' should raise PermissionDenied for users without the 'add'
  2611. permission.
  2612. """
  2613. change_dict_save_as_new = {
  2614. "_saveasnew": "Save as new",
  2615. "title": "Ikke fordømt",
  2616. "content": "<p>edited article</p>",
  2617. "date_0": "2008-03-18",
  2618. "date_1": "10:54:39",
  2619. "section": self.s1.pk,
  2620. }
  2621. article_change_url = reverse(
  2622. "admin:admin_views_article_change", args=(self.a1.pk,)
  2623. )
  2624. # Add user can perform "Save as new".
  2625. article_count = Article.objects.count()
  2626. self.client.force_login(self.adduser)
  2627. post = self.client.post(article_change_url, change_dict_save_as_new)
  2628. self.assertRedirects(post, self.index_url)
  2629. self.assertEqual(Article.objects.count(), article_count + 1)
  2630. self.client.logout()
  2631. # Change user cannot perform "Save as new" (no 'add' permission).
  2632. article_count = Article.objects.count()
  2633. self.client.force_login(self.changeuser)
  2634. post = self.client.post(article_change_url, change_dict_save_as_new)
  2635. self.assertEqual(post.status_code, 403)
  2636. self.assertEqual(Article.objects.count(), article_count)
  2637. # User with both add and change permissions should be redirected to the
  2638. # change page for the newly created object.
  2639. article_count = Article.objects.count()
  2640. self.client.force_login(self.superuser)
  2641. post = self.client.post(article_change_url, change_dict_save_as_new)
  2642. self.assertEqual(Article.objects.count(), article_count + 1)
  2643. new_article = Article.objects.latest("id")
  2644. self.assertRedirects(
  2645. post, reverse("admin:admin_views_article_change", args=(new_article.pk,))
  2646. )
  2647. def test_change_view_with_view_only_inlines(self):
  2648. """
  2649. User with change permission to a section but view-only for inlines.
  2650. """
  2651. self.viewuser.user_permissions.add(
  2652. get_perm(Section, get_permission_codename("change", Section._meta))
  2653. )
  2654. self.client.force_login(self.viewuser)
  2655. # GET shows inlines.
  2656. response = self.client.get(
  2657. reverse("admin:admin_views_section_change", args=(self.s1.pk,))
  2658. )
  2659. self.assertEqual(len(response.context["inline_admin_formsets"]), 1)
  2660. formset = response.context["inline_admin_formsets"][0]
  2661. self.assertEqual(len(formset.forms), 3)
  2662. # Valid POST changes the name.
  2663. data = {
  2664. "name": "Can edit name with view-only inlines",
  2665. "article_set-TOTAL_FORMS": 3,
  2666. "article_set-INITIAL_FORMS": 3,
  2667. }
  2668. response = self.client.post(
  2669. reverse("admin:admin_views_section_change", args=(self.s1.pk,)), data
  2670. )
  2671. self.assertRedirects(response, reverse("admin:admin_views_section_changelist"))
  2672. self.assertEqual(Section.objects.get(pk=self.s1.pk).name, data["name"])
  2673. # Invalid POST reshows inlines.
  2674. del data["name"]
  2675. response = self.client.post(
  2676. reverse("admin:admin_views_section_change", args=(self.s1.pk,)), data
  2677. )
  2678. self.assertEqual(response.status_code, 200)
  2679. self.assertEqual(len(response.context["inline_admin_formsets"]), 1)
  2680. formset = response.context["inline_admin_formsets"][0]
  2681. self.assertEqual(len(formset.forms), 3)
  2682. def test_change_view_with_view_only_last_inline(self):
  2683. self.viewuser.user_permissions.add(
  2684. get_perm(Section, get_permission_codename("view", Section._meta))
  2685. )
  2686. self.client.force_login(self.viewuser)
  2687. response = self.client.get(
  2688. reverse("admin:admin_views_section_change", args=(self.s1.pk,))
  2689. )
  2690. self.assertEqual(len(response.context["inline_admin_formsets"]), 1)
  2691. formset = response.context["inline_admin_formsets"][0]
  2692. self.assertEqual(len(formset.forms), 3)
  2693. # The last inline is not marked as empty.
  2694. self.assertContains(response, 'id="article_set-2"')
  2695. def test_change_view_with_view_and_add_inlines(self):
  2696. """User has view and add permissions on the inline model."""
  2697. self.viewuser.user_permissions.add(
  2698. get_perm(Section, get_permission_codename("change", Section._meta))
  2699. )
  2700. self.viewuser.user_permissions.add(
  2701. get_perm(Article, get_permission_codename("add", Article._meta))
  2702. )
  2703. self.client.force_login(self.viewuser)
  2704. # GET shows inlines.
  2705. response = self.client.get(
  2706. reverse("admin:admin_views_section_change", args=(self.s1.pk,))
  2707. )
  2708. self.assertEqual(len(response.context["inline_admin_formsets"]), 1)
  2709. formset = response.context["inline_admin_formsets"][0]
  2710. self.assertEqual(len(formset.forms), 6)
  2711. # Valid POST creates a new article.
  2712. data = {
  2713. "name": "Can edit name with view-only inlines",
  2714. "article_set-TOTAL_FORMS": 6,
  2715. "article_set-INITIAL_FORMS": 3,
  2716. "article_set-3-id": [""],
  2717. "article_set-3-title": ["A title"],
  2718. "article_set-3-content": ["Added content"],
  2719. "article_set-3-date_0": ["2008-3-18"],
  2720. "article_set-3-date_1": ["11:54:58"],
  2721. "article_set-3-section": [str(self.s1.pk)],
  2722. }
  2723. response = self.client.post(
  2724. reverse("admin:admin_views_section_change", args=(self.s1.pk,)), data
  2725. )
  2726. self.assertRedirects(response, reverse("admin:admin_views_section_changelist"))
  2727. self.assertEqual(Section.objects.get(pk=self.s1.pk).name, data["name"])
  2728. self.assertEqual(Article.objects.count(), 4)
  2729. # Invalid POST reshows inlines.
  2730. del data["name"]
  2731. response = self.client.post(
  2732. reverse("admin:admin_views_section_change", args=(self.s1.pk,)), data
  2733. )
  2734. self.assertEqual(response.status_code, 200)
  2735. self.assertEqual(len(response.context["inline_admin_formsets"]), 1)
  2736. formset = response.context["inline_admin_formsets"][0]
  2737. self.assertEqual(len(formset.forms), 6)
  2738. def test_change_view_with_view_and_delete_inlines(self):
  2739. """User has view and delete permissions on the inline model."""
  2740. self.viewuser.user_permissions.add(
  2741. get_perm(Section, get_permission_codename("change", Section._meta))
  2742. )
  2743. self.client.force_login(self.viewuser)
  2744. data = {
  2745. "name": "Name is required.",
  2746. "article_set-TOTAL_FORMS": 6,
  2747. "article_set-INITIAL_FORMS": 3,
  2748. "article_set-0-id": [str(self.a1.pk)],
  2749. "article_set-0-DELETE": ["on"],
  2750. }
  2751. # Inline POST details are ignored without delete permission.
  2752. response = self.client.post(
  2753. reverse("admin:admin_views_section_change", args=(self.s1.pk,)), data
  2754. )
  2755. self.assertRedirects(response, reverse("admin:admin_views_section_changelist"))
  2756. self.assertEqual(Article.objects.count(), 3)
  2757. # Deletion successful when delete permission is added.
  2758. self.viewuser.user_permissions.add(
  2759. get_perm(Article, get_permission_codename("delete", Article._meta))
  2760. )
  2761. data = {
  2762. "name": "Name is required.",
  2763. "article_set-TOTAL_FORMS": 6,
  2764. "article_set-INITIAL_FORMS": 3,
  2765. "article_set-0-id": [str(self.a1.pk)],
  2766. "article_set-0-DELETE": ["on"],
  2767. }
  2768. response = self.client.post(
  2769. reverse("admin:admin_views_section_change", args=(self.s1.pk,)), data
  2770. )
  2771. self.assertRedirects(response, reverse("admin:admin_views_section_changelist"))
  2772. self.assertEqual(Article.objects.count(), 2)
  2773. def test_delete_view(self):
  2774. """Delete view should restrict access and actually delete items."""
  2775. delete_dict = {"post": "yes"}
  2776. delete_url = reverse("admin:admin_views_article_delete", args=(self.a1.pk,))
  2777. # add user should not be able to delete articles
  2778. self.client.force_login(self.adduser)
  2779. response = self.client.get(delete_url)
  2780. self.assertEqual(response.status_code, 403)
  2781. post = self.client.post(delete_url, delete_dict)
  2782. self.assertEqual(post.status_code, 403)
  2783. self.assertEqual(Article.objects.count(), 3)
  2784. self.client.logout()
  2785. # view user should not be able to delete articles
  2786. self.client.force_login(self.viewuser)
  2787. response = self.client.get(delete_url)
  2788. self.assertEqual(response.status_code, 403)
  2789. post = self.client.post(delete_url, delete_dict)
  2790. self.assertEqual(post.status_code, 403)
  2791. self.assertEqual(Article.objects.count(), 3)
  2792. self.client.logout()
  2793. # Delete user can delete
  2794. self.client.force_login(self.deleteuser)
  2795. response = self.client.get(
  2796. reverse("admin:admin_views_section_delete", args=(self.s1.pk,))
  2797. )
  2798. self.assertContains(response, "<h1>Delete</h1>")
  2799. self.assertContains(response, "<h2>Summary</h2>")
  2800. self.assertContains(response, "<li>Articles: 3</li>")
  2801. # test response contains link to related Article
  2802. self.assertContains(response, "admin_views/article/%s/" % self.a1.pk)
  2803. response = self.client.get(delete_url)
  2804. self.assertContains(response, "admin_views/article/%s/" % self.a1.pk)
  2805. self.assertContains(response, "<h2>Summary</h2>")
  2806. self.assertContains(response, "<li>Articles: 1</li>")
  2807. post = self.client.post(delete_url, delete_dict)
  2808. self.assertRedirects(post, self.index_url)
  2809. self.assertEqual(Article.objects.count(), 2)
  2810. self.assertEqual(len(mail.outbox), 1)
  2811. self.assertEqual(mail.outbox[0].subject, "Greetings from a deleted object")
  2812. article_ct = ContentType.objects.get_for_model(Article)
  2813. logged = LogEntry.objects.get(content_type=article_ct, action_flag=DELETION)
  2814. self.assertEqual(logged.object_id, str(self.a1.pk))
  2815. def test_delete_view_with_no_default_permissions(self):
  2816. """
  2817. The delete view allows users to delete collected objects without a
  2818. 'delete' permission (ReadOnlyPizza.Meta.default_permissions is empty).
  2819. """
  2820. pizza = ReadOnlyPizza.objects.create(name="Double Cheese")
  2821. delete_url = reverse("admin:admin_views_readonlypizza_delete", args=(pizza.pk,))
  2822. self.client.force_login(self.adduser)
  2823. response = self.client.get(delete_url)
  2824. self.assertContains(response, "admin_views/readonlypizza/%s/" % pizza.pk)
  2825. self.assertContains(response, "<h2>Summary</h2>")
  2826. self.assertContains(response, "<li>Read only pizzas: 1</li>")
  2827. post = self.client.post(delete_url, {"post": "yes"})
  2828. self.assertRedirects(
  2829. post, reverse("admin:admin_views_readonlypizza_changelist")
  2830. )
  2831. self.assertEqual(ReadOnlyPizza.objects.count(), 0)
  2832. def test_delete_view_nonexistent_obj(self):
  2833. self.client.force_login(self.deleteuser)
  2834. url = reverse("admin:admin_views_article_delete", args=("nonexistent",))
  2835. response = self.client.get(url, follow=True)
  2836. self.assertRedirects(response, reverse("admin:index"))
  2837. self.assertEqual(
  2838. [m.message for m in response.context["messages"]],
  2839. ["article with ID “nonexistent” doesn’t exist. Perhaps it was deleted?"],
  2840. )
  2841. def test_history_view(self):
  2842. """History view should restrict access."""
  2843. # add user should not be able to view the list of article or change any of them
  2844. self.client.force_login(self.adduser)
  2845. response = self.client.get(
  2846. reverse("admin:admin_views_article_history", args=(self.a1.pk,))
  2847. )
  2848. self.assertEqual(response.status_code, 403)
  2849. self.client.post(reverse("admin:logout"))
  2850. # view user can view all items
  2851. self.client.force_login(self.viewuser)
  2852. response = self.client.get(
  2853. reverse("admin:admin_views_article_history", args=(self.a1.pk,))
  2854. )
  2855. self.assertEqual(response.status_code, 200)
  2856. self.client.post(reverse("admin:logout"))
  2857. # change user can view all items and edit them
  2858. self.client.force_login(self.changeuser)
  2859. response = self.client.get(
  2860. reverse("admin:admin_views_article_history", args=(self.a1.pk,))
  2861. )
  2862. self.assertEqual(response.status_code, 200)
  2863. # Test redirection when using row-level change permissions. Refs #11513.
  2864. rl1 = RowLevelChangePermissionModel.objects.create(id=1, name="odd id")
  2865. rl2 = RowLevelChangePermissionModel.objects.create(id=2, name="even id")
  2866. logins = [
  2867. self.superuser,
  2868. self.viewuser,
  2869. self.adduser,
  2870. self.changeuser,
  2871. self.deleteuser,
  2872. ]
  2873. for login_user in logins:
  2874. with self.subTest(login_user.username):
  2875. self.client.force_login(login_user)
  2876. url = reverse(
  2877. "admin:admin_views_rowlevelchangepermissionmodel_history",
  2878. args=(rl1.pk,),
  2879. )
  2880. response = self.client.get(url)
  2881. self.assertEqual(response.status_code, 403)
  2882. url = reverse(
  2883. "admin:admin_views_rowlevelchangepermissionmodel_history",
  2884. args=(rl2.pk,),
  2885. )
  2886. response = self.client.get(url)
  2887. self.assertEqual(response.status_code, 200)
  2888. self.client.post(reverse("admin:logout"))
  2889. for login_user in [self.joepublicuser, self.nostaffuser]:
  2890. with self.subTest(login_user.username):
  2891. self.client.force_login(login_user)
  2892. url = reverse(
  2893. "admin:admin_views_rowlevelchangepermissionmodel_history",
  2894. args=(rl1.pk,),
  2895. )
  2896. response = self.client.get(url, follow=True)
  2897. self.assertContains(response, "login-form")
  2898. url = reverse(
  2899. "admin:admin_views_rowlevelchangepermissionmodel_history",
  2900. args=(rl2.pk,),
  2901. )
  2902. response = self.client.get(url, follow=True)
  2903. self.assertContains(response, "login-form")
  2904. self.client.post(reverse("admin:logout"))
  2905. def test_history_view_bad_url(self):
  2906. self.client.force_login(self.changeuser)
  2907. response = self.client.get(
  2908. reverse("admin:admin_views_article_history", args=("foo",)), follow=True
  2909. )
  2910. self.assertRedirects(response, reverse("admin:index"))
  2911. self.assertEqual(
  2912. [m.message for m in response.context["messages"]],
  2913. ["article with ID “foo” doesn’t exist. Perhaps it was deleted?"],
  2914. )
  2915. def test_conditionally_show_add_section_link(self):
  2916. """
  2917. The foreign key widget should only show the "add related" button if the
  2918. user has permission to add that related item.
  2919. """
  2920. self.client.force_login(self.adduser)
  2921. # The user can't add sections yet, so they shouldn't see the "add section" link.
  2922. url = reverse("admin:admin_views_article_add")
  2923. add_link_text = "add_id_section"
  2924. response = self.client.get(url)
  2925. self.assertNotContains(response, add_link_text)
  2926. # Allow the user to add sections too. Now they can see the "add section" link.
  2927. user = User.objects.get(username="adduser")
  2928. perm = get_perm(Section, get_permission_codename("add", Section._meta))
  2929. user.user_permissions.add(perm)
  2930. response = self.client.get(url)
  2931. self.assertContains(response, add_link_text)
  2932. def test_conditionally_show_change_section_link(self):
  2933. """
  2934. The foreign key widget should only show the "change related" button if
  2935. the user has permission to change that related item.
  2936. """
  2937. def get_change_related(response):
  2938. return (
  2939. response.context["adminform"]
  2940. .form.fields["section"]
  2941. .widget.can_change_related
  2942. )
  2943. self.client.force_login(self.adduser)
  2944. # The user can't change sections yet, so they shouldn't see the
  2945. # "change section" link.
  2946. url = reverse("admin:admin_views_article_add")
  2947. change_link_text = "change_id_section"
  2948. response = self.client.get(url)
  2949. self.assertFalse(get_change_related(response))
  2950. self.assertNotContains(response, change_link_text)
  2951. # Allow the user to change sections too. Now they can see the
  2952. # "change section" link.
  2953. user = User.objects.get(username="adduser")
  2954. perm = get_perm(Section, get_permission_codename("change", Section._meta))
  2955. user.user_permissions.add(perm)
  2956. response = self.client.get(url)
  2957. self.assertTrue(get_change_related(response))
  2958. self.assertContains(response, change_link_text)
  2959. def test_conditionally_show_delete_section_link(self):
  2960. """
  2961. The foreign key widget should only show the "delete related" button if
  2962. the user has permission to delete that related item.
  2963. """
  2964. def get_delete_related(response):
  2965. return (
  2966. response.context["adminform"]
  2967. .form.fields["sub_section"]
  2968. .widget.can_delete_related
  2969. )
  2970. self.client.force_login(self.adduser)
  2971. # The user can't delete sections yet, so they shouldn't see the
  2972. # "delete section" link.
  2973. url = reverse("admin:admin_views_article_add")
  2974. delete_link_text = "delete_id_sub_section"
  2975. response = self.client.get(url)
  2976. self.assertFalse(get_delete_related(response))
  2977. self.assertNotContains(response, delete_link_text)
  2978. # Allow the user to delete sections too. Now they can see the
  2979. # "delete section" link.
  2980. user = User.objects.get(username="adduser")
  2981. perm = get_perm(Section, get_permission_codename("delete", Section._meta))
  2982. user.user_permissions.add(perm)
  2983. response = self.client.get(url)
  2984. self.assertTrue(get_delete_related(response))
  2985. self.assertContains(response, delete_link_text)
  2986. def test_disabled_permissions_when_logged_in(self):
  2987. self.client.force_login(self.superuser)
  2988. superuser = User.objects.get(username="super")
  2989. superuser.is_active = False
  2990. superuser.save()
  2991. response = self.client.get(self.index_url, follow=True)
  2992. self.assertContains(response, 'id="login-form"')
  2993. self.assertNotContains(response, "Log out")
  2994. response = self.client.get(reverse("secure_view"), follow=True)
  2995. self.assertContains(response, 'id="login-form"')
  2996. def test_disabled_staff_permissions_when_logged_in(self):
  2997. self.client.force_login(self.superuser)
  2998. superuser = User.objects.get(username="super")
  2999. superuser.is_staff = False
  3000. superuser.save()
  3001. response = self.client.get(self.index_url, follow=True)
  3002. self.assertContains(response, 'id="login-form"')
  3003. self.assertNotContains(response, "Log out")
  3004. response = self.client.get(reverse("secure_view"), follow=True)
  3005. self.assertContains(response, 'id="login-form"')
  3006. def test_app_list_permissions(self):
  3007. """
  3008. If a user has no module perms, the app list returns a 404.
  3009. """
  3010. opts = Article._meta
  3011. change_user = User.objects.get(username="changeuser")
  3012. permission = get_perm(Article, get_permission_codename("change", opts))
  3013. self.client.force_login(self.changeuser)
  3014. # the user has no module permissions
  3015. change_user.user_permissions.remove(permission)
  3016. response = self.client.get(reverse("admin:app_list", args=("admin_views",)))
  3017. self.assertEqual(response.status_code, 404)
  3018. # the user now has module permissions
  3019. change_user.user_permissions.add(permission)
  3020. response = self.client.get(reverse("admin:app_list", args=("admin_views",)))
  3021. self.assertEqual(response.status_code, 200)
  3022. def test_shortcut_view_only_available_to_staff(self):
  3023. """
  3024. Only admin users should be able to use the admin shortcut view.
  3025. """
  3026. model_ctype = ContentType.objects.get_for_model(ModelWithStringPrimaryKey)
  3027. obj = ModelWithStringPrimaryKey.objects.create(string_pk="foo")
  3028. shortcut_url = reverse("admin:view_on_site", args=(model_ctype.pk, obj.pk))
  3029. # Not logged in: we should see the login page.
  3030. response = self.client.get(shortcut_url, follow=True)
  3031. self.assertTemplateUsed(response, "admin/login.html")
  3032. # Logged in? Redirect.
  3033. self.client.force_login(self.superuser)
  3034. response = self.client.get(shortcut_url, follow=False)
  3035. # Can't use self.assertRedirects() because User.get_absolute_url() is silly.
  3036. self.assertEqual(response.status_code, 302)
  3037. # Domain may depend on contrib.sites tests also run
  3038. self.assertRegex(response.url, "http://(testserver|example.com)/dummy/foo/")
  3039. def test_has_module_permission(self):
  3040. """
  3041. has_module_permission() returns True for all users who
  3042. have any permission for that module (add, change, or delete), so that
  3043. the module is displayed on the admin index page.
  3044. """
  3045. self.client.force_login(self.superuser)
  3046. response = self.client.get(self.index_url)
  3047. self.assertContains(response, "admin_views")
  3048. self.assertContains(response, "Articles")
  3049. self.client.logout()
  3050. self.client.force_login(self.viewuser)
  3051. response = self.client.get(self.index_url)
  3052. self.assertContains(response, "admin_views")
  3053. self.assertContains(response, "Articles")
  3054. self.client.logout()
  3055. self.client.force_login(self.adduser)
  3056. response = self.client.get(self.index_url)
  3057. self.assertContains(response, "admin_views")
  3058. self.assertContains(response, "Articles")
  3059. self.client.logout()
  3060. self.client.force_login(self.changeuser)
  3061. response = self.client.get(self.index_url)
  3062. self.assertContains(response, "admin_views")
  3063. self.assertContains(response, "Articles")
  3064. self.client.logout()
  3065. self.client.force_login(self.deleteuser)
  3066. response = self.client.get(self.index_url)
  3067. self.assertContains(response, "admin_views")
  3068. self.assertContains(response, "Articles")
  3069. def test_overriding_has_module_permission(self):
  3070. """
  3071. If has_module_permission() always returns False, the module shouldn't
  3072. be displayed on the admin index page for any users.
  3073. """
  3074. articles = Article._meta.verbose_name_plural.title()
  3075. sections = Section._meta.verbose_name_plural.title()
  3076. index_url = reverse("admin7:index")
  3077. self.client.force_login(self.superuser)
  3078. response = self.client.get(index_url)
  3079. self.assertContains(response, sections)
  3080. self.assertNotContains(response, articles)
  3081. self.client.logout()
  3082. self.client.force_login(self.viewuser)
  3083. response = self.client.get(index_url)
  3084. self.assertNotContains(response, "admin_views")
  3085. self.assertNotContains(response, articles)
  3086. self.client.logout()
  3087. self.client.force_login(self.adduser)
  3088. response = self.client.get(index_url)
  3089. self.assertNotContains(response, "admin_views")
  3090. self.assertNotContains(response, articles)
  3091. self.client.logout()
  3092. self.client.force_login(self.changeuser)
  3093. response = self.client.get(index_url)
  3094. self.assertNotContains(response, "admin_views")
  3095. self.assertNotContains(response, articles)
  3096. self.client.logout()
  3097. self.client.force_login(self.deleteuser)
  3098. response = self.client.get(index_url)
  3099. self.assertNotContains(response, articles)
  3100. # The app list displays Sections but not Articles as the latter has
  3101. # ModelAdmin.has_module_permission() = False.
  3102. self.client.force_login(self.superuser)
  3103. response = self.client.get(reverse("admin7:app_list", args=("admin_views",)))
  3104. self.assertContains(response, sections)
  3105. self.assertNotContains(response, articles)
  3106. def test_post_save_message_no_forbidden_links_visible(self):
  3107. """
  3108. Post-save message shouldn't contain a link to the change form if the
  3109. user doesn't have the change permission.
  3110. """
  3111. self.client.force_login(self.adduser)
  3112. # Emulate Article creation for user with add-only permission.
  3113. post_data = {
  3114. "title": "Fun & games",
  3115. "content": "Some content",
  3116. "date_0": "2015-10-31",
  3117. "date_1": "16:35:00",
  3118. "_save": "Save",
  3119. }
  3120. response = self.client.post(
  3121. reverse("admin:admin_views_article_add"), post_data, follow=True
  3122. )
  3123. self.assertContains(
  3124. response,
  3125. '<li class="success">The article “Fun &amp; games” was added successfully.'
  3126. "</li>",
  3127. html=True,
  3128. )
  3129. @override_settings(
  3130. ROOT_URLCONF="admin_views.urls",
  3131. TEMPLATES=[
  3132. {
  3133. "BACKEND": "django.template.backends.django.DjangoTemplates",
  3134. "APP_DIRS": True,
  3135. "OPTIONS": {
  3136. "context_processors": [
  3137. "django.template.context_processors.request",
  3138. "django.contrib.auth.context_processors.auth",
  3139. "django.contrib.messages.context_processors.messages",
  3140. ],
  3141. },
  3142. }
  3143. ],
  3144. )
  3145. class AdminViewProxyModelPermissionsTests(TestCase):
  3146. """Tests for proxy models permissions in the admin."""
  3147. @classmethod
  3148. def setUpTestData(cls):
  3149. cls.viewuser = User.objects.create_user(
  3150. username="viewuser", password="secret", is_staff=True
  3151. )
  3152. cls.adduser = User.objects.create_user(
  3153. username="adduser", password="secret", is_staff=True
  3154. )
  3155. cls.changeuser = User.objects.create_user(
  3156. username="changeuser", password="secret", is_staff=True
  3157. )
  3158. cls.deleteuser = User.objects.create_user(
  3159. username="deleteuser", password="secret", is_staff=True
  3160. )
  3161. # Setup permissions.
  3162. opts = UserProxy._meta
  3163. cls.viewuser.user_permissions.add(
  3164. get_perm(UserProxy, get_permission_codename("view", opts))
  3165. )
  3166. cls.adduser.user_permissions.add(
  3167. get_perm(UserProxy, get_permission_codename("add", opts))
  3168. )
  3169. cls.changeuser.user_permissions.add(
  3170. get_perm(UserProxy, get_permission_codename("change", opts))
  3171. )
  3172. cls.deleteuser.user_permissions.add(
  3173. get_perm(UserProxy, get_permission_codename("delete", opts))
  3174. )
  3175. # UserProxy instances.
  3176. cls.user_proxy = UserProxy.objects.create(
  3177. username="user_proxy", password="secret"
  3178. )
  3179. def test_add(self):
  3180. self.client.force_login(self.adduser)
  3181. url = reverse("admin:admin_views_userproxy_add")
  3182. data = {
  3183. "username": "can_add",
  3184. "password": "secret",
  3185. "date_joined_0": "2019-01-15",
  3186. "date_joined_1": "16:59:10",
  3187. }
  3188. response = self.client.post(url, data, follow=True)
  3189. self.assertEqual(response.status_code, 200)
  3190. self.assertTrue(UserProxy.objects.filter(username="can_add").exists())
  3191. def test_view(self):
  3192. self.client.force_login(self.viewuser)
  3193. response = self.client.get(reverse("admin:admin_views_userproxy_changelist"))
  3194. self.assertContains(response, "<h1>Select user proxy to view</h1>")
  3195. response = self.client.get(
  3196. reverse("admin:admin_views_userproxy_change", args=(self.user_proxy.pk,))
  3197. )
  3198. self.assertContains(response, "<h1>View user proxy</h1>")
  3199. self.assertContains(response, '<div class="readonly">user_proxy</div>')
  3200. def test_change(self):
  3201. self.client.force_login(self.changeuser)
  3202. data = {
  3203. "password": self.user_proxy.password,
  3204. "username": self.user_proxy.username,
  3205. "date_joined_0": self.user_proxy.date_joined.strftime("%Y-%m-%d"),
  3206. "date_joined_1": self.user_proxy.date_joined.strftime("%H:%M:%S"),
  3207. "first_name": "first_name",
  3208. }
  3209. url = reverse("admin:admin_views_userproxy_change", args=(self.user_proxy.pk,))
  3210. response = self.client.post(url, data)
  3211. self.assertRedirects(
  3212. response, reverse("admin:admin_views_userproxy_changelist")
  3213. )
  3214. self.assertEqual(
  3215. UserProxy.objects.get(pk=self.user_proxy.pk).first_name, "first_name"
  3216. )
  3217. def test_delete(self):
  3218. self.client.force_login(self.deleteuser)
  3219. url = reverse("admin:admin_views_userproxy_delete", args=(self.user_proxy.pk,))
  3220. response = self.client.post(url, {"post": "yes"}, follow=True)
  3221. self.assertEqual(response.status_code, 200)
  3222. self.assertFalse(UserProxy.objects.filter(pk=self.user_proxy.pk).exists())
  3223. @override_settings(ROOT_URLCONF="admin_views.urls")
  3224. class AdminViewsNoUrlTest(TestCase):
  3225. """Regression test for #17333"""
  3226. @classmethod
  3227. def setUpTestData(cls):
  3228. # User who can change Reports
  3229. cls.changeuser = User.objects.create_user(
  3230. username="changeuser", password="secret", is_staff=True
  3231. )
  3232. cls.changeuser.user_permissions.add(
  3233. get_perm(Report, get_permission_codename("change", Report._meta))
  3234. )
  3235. def test_no_standard_modeladmin_urls(self):
  3236. """Admin index views don't break when user's ModelAdmin removes standard urls"""
  3237. self.client.force_login(self.changeuser)
  3238. r = self.client.get(reverse("admin:index"))
  3239. # we shouldn't get a 500 error caused by a NoReverseMatch
  3240. self.assertEqual(r.status_code, 200)
  3241. self.client.post(reverse("admin:logout"))
  3242. @skipUnlessDBFeature("can_defer_constraint_checks")
  3243. @override_settings(ROOT_URLCONF="admin_views.urls")
  3244. class AdminViewDeletedObjectsTest(TestCase):
  3245. @classmethod
  3246. def setUpTestData(cls):
  3247. cls.superuser = User.objects.create_superuser(
  3248. username="super", password="secret", email="super@example.com"
  3249. )
  3250. cls.deleteuser = User.objects.create_user(
  3251. username="deleteuser", password="secret", is_staff=True
  3252. )
  3253. cls.s1 = Section.objects.create(name="Test section")
  3254. cls.a1 = Article.objects.create(
  3255. content="<p>Middle content</p>",
  3256. date=datetime.datetime(2008, 3, 18, 11, 54, 58),
  3257. section=cls.s1,
  3258. )
  3259. cls.a2 = Article.objects.create(
  3260. content="<p>Oldest content</p>",
  3261. date=datetime.datetime(2000, 3, 18, 11, 54, 58),
  3262. section=cls.s1,
  3263. )
  3264. cls.a3 = Article.objects.create(
  3265. content="<p>Newest content</p>",
  3266. date=datetime.datetime(2009, 3, 18, 11, 54, 58),
  3267. section=cls.s1,
  3268. )
  3269. cls.p1 = PrePopulatedPost.objects.create(
  3270. title="A Long Title", published=True, slug="a-long-title"
  3271. )
  3272. cls.v1 = Villain.objects.create(name="Adam")
  3273. cls.v2 = Villain.objects.create(name="Sue")
  3274. cls.sv1 = SuperVillain.objects.create(name="Bob")
  3275. cls.pl1 = Plot.objects.create(
  3276. name="World Domination", team_leader=cls.v1, contact=cls.v2
  3277. )
  3278. cls.pl2 = Plot.objects.create(
  3279. name="World Peace", team_leader=cls.v2, contact=cls.v2
  3280. )
  3281. cls.pl3 = Plot.objects.create(
  3282. name="Corn Conspiracy", team_leader=cls.v1, contact=cls.v1
  3283. )
  3284. cls.pd1 = PlotDetails.objects.create(details="almost finished", plot=cls.pl1)
  3285. cls.sh1 = SecretHideout.objects.create(
  3286. location="underground bunker", villain=cls.v1
  3287. )
  3288. cls.sh2 = SecretHideout.objects.create(
  3289. location="floating castle", villain=cls.sv1
  3290. )
  3291. cls.ssh1 = SuperSecretHideout.objects.create(
  3292. location="super floating castle!", supervillain=cls.sv1
  3293. )
  3294. cls.cy1 = CyclicOne.objects.create(pk=1, name="I am recursive", two_id=1)
  3295. cls.cy2 = CyclicTwo.objects.create(pk=1, name="I am recursive too", one_id=1)
  3296. def setUp(self):
  3297. self.client.force_login(self.superuser)
  3298. def test_nesting(self):
  3299. """
  3300. Objects should be nested to display the relationships that
  3301. cause them to be scheduled for deletion.
  3302. """
  3303. pattern = re.compile(
  3304. r'<li>Plot: <a href="%s">World Domination</a>\s*<ul>\s*'
  3305. r'<li>Plot details: <a href="%s">almost finished</a>'
  3306. % (
  3307. reverse("admin:admin_views_plot_change", args=(self.pl1.pk,)),
  3308. reverse("admin:admin_views_plotdetails_change", args=(self.pd1.pk,)),
  3309. )
  3310. )
  3311. response = self.client.get(
  3312. reverse("admin:admin_views_villain_delete", args=(self.v1.pk,))
  3313. )
  3314. self.assertRegex(response.text, pattern)
  3315. def test_cyclic(self):
  3316. """
  3317. Cyclic relationships should still cause each object to only be
  3318. listed once.
  3319. """
  3320. one = '<li>Cyclic one: <a href="%s">I am recursive</a>' % (
  3321. reverse("admin:admin_views_cyclicone_change", args=(self.cy1.pk,)),
  3322. )
  3323. two = '<li>Cyclic two: <a href="%s">I am recursive too</a>' % (
  3324. reverse("admin:admin_views_cyclictwo_change", args=(self.cy2.pk,)),
  3325. )
  3326. response = self.client.get(
  3327. reverse("admin:admin_views_cyclicone_delete", args=(self.cy1.pk,))
  3328. )
  3329. self.assertContains(response, one, 1)
  3330. self.assertContains(response, two, 1)
  3331. def test_perms_needed(self):
  3332. self.client.logout()
  3333. delete_user = User.objects.get(username="deleteuser")
  3334. delete_user.user_permissions.add(
  3335. get_perm(Plot, get_permission_codename("delete", Plot._meta))
  3336. )
  3337. self.client.force_login(self.deleteuser)
  3338. response = self.client.get(
  3339. reverse("admin:admin_views_plot_delete", args=(self.pl1.pk,))
  3340. )
  3341. self.assertContains(
  3342. response,
  3343. "your account doesn't have permission to delete the following types of "
  3344. "objects",
  3345. )
  3346. self.assertContains(response, "<li>plot details</li>")
  3347. def test_protected(self):
  3348. q = Question.objects.create(question="Why?")
  3349. a1 = Answer.objects.create(question=q, answer="Because.")
  3350. a2 = Answer.objects.create(question=q, answer="Yes.")
  3351. response = self.client.get(
  3352. reverse("admin:admin_views_question_delete", args=(q.pk,))
  3353. )
  3354. self.assertContains(
  3355. response, "would require deleting the following protected related objects"
  3356. )
  3357. self.assertContains(
  3358. response,
  3359. '<li>Answer: <a href="%s">Because.</a></li>'
  3360. % reverse("admin:admin_views_answer_change", args=(a1.pk,)),
  3361. )
  3362. self.assertContains(
  3363. response,
  3364. '<li>Answer: <a href="%s">Yes.</a></li>'
  3365. % reverse("admin:admin_views_answer_change", args=(a2.pk,)),
  3366. )
  3367. def test_post_delete_protected(self):
  3368. """
  3369. A POST request to delete protected objects should display the page
  3370. which says the deletion is prohibited.
  3371. """
  3372. q = Question.objects.create(question="Why?")
  3373. Answer.objects.create(question=q, answer="Because.")
  3374. response = self.client.post(
  3375. reverse("admin:admin_views_question_delete", args=(q.pk,)), {"post": "yes"}
  3376. )
  3377. self.assertEqual(Question.objects.count(), 1)
  3378. self.assertContains(
  3379. response, "would require deleting the following protected related objects"
  3380. )
  3381. def test_restricted(self):
  3382. album = Album.objects.create(title="Amaryllis")
  3383. song = Song.objects.create(album=album, name="Unity")
  3384. response = self.client.get(
  3385. reverse("admin:admin_views_album_delete", args=(album.pk,))
  3386. )
  3387. self.assertContains(
  3388. response,
  3389. "would require deleting the following protected related objects",
  3390. )
  3391. self.assertContains(
  3392. response,
  3393. '<li>Song: <a href="%s">Unity</a></li>'
  3394. % reverse("admin:admin_views_song_change", args=(song.pk,)),
  3395. )
  3396. def test_post_delete_restricted(self):
  3397. album = Album.objects.create(title="Amaryllis")
  3398. Song.objects.create(album=album, name="Unity")
  3399. response = self.client.post(
  3400. reverse("admin:admin_views_album_delete", args=(album.pk,)),
  3401. {"post": "yes"},
  3402. )
  3403. self.assertEqual(Album.objects.count(), 1)
  3404. self.assertContains(
  3405. response,
  3406. "would require deleting the following protected related objects",
  3407. )
  3408. def test_not_registered(self):
  3409. should_contain = """<li>Secret hideout: underground bunker"""
  3410. response = self.client.get(
  3411. reverse("admin:admin_views_villain_delete", args=(self.v1.pk,))
  3412. )
  3413. self.assertContains(response, should_contain, 1)
  3414. def test_multiple_fkeys_to_same_model(self):
  3415. """
  3416. If a deleted object has two relationships from another model,
  3417. both of those should be followed in looking for related
  3418. objects to delete.
  3419. """
  3420. should_contain = '<li>Plot: <a href="%s">World Domination</a>' % reverse(
  3421. "admin:admin_views_plot_change", args=(self.pl1.pk,)
  3422. )
  3423. response = self.client.get(
  3424. reverse("admin:admin_views_villain_delete", args=(self.v1.pk,))
  3425. )
  3426. self.assertContains(response, should_contain)
  3427. response = self.client.get(
  3428. reverse("admin:admin_views_villain_delete", args=(self.v2.pk,))
  3429. )
  3430. self.assertContains(response, should_contain)
  3431. def test_multiple_fkeys_to_same_instance(self):
  3432. """
  3433. If a deleted object has two relationships pointing to it from
  3434. another object, the other object should still only be listed
  3435. once.
  3436. """
  3437. should_contain = '<li>Plot: <a href="%s">World Peace</a></li>' % reverse(
  3438. "admin:admin_views_plot_change", args=(self.pl2.pk,)
  3439. )
  3440. response = self.client.get(
  3441. reverse("admin:admin_views_villain_delete", args=(self.v2.pk,))
  3442. )
  3443. self.assertContains(response, should_contain, 1)
  3444. def test_inheritance(self):
  3445. """
  3446. In the case of an inherited model, if either the child or
  3447. parent-model instance is deleted, both instances are listed
  3448. for deletion, as well as any relationships they have.
  3449. """
  3450. should_contain = [
  3451. '<li>Villain: <a href="%s">Bob</a>'
  3452. % reverse("admin:admin_views_villain_change", args=(self.sv1.pk,)),
  3453. '<li>Super villain: <a href="%s">Bob</a>'
  3454. % reverse("admin:admin_views_supervillain_change", args=(self.sv1.pk,)),
  3455. "<li>Secret hideout: floating castle",
  3456. "<li>Super secret hideout: super floating castle!",
  3457. ]
  3458. response = self.client.get(
  3459. reverse("admin:admin_views_villain_delete", args=(self.sv1.pk,))
  3460. )
  3461. for should in should_contain:
  3462. self.assertContains(response, should, 1)
  3463. response = self.client.get(
  3464. reverse("admin:admin_views_supervillain_delete", args=(self.sv1.pk,))
  3465. )
  3466. for should in should_contain:
  3467. self.assertContains(response, should, 1)
  3468. def test_generic_relations(self):
  3469. """
  3470. If a deleted object has GenericForeignKeys pointing to it,
  3471. those objects should be listed for deletion.
  3472. """
  3473. plot = self.pl3
  3474. tag = FunkyTag.objects.create(content_object=plot, name="hott")
  3475. should_contain = '<li>Funky tag: <a href="%s">hott' % reverse(
  3476. "admin:admin_views_funkytag_change", args=(tag.id,)
  3477. )
  3478. response = self.client.get(
  3479. reverse("admin:admin_views_plot_delete", args=(plot.pk,))
  3480. )
  3481. self.assertContains(response, should_contain)
  3482. def test_generic_relations_with_related_query_name(self):
  3483. """
  3484. If a deleted object has GenericForeignKey with
  3485. GenericRelation(related_query_name='...') pointing to it, those objects
  3486. should be listed for deletion.
  3487. """
  3488. bookmark = Bookmark.objects.create(name="djangoproject")
  3489. tag = FunkyTag.objects.create(content_object=bookmark, name="django")
  3490. tag_url = reverse("admin:admin_views_funkytag_change", args=(tag.id,))
  3491. should_contain = '<li>Funky tag: <a href="%s">django' % tag_url
  3492. response = self.client.get(
  3493. reverse("admin:admin_views_bookmark_delete", args=(bookmark.pk,))
  3494. )
  3495. self.assertContains(response, should_contain)
  3496. def test_delete_view_uses_get_deleted_objects(self):
  3497. """The delete view uses ModelAdmin.get_deleted_objects()."""
  3498. book = Book.objects.create(name="Test Book")
  3499. response = self.client.get(
  3500. reverse("admin2:admin_views_book_delete", args=(book.pk,))
  3501. )
  3502. # BookAdmin.get_deleted_objects() returns custom text.
  3503. self.assertContains(response, "a deletable object")
  3504. @override_settings(ROOT_URLCONF="admin_views.urls")
  3505. class TestGenericRelations(TestCase):
  3506. @classmethod
  3507. def setUpTestData(cls):
  3508. cls.superuser = User.objects.create_superuser(
  3509. username="super", password="secret", email="super@example.com"
  3510. )
  3511. cls.v1 = Villain.objects.create(name="Adam")
  3512. cls.pl3 = Plot.objects.create(
  3513. name="Corn Conspiracy", team_leader=cls.v1, contact=cls.v1
  3514. )
  3515. def setUp(self):
  3516. self.client.force_login(self.superuser)
  3517. def test_generic_content_object_in_list_display(self):
  3518. FunkyTag.objects.create(content_object=self.pl3, name="hott")
  3519. response = self.client.get(reverse("admin:admin_views_funkytag_changelist"))
  3520. self.assertContains(response, "%s</td>" % self.pl3)
  3521. @override_settings(ROOT_URLCONF="admin_views.urls")
  3522. class AdminViewStringPrimaryKeyTest(TestCase):
  3523. @classmethod
  3524. def setUpTestData(cls):
  3525. cls.superuser = User.objects.create_superuser(
  3526. username="super", password="secret", email="super@example.com"
  3527. )
  3528. cls.s1 = Section.objects.create(name="Test section")
  3529. cls.a1 = Article.objects.create(
  3530. content="<p>Middle content</p>",
  3531. date=datetime.datetime(2008, 3, 18, 11, 54, 58),
  3532. section=cls.s1,
  3533. )
  3534. cls.a2 = Article.objects.create(
  3535. content="<p>Oldest content</p>",
  3536. date=datetime.datetime(2000, 3, 18, 11, 54, 58),
  3537. section=cls.s1,
  3538. )
  3539. cls.a3 = Article.objects.create(
  3540. content="<p>Newest content</p>",
  3541. date=datetime.datetime(2009, 3, 18, 11, 54, 58),
  3542. section=cls.s1,
  3543. )
  3544. cls.p1 = PrePopulatedPost.objects.create(
  3545. title="A Long Title", published=True, slug="a-long-title"
  3546. )
  3547. cls.pk = (
  3548. "abcdefghijklmnopqrstuvwxyz ABCDEFGHIJKLMNOPQRSTUVWXYZ 1234567890 "
  3549. r"""-_.!~*'() ;/?:@&=+$, <>#%" {}|\^[]`"""
  3550. )
  3551. cls.m1 = ModelWithStringPrimaryKey.objects.create(string_pk=cls.pk)
  3552. user_pk = cls.superuser.pk
  3553. LogEntry.objects.log_actions(
  3554. user_pk,
  3555. [cls.m1],
  3556. 2,
  3557. change_message="Changed something",
  3558. single_object=True,
  3559. )
  3560. LogEntry.objects.log_actions(
  3561. user_pk,
  3562. [cls.m1],
  3563. 1,
  3564. change_message="Added something",
  3565. single_object=True,
  3566. )
  3567. LogEntry.objects.log_actions(
  3568. user_pk,
  3569. [cls.m1],
  3570. 3,
  3571. change_message="Deleted something",
  3572. single_object=True,
  3573. )
  3574. def setUp(self):
  3575. self.client.force_login(self.superuser)
  3576. def test_get_history_view(self):
  3577. """
  3578. Retrieving the history for an object using urlencoded form of primary
  3579. key should work.
  3580. Refs #12349, #18550.
  3581. """
  3582. response = self.client.get(
  3583. reverse(
  3584. "admin:admin_views_modelwithstringprimarykey_history", args=(self.pk,)
  3585. )
  3586. )
  3587. self.assertContains(response, escape(self.pk))
  3588. self.assertContains(response, "Changed something")
  3589. def test_get_change_view(self):
  3590. "Retrieving the object using urlencoded form of primary key should work"
  3591. response = self.client.get(
  3592. reverse(
  3593. "admin:admin_views_modelwithstringprimarykey_change", args=(self.pk,)
  3594. )
  3595. )
  3596. self.assertContains(response, escape(self.pk))
  3597. def test_changelist_to_changeform_link(self):
  3598. """
  3599. Link to the changeform of the object in changelist should use reverse()
  3600. and be quoted.
  3601. """
  3602. response = self.client.get(
  3603. reverse("admin:admin_views_modelwithstringprimarykey_changelist")
  3604. )
  3605. # this URL now comes through reverse(), thus url quoting and iri_to_uri encoding
  3606. pk_final_url = escape(iri_to_uri(quote(self.pk)))
  3607. change_url = reverse(
  3608. "admin:admin_views_modelwithstringprimarykey_change", args=("__fk__",)
  3609. ).replace("__fk__", pk_final_url)
  3610. should_contain = '<th class="field-__str__"><a href="%s">%s</a></th>' % (
  3611. change_url,
  3612. escape(self.pk),
  3613. )
  3614. self.assertContains(response, should_contain)
  3615. def test_recentactions_link(self):
  3616. """
  3617. The link from the recent actions list referring to the changeform of
  3618. the object should be quoted.
  3619. """
  3620. response = self.client.get(reverse("admin:index"))
  3621. link = reverse(
  3622. "admin:admin_views_modelwithstringprimarykey_change", args=(quote(self.pk),)
  3623. )
  3624. should_contain = """<a href="%s">%s</a>""" % (escape(link), escape(self.pk))
  3625. self.assertContains(response, should_contain)
  3626. def test_recentactions_description(self):
  3627. response = self.client.get(reverse("admin:index"))
  3628. for operation in ["Added", "Changed", "Deleted"]:
  3629. with self.subTest(operation):
  3630. self.assertContains(
  3631. response, f'<span class="visually-hidden">{operation}:'
  3632. )
  3633. def test_deleteconfirmation_link(self):
  3634. """
  3635. The link from the delete confirmation page referring back to the
  3636. changeform of the object should be quoted.
  3637. """
  3638. url = reverse(
  3639. "admin:admin_views_modelwithstringprimarykey_delete", args=(quote(self.pk),)
  3640. )
  3641. response = self.client.get(url)
  3642. # this URL now comes through reverse(), thus url quoting and iri_to_uri encoding
  3643. change_url = reverse(
  3644. "admin:admin_views_modelwithstringprimarykey_change", args=("__fk__",)
  3645. ).replace("__fk__", escape(iri_to_uri(quote(self.pk))))
  3646. should_contain = '<a href="%s">%s</a>' % (change_url, escape(self.pk))
  3647. self.assertContains(response, should_contain)
  3648. def test_url_conflicts_with_add(self):
  3649. "A model with a primary key that ends with add or is `add` should be visible"
  3650. add_model = ModelWithStringPrimaryKey.objects.create(
  3651. pk="i have something to add"
  3652. )
  3653. add_model.save()
  3654. response = self.client.get(
  3655. reverse(
  3656. "admin:admin_views_modelwithstringprimarykey_change",
  3657. args=(quote(add_model.pk),),
  3658. )
  3659. )
  3660. should_contain = """<h1>Change model with string primary key</h1>"""
  3661. self.assertContains(response, should_contain)
  3662. add_model2 = ModelWithStringPrimaryKey.objects.create(pk="add")
  3663. add_url = reverse("admin:admin_views_modelwithstringprimarykey_add")
  3664. change_url = reverse(
  3665. "admin:admin_views_modelwithstringprimarykey_change",
  3666. args=(quote(add_model2.pk),),
  3667. )
  3668. self.assertNotEqual(add_url, change_url)
  3669. def test_url_conflicts_with_delete(self):
  3670. "A model with a primary key that ends with delete should be visible"
  3671. delete_model = ModelWithStringPrimaryKey(pk="delete")
  3672. delete_model.save()
  3673. response = self.client.get(
  3674. reverse(
  3675. "admin:admin_views_modelwithstringprimarykey_change",
  3676. args=(quote(delete_model.pk),),
  3677. )
  3678. )
  3679. should_contain = """<h1>Change model with string primary key</h1>"""
  3680. self.assertContains(response, should_contain)
  3681. def test_url_conflicts_with_history(self):
  3682. "A model with a primary key that ends with history should be visible"
  3683. history_model = ModelWithStringPrimaryKey(pk="history")
  3684. history_model.save()
  3685. response = self.client.get(
  3686. reverse(
  3687. "admin:admin_views_modelwithstringprimarykey_change",
  3688. args=(quote(history_model.pk),),
  3689. )
  3690. )
  3691. should_contain = """<h1>Change model with string primary key</h1>"""
  3692. self.assertContains(response, should_contain)
  3693. def test_shortcut_view_with_escaping(self):
  3694. "'View on site should' work properly with char fields"
  3695. model = ModelWithStringPrimaryKey(pk="abc_123")
  3696. model.save()
  3697. response = self.client.get(
  3698. reverse(
  3699. "admin:admin_views_modelwithstringprimarykey_change",
  3700. args=(quote(model.pk),),
  3701. )
  3702. )
  3703. should_contain = '/%s/" class="viewsitelink">' % model.pk
  3704. self.assertContains(response, should_contain)
  3705. def test_change_view_history_link(self):
  3706. """Object history button link should work and contain the pk value quoted."""
  3707. url = reverse(
  3708. "admin:%s_modelwithstringprimarykey_change"
  3709. % ModelWithStringPrimaryKey._meta.app_label,
  3710. args=(quote(self.pk),),
  3711. )
  3712. response = self.client.get(url)
  3713. self.assertEqual(response.status_code, 200)
  3714. expected_link = reverse(
  3715. "admin:%s_modelwithstringprimarykey_history"
  3716. % ModelWithStringPrimaryKey._meta.app_label,
  3717. args=(quote(self.pk),),
  3718. )
  3719. self.assertContains(
  3720. response, '<a href="%s" class="historylink"' % escape(expected_link)
  3721. )
  3722. def test_redirect_on_add_view_continue_button(self):
  3723. """As soon as an object is added using "Save and continue editing"
  3724. button, the user should be redirected to the object's change_view.
  3725. In case primary key is a string containing some special characters
  3726. like slash or underscore, these characters must be escaped (see #22266)
  3727. """
  3728. response = self.client.post(
  3729. reverse("admin:admin_views_modelwithstringprimarykey_add"),
  3730. {
  3731. "string_pk": "123/history",
  3732. "_continue": "1", # Save and continue editing
  3733. },
  3734. )
  3735. self.assertEqual(response.status_code, 302) # temporary redirect
  3736. self.assertIn("/123_2Fhistory/", response.headers["location"]) # PK is quoted
  3737. @override_settings(ROOT_URLCONF="admin_views.urls")
  3738. class SecureViewTests(TestCase):
  3739. """
  3740. Test behavior of a view protected by the staff_member_required decorator.
  3741. """
  3742. def test_secure_view_shows_login_if_not_logged_in(self):
  3743. secure_url = reverse("secure_view")
  3744. response = self.client.get(secure_url)
  3745. self.assertRedirects(
  3746. response, "%s?next=%s" % (reverse("admin:login"), secure_url)
  3747. )
  3748. response = self.client.get(secure_url, follow=True)
  3749. self.assertTemplateUsed(response, "admin/login.html")
  3750. self.assertEqual(response.context[REDIRECT_FIELD_NAME], secure_url)
  3751. def test_staff_member_required_decorator_works_with_argument(self):
  3752. """
  3753. Staff_member_required decorator works with an argument
  3754. (redirect_field_name).
  3755. """
  3756. secure_url = "/test_admin/admin/secure-view2/"
  3757. response = self.client.get(secure_url)
  3758. self.assertRedirects(
  3759. response, "%s?myfield=%s" % (reverse("admin:login"), secure_url)
  3760. )
  3761. @override_settings(ROOT_URLCONF="admin_views.urls")
  3762. class AdminViewUnicodeTest(TestCase):
  3763. @classmethod
  3764. def setUpTestData(cls):
  3765. cls.superuser = User.objects.create_superuser(
  3766. username="super", password="secret", email="super@example.com"
  3767. )
  3768. cls.b1 = Book.objects.create(name="Lærdommer")
  3769. cls.p1 = Promo.objects.create(name="<Promo for Lærdommer>", book=cls.b1)
  3770. cls.chap1 = Chapter.objects.create(
  3771. title="Norske bostaver æøå skaper problemer",
  3772. content="<p>Svært frustrerende med UnicodeDecodeErro</p>",
  3773. book=cls.b1,
  3774. )
  3775. cls.chap2 = Chapter.objects.create(
  3776. title="Kjærlighet",
  3777. content="<p>La kjærligheten til de lidende seire.</p>",
  3778. book=cls.b1,
  3779. )
  3780. cls.chap3 = Chapter.objects.create(
  3781. title="Kjærlighet", content="<p>Noe innhold</p>", book=cls.b1
  3782. )
  3783. cls.chap4 = ChapterXtra1.objects.create(
  3784. chap=cls.chap1, xtra="<Xtra(1) Norske bostaver æøå skaper problemer>"
  3785. )
  3786. cls.chap5 = ChapterXtra1.objects.create(
  3787. chap=cls.chap2, xtra="<Xtra(1) Kjærlighet>"
  3788. )
  3789. cls.chap6 = ChapterXtra1.objects.create(
  3790. chap=cls.chap3, xtra="<Xtra(1) Kjærlighet>"
  3791. )
  3792. cls.chap7 = ChapterXtra2.objects.create(
  3793. chap=cls.chap1, xtra="<Xtra(2) Norske bostaver æøå skaper problemer>"
  3794. )
  3795. cls.chap8 = ChapterXtra2.objects.create(
  3796. chap=cls.chap2, xtra="<Xtra(2) Kjærlighet>"
  3797. )
  3798. cls.chap9 = ChapterXtra2.objects.create(
  3799. chap=cls.chap3, xtra="<Xtra(2) Kjærlighet>"
  3800. )
  3801. def setUp(self):
  3802. self.client.force_login(self.superuser)
  3803. def test_unicode_edit(self):
  3804. """
  3805. A test to ensure that POST on edit_view handles non-ASCII characters.
  3806. """
  3807. post_data = {
  3808. "name": "Test lærdommer",
  3809. # inline data
  3810. "chapter_set-TOTAL_FORMS": "6",
  3811. "chapter_set-INITIAL_FORMS": "3",
  3812. "chapter_set-MAX_NUM_FORMS": "0",
  3813. "chapter_set-0-id": self.chap1.pk,
  3814. "chapter_set-0-title": "Norske bostaver æøå skaper problemer",
  3815. "chapter_set-0-content": (
  3816. "&lt;p&gt;Svært frustrerende med UnicodeDecodeError&lt;/p&gt;"
  3817. ),
  3818. "chapter_set-1-id": self.chap2.id,
  3819. "chapter_set-1-title": "Kjærlighet.",
  3820. "chapter_set-1-content": (
  3821. "&lt;p&gt;La kjærligheten til de lidende seire.&lt;/p&gt;"
  3822. ),
  3823. "chapter_set-2-id": self.chap3.id,
  3824. "chapter_set-2-title": "Need a title.",
  3825. "chapter_set-2-content": "&lt;p&gt;Newest content&lt;/p&gt;",
  3826. "chapter_set-3-id": "",
  3827. "chapter_set-3-title": "",
  3828. "chapter_set-3-content": "",
  3829. "chapter_set-4-id": "",
  3830. "chapter_set-4-title": "",
  3831. "chapter_set-4-content": "",
  3832. "chapter_set-5-id": "",
  3833. "chapter_set-5-title": "",
  3834. "chapter_set-5-content": "",
  3835. }
  3836. response = self.client.post(
  3837. reverse("admin:admin_views_book_change", args=(self.b1.pk,)), post_data
  3838. )
  3839. self.assertEqual(response.status_code, 302) # redirect somewhere
  3840. def test_unicode_delete(self):
  3841. """
  3842. The delete_view handles non-ASCII characters
  3843. """
  3844. delete_dict = {"post": "yes"}
  3845. delete_url = reverse("admin:admin_views_book_delete", args=(self.b1.pk,))
  3846. response = self.client.get(delete_url)
  3847. self.assertEqual(response.status_code, 200)
  3848. response = self.client.post(delete_url, delete_dict)
  3849. self.assertRedirects(response, reverse("admin:admin_views_book_changelist"))
  3850. @override_settings(ROOT_URLCONF="admin_views.urls")
  3851. class AdminViewListEditable(TestCase):
  3852. @classmethod
  3853. def setUpTestData(cls):
  3854. cls.superuser = User.objects.create_superuser(
  3855. username="super", password="secret", email="super@example.com"
  3856. )
  3857. cls.s1 = Section.objects.create(name="Test section")
  3858. cls.a1 = Article.objects.create(
  3859. content="<p>Middle content</p>",
  3860. date=datetime.datetime(2008, 3, 18, 11, 54, 58),
  3861. section=cls.s1,
  3862. )
  3863. cls.a2 = Article.objects.create(
  3864. content="<p>Oldest content</p>",
  3865. date=datetime.datetime(2000, 3, 18, 11, 54, 58),
  3866. section=cls.s1,
  3867. )
  3868. cls.a3 = Article.objects.create(
  3869. content="<p>Newest content</p>",
  3870. date=datetime.datetime(2009, 3, 18, 11, 54, 58),
  3871. section=cls.s1,
  3872. )
  3873. cls.p1 = PrePopulatedPost.objects.create(
  3874. title="A Long Title", published=True, slug="a-long-title"
  3875. )
  3876. cls.per1 = Person.objects.create(name="John Mauchly", gender=1, alive=True)
  3877. cls.per2 = Person.objects.create(name="Grace Hopper", gender=1, alive=False)
  3878. cls.per3 = Person.objects.create(name="Guido van Rossum", gender=1, alive=True)
  3879. def setUp(self):
  3880. self.client.force_login(self.superuser)
  3881. def test_inheritance(self):
  3882. Podcast.objects.create(
  3883. name="This Week in Django", release_date=datetime.date.today()
  3884. )
  3885. response = self.client.get(reverse("admin:admin_views_podcast_changelist"))
  3886. self.assertEqual(response.status_code, 200)
  3887. def test_inheritance_2(self):
  3888. Vodcast.objects.create(name="This Week in Django", released=True)
  3889. response = self.client.get(reverse("admin:admin_views_vodcast_changelist"))
  3890. self.assertEqual(response.status_code, 200)
  3891. def test_custom_pk(self):
  3892. Language.objects.create(iso="en", name="English", english_name="English")
  3893. response = self.client.get(reverse("admin:admin_views_language_changelist"))
  3894. self.assertEqual(response.status_code, 200)
  3895. def test_changelist_input_html(self):
  3896. response = self.client.get(reverse("admin:admin_views_person_changelist"))
  3897. # 2 inputs per object(the field and the hidden id field) = 6
  3898. # 4 management hidden fields = 4
  3899. # 4 action inputs (3 regular checkboxes, 1 checkbox to select all)
  3900. # main form submit button = 1
  3901. # search field and search submit button = 2
  3902. # CSRF field = 2
  3903. # field to track 'select all' across paginated views = 1
  3904. # 6 + 4 + 4 + 1 + 2 + 2 + 1 = 20 inputs
  3905. self.assertContains(response, "<input", count=21)
  3906. # 1 select per object = 3 selects
  3907. self.assertContains(response, "<select", count=4)
  3908. def test_post_messages(self):
  3909. # Ticket 12707: Saving inline editable should not show admin
  3910. # action warnings
  3911. data = {
  3912. "form-TOTAL_FORMS": "3",
  3913. "form-INITIAL_FORMS": "3",
  3914. "form-MAX_NUM_FORMS": "0",
  3915. "form-0-gender": "1",
  3916. "form-0-id": str(self.per1.pk),
  3917. "form-1-gender": "2",
  3918. "form-1-id": str(self.per2.pk),
  3919. "form-2-alive": "checked",
  3920. "form-2-gender": "1",
  3921. "form-2-id": str(self.per3.pk),
  3922. "_save": "Save",
  3923. }
  3924. response = self.client.post(
  3925. reverse("admin:admin_views_person_changelist"), data, follow=True
  3926. )
  3927. self.assertEqual(len(response.context["messages"]), 1)
  3928. def test_post_submission(self):
  3929. data = {
  3930. "form-TOTAL_FORMS": "3",
  3931. "form-INITIAL_FORMS": "3",
  3932. "form-MAX_NUM_FORMS": "0",
  3933. "form-0-gender": "1",
  3934. "form-0-id": str(self.per1.pk),
  3935. "form-1-gender": "2",
  3936. "form-1-id": str(self.per2.pk),
  3937. "form-2-alive": "checked",
  3938. "form-2-gender": "1",
  3939. "form-2-id": str(self.per3.pk),
  3940. "_save": "Save",
  3941. }
  3942. self.client.post(reverse("admin:admin_views_person_changelist"), data)
  3943. self.assertIs(Person.objects.get(name="John Mauchly").alive, False)
  3944. self.assertEqual(Person.objects.get(name="Grace Hopper").gender, 2)
  3945. # test a filtered page
  3946. data = {
  3947. "form-TOTAL_FORMS": "2",
  3948. "form-INITIAL_FORMS": "2",
  3949. "form-MAX_NUM_FORMS": "0",
  3950. "form-0-id": str(self.per1.pk),
  3951. "form-0-gender": "1",
  3952. "form-0-alive": "checked",
  3953. "form-1-id": str(self.per3.pk),
  3954. "form-1-gender": "1",
  3955. "form-1-alive": "checked",
  3956. "_save": "Save",
  3957. }
  3958. self.client.post(
  3959. reverse("admin:admin_views_person_changelist") + "?gender__exact=1", data
  3960. )
  3961. self.assertIs(Person.objects.get(name="John Mauchly").alive, True)
  3962. # test a searched page
  3963. data = {
  3964. "form-TOTAL_FORMS": "1",
  3965. "form-INITIAL_FORMS": "1",
  3966. "form-MAX_NUM_FORMS": "0",
  3967. "form-0-id": str(self.per1.pk),
  3968. "form-0-gender": "1",
  3969. "_save": "Save",
  3970. }
  3971. self.client.post(
  3972. reverse("admin:admin_views_person_changelist") + "?q=john", data
  3973. )
  3974. self.assertIs(Person.objects.get(name="John Mauchly").alive, False)
  3975. def test_non_field_errors(self):
  3976. """
  3977. Non-field errors are displayed for each of the forms in the
  3978. changelist's formset.
  3979. """
  3980. fd1 = FoodDelivery.objects.create(
  3981. reference="123", driver="bill", restaurant="thai"
  3982. )
  3983. fd2 = FoodDelivery.objects.create(
  3984. reference="456", driver="bill", restaurant="india"
  3985. )
  3986. fd3 = FoodDelivery.objects.create(
  3987. reference="789", driver="bill", restaurant="pizza"
  3988. )
  3989. data = {
  3990. "form-TOTAL_FORMS": "3",
  3991. "form-INITIAL_FORMS": "3",
  3992. "form-MAX_NUM_FORMS": "0",
  3993. "form-0-id": str(fd1.id),
  3994. "form-0-reference": "123",
  3995. "form-0-driver": "bill",
  3996. "form-0-restaurant": "thai",
  3997. # Same data as above: Forbidden because of unique_together!
  3998. "form-1-id": str(fd2.id),
  3999. "form-1-reference": "456",
  4000. "form-1-driver": "bill",
  4001. "form-1-restaurant": "thai",
  4002. "form-2-id": str(fd3.id),
  4003. "form-2-reference": "789",
  4004. "form-2-driver": "bill",
  4005. "form-2-restaurant": "pizza",
  4006. "_save": "Save",
  4007. }
  4008. response = self.client.post(
  4009. reverse("admin:admin_views_fooddelivery_changelist"), data
  4010. )
  4011. self.assertContains(
  4012. response,
  4013. '<tr><td colspan="4"><ul class="errorlist nonfield"><li>Food delivery '
  4014. "with this Driver and Restaurant already exists.</li></ul></td></tr>",
  4015. 1,
  4016. html=True,
  4017. )
  4018. data = {
  4019. "form-TOTAL_FORMS": "3",
  4020. "form-INITIAL_FORMS": "3",
  4021. "form-MAX_NUM_FORMS": "0",
  4022. "form-0-id": str(fd1.id),
  4023. "form-0-reference": "123",
  4024. "form-0-driver": "bill",
  4025. "form-0-restaurant": "thai",
  4026. # Same data as above: Forbidden because of unique_together!
  4027. "form-1-id": str(fd2.id),
  4028. "form-1-reference": "456",
  4029. "form-1-driver": "bill",
  4030. "form-1-restaurant": "thai",
  4031. # Same data also.
  4032. "form-2-id": str(fd3.id),
  4033. "form-2-reference": "789",
  4034. "form-2-driver": "bill",
  4035. "form-2-restaurant": "thai",
  4036. "_save": "Save",
  4037. }
  4038. response = self.client.post(
  4039. reverse("admin:admin_views_fooddelivery_changelist"), data
  4040. )
  4041. self.assertContains(
  4042. response,
  4043. '<tr><td colspan="4"><ul class="errorlist nonfield"><li>Food delivery '
  4044. "with this Driver and Restaurant already exists.</li></ul></td></tr>",
  4045. 2,
  4046. html=True,
  4047. )
  4048. def test_non_form_errors(self):
  4049. # test if non-form errors are handled; ticket #12716
  4050. data = {
  4051. "form-TOTAL_FORMS": "1",
  4052. "form-INITIAL_FORMS": "1",
  4053. "form-MAX_NUM_FORMS": "0",
  4054. "form-0-id": str(self.per2.pk),
  4055. "form-0-alive": "1",
  4056. "form-0-gender": "2",
  4057. # The form processing understands this as a list_editable "Save"
  4058. # and not an action "Go".
  4059. "_save": "Save",
  4060. }
  4061. response = self.client.post(
  4062. reverse("admin:admin_views_person_changelist"), data
  4063. )
  4064. self.assertContains(response, "Grace is not a Zombie")
  4065. def test_non_form_errors_is_errorlist(self):
  4066. # test if non-form errors are correctly handled; ticket #12878
  4067. data = {
  4068. "form-TOTAL_FORMS": "1",
  4069. "form-INITIAL_FORMS": "1",
  4070. "form-MAX_NUM_FORMS": "0",
  4071. "form-0-id": str(self.per2.pk),
  4072. "form-0-alive": "1",
  4073. "form-0-gender": "2",
  4074. "_save": "Save",
  4075. }
  4076. response = self.client.post(
  4077. reverse("admin:admin_views_person_changelist"), data
  4078. )
  4079. non_form_errors = response.context["cl"].formset.non_form_errors()
  4080. self.assertIsInstance(non_form_errors, ErrorList)
  4081. self.assertEqual(
  4082. str(non_form_errors),
  4083. str(ErrorList(["Grace is not a Zombie"], error_class="nonform")),
  4084. )
  4085. def test_list_editable_ordering(self):
  4086. collector = Collector.objects.create(id=1, name="Frederick Clegg")
  4087. Category.objects.create(id=1, order=1, collector=collector)
  4088. Category.objects.create(id=2, order=2, collector=collector)
  4089. Category.objects.create(id=3, order=0, collector=collector)
  4090. Category.objects.create(id=4, order=0, collector=collector)
  4091. # NB: The order values must be changed so that the items are reordered.
  4092. data = {
  4093. "form-TOTAL_FORMS": "4",
  4094. "form-INITIAL_FORMS": "4",
  4095. "form-MAX_NUM_FORMS": "0",
  4096. "form-0-order": "14",
  4097. "form-0-id": "1",
  4098. "form-0-collector": "1",
  4099. "form-1-order": "13",
  4100. "form-1-id": "2",
  4101. "form-1-collector": "1",
  4102. "form-2-order": "1",
  4103. "form-2-id": "3",
  4104. "form-2-collector": "1",
  4105. "form-3-order": "0",
  4106. "form-3-id": "4",
  4107. "form-3-collector": "1",
  4108. # The form processing understands this as a list_editable "Save"
  4109. # and not an action "Go".
  4110. "_save": "Save",
  4111. }
  4112. response = self.client.post(
  4113. reverse("admin:admin_views_category_changelist"), data
  4114. )
  4115. # Successful post will redirect
  4116. self.assertEqual(response.status_code, 302)
  4117. # The order values have been applied to the right objects
  4118. self.assertEqual(Category.objects.get(id=1).order, 14)
  4119. self.assertEqual(Category.objects.get(id=2).order, 13)
  4120. self.assertEqual(Category.objects.get(id=3).order, 1)
  4121. self.assertEqual(Category.objects.get(id=4).order, 0)
  4122. def test_list_editable_pagination(self):
  4123. """
  4124. Pagination works for list_editable items.
  4125. """
  4126. UnorderedObject.objects.create(id=1, name="Unordered object #1")
  4127. UnorderedObject.objects.create(id=2, name="Unordered object #2")
  4128. UnorderedObject.objects.create(id=3, name="Unordered object #3")
  4129. response = self.client.get(
  4130. reverse("admin:admin_views_unorderedobject_changelist")
  4131. )
  4132. self.assertContains(response, "Unordered object #3")
  4133. self.assertContains(response, "Unordered object #2")
  4134. self.assertNotContains(response, "Unordered object #1")
  4135. response = self.client.get(
  4136. reverse("admin:admin_views_unorderedobject_changelist") + "?p=2"
  4137. )
  4138. self.assertNotContains(response, "Unordered object #3")
  4139. self.assertNotContains(response, "Unordered object #2")
  4140. self.assertContains(response, "Unordered object #1")
  4141. def test_list_editable_action_submit(self):
  4142. # List editable changes should not be executed if the action "Go" button is
  4143. # used to submit the form.
  4144. data = {
  4145. "form-TOTAL_FORMS": "3",
  4146. "form-INITIAL_FORMS": "3",
  4147. "form-MAX_NUM_FORMS": "0",
  4148. "form-0-gender": "1",
  4149. "form-0-id": "1",
  4150. "form-1-gender": "2",
  4151. "form-1-id": "2",
  4152. "form-2-alive": "checked",
  4153. "form-2-gender": "1",
  4154. "form-2-id": "3",
  4155. "index": "0",
  4156. "_selected_action": ["3"],
  4157. "action": ["", "delete_selected"],
  4158. }
  4159. self.client.post(reverse("admin:admin_views_person_changelist"), data)
  4160. self.assertIs(Person.objects.get(name="John Mauchly").alive, True)
  4161. self.assertEqual(Person.objects.get(name="Grace Hopper").gender, 1)
  4162. def test_list_editable_action_choices(self):
  4163. # List editable changes should be executed if the "Save" button is
  4164. # used to submit the form - any action choices should be ignored.
  4165. data = {
  4166. "form-TOTAL_FORMS": "3",
  4167. "form-INITIAL_FORMS": "3",
  4168. "form-MAX_NUM_FORMS": "0",
  4169. "form-0-gender": "1",
  4170. "form-0-id": str(self.per1.pk),
  4171. "form-1-gender": "2",
  4172. "form-1-id": str(self.per2.pk),
  4173. "form-2-alive": "checked",
  4174. "form-2-gender": "1",
  4175. "form-2-id": str(self.per3.pk),
  4176. "_save": "Save",
  4177. "_selected_action": ["1"],
  4178. "action": ["", "delete_selected"],
  4179. }
  4180. self.client.post(reverse("admin:admin_views_person_changelist"), data)
  4181. self.assertIs(Person.objects.get(name="John Mauchly").alive, False)
  4182. self.assertEqual(Person.objects.get(name="Grace Hopper").gender, 2)
  4183. def test_list_editable_popup(self):
  4184. """
  4185. Fields should not be list-editable in popups.
  4186. """
  4187. response = self.client.get(reverse("admin:admin_views_person_changelist"))
  4188. self.assertNotEqual(response.context["cl"].list_editable, ())
  4189. response = self.client.get(
  4190. reverse("admin:admin_views_person_changelist") + "?%s" % IS_POPUP_VAR
  4191. )
  4192. self.assertEqual(response.context["cl"].list_editable, ())
  4193. def test_pk_hidden_fields(self):
  4194. """
  4195. hidden pk fields aren't displayed in the table body and their
  4196. corresponding human-readable value is displayed instead. The hidden pk
  4197. fields are displayed but separately (not in the table) and only once.
  4198. """
  4199. story1 = Story.objects.create(
  4200. title="The adventures of Guido", content="Once upon a time in Djangoland..."
  4201. )
  4202. story2 = Story.objects.create(
  4203. title="Crouching Tiger, Hidden Python",
  4204. content="The Python was sneaking into...",
  4205. )
  4206. response = self.client.get(reverse("admin:admin_views_story_changelist"))
  4207. # Only one hidden field, in a separate place than the table.
  4208. self.assertContains(response, 'id="id_form-0-id"', 1)
  4209. self.assertContains(response, 'id="id_form-1-id"', 1)
  4210. self.assertContains(
  4211. response,
  4212. '<div class="hiddenfields">\n'
  4213. '<input type="hidden" name="form-0-id" value="%d" id="id_form-0-id">'
  4214. '<input type="hidden" name="form-1-id" value="%d" id="id_form-1-id">\n'
  4215. "</div>" % (story2.id, story1.id),
  4216. html=True,
  4217. )
  4218. self.assertContains(response, '<td class="field-id">%d</td>' % story1.id, 1)
  4219. self.assertContains(response, '<td class="field-id">%d</td>' % story2.id, 1)
  4220. def test_pk_hidden_fields_with_list_display_links(self):
  4221. """Similarly as test_pk_hidden_fields, but when the hidden pk fields are
  4222. referenced in list_display_links.
  4223. Refs #12475.
  4224. """
  4225. story1 = OtherStory.objects.create(
  4226. title="The adventures of Guido",
  4227. content="Once upon a time in Djangoland...",
  4228. )
  4229. story2 = OtherStory.objects.create(
  4230. title="Crouching Tiger, Hidden Python",
  4231. content="The Python was sneaking into...",
  4232. )
  4233. link1 = reverse("admin:admin_views_otherstory_change", args=(story1.pk,))
  4234. link2 = reverse("admin:admin_views_otherstory_change", args=(story2.pk,))
  4235. response = self.client.get(reverse("admin:admin_views_otherstory_changelist"))
  4236. # Only one hidden field, in a separate place than the table.
  4237. self.assertContains(response, 'id="id_form-0-id"', 1)
  4238. self.assertContains(response, 'id="id_form-1-id"', 1)
  4239. self.assertContains(
  4240. response,
  4241. '<div class="hiddenfields">\n'
  4242. '<input type="hidden" name="form-0-id" value="%d" id="id_form-0-id">'
  4243. '<input type="hidden" name="form-1-id" value="%d" id="id_form-1-id">\n'
  4244. "</div>" % (story2.id, story1.id),
  4245. html=True,
  4246. )
  4247. self.assertContains(
  4248. response,
  4249. '<th class="field-id"><a href="%s">%d</a></th>' % (link1, story1.id),
  4250. 1,
  4251. )
  4252. self.assertContains(
  4253. response,
  4254. '<th class="field-id"><a href="%s">%d</a></th>' % (link2, story2.id),
  4255. 1,
  4256. )
  4257. @override_settings(ROOT_URLCONF="admin_views.urls")
  4258. class AdminSearchTest(TestCase):
  4259. @classmethod
  4260. def setUpTestData(cls):
  4261. cls.superuser = User.objects.create_superuser(
  4262. username="super", password="secret", email="super@example.com"
  4263. )
  4264. cls.joepublicuser = User.objects.create_user(
  4265. username="joepublic", password="secret"
  4266. )
  4267. cls.s1 = Section.objects.create(name="Test section")
  4268. cls.a1 = Article.objects.create(
  4269. content="<p>Middle content</p>",
  4270. date=datetime.datetime(2008, 3, 18, 11, 54, 58),
  4271. section=cls.s1,
  4272. )
  4273. cls.a2 = Article.objects.create(
  4274. content="<p>Oldest content</p>",
  4275. date=datetime.datetime(2000, 3, 18, 11, 54, 58),
  4276. section=cls.s1,
  4277. )
  4278. cls.a3 = Article.objects.create(
  4279. content="<p>Newest content</p>",
  4280. date=datetime.datetime(2009, 3, 18, 11, 54, 58),
  4281. section=cls.s1,
  4282. )
  4283. cls.p1 = PrePopulatedPost.objects.create(
  4284. title="A Long Title", published=True, slug="a-long-title"
  4285. )
  4286. cls.per1 = Person.objects.create(name="John Mauchly", gender=1, alive=True)
  4287. cls.per2 = Person.objects.create(name="Grace Hopper", gender=1, alive=False)
  4288. cls.per3 = Person.objects.create(name="Guido van Rossum", gender=1, alive=True)
  4289. Person.objects.create(name="John Doe", gender=1)
  4290. Person.objects.create(name='John O"Hara', gender=1)
  4291. Person.objects.create(name="John O'Hara", gender=1)
  4292. cls.t1 = Recommender.objects.create()
  4293. cls.t2 = Recommendation.objects.create(the_recommender=cls.t1)
  4294. cls.t3 = Recommender.objects.create()
  4295. cls.t4 = Recommendation.objects.create(the_recommender=cls.t3)
  4296. cls.tt1 = TitleTranslation.objects.create(title=cls.t1, text="Bar")
  4297. cls.tt2 = TitleTranslation.objects.create(title=cls.t2, text="Foo")
  4298. cls.tt3 = TitleTranslation.objects.create(title=cls.t3, text="Few")
  4299. cls.tt4 = TitleTranslation.objects.create(title=cls.t4, text="Bas")
  4300. def setUp(self):
  4301. self.client.force_login(self.superuser)
  4302. def test_search_on_sibling_models(self):
  4303. "A search that mentions sibling models"
  4304. response = self.client.get(
  4305. reverse("admin:admin_views_recommendation_changelist") + "?q=bar"
  4306. )
  4307. # confirm the search returned 1 object
  4308. self.assertContains(response, "\n1 recommendation\n")
  4309. def test_with_fk_to_field(self):
  4310. """
  4311. The to_field GET parameter is preserved when a search is performed.
  4312. Refs #10918.
  4313. """
  4314. response = self.client.get(
  4315. reverse("admin:auth_user_changelist") + "?q=joe&%s=id" % TO_FIELD_VAR
  4316. )
  4317. self.assertContains(response, "\n1 user\n")
  4318. self.assertContains(
  4319. response,
  4320. '<input type="hidden" name="%s" value="id">' % TO_FIELD_VAR,
  4321. html=True,
  4322. )
  4323. def test_exact_matches(self):
  4324. response = self.client.get(
  4325. reverse("admin:admin_views_recommendation_changelist") + "?q=bar"
  4326. )
  4327. # confirm the search returned one object
  4328. self.assertContains(response, "\n1 recommendation\n")
  4329. response = self.client.get(
  4330. reverse("admin:admin_views_recommendation_changelist") + "?q=ba"
  4331. )
  4332. # confirm the search returned zero objects
  4333. self.assertContains(response, "\n0 recommendations\n")
  4334. def test_beginning_matches(self):
  4335. response = self.client.get(
  4336. reverse("admin:admin_views_person_changelist") + "?q=Gui"
  4337. )
  4338. # confirm the search returned one object
  4339. self.assertContains(response, "\n1 person\n")
  4340. self.assertContains(response, "Guido")
  4341. response = self.client.get(
  4342. reverse("admin:admin_views_person_changelist") + "?q=uido"
  4343. )
  4344. # confirm the search returned zero objects
  4345. self.assertContains(response, "\n0 persons\n")
  4346. self.assertNotContains(response, "Guido")
  4347. def test_pluggable_search(self):
  4348. PluggableSearchPerson.objects.create(name="Bob", age=10)
  4349. PluggableSearchPerson.objects.create(name="Amy", age=20)
  4350. response = self.client.get(
  4351. reverse("admin:admin_views_pluggablesearchperson_changelist") + "?q=Bob"
  4352. )
  4353. # confirm the search returned one object
  4354. self.assertContains(response, "\n1 pluggable search person\n")
  4355. self.assertContains(response, "Bob")
  4356. response = self.client.get(
  4357. reverse("admin:admin_views_pluggablesearchperson_changelist") + "?q=20"
  4358. )
  4359. # confirm the search returned one object
  4360. self.assertContains(response, "\n1 pluggable search person\n")
  4361. self.assertContains(response, "Amy")
  4362. def test_reset_link(self):
  4363. """
  4364. Test presence of reset link in search bar ("1 result (_x total_)").
  4365. """
  4366. # 1 query for session + 1 for fetching user
  4367. # + 1 for filtered result + 1 for filtered count
  4368. # + 1 for total count
  4369. with self.assertNumQueries(5):
  4370. response = self.client.get(
  4371. reverse("admin:admin_views_person_changelist") + "?q=Gui"
  4372. )
  4373. self.assertContains(
  4374. response,
  4375. """<span class="small quiet">1 result (<a href="?">6 total</a>)</span>""",
  4376. html=True,
  4377. )
  4378. def test_no_total_count(self):
  4379. """
  4380. #8408 -- "Show all" should be displayed instead of the total count if
  4381. ModelAdmin.show_full_result_count is False.
  4382. """
  4383. # 1 query for session + 1 for fetching user
  4384. # + 1 for filtered result + 1 for filtered count
  4385. with self.assertNumQueries(4):
  4386. response = self.client.get(
  4387. reverse("admin:admin_views_recommendation_changelist") + "?q=bar"
  4388. )
  4389. self.assertContains(
  4390. response,
  4391. """<span class="small quiet">1 result (<a href="?">Show all</a>)</span>""",
  4392. html=True,
  4393. )
  4394. self.assertTrue(response.context["cl"].show_admin_actions)
  4395. def test_search_with_spaces(self):
  4396. url = reverse("admin:admin_views_person_changelist") + "?q=%s"
  4397. tests = [
  4398. ('"John Doe"', 1),
  4399. ("'John Doe'", 1),
  4400. ("John Doe", 0),
  4401. ('"John Doe" John', 1),
  4402. ("'John Doe' John", 1),
  4403. ("John Doe John", 0),
  4404. ('"John Do"', 1),
  4405. ("'John Do'", 1),
  4406. ("'John O'Hara'", 0),
  4407. ("'John O\\'Hara'", 1),
  4408. ('"John O"Hara"', 0),
  4409. ('"John O\\"Hara"', 1),
  4410. ]
  4411. for search, hits in tests:
  4412. with self.subTest(search=search):
  4413. response = self.client.get(url % search)
  4414. self.assertContains(response, "\n%s person" % hits)
  4415. @override_settings(ROOT_URLCONF="admin_views.urls")
  4416. class AdminInheritedInlinesTest(TestCase):
  4417. @classmethod
  4418. def setUpTestData(cls):
  4419. cls.superuser = User.objects.create_superuser(
  4420. username="super", password="secret", email="super@example.com"
  4421. )
  4422. def setUp(self):
  4423. self.client.force_login(self.superuser)
  4424. def test_inline(self):
  4425. """
  4426. Inline models which inherit from a common parent are correctly handled.
  4427. """
  4428. foo_user = "foo username"
  4429. bar_user = "bar username"
  4430. name_re = re.compile(b'name="(.*?)"')
  4431. # test the add case
  4432. response = self.client.get(reverse("admin:admin_views_persona_add"))
  4433. names = name_re.findall(response.content)
  4434. names.remove(b"csrfmiddlewaretoken")
  4435. # make sure we have no duplicate HTML names
  4436. self.assertEqual(len(names), len(set(names)))
  4437. # test the add case
  4438. post_data = {
  4439. "name": "Test Name",
  4440. # inline data
  4441. "accounts-TOTAL_FORMS": "1",
  4442. "accounts-INITIAL_FORMS": "0",
  4443. "accounts-MAX_NUM_FORMS": "0",
  4444. "accounts-0-username": foo_user,
  4445. "accounts-2-TOTAL_FORMS": "1",
  4446. "accounts-2-INITIAL_FORMS": "0",
  4447. "accounts-2-MAX_NUM_FORMS": "0",
  4448. "accounts-2-0-username": bar_user,
  4449. }
  4450. response = self.client.post(reverse("admin:admin_views_persona_add"), post_data)
  4451. self.assertEqual(response.status_code, 302) # redirect somewhere
  4452. self.assertEqual(Persona.objects.count(), 1)
  4453. self.assertEqual(FooAccount.objects.count(), 1)
  4454. self.assertEqual(BarAccount.objects.count(), 1)
  4455. self.assertEqual(FooAccount.objects.all()[0].username, foo_user)
  4456. self.assertEqual(BarAccount.objects.all()[0].username, bar_user)
  4457. self.assertEqual(Persona.objects.all()[0].accounts.count(), 2)
  4458. persona_id = Persona.objects.all()[0].id
  4459. foo_id = FooAccount.objects.all()[0].id
  4460. bar_id = BarAccount.objects.all()[0].id
  4461. # test the edit case
  4462. response = self.client.get(
  4463. reverse("admin:admin_views_persona_change", args=(persona_id,))
  4464. )
  4465. names = name_re.findall(response.content)
  4466. names.remove(b"csrfmiddlewaretoken")
  4467. # make sure we have no duplicate HTML names
  4468. self.assertEqual(len(names), len(set(names)))
  4469. post_data = {
  4470. "name": "Test Name",
  4471. "accounts-TOTAL_FORMS": "2",
  4472. "accounts-INITIAL_FORMS": "1",
  4473. "accounts-MAX_NUM_FORMS": "0",
  4474. "accounts-0-username": "%s-1" % foo_user,
  4475. "accounts-0-account_ptr": str(foo_id),
  4476. "accounts-0-persona": str(persona_id),
  4477. "accounts-2-TOTAL_FORMS": "2",
  4478. "accounts-2-INITIAL_FORMS": "1",
  4479. "accounts-2-MAX_NUM_FORMS": "0",
  4480. "accounts-2-0-username": "%s-1" % bar_user,
  4481. "accounts-2-0-account_ptr": str(bar_id),
  4482. "accounts-2-0-persona": str(persona_id),
  4483. }
  4484. response = self.client.post(
  4485. reverse("admin:admin_views_persona_change", args=(persona_id,)), post_data
  4486. )
  4487. self.assertEqual(response.status_code, 302)
  4488. self.assertEqual(Persona.objects.count(), 1)
  4489. self.assertEqual(FooAccount.objects.count(), 1)
  4490. self.assertEqual(BarAccount.objects.count(), 1)
  4491. self.assertEqual(FooAccount.objects.all()[0].username, "%s-1" % foo_user)
  4492. self.assertEqual(BarAccount.objects.all()[0].username, "%s-1" % bar_user)
  4493. self.assertEqual(Persona.objects.all()[0].accounts.count(), 2)
  4494. @override_settings(ROOT_URLCONF="admin_views.urls")
  4495. class TestCustomChangeList(TestCase):
  4496. @classmethod
  4497. def setUpTestData(cls):
  4498. cls.superuser = User.objects.create_superuser(
  4499. username="super", password="secret", email="super@example.com"
  4500. )
  4501. def setUp(self):
  4502. self.client.force_login(self.superuser)
  4503. def test_custom_changelist(self):
  4504. """
  4505. Validate that a custom ChangeList class can be used (#9749)
  4506. """
  4507. # Insert some data
  4508. post_data = {"name": "First Gadget"}
  4509. response = self.client.post(reverse("admin:admin_views_gadget_add"), post_data)
  4510. self.assertEqual(response.status_code, 302) # redirect somewhere
  4511. # Hit the page once to get messages out of the queue message list
  4512. response = self.client.get(reverse("admin:admin_views_gadget_changelist"))
  4513. # Data is still not visible on the page
  4514. response = self.client.get(reverse("admin:admin_views_gadget_changelist"))
  4515. self.assertNotContains(response, "First Gadget")
  4516. @override_settings(ROOT_URLCONF="admin_views.urls")
  4517. class TestInlineNotEditable(TestCase):
  4518. @classmethod
  4519. def setUpTestData(cls):
  4520. cls.superuser = User.objects.create_superuser(
  4521. username="super", password="secret", email="super@example.com"
  4522. )
  4523. def setUp(self):
  4524. self.client.force_login(self.superuser)
  4525. def test_GET_parent_add(self):
  4526. """
  4527. InlineModelAdmin broken?
  4528. """
  4529. response = self.client.get(reverse("admin:admin_views_parent_add"))
  4530. self.assertEqual(response.status_code, 200)
  4531. @override_settings(ROOT_URLCONF="admin_views.urls")
  4532. class AdminCustomQuerysetTest(TestCase):
  4533. @classmethod
  4534. def setUpTestData(cls):
  4535. cls.superuser = User.objects.create_superuser(
  4536. username="super", password="secret", email="super@example.com"
  4537. )
  4538. cls.pks = [EmptyModel.objects.create().id for i in range(3)]
  4539. def setUp(self):
  4540. self.client.force_login(self.superuser)
  4541. self.super_login = {
  4542. REDIRECT_FIELD_NAME: reverse("admin:index"),
  4543. "username": "super",
  4544. "password": "secret",
  4545. }
  4546. def test_changelist_view(self):
  4547. response = self.client.get(reverse("admin:admin_views_emptymodel_changelist"))
  4548. for i in self.pks:
  4549. if i > 1:
  4550. self.assertContains(response, "Primary key = %s" % i)
  4551. else:
  4552. self.assertNotContains(response, "Primary key = %s" % i)
  4553. def test_changelist_view_count_queries(self):
  4554. # create 2 Person objects
  4555. Person.objects.create(name="person1", gender=1)
  4556. Person.objects.create(name="person2", gender=2)
  4557. changelist_url = reverse("admin:admin_views_person_changelist")
  4558. # 5 queries are expected: 1 for the session, 1 for the user,
  4559. # 2 for the counts and 1 for the objects on the page
  4560. with self.assertNumQueries(5):
  4561. resp = self.client.get(changelist_url)
  4562. self.assertEqual(resp.context["selection_note"], "0 of 2 selected")
  4563. self.assertEqual(resp.context["selection_note_all"], "All 2 selected")
  4564. with self.assertNumQueries(5):
  4565. extra = {"q": "not_in_name"}
  4566. resp = self.client.get(changelist_url, extra)
  4567. self.assertEqual(resp.context["selection_note"], "0 of 0 selected")
  4568. self.assertEqual(resp.context["selection_note_all"], "All 0 selected")
  4569. with self.assertNumQueries(5):
  4570. extra = {"q": "person"}
  4571. resp = self.client.get(changelist_url, extra)
  4572. self.assertEqual(resp.context["selection_note"], "0 of 2 selected")
  4573. self.assertEqual(resp.context["selection_note_all"], "All 2 selected")
  4574. with self.assertNumQueries(5):
  4575. extra = {"gender__exact": "1"}
  4576. resp = self.client.get(changelist_url, extra)
  4577. self.assertEqual(resp.context["selection_note"], "0 of 1 selected")
  4578. self.assertEqual(resp.context["selection_note_all"], "1 selected")
  4579. def test_change_view(self):
  4580. for i in self.pks:
  4581. url = reverse("admin:admin_views_emptymodel_change", args=(i,))
  4582. response = self.client.get(url, follow=True)
  4583. if i > 1:
  4584. self.assertEqual(response.status_code, 200)
  4585. else:
  4586. self.assertRedirects(response, reverse("admin:index"))
  4587. self.assertEqual(
  4588. [m.message for m in response.context["messages"]],
  4589. ["empty model with ID “1” doesn’t exist. Perhaps it was deleted?"],
  4590. )
  4591. def test_add_model_modeladmin_defer_qs(self):
  4592. # Test for #14529. defer() is used in ModelAdmin.get_queryset()
  4593. # model has __str__ method
  4594. self.assertEqual(CoverLetter.objects.count(), 0)
  4595. # Emulate model instance creation via the admin
  4596. post_data = {
  4597. "author": "Candidate, Best",
  4598. "_save": "Save",
  4599. }
  4600. response = self.client.post(
  4601. reverse("admin:admin_views_coverletter_add"), post_data, follow=True
  4602. )
  4603. self.assertEqual(response.status_code, 200)
  4604. self.assertEqual(CoverLetter.objects.count(), 1)
  4605. # Message should contain non-ugly model verbose name
  4606. pk = CoverLetter.objects.all()[0].pk
  4607. self.assertContains(
  4608. response,
  4609. '<li class="success">The cover letter “<a href="%s">'
  4610. "Candidate, Best</a>” was added successfully.</li>"
  4611. % reverse("admin:admin_views_coverletter_change", args=(pk,)),
  4612. html=True,
  4613. )
  4614. # model has no __str__ method
  4615. self.assertEqual(ShortMessage.objects.count(), 0)
  4616. # Emulate model instance creation via the admin
  4617. post_data = {
  4618. "content": "What's this SMS thing?",
  4619. "_save": "Save",
  4620. }
  4621. response = self.client.post(
  4622. reverse("admin:admin_views_shortmessage_add"), post_data, follow=True
  4623. )
  4624. self.assertEqual(response.status_code, 200)
  4625. self.assertEqual(ShortMessage.objects.count(), 1)
  4626. # Message should contain non-ugly model verbose name
  4627. sm = ShortMessage.objects.all()[0]
  4628. self.assertContains(
  4629. response,
  4630. '<li class="success">The short message “<a href="%s">'
  4631. "%s</a>” was added successfully.</li>"
  4632. % (reverse("admin:admin_views_shortmessage_change", args=(sm.pk,)), sm),
  4633. html=True,
  4634. )
  4635. def test_add_model_modeladmin_only_qs(self):
  4636. # Test for #14529. only() is used in ModelAdmin.get_queryset()
  4637. # model has __str__ method
  4638. self.assertEqual(Telegram.objects.count(), 0)
  4639. # Emulate model instance creation via the admin
  4640. post_data = {
  4641. "title": "Urgent telegram",
  4642. "_save": "Save",
  4643. }
  4644. response = self.client.post(
  4645. reverse("admin:admin_views_telegram_add"), post_data, follow=True
  4646. )
  4647. self.assertEqual(response.status_code, 200)
  4648. self.assertEqual(Telegram.objects.count(), 1)
  4649. # Message should contain non-ugly model verbose name
  4650. pk = Telegram.objects.all()[0].pk
  4651. self.assertContains(
  4652. response,
  4653. '<li class="success">The telegram “<a href="%s">'
  4654. "Urgent telegram</a>” was added successfully.</li>"
  4655. % reverse("admin:admin_views_telegram_change", args=(pk,)),
  4656. html=True,
  4657. )
  4658. # model has no __str__ method
  4659. self.assertEqual(Paper.objects.count(), 0)
  4660. # Emulate model instance creation via the admin
  4661. post_data = {
  4662. "title": "My Modified Paper Title",
  4663. "_save": "Save",
  4664. }
  4665. response = self.client.post(
  4666. reverse("admin:admin_views_paper_add"), post_data, follow=True
  4667. )
  4668. self.assertEqual(response.status_code, 200)
  4669. self.assertEqual(Paper.objects.count(), 1)
  4670. # Message should contain non-ugly model verbose name
  4671. p = Paper.objects.all()[0]
  4672. self.assertContains(
  4673. response,
  4674. '<li class="success">The paper “<a href="%s">'
  4675. "%s</a>” was added successfully.</li>"
  4676. % (reverse("admin:admin_views_paper_change", args=(p.pk,)), p),
  4677. html=True,
  4678. )
  4679. def test_edit_model_modeladmin_defer_qs(self):
  4680. # Test for #14529. defer() is used in ModelAdmin.get_queryset()
  4681. # model has __str__ method
  4682. cl = CoverLetter.objects.create(author="John Doe")
  4683. self.assertEqual(CoverLetter.objects.count(), 1)
  4684. response = self.client.get(
  4685. reverse("admin:admin_views_coverletter_change", args=(cl.pk,))
  4686. )
  4687. self.assertEqual(response.status_code, 200)
  4688. # Emulate model instance edit via the admin
  4689. post_data = {
  4690. "author": "John Doe II",
  4691. "_save": "Save",
  4692. }
  4693. url = reverse("admin:admin_views_coverletter_change", args=(cl.pk,))
  4694. response = self.client.post(url, post_data, follow=True)
  4695. self.assertEqual(response.status_code, 200)
  4696. self.assertEqual(CoverLetter.objects.count(), 1)
  4697. # Message should contain non-ugly model verbose name. Instance
  4698. # representation is set by model's __str__()
  4699. self.assertContains(
  4700. response,
  4701. '<li class="success">The cover letter “<a href="%s">'
  4702. "John Doe II</a>” was changed successfully.</li>"
  4703. % reverse("admin:admin_views_coverletter_change", args=(cl.pk,)),
  4704. html=True,
  4705. )
  4706. # model has no __str__ method
  4707. sm = ShortMessage.objects.create(content="This is expensive")
  4708. self.assertEqual(ShortMessage.objects.count(), 1)
  4709. response = self.client.get(
  4710. reverse("admin:admin_views_shortmessage_change", args=(sm.pk,))
  4711. )
  4712. self.assertEqual(response.status_code, 200)
  4713. # Emulate model instance edit via the admin
  4714. post_data = {
  4715. "content": "Too expensive",
  4716. "_save": "Save",
  4717. }
  4718. url = reverse("admin:admin_views_shortmessage_change", args=(sm.pk,))
  4719. response = self.client.post(url, post_data, follow=True)
  4720. self.assertEqual(response.status_code, 200)
  4721. self.assertEqual(ShortMessage.objects.count(), 1)
  4722. # Message should contain non-ugly model verbose name. The ugly(!)
  4723. # instance representation is set by __str__().
  4724. self.assertContains(
  4725. response,
  4726. '<li class="success">The short message “<a href="%s">'
  4727. "%s</a>” was changed successfully.</li>"
  4728. % (reverse("admin:admin_views_shortmessage_change", args=(sm.pk,)), sm),
  4729. html=True,
  4730. )
  4731. def test_edit_model_modeladmin_only_qs(self):
  4732. # Test for #14529. only() is used in ModelAdmin.get_queryset()
  4733. # model has __str__ method
  4734. t = Telegram.objects.create(title="First Telegram")
  4735. self.assertEqual(Telegram.objects.count(), 1)
  4736. response = self.client.get(
  4737. reverse("admin:admin_views_telegram_change", args=(t.pk,))
  4738. )
  4739. self.assertEqual(response.status_code, 200)
  4740. # Emulate model instance edit via the admin
  4741. post_data = {
  4742. "title": "Telegram without typo",
  4743. "_save": "Save",
  4744. }
  4745. response = self.client.post(
  4746. reverse("admin:admin_views_telegram_change", args=(t.pk,)),
  4747. post_data,
  4748. follow=True,
  4749. )
  4750. self.assertEqual(response.status_code, 200)
  4751. self.assertEqual(Telegram.objects.count(), 1)
  4752. # Message should contain non-ugly model verbose name. The instance
  4753. # representation is set by model's __str__()
  4754. self.assertContains(
  4755. response,
  4756. '<li class="success">The telegram “<a href="%s">'
  4757. "Telegram without typo</a>” was changed successfully.</li>"
  4758. % reverse("admin:admin_views_telegram_change", args=(t.pk,)),
  4759. html=True,
  4760. )
  4761. # model has no __str__ method
  4762. p = Paper.objects.create(title="My Paper Title")
  4763. self.assertEqual(Paper.objects.count(), 1)
  4764. response = self.client.get(
  4765. reverse("admin:admin_views_paper_change", args=(p.pk,))
  4766. )
  4767. self.assertEqual(response.status_code, 200)
  4768. # Emulate model instance edit via the admin
  4769. post_data = {
  4770. "title": "My Modified Paper Title",
  4771. "_save": "Save",
  4772. }
  4773. response = self.client.post(
  4774. reverse("admin:admin_views_paper_change", args=(p.pk,)),
  4775. post_data,
  4776. follow=True,
  4777. )
  4778. self.assertEqual(response.status_code, 200)
  4779. self.assertEqual(Paper.objects.count(), 1)
  4780. # Message should contain non-ugly model verbose name. The ugly(!)
  4781. # instance representation is set by __str__().
  4782. self.assertContains(
  4783. response,
  4784. '<li class="success">The paper “<a href="%s">'
  4785. "%s</a>” was changed successfully.</li>"
  4786. % (reverse("admin:admin_views_paper_change", args=(p.pk,)), p),
  4787. html=True,
  4788. )
  4789. def test_history_view_custom_qs(self):
  4790. """
  4791. Custom querysets are considered for the admin history view.
  4792. """
  4793. self.client.post(reverse("admin:login"), self.super_login)
  4794. FilteredManager.objects.create(pk=1)
  4795. FilteredManager.objects.create(pk=2)
  4796. response = self.client.get(
  4797. reverse("admin:admin_views_filteredmanager_changelist")
  4798. )
  4799. self.assertContains(response, "PK=1")
  4800. self.assertContains(response, "PK=2")
  4801. self.assertEqual(
  4802. self.client.get(
  4803. reverse("admin:admin_views_filteredmanager_history", args=(1,))
  4804. ).status_code,
  4805. 200,
  4806. )
  4807. self.assertEqual(
  4808. self.client.get(
  4809. reverse("admin:admin_views_filteredmanager_history", args=(2,))
  4810. ).status_code,
  4811. 200,
  4812. )
  4813. @override_settings(ROOT_URLCONF="admin_views.urls")
  4814. class AdminInlineFileUploadTest(TestCase):
  4815. @classmethod
  4816. def setUpTestData(cls):
  4817. cls.superuser = User.objects.create_superuser(
  4818. username="super", password="secret", email="super@example.com"
  4819. )
  4820. file1 = tempfile.NamedTemporaryFile(suffix=".file1")
  4821. file1.write(b"a" * (2**21))
  4822. filename = file1.name
  4823. file1.close()
  4824. cls.gallery = Gallery.objects.create(name="Test Gallery")
  4825. cls.picture = Picture.objects.create(
  4826. name="Test Picture",
  4827. image=filename,
  4828. gallery=cls.gallery,
  4829. )
  4830. def setUp(self):
  4831. self.client.force_login(self.superuser)
  4832. def test_form_has_multipart_enctype(self):
  4833. response = self.client.get(
  4834. reverse("admin:admin_views_gallery_change", args=(self.gallery.id,))
  4835. )
  4836. self.assertIs(response.context["has_file_field"], True)
  4837. self.assertContains(response, MULTIPART_ENCTYPE)
  4838. def test_inline_file_upload_edit_validation_error_post(self):
  4839. """
  4840. Inline file uploads correctly display prior data (#10002).
  4841. """
  4842. post_data = {
  4843. "name": "Test Gallery",
  4844. "pictures-TOTAL_FORMS": "2",
  4845. "pictures-INITIAL_FORMS": "1",
  4846. "pictures-MAX_NUM_FORMS": "0",
  4847. "pictures-0-id": str(self.picture.id),
  4848. "pictures-0-gallery": str(self.gallery.id),
  4849. "pictures-0-name": "Test Picture",
  4850. "pictures-0-image": "",
  4851. "pictures-1-id": "",
  4852. "pictures-1-gallery": str(self.gallery.id),
  4853. "pictures-1-name": "Test Picture 2",
  4854. "pictures-1-image": "",
  4855. }
  4856. response = self.client.post(
  4857. reverse("admin:admin_views_gallery_change", args=(self.gallery.id,)),
  4858. post_data,
  4859. )
  4860. self.assertContains(response, b"Currently")
  4861. @override_settings(ROOT_URLCONF="admin_views.urls")
  4862. class AdminInlineTests(TestCase):
  4863. @classmethod
  4864. def setUpTestData(cls):
  4865. cls.superuser = User.objects.create_superuser(
  4866. username="super", password="secret", email="super@example.com"
  4867. )
  4868. cls.collector = Collector.objects.create(pk=1, name="John Fowles")
  4869. def setUp(self):
  4870. self.post_data = {
  4871. "name": "Test Name",
  4872. "widget_set-TOTAL_FORMS": "3",
  4873. "widget_set-INITIAL_FORMS": "0",
  4874. "widget_set-MAX_NUM_FORMS": "0",
  4875. "widget_set-0-id": "",
  4876. "widget_set-0-owner": "1",
  4877. "widget_set-0-name": "",
  4878. "widget_set-1-id": "",
  4879. "widget_set-1-owner": "1",
  4880. "widget_set-1-name": "",
  4881. "widget_set-2-id": "",
  4882. "widget_set-2-owner": "1",
  4883. "widget_set-2-name": "",
  4884. "doohickey_set-TOTAL_FORMS": "3",
  4885. "doohickey_set-INITIAL_FORMS": "0",
  4886. "doohickey_set-MAX_NUM_FORMS": "0",
  4887. "doohickey_set-0-owner": "1",
  4888. "doohickey_set-0-code": "",
  4889. "doohickey_set-0-name": "",
  4890. "doohickey_set-1-owner": "1",
  4891. "doohickey_set-1-code": "",
  4892. "doohickey_set-1-name": "",
  4893. "doohickey_set-2-owner": "1",
  4894. "doohickey_set-2-code": "",
  4895. "doohickey_set-2-name": "",
  4896. "grommet_set-TOTAL_FORMS": "3",
  4897. "grommet_set-INITIAL_FORMS": "0",
  4898. "grommet_set-MAX_NUM_FORMS": "0",
  4899. "grommet_set-0-code": "",
  4900. "grommet_set-0-owner": "1",
  4901. "grommet_set-0-name": "",
  4902. "grommet_set-1-code": "",
  4903. "grommet_set-1-owner": "1",
  4904. "grommet_set-1-name": "",
  4905. "grommet_set-2-code": "",
  4906. "grommet_set-2-owner": "1",
  4907. "grommet_set-2-name": "",
  4908. "whatsit_set-TOTAL_FORMS": "3",
  4909. "whatsit_set-INITIAL_FORMS": "0",
  4910. "whatsit_set-MAX_NUM_FORMS": "0",
  4911. "whatsit_set-0-owner": "1",
  4912. "whatsit_set-0-index": "",
  4913. "whatsit_set-0-name": "",
  4914. "whatsit_set-1-owner": "1",
  4915. "whatsit_set-1-index": "",
  4916. "whatsit_set-1-name": "",
  4917. "whatsit_set-2-owner": "1",
  4918. "whatsit_set-2-index": "",
  4919. "whatsit_set-2-name": "",
  4920. "fancydoodad_set-TOTAL_FORMS": "3",
  4921. "fancydoodad_set-INITIAL_FORMS": "0",
  4922. "fancydoodad_set-MAX_NUM_FORMS": "0",
  4923. "fancydoodad_set-0-doodad_ptr": "",
  4924. "fancydoodad_set-0-owner": "1",
  4925. "fancydoodad_set-0-name": "",
  4926. "fancydoodad_set-0-expensive": "on",
  4927. "fancydoodad_set-1-doodad_ptr": "",
  4928. "fancydoodad_set-1-owner": "1",
  4929. "fancydoodad_set-1-name": "",
  4930. "fancydoodad_set-1-expensive": "on",
  4931. "fancydoodad_set-2-doodad_ptr": "",
  4932. "fancydoodad_set-2-owner": "1",
  4933. "fancydoodad_set-2-name": "",
  4934. "fancydoodad_set-2-expensive": "on",
  4935. "category_set-TOTAL_FORMS": "3",
  4936. "category_set-INITIAL_FORMS": "0",
  4937. "category_set-MAX_NUM_FORMS": "0",
  4938. "category_set-0-order": "",
  4939. "category_set-0-id": "",
  4940. "category_set-0-collector": "1",
  4941. "category_set-1-order": "",
  4942. "category_set-1-id": "",
  4943. "category_set-1-collector": "1",
  4944. "category_set-2-order": "",
  4945. "category_set-2-id": "",
  4946. "category_set-2-collector": "1",
  4947. }
  4948. self.client.force_login(self.superuser)
  4949. def test_simple_inline(self):
  4950. "A simple model can be saved as inlines"
  4951. # First add a new inline
  4952. self.post_data["widget_set-0-name"] = "Widget 1"
  4953. collector_url = reverse(
  4954. "admin:admin_views_collector_change", args=(self.collector.pk,)
  4955. )
  4956. response = self.client.post(collector_url, self.post_data)
  4957. self.assertEqual(response.status_code, 302)
  4958. self.assertEqual(Widget.objects.count(), 1)
  4959. self.assertEqual(Widget.objects.all()[0].name, "Widget 1")
  4960. widget_id = Widget.objects.all()[0].id
  4961. # The PK link exists on the rendered form
  4962. response = self.client.get(collector_url)
  4963. self.assertContains(response, 'name="widget_set-0-id"')
  4964. # No file or image fields, no enctype on the forms
  4965. self.assertIs(response.context["has_file_field"], False)
  4966. self.assertNotContains(response, MULTIPART_ENCTYPE)
  4967. # Now resave that inline
  4968. self.post_data["widget_set-INITIAL_FORMS"] = "1"
  4969. self.post_data["widget_set-0-id"] = str(widget_id)
  4970. self.post_data["widget_set-0-name"] = "Widget 1"
  4971. response = self.client.post(collector_url, self.post_data)
  4972. self.assertEqual(response.status_code, 302)
  4973. self.assertEqual(Widget.objects.count(), 1)
  4974. self.assertEqual(Widget.objects.all()[0].name, "Widget 1")
  4975. # Now modify that inline
  4976. self.post_data["widget_set-INITIAL_FORMS"] = "1"
  4977. self.post_data["widget_set-0-id"] = str(widget_id)
  4978. self.post_data["widget_set-0-name"] = "Widget 1 Updated"
  4979. response = self.client.post(collector_url, self.post_data)
  4980. self.assertEqual(response.status_code, 302)
  4981. self.assertEqual(Widget.objects.count(), 1)
  4982. self.assertEqual(Widget.objects.all()[0].name, "Widget 1 Updated")
  4983. def test_explicit_autofield_inline(self):
  4984. """
  4985. A model with an explicit autofield primary key can be saved as inlines.
  4986. """
  4987. # First add a new inline
  4988. self.post_data["grommet_set-0-name"] = "Grommet 1"
  4989. collector_url = reverse(
  4990. "admin:admin_views_collector_change", args=(self.collector.pk,)
  4991. )
  4992. response = self.client.post(collector_url, self.post_data)
  4993. self.assertEqual(response.status_code, 302)
  4994. self.assertEqual(Grommet.objects.count(), 1)
  4995. self.assertEqual(Grommet.objects.all()[0].name, "Grommet 1")
  4996. # The PK link exists on the rendered form
  4997. response = self.client.get(collector_url)
  4998. self.assertContains(response, 'name="grommet_set-0-code"')
  4999. # Now resave that inline
  5000. self.post_data["grommet_set-INITIAL_FORMS"] = "1"
  5001. self.post_data["grommet_set-0-code"] = str(Grommet.objects.all()[0].code)
  5002. self.post_data["grommet_set-0-name"] = "Grommet 1"
  5003. response = self.client.post(collector_url, self.post_data)
  5004. self.assertEqual(response.status_code, 302)
  5005. self.assertEqual(Grommet.objects.count(), 1)
  5006. self.assertEqual(Grommet.objects.all()[0].name, "Grommet 1")
  5007. # Now modify that inline
  5008. self.post_data["grommet_set-INITIAL_FORMS"] = "1"
  5009. self.post_data["grommet_set-0-code"] = str(Grommet.objects.all()[0].code)
  5010. self.post_data["grommet_set-0-name"] = "Grommet 1 Updated"
  5011. response = self.client.post(collector_url, self.post_data)
  5012. self.assertEqual(response.status_code, 302)
  5013. self.assertEqual(Grommet.objects.count(), 1)
  5014. self.assertEqual(Grommet.objects.all()[0].name, "Grommet 1 Updated")
  5015. def test_char_pk_inline(self):
  5016. "A model with a character PK can be saved as inlines. Regression for #10992"
  5017. # First add a new inline
  5018. self.post_data["doohickey_set-0-code"] = "DH1"
  5019. self.post_data["doohickey_set-0-name"] = "Doohickey 1"
  5020. collector_url = reverse(
  5021. "admin:admin_views_collector_change", args=(self.collector.pk,)
  5022. )
  5023. response = self.client.post(collector_url, self.post_data)
  5024. self.assertEqual(response.status_code, 302)
  5025. self.assertEqual(DooHickey.objects.count(), 1)
  5026. self.assertEqual(DooHickey.objects.all()[0].name, "Doohickey 1")
  5027. # The PK link exists on the rendered form
  5028. response = self.client.get(collector_url)
  5029. self.assertContains(response, 'name="doohickey_set-0-code"')
  5030. # Now resave that inline
  5031. self.post_data["doohickey_set-INITIAL_FORMS"] = "1"
  5032. self.post_data["doohickey_set-0-code"] = "DH1"
  5033. self.post_data["doohickey_set-0-name"] = "Doohickey 1"
  5034. response = self.client.post(collector_url, self.post_data)
  5035. self.assertEqual(response.status_code, 302)
  5036. self.assertEqual(DooHickey.objects.count(), 1)
  5037. self.assertEqual(DooHickey.objects.all()[0].name, "Doohickey 1")
  5038. # Now modify that inline
  5039. self.post_data["doohickey_set-INITIAL_FORMS"] = "1"
  5040. self.post_data["doohickey_set-0-code"] = "DH1"
  5041. self.post_data["doohickey_set-0-name"] = "Doohickey 1 Updated"
  5042. response = self.client.post(collector_url, self.post_data)
  5043. self.assertEqual(response.status_code, 302)
  5044. self.assertEqual(DooHickey.objects.count(), 1)
  5045. self.assertEqual(DooHickey.objects.all()[0].name, "Doohickey 1 Updated")
  5046. def test_integer_pk_inline(self):
  5047. "A model with an integer PK can be saved as inlines. Regression for #10992"
  5048. # First add a new inline
  5049. self.post_data["whatsit_set-0-index"] = "42"
  5050. self.post_data["whatsit_set-0-name"] = "Whatsit 1"
  5051. collector_url = reverse(
  5052. "admin:admin_views_collector_change", args=(self.collector.pk,)
  5053. )
  5054. response = self.client.post(collector_url, self.post_data)
  5055. self.assertEqual(response.status_code, 302)
  5056. self.assertEqual(Whatsit.objects.count(), 1)
  5057. self.assertEqual(Whatsit.objects.all()[0].name, "Whatsit 1")
  5058. # The PK link exists on the rendered form
  5059. response = self.client.get(collector_url)
  5060. self.assertContains(response, 'name="whatsit_set-0-index"')
  5061. # Now resave that inline
  5062. self.post_data["whatsit_set-INITIAL_FORMS"] = "1"
  5063. self.post_data["whatsit_set-0-index"] = "42"
  5064. self.post_data["whatsit_set-0-name"] = "Whatsit 1"
  5065. response = self.client.post(collector_url, self.post_data)
  5066. self.assertEqual(response.status_code, 302)
  5067. self.assertEqual(Whatsit.objects.count(), 1)
  5068. self.assertEqual(Whatsit.objects.all()[0].name, "Whatsit 1")
  5069. # Now modify that inline
  5070. self.post_data["whatsit_set-INITIAL_FORMS"] = "1"
  5071. self.post_data["whatsit_set-0-index"] = "42"
  5072. self.post_data["whatsit_set-0-name"] = "Whatsit 1 Updated"
  5073. response = self.client.post(collector_url, self.post_data)
  5074. self.assertEqual(response.status_code, 302)
  5075. self.assertEqual(Whatsit.objects.count(), 1)
  5076. self.assertEqual(Whatsit.objects.all()[0].name, "Whatsit 1 Updated")
  5077. def test_inherited_inline(self):
  5078. "An inherited model can be saved as inlines. Regression for #11042"
  5079. # First add a new inline
  5080. self.post_data["fancydoodad_set-0-name"] = "Fancy Doodad 1"
  5081. collector_url = reverse(
  5082. "admin:admin_views_collector_change", args=(self.collector.pk,)
  5083. )
  5084. response = self.client.post(collector_url, self.post_data)
  5085. self.assertEqual(response.status_code, 302)
  5086. self.assertEqual(FancyDoodad.objects.count(), 1)
  5087. self.assertEqual(FancyDoodad.objects.all()[0].name, "Fancy Doodad 1")
  5088. doodad_pk = FancyDoodad.objects.all()[0].pk
  5089. # The PK link exists on the rendered form
  5090. response = self.client.get(collector_url)
  5091. self.assertContains(response, 'name="fancydoodad_set-0-doodad_ptr"')
  5092. # Now resave that inline
  5093. self.post_data["fancydoodad_set-INITIAL_FORMS"] = "1"
  5094. self.post_data["fancydoodad_set-0-doodad_ptr"] = str(doodad_pk)
  5095. self.post_data["fancydoodad_set-0-name"] = "Fancy Doodad 1"
  5096. response = self.client.post(collector_url, self.post_data)
  5097. self.assertEqual(response.status_code, 302)
  5098. self.assertEqual(FancyDoodad.objects.count(), 1)
  5099. self.assertEqual(FancyDoodad.objects.all()[0].name, "Fancy Doodad 1")
  5100. # Now modify that inline
  5101. self.post_data["fancydoodad_set-INITIAL_FORMS"] = "1"
  5102. self.post_data["fancydoodad_set-0-doodad_ptr"] = str(doodad_pk)
  5103. self.post_data["fancydoodad_set-0-name"] = "Fancy Doodad 1 Updated"
  5104. response = self.client.post(collector_url, self.post_data)
  5105. self.assertEqual(response.status_code, 302)
  5106. self.assertEqual(FancyDoodad.objects.count(), 1)
  5107. self.assertEqual(FancyDoodad.objects.all()[0].name, "Fancy Doodad 1 Updated")
  5108. def test_ordered_inline(self):
  5109. """
  5110. An inline with an editable ordering fields is updated correctly.
  5111. """
  5112. # Create some objects with an initial ordering
  5113. Category.objects.create(id=1, order=1, collector=self.collector)
  5114. Category.objects.create(id=2, order=2, collector=self.collector)
  5115. Category.objects.create(id=3, order=0, collector=self.collector)
  5116. Category.objects.create(id=4, order=0, collector=self.collector)
  5117. # NB: The order values must be changed so that the items are reordered.
  5118. self.post_data.update(
  5119. {
  5120. "name": "Frederick Clegg",
  5121. "category_set-TOTAL_FORMS": "7",
  5122. "category_set-INITIAL_FORMS": "4",
  5123. "category_set-MAX_NUM_FORMS": "0",
  5124. "category_set-0-order": "14",
  5125. "category_set-0-id": "1",
  5126. "category_set-0-collector": "1",
  5127. "category_set-1-order": "13",
  5128. "category_set-1-id": "2",
  5129. "category_set-1-collector": "1",
  5130. "category_set-2-order": "1",
  5131. "category_set-2-id": "3",
  5132. "category_set-2-collector": "1",
  5133. "category_set-3-order": "0",
  5134. "category_set-3-id": "4",
  5135. "category_set-3-collector": "1",
  5136. "category_set-4-order": "",
  5137. "category_set-4-id": "",
  5138. "category_set-4-collector": "1",
  5139. "category_set-5-order": "",
  5140. "category_set-5-id": "",
  5141. "category_set-5-collector": "1",
  5142. "category_set-6-order": "",
  5143. "category_set-6-id": "",
  5144. "category_set-6-collector": "1",
  5145. }
  5146. )
  5147. collector_url = reverse(
  5148. "admin:admin_views_collector_change", args=(self.collector.pk,)
  5149. )
  5150. response = self.client.post(collector_url, self.post_data)
  5151. # Successful post will redirect
  5152. self.assertEqual(response.status_code, 302)
  5153. # The order values have been applied to the right objects
  5154. self.assertEqual(self.collector.category_set.count(), 4)
  5155. self.assertEqual(Category.objects.get(id=1).order, 14)
  5156. self.assertEqual(Category.objects.get(id=2).order, 13)
  5157. self.assertEqual(Category.objects.get(id=3).order, 1)
  5158. self.assertEqual(Category.objects.get(id=4).order, 0)
  5159. @override_settings(ROOT_URLCONF="admin_views.urls")
  5160. class NeverCacheTests(TestCase):
  5161. @classmethod
  5162. def setUpTestData(cls):
  5163. cls.superuser = User.objects.create_superuser(
  5164. username="super", password="secret", email="super@example.com"
  5165. )
  5166. cls.s1 = Section.objects.create(name="Test section")
  5167. def setUp(self):
  5168. self.client.force_login(self.superuser)
  5169. def test_admin_index(self):
  5170. "Check the never-cache status of the main index"
  5171. response = self.client.get(reverse("admin:index"))
  5172. self.assertEqual(get_max_age(response), 0)
  5173. def test_app_index(self):
  5174. "Check the never-cache status of an application index"
  5175. response = self.client.get(reverse("admin:app_list", args=("admin_views",)))
  5176. self.assertEqual(get_max_age(response), 0)
  5177. def test_model_index(self):
  5178. "Check the never-cache status of a model index"
  5179. response = self.client.get(reverse("admin:admin_views_fabric_changelist"))
  5180. self.assertEqual(get_max_age(response), 0)
  5181. def test_model_add(self):
  5182. "Check the never-cache status of a model add page"
  5183. response = self.client.get(reverse("admin:admin_views_fabric_add"))
  5184. self.assertEqual(get_max_age(response), 0)
  5185. def test_model_view(self):
  5186. "Check the never-cache status of a model edit page"
  5187. response = self.client.get(
  5188. reverse("admin:admin_views_section_change", args=(self.s1.pk,))
  5189. )
  5190. self.assertEqual(get_max_age(response), 0)
  5191. def test_model_history(self):
  5192. "Check the never-cache status of a model history page"
  5193. response = self.client.get(
  5194. reverse("admin:admin_views_section_history", args=(self.s1.pk,))
  5195. )
  5196. self.assertEqual(get_max_age(response), 0)
  5197. def test_model_delete(self):
  5198. "Check the never-cache status of a model delete page"
  5199. response = self.client.get(
  5200. reverse("admin:admin_views_section_delete", args=(self.s1.pk,))
  5201. )
  5202. self.assertEqual(get_max_age(response), 0)
  5203. def test_login(self):
  5204. "Check the never-cache status of login views"
  5205. self.client.logout()
  5206. response = self.client.get(reverse("admin:index"))
  5207. self.assertEqual(get_max_age(response), 0)
  5208. def test_logout(self):
  5209. "Check the never-cache status of logout view"
  5210. response = self.client.post(reverse("admin:logout"))
  5211. self.assertEqual(get_max_age(response), 0)
  5212. def test_password_change(self):
  5213. "Check the never-cache status of the password change view"
  5214. self.client.logout()
  5215. response = self.client.get(reverse("admin:password_change"))
  5216. self.assertIsNone(get_max_age(response))
  5217. def test_password_change_done(self):
  5218. "Check the never-cache status of the password change done view"
  5219. response = self.client.get(reverse("admin:password_change_done"))
  5220. self.assertIsNone(get_max_age(response))
  5221. def test_JS_i18n(self):
  5222. "Check the never-cache status of the JavaScript i18n view"
  5223. response = self.client.get(reverse("admin:jsi18n"))
  5224. self.assertIsNone(get_max_age(response))
  5225. @override_settings(ROOT_URLCONF="admin_views.urls")
  5226. class PrePopulatedTest(TestCase):
  5227. @classmethod
  5228. def setUpTestData(cls):
  5229. cls.superuser = User.objects.create_superuser(
  5230. username="super", password="secret", email="super@example.com"
  5231. )
  5232. cls.p1 = PrePopulatedPost.objects.create(
  5233. title="A Long Title", published=True, slug="a-long-title"
  5234. )
  5235. def setUp(self):
  5236. self.client.force_login(self.superuser)
  5237. def test_prepopulated_on(self):
  5238. response = self.client.get(reverse("admin:admin_views_prepopulatedpost_add"))
  5239. self.assertContains(response, "&quot;id&quot;: &quot;#id_slug&quot;")
  5240. self.assertContains(
  5241. response, "&quot;dependency_ids&quot;: [&quot;#id_title&quot;]"
  5242. )
  5243. self.assertContains(
  5244. response,
  5245. "&quot;id&quot;: &quot;#id_prepopulatedsubpost_set-0-subslug&quot;",
  5246. )
  5247. def test_prepopulated_off(self):
  5248. response = self.client.get(
  5249. reverse("admin:admin_views_prepopulatedpost_change", args=(self.p1.pk,))
  5250. )
  5251. self.assertContains(response, "A Long Title")
  5252. self.assertNotContains(response, "&quot;id&quot;: &quot;#id_slug&quot;")
  5253. self.assertNotContains(
  5254. response, "&quot;dependency_ids&quot;: [&quot;#id_title&quot;]"
  5255. )
  5256. self.assertNotContains(
  5257. response,
  5258. "&quot;id&quot;: &quot;#id_prepopulatedsubpost_set-0-subslug&quot;",
  5259. )
  5260. @override_settings(USE_THOUSAND_SEPARATOR=True)
  5261. def test_prepopulated_maxlength_localized(self):
  5262. """
  5263. Regression test for #15938: if USE_THOUSAND_SEPARATOR is set, make sure
  5264. that maxLength (in the JavaScript) is rendered without separators.
  5265. """
  5266. response = self.client.get(
  5267. reverse("admin:admin_views_prepopulatedpostlargeslug_add")
  5268. )
  5269. self.assertContains(response, "&quot;maxLength&quot;: 1000") # instead of 1,000
  5270. def test_view_only_add_form(self):
  5271. """
  5272. PrePopulatedPostReadOnlyAdmin.prepopulated_fields includes 'slug'
  5273. which is present in the add view, even if the
  5274. ModelAdmin.has_change_permission() returns False.
  5275. """
  5276. response = self.client.get(reverse("admin7:admin_views_prepopulatedpost_add"))
  5277. self.assertContains(response, "data-prepopulated-fields=")
  5278. self.assertContains(response, "&quot;id&quot;: &quot;#id_slug&quot;")
  5279. def test_view_only_change_form(self):
  5280. """
  5281. PrePopulatedPostReadOnlyAdmin.prepopulated_fields includes 'slug'. That
  5282. doesn't break a view-only change view.
  5283. """
  5284. response = self.client.get(
  5285. reverse("admin7:admin_views_prepopulatedpost_change", args=(self.p1.pk,))
  5286. )
  5287. self.assertContains(response, 'data-prepopulated-fields="[]"')
  5288. self.assertContains(response, '<div class="readonly">%s</div>' % self.p1.slug)
  5289. def _clean_sidebar_state(driver):
  5290. driver.execute_script("localStorage.removeItem('django.admin.navSidebarIsOpen')")
  5291. @override_settings(ROOT_URLCONF="admin_views.urls")
  5292. class SeleniumTests(AdminSeleniumTestCase):
  5293. available_apps = ["admin_views"] + AdminSeleniumTestCase.available_apps
  5294. def setUp(self):
  5295. self.superuser = User.objects.create_superuser(
  5296. username="super", password="secret", email="super@example.com"
  5297. )
  5298. self.p1 = PrePopulatedPost.objects.create(
  5299. title="A Long Title", published=True, slug="a-long-title"
  5300. )
  5301. @screenshot_cases(["desktop_size", "mobile_size", "rtl", "dark", "high_contrast"])
  5302. def test_login_button_centered(self):
  5303. from selenium.webdriver.common.by import By
  5304. self.selenium.get(self.live_server_url + reverse("admin:login"))
  5305. button = self.selenium.find_element(By.CSS_SELECTOR, ".submit-row input")
  5306. offset_left = button.get_property("offsetLeft")
  5307. offset_right = button.get_property("offsetParent").get_property(
  5308. "offsetWidth"
  5309. ) - (offset_left + button.get_property("offsetWidth"))
  5310. # Use assertAlmostEqual to avoid pixel rounding errors.
  5311. self.assertAlmostEqual(offset_left, offset_right, delta=3)
  5312. self.take_screenshot("login")
  5313. def test_prepopulated_fields(self):
  5314. """
  5315. The JavaScript-automated prepopulated fields work with the main form
  5316. and with stacked and tabular inlines.
  5317. Refs #13068, #9264, #9983, #9784.
  5318. """
  5319. from selenium.webdriver import ActionChains
  5320. from selenium.webdriver.common.by import By
  5321. self.admin_login(
  5322. username="super", password="secret", login_url=reverse("admin:index")
  5323. )
  5324. self.selenium.get(
  5325. self.live_server_url + reverse("admin:admin_views_mainprepopulated_add")
  5326. )
  5327. self.wait_for(".select2")
  5328. # Main form ----------------------------------------------------------
  5329. self.selenium.find_element(By.ID, "id_pubdate").send_keys("2012-02-18")
  5330. status = self.selenium.find_element(By.ID, "id_status")
  5331. ActionChains(self.selenium).move_to_element(status).click(status).perform()
  5332. self.select_option("#id_status", "option two")
  5333. self.selenium.find_element(By.ID, "id_name").send_keys(
  5334. " the mAin nÀMë and it's awεšomeıııİ"
  5335. )
  5336. slug1 = self.selenium.find_element(By.ID, "id_slug1").get_attribute("value")
  5337. slug2 = self.selenium.find_element(By.ID, "id_slug2").get_attribute("value")
  5338. slug3 = self.selenium.find_element(By.ID, "id_slug3").get_attribute("value")
  5339. self.assertEqual(slug1, "the-main-name-and-its-awesomeiiii-2012-02-18")
  5340. self.assertEqual(slug2, "option-two-the-main-name-and-its-awesomeiiii")
  5341. self.assertEqual(
  5342. slug3, "the-main-n\xe0m\xeb-and-its-aw\u03b5\u0161ome\u0131\u0131\u0131i"
  5343. )
  5344. # Stacked inlines with fieldsets -------------------------------------
  5345. # Initial inline
  5346. self.selenium.find_element(
  5347. By.ID, "id_relatedprepopulated_set-0-pubdate"
  5348. ).send_keys("2011-12-17")
  5349. status = self.selenium.find_element(
  5350. By.ID, "id_relatedprepopulated_set-0-status"
  5351. )
  5352. ActionChains(self.selenium).move_to_element(status).click(status).perform()
  5353. self.select_option("#id_relatedprepopulated_set-0-status", "option one")
  5354. self.selenium.find_element(
  5355. By.ID, "id_relatedprepopulated_set-0-name"
  5356. ).send_keys(" here is a sŤāÇkeð inline ! ")
  5357. slug1 = self.selenium.find_element(
  5358. By.ID, "id_relatedprepopulated_set-0-slug1"
  5359. ).get_attribute("value")
  5360. slug2 = self.selenium.find_element(
  5361. By.ID, "id_relatedprepopulated_set-0-slug2"
  5362. ).get_attribute("value")
  5363. self.assertEqual(slug1, "here-is-a-stacked-inline-2011-12-17")
  5364. self.assertEqual(slug2, "option-one-here-is-a-stacked-inline")
  5365. initial_select2_inputs = self.selenium.find_elements(
  5366. By.CLASS_NAME, "select2-selection"
  5367. )
  5368. # Inline formsets have empty/invisible forms.
  5369. # Only the 4 visible select2 inputs are initialized.
  5370. num_initial_select2_inputs = len(initial_select2_inputs)
  5371. self.assertEqual(num_initial_select2_inputs, 4)
  5372. # Add an inline
  5373. self.selenium.find_elements(By.LINK_TEXT, "Add another Related prepopulated")[
  5374. 0
  5375. ].click()
  5376. self.assertEqual(
  5377. len(self.selenium.find_elements(By.CLASS_NAME, "select2-selection")),
  5378. num_initial_select2_inputs + 2,
  5379. )
  5380. self.selenium.find_element(
  5381. By.ID, "id_relatedprepopulated_set-1-pubdate"
  5382. ).send_keys("1999-01-25")
  5383. status = self.selenium.find_element(
  5384. By.ID, "id_relatedprepopulated_set-1-status"
  5385. )
  5386. ActionChains(self.selenium).move_to_element(status).click(status).perform()
  5387. self.select_option("#id_relatedprepopulated_set-1-status", "option two")
  5388. self.selenium.find_element(
  5389. By.ID, "id_relatedprepopulated_set-1-name"
  5390. ).send_keys(
  5391. " now you haVe anöther sŤāÇkeð inline with a very ... "
  5392. "loooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooog "
  5393. "text... "
  5394. )
  5395. slug1 = self.selenium.find_element(
  5396. By.ID, "id_relatedprepopulated_set-1-slug1"
  5397. ).get_attribute("value")
  5398. slug2 = self.selenium.find_element(
  5399. By.ID, "id_relatedprepopulated_set-1-slug2"
  5400. ).get_attribute("value")
  5401. # 50 characters maximum for slug1 field
  5402. self.assertEqual(slug1, "now-you-have-another-stacked-inline-with-a-very-lo")
  5403. # 60 characters maximum for slug2 field
  5404. self.assertEqual(
  5405. slug2, "option-two-now-you-have-another-stacked-inline-with-a-very-l"
  5406. )
  5407. # Tabular inlines ----------------------------------------------------
  5408. # Initial inline
  5409. status = self.selenium.find_element(
  5410. By.ID, "id_relatedprepopulated_set-2-0-status"
  5411. )
  5412. ActionChains(self.selenium).move_to_element(status).click(status).perform()
  5413. self.selenium.find_element(
  5414. By.ID, "id_relatedprepopulated_set-2-0-pubdate"
  5415. ).send_keys("1234-12-07")
  5416. self.select_option("#id_relatedprepopulated_set-2-0-status", "option two")
  5417. self.selenium.find_element(
  5418. By.ID, "id_relatedprepopulated_set-2-0-name"
  5419. ).send_keys("And now, with a tÃbűlaŘ inline !!!")
  5420. slug1 = self.selenium.find_element(
  5421. By.ID, "id_relatedprepopulated_set-2-0-slug1"
  5422. ).get_attribute("value")
  5423. slug2 = self.selenium.find_element(
  5424. By.ID, "id_relatedprepopulated_set-2-0-slug2"
  5425. ).get_attribute("value")
  5426. self.assertEqual(slug1, "and-now-with-a-tabular-inline-1234-12-07")
  5427. self.assertEqual(slug2, "option-two-and-now-with-a-tabular-inline")
  5428. # Add an inline
  5429. # Button may be outside the browser frame.
  5430. element = self.selenium.find_elements(
  5431. By.LINK_TEXT, "Add another Related prepopulated"
  5432. )[1]
  5433. self.selenium.execute_script("window.scrollTo(0, %s);" % element.location["y"])
  5434. element.click()
  5435. self.assertEqual(
  5436. len(self.selenium.find_elements(By.CLASS_NAME, "select2-selection")),
  5437. num_initial_select2_inputs + 4,
  5438. )
  5439. self.selenium.find_element(
  5440. By.ID, "id_relatedprepopulated_set-2-1-pubdate"
  5441. ).send_keys("1981-08-22")
  5442. status = self.selenium.find_element(
  5443. By.ID, "id_relatedprepopulated_set-2-1-status"
  5444. )
  5445. ActionChains(self.selenium).move_to_element(status).click(status).perform()
  5446. self.select_option("#id_relatedprepopulated_set-2-1-status", "option one")
  5447. self.selenium.find_element(
  5448. By.ID, "id_relatedprepopulated_set-2-1-name"
  5449. ).send_keys(r'tÃbűlaŘ inline with ignored ;"&*^\%$#@-/`~ characters')
  5450. slug1 = self.selenium.find_element(
  5451. By.ID, "id_relatedprepopulated_set-2-1-slug1"
  5452. ).get_attribute("value")
  5453. slug2 = self.selenium.find_element(
  5454. By.ID, "id_relatedprepopulated_set-2-1-slug2"
  5455. ).get_attribute("value")
  5456. self.assertEqual(slug1, "tabular-inline-with-ignored-characters-1981-08-22")
  5457. self.assertEqual(slug2, "option-one-tabular-inline-with-ignored-characters")
  5458. # Add an inline without an initial inline.
  5459. # The button is outside of the browser frame.
  5460. self.selenium.execute_script("window.scrollTo(0, document.body.scrollHeight);")
  5461. self.selenium.find_elements(By.LINK_TEXT, "Add another Related prepopulated")[
  5462. 2
  5463. ].click()
  5464. self.assertEqual(
  5465. len(self.selenium.find_elements(By.CLASS_NAME, "select2-selection")),
  5466. num_initial_select2_inputs + 6,
  5467. )
  5468. # Stacked Inlines without fieldsets ----------------------------------
  5469. # Initial inline.
  5470. row_id = "id_relatedprepopulated_set-4-0-"
  5471. self.selenium.find_element(By.ID, f"{row_id}pubdate").send_keys("2011-12-12")
  5472. status = self.selenium.find_element(By.ID, f"{row_id}status")
  5473. ActionChains(self.selenium).move_to_element(status).click(status).perform()
  5474. self.select_option(f"#{row_id}status", "option one")
  5475. self.selenium.find_element(By.ID, f"{row_id}name").send_keys(
  5476. " sŤāÇkeð inline ! "
  5477. )
  5478. slug1 = self.selenium.find_element(By.ID, f"{row_id}slug1").get_attribute(
  5479. "value"
  5480. )
  5481. slug2 = self.selenium.find_element(By.ID, f"{row_id}slug2").get_attribute(
  5482. "value"
  5483. )
  5484. self.assertEqual(slug1, "stacked-inline-2011-12-12")
  5485. self.assertEqual(slug2, "option-one")
  5486. # Add inline.
  5487. self.selenium.find_elements(
  5488. By.LINK_TEXT,
  5489. "Add another Related prepopulated",
  5490. )[3].click()
  5491. row_id = "id_relatedprepopulated_set-4-1-"
  5492. self.selenium.find_element(By.ID, f"{row_id}pubdate").send_keys("1999-01-20")
  5493. status = self.selenium.find_element(By.ID, f"{row_id}status")
  5494. ActionChains(self.selenium).move_to_element(status).click(status).perform()
  5495. self.select_option(f"#{row_id}status", "option two")
  5496. self.selenium.find_element(By.ID, f"{row_id}name").send_keys(
  5497. " now you haVe anöther sŤāÇkeð inline with a very loooong "
  5498. )
  5499. slug1 = self.selenium.find_element(By.ID, f"{row_id}slug1").get_attribute(
  5500. "value"
  5501. )
  5502. slug2 = self.selenium.find_element(By.ID, f"{row_id}slug2").get_attribute(
  5503. "value"
  5504. )
  5505. self.assertEqual(slug1, "now-you-have-another-stacked-inline-with-a-very-lo")
  5506. self.assertEqual(slug2, "option-two")
  5507. # Save and check that everything is properly stored in the database
  5508. with self.wait_page_loaded():
  5509. self.selenium.find_element(By.XPATH, '//input[@value="Save"]').click()
  5510. self.assertEqual(MainPrepopulated.objects.count(), 1)
  5511. MainPrepopulated.objects.get(
  5512. name=" the mAin nÀMë and it's awεšomeıııİ",
  5513. pubdate="2012-02-18",
  5514. status="option two",
  5515. slug1="the-main-name-and-its-awesomeiiii-2012-02-18",
  5516. slug2="option-two-the-main-name-and-its-awesomeiiii",
  5517. slug3="the-main-nàmë-and-its-awεšomeıııi",
  5518. )
  5519. self.assertEqual(RelatedPrepopulated.objects.count(), 6)
  5520. RelatedPrepopulated.objects.get(
  5521. name=" here is a sŤāÇkeð inline ! ",
  5522. pubdate="2011-12-17",
  5523. status="option one",
  5524. slug1="here-is-a-stacked-inline-2011-12-17",
  5525. slug2="option-one-here-is-a-stacked-inline",
  5526. )
  5527. RelatedPrepopulated.objects.get(
  5528. # 75 characters in name field
  5529. name=(
  5530. " now you haVe anöther sŤāÇkeð inline with a very ... "
  5531. "loooooooooooooooooo"
  5532. ),
  5533. pubdate="1999-01-25",
  5534. status="option two",
  5535. slug1="now-you-have-another-stacked-inline-with-a-very-lo",
  5536. slug2="option-two-now-you-have-another-stacked-inline-with-a-very-l",
  5537. )
  5538. RelatedPrepopulated.objects.get(
  5539. name="And now, with a tÃbűlaŘ inline !!!",
  5540. pubdate="1234-12-07",
  5541. status="option two",
  5542. slug1="and-now-with-a-tabular-inline-1234-12-07",
  5543. slug2="option-two-and-now-with-a-tabular-inline",
  5544. )
  5545. RelatedPrepopulated.objects.get(
  5546. name=r'tÃbűlaŘ inline with ignored ;"&*^\%$#@-/`~ characters',
  5547. pubdate="1981-08-22",
  5548. status="option one",
  5549. slug1="tabular-inline-with-ignored-characters-1981-08-22",
  5550. slug2="option-one-tabular-inline-with-ignored-characters",
  5551. )
  5552. def test_populate_existing_object(self):
  5553. """
  5554. The prepopulation works for existing objects too, as long as
  5555. the original field is empty (#19082).
  5556. """
  5557. from selenium.webdriver.common.by import By
  5558. # Slugs are empty to start with.
  5559. item = MainPrepopulated.objects.create(
  5560. name=" this is the mAin nÀMë",
  5561. pubdate="2012-02-18",
  5562. status="option two",
  5563. slug1="",
  5564. slug2="",
  5565. )
  5566. self.admin_login(
  5567. username="super", password="secret", login_url=reverse("admin:index")
  5568. )
  5569. object_url = self.live_server_url + reverse(
  5570. "admin:admin_views_mainprepopulated_change", args=(item.id,)
  5571. )
  5572. self.selenium.get(object_url)
  5573. self.selenium.find_element(By.ID, "id_name").send_keys(" the best")
  5574. # The slugs got prepopulated since they were originally empty
  5575. slug1 = self.selenium.find_element(By.ID, "id_slug1").get_attribute("value")
  5576. slug2 = self.selenium.find_element(By.ID, "id_slug2").get_attribute("value")
  5577. self.assertEqual(slug1, "this-is-the-main-name-the-best-2012-02-18")
  5578. self.assertEqual(slug2, "option-two-this-is-the-main-name-the-best")
  5579. # Save the object
  5580. with self.wait_page_loaded():
  5581. self.selenium.find_element(By.XPATH, '//input[@value="Save"]').click()
  5582. self.selenium.get(object_url)
  5583. self.selenium.find_element(By.ID, "id_name").send_keys(" hello")
  5584. # The slugs got prepopulated didn't change since they were originally not empty
  5585. slug1 = self.selenium.find_element(By.ID, "id_slug1").get_attribute("value")
  5586. slug2 = self.selenium.find_element(By.ID, "id_slug2").get_attribute("value")
  5587. self.assertEqual(slug1, "this-is-the-main-name-the-best-2012-02-18")
  5588. self.assertEqual(slug2, "option-two-this-is-the-main-name-the-best")
  5589. @screenshot_cases(["desktop_size", "mobile_size", "dark", "high_contrast"])
  5590. def test_collapsible_fieldset(self):
  5591. """
  5592. The 'collapse' class in fieldsets definition allows to
  5593. show/hide the appropriate field section.
  5594. """
  5595. from selenium.webdriver.common.by import By
  5596. self.admin_login(
  5597. username="super", password="secret", login_url=reverse("admin:index")
  5598. )
  5599. self.selenium.get(
  5600. self.live_server_url + reverse("admin:admin_views_article_add")
  5601. )
  5602. self.assertFalse(self.selenium.find_element(By.ID, "id_title").is_displayed())
  5603. self.take_screenshot("collapsed")
  5604. self.selenium.find_elements(By.TAG_NAME, "summary")[0].click()
  5605. self.assertTrue(self.selenium.find_element(By.ID, "id_title").is_displayed())
  5606. self.take_screenshot("expanded")
  5607. @screenshot_cases(["desktop_size", "mobile_size", "rtl", "dark", "high_contrast"])
  5608. def test_selectbox_height_collapsible_fieldset(self):
  5609. from selenium.webdriver.common.by import By
  5610. self.admin_login(
  5611. username="super",
  5612. password="secret",
  5613. login_url=reverse("admin7:index"),
  5614. )
  5615. url = self.live_server_url + reverse("admin7:admin_views_pizza_add")
  5616. self.selenium.get(url)
  5617. self.selenium.find_elements(By.TAG_NAME, "summary")[0].click()
  5618. from_filter_box = self.selenium.find_element(By.ID, "id_toppings_filter")
  5619. from_box = self.selenium.find_element(By.ID, "id_toppings_from")
  5620. to_filter_box = self.selenium.find_element(By.ID, "id_toppings_filter_selected")
  5621. to_box = self.selenium.find_element(By.ID, "id_toppings_to")
  5622. self.assertEqual(
  5623. (
  5624. to_filter_box.get_property("offsetHeight")
  5625. + to_box.get_property("offsetHeight")
  5626. ),
  5627. (
  5628. from_filter_box.get_property("offsetHeight")
  5629. + from_box.get_property("offsetHeight")
  5630. ),
  5631. )
  5632. self.take_screenshot("selectbox-collapsible")
  5633. @screenshot_cases(["desktop_size", "mobile_size", "rtl", "dark", "high_contrast"])
  5634. def test_selectbox_height_not_collapsible_fieldset(self):
  5635. from selenium.webdriver.common.by import By
  5636. self.admin_login(
  5637. username="super",
  5638. password="secret",
  5639. login_url=reverse("admin7:index"),
  5640. )
  5641. url = self.live_server_url + reverse("admin7:admin_views_question_add")
  5642. self.selenium.get(url)
  5643. from_filter_box = self.selenium.find_element(
  5644. By.ID, "id_related_questions_filter"
  5645. )
  5646. from_box = self.selenium.find_element(By.ID, "id_related_questions_from")
  5647. to_filter_box = self.selenium.find_element(
  5648. By.ID, "id_related_questions_filter_selected"
  5649. )
  5650. to_box = self.selenium.find_element(By.ID, "id_related_questions_to")
  5651. self.assertEqual(
  5652. (
  5653. to_filter_box.get_property("offsetHeight")
  5654. + to_box.get_property("offsetHeight")
  5655. ),
  5656. (
  5657. from_filter_box.get_property("offsetHeight")
  5658. + from_box.get_property("offsetHeight")
  5659. ),
  5660. )
  5661. self.take_screenshot("selectbox-non-collapsible")
  5662. @screenshot_cases(["desktop_size", "mobile_size", "rtl", "dark", "high_contrast"])
  5663. def test_selectbox_selected_rows(self):
  5664. from selenium.webdriver import ActionChains
  5665. from selenium.webdriver.common.by import By
  5666. from selenium.webdriver.common.keys import Keys
  5667. self.admin_login(
  5668. username="super", password="secret", login_url=reverse("admin:index")
  5669. )
  5670. # Create a new user to ensure that no extra permissions have been set.
  5671. user = User.objects.create_user(username="new", password="newuser")
  5672. url = self.live_server_url + reverse("admin:auth_user_change", args=[user.id])
  5673. self.selenium.get(url)
  5674. # Scroll to the User permissions section.
  5675. user_permissions = self.selenium.find_element(
  5676. By.CSS_SELECTOR, "#id_user_permissions_from"
  5677. )
  5678. ActionChains(self.selenium).move_to_element(user_permissions).perform()
  5679. self.take_screenshot("selectbox-available-perms-none-selected")
  5680. # Select multiple permissions from the "Available" list.
  5681. ct = ContentType.objects.get_for_model(Permission)
  5682. perms = list(Permission.objects.filter(content_type=ct))
  5683. for perm in perms:
  5684. elem = self.selenium.find_element(
  5685. By.CSS_SELECTOR, f"#id_user_permissions_from option[value='{perm.id}']"
  5686. )
  5687. ActionChains(self.selenium).key_down(Keys.CONTROL).click(elem).key_up(
  5688. Keys.CONTROL
  5689. ).perform()
  5690. # Move focus to other element.
  5691. self.selenium.find_element(
  5692. By.CSS_SELECTOR, "#id_user_permissions_input"
  5693. ).click()
  5694. self.take_screenshot("selectbox-available-perms-some-selected")
  5695. # Move permissions to the "Chosen" list, but none is selected yet.
  5696. self.selenium.find_element(By.CSS_SELECTOR, "#id_user_permissions_add").click()
  5697. self.take_screenshot("selectbox-chosen-perms-none-selected")
  5698. # Select some permissions from the "Chosen" list.
  5699. for perm in [perms[0], perms[-1]]:
  5700. elem = self.selenium.find_element(
  5701. By.CSS_SELECTOR, f"#id_user_permissions_to option[value='{perm.id}']"
  5702. )
  5703. ActionChains(self.selenium).key_down(Keys.CONTROL).click(elem).key_up(
  5704. Keys.CONTROL
  5705. ).perform()
  5706. # Move focus to other element.
  5707. self.selenium.find_element(
  5708. By.CSS_SELECTOR, "#id_user_permissions_selected_input"
  5709. ).click()
  5710. self.take_screenshot("selectbox-chosen-perms-some-selected")
  5711. @screenshot_cases(["desktop_size", "mobile_size", "rtl", "dark", "high_contrast"])
  5712. def test_first_field_focus(self):
  5713. """JavaScript-assisted auto-focus on first usable form field."""
  5714. from selenium.webdriver.common.by import By
  5715. # First form field has a single widget
  5716. self.admin_login(
  5717. username="super", password="secret", login_url=reverse("admin:index")
  5718. )
  5719. with self.wait_page_loaded():
  5720. self.selenium.get(
  5721. self.live_server_url + reverse("admin:admin_views_picture_add")
  5722. )
  5723. self.assertEqual(
  5724. self.selenium.switch_to.active_element,
  5725. self.selenium.find_element(By.ID, "id_name"),
  5726. )
  5727. self.take_screenshot("focus-single-widget")
  5728. # First form field has a MultiWidget
  5729. with self.wait_page_loaded():
  5730. self.selenium.get(
  5731. self.live_server_url + reverse("admin:admin_views_reservation_add")
  5732. )
  5733. self.assertEqual(
  5734. self.selenium.switch_to.active_element,
  5735. self.selenium.find_element(By.ID, "id_start_date_0"),
  5736. )
  5737. self.take_screenshot("focus-multi-widget")
  5738. def test_cancel_delete_confirmation(self):
  5739. "Cancelling the deletion of an object takes the user back one page."
  5740. from selenium.webdriver.common.by import By
  5741. pizza = Pizza.objects.create(name="Double Cheese")
  5742. url = reverse("admin:admin_views_pizza_change", args=(pizza.id,))
  5743. full_url = self.live_server_url + url
  5744. self.admin_login(
  5745. username="super", password="secret", login_url=reverse("admin:index")
  5746. )
  5747. self.selenium.get(full_url)
  5748. self.selenium.find_element(By.CLASS_NAME, "deletelink").click()
  5749. # Click 'cancel' on the delete page.
  5750. self.selenium.find_element(By.CLASS_NAME, "cancel-link").click()
  5751. # Wait until we're back on the change page.
  5752. self.wait_for_text("#content h1", "Change pizza")
  5753. self.assertEqual(self.selenium.current_url, full_url)
  5754. self.assertEqual(Pizza.objects.count(), 1)
  5755. def test_cancel_delete_related_confirmation(self):
  5756. """
  5757. Cancelling the deletion of an object with relations takes the user back
  5758. one page.
  5759. """
  5760. from selenium.webdriver.common.by import By
  5761. pizza = Pizza.objects.create(name="Double Cheese")
  5762. topping1 = Topping.objects.create(name="Cheddar")
  5763. topping2 = Topping.objects.create(name="Mozzarella")
  5764. pizza.toppings.add(topping1, topping2)
  5765. url = reverse("admin:admin_views_pizza_change", args=(pizza.id,))
  5766. full_url = self.live_server_url + url
  5767. self.admin_login(
  5768. username="super", password="secret", login_url=reverse("admin:index")
  5769. )
  5770. self.selenium.get(full_url)
  5771. self.selenium.find_element(By.CLASS_NAME, "deletelink").click()
  5772. # Click 'cancel' on the delete page.
  5773. self.selenium.find_element(By.CLASS_NAME, "cancel-link").click()
  5774. # Wait until we're back on the change page.
  5775. self.wait_for_text("#content h1", "Change pizza")
  5776. self.assertEqual(self.selenium.current_url, full_url)
  5777. self.assertEqual(Pizza.objects.count(), 1)
  5778. self.assertEqual(Topping.objects.count(), 2)
  5779. def test_list_editable_popups(self):
  5780. """
  5781. list_editable foreign keys have add/change popups.
  5782. """
  5783. from selenium.webdriver.common.by import By
  5784. from selenium.webdriver.support.ui import Select
  5785. s1 = Section.objects.create(name="Test section")
  5786. Article.objects.create(
  5787. title="foo",
  5788. content="<p>Middle content</p>",
  5789. date=datetime.datetime(2008, 3, 18, 11, 54, 58),
  5790. section=s1,
  5791. )
  5792. self.admin_login(
  5793. username="super", password="secret", login_url=reverse("admin:index")
  5794. )
  5795. self.selenium.get(
  5796. self.live_server_url + reverse("admin:admin_views_article_changelist")
  5797. )
  5798. # Change popup
  5799. self.selenium.find_element(By.ID, "change_id_form-0-section").click()
  5800. self.wait_for_and_switch_to_popup()
  5801. self.wait_for_text("#content h1", "Change section")
  5802. name_input = self.selenium.find_element(By.ID, "id_name")
  5803. name_input.clear()
  5804. name_input.send_keys("<i>edited section</i>")
  5805. self.selenium.find_element(By.XPATH, '//input[@value="Save"]').click()
  5806. self.wait_until(lambda d: len(d.window_handles) == 1, 1)
  5807. self.selenium.switch_to.window(self.selenium.window_handles[0])
  5808. # Hide sidebar.
  5809. toggle_button = self.selenium.find_element(
  5810. By.CSS_SELECTOR, "#toggle-nav-sidebar"
  5811. )
  5812. toggle_button.click()
  5813. self.addCleanup(_clean_sidebar_state, self.selenium)
  5814. select = Select(self.selenium.find_element(By.ID, "id_form-0-section"))
  5815. self.assertEqual(select.first_selected_option.text, "<i>edited section</i>")
  5816. # Rendered select2 input.
  5817. select2_display = self.selenium.find_element(
  5818. By.CLASS_NAME, "select2-selection__rendered"
  5819. )
  5820. # Clear button (×\n) is included in text.
  5821. self.assertEqual(select2_display.text, "×\n<i>edited section</i>")
  5822. # Add popup
  5823. self.selenium.find_element(By.ID, "add_id_form-0-section").click()
  5824. self.wait_for_and_switch_to_popup()
  5825. self.wait_for_text("#content h1", "Add section")
  5826. self.selenium.find_element(By.ID, "id_name").send_keys("new section")
  5827. self.selenium.find_element(By.XPATH, '//input[@value="Save"]').click()
  5828. self.wait_until(lambda d: len(d.window_handles) == 1, 1)
  5829. self.selenium.switch_to.window(self.selenium.window_handles[0])
  5830. select = Select(self.selenium.find_element(By.ID, "id_form-0-section"))
  5831. self.assertEqual(select.first_selected_option.text, "new section")
  5832. select2_display = self.selenium.find_element(
  5833. By.CLASS_NAME, "select2-selection__rendered"
  5834. )
  5835. # Clear button (×\n) is included in text.
  5836. self.assertEqual(select2_display.text, "×\nnew section")
  5837. def test_inline_uuid_pk_edit_with_popup(self):
  5838. from selenium.webdriver import ActionChains
  5839. from selenium.webdriver.common.by import By
  5840. from selenium.webdriver.support.ui import Select
  5841. parent = ParentWithUUIDPK.objects.create(title="test")
  5842. related_with_parent = RelatedWithUUIDPKModel.objects.create(parent=parent)
  5843. self.admin_login(
  5844. username="super", password="secret", login_url=reverse("admin:index")
  5845. )
  5846. change_url = reverse(
  5847. "admin:admin_views_relatedwithuuidpkmodel_change",
  5848. args=(related_with_parent.id,),
  5849. )
  5850. with self.wait_page_loaded():
  5851. self.selenium.get(self.live_server_url + change_url)
  5852. change_parent = self.selenium.find_element(By.ID, "change_id_parent")
  5853. ActionChains(self.selenium).move_to_element(change_parent).click().perform()
  5854. self.wait_for_and_switch_to_popup()
  5855. self.selenium.find_element(By.XPATH, '//input[@value="Save"]').click()
  5856. self.selenium.switch_to.window(self.selenium.window_handles[0])
  5857. select = Select(self.selenium.find_element(By.ID, "id_parent"))
  5858. self.assertEqual(select.first_selected_option.text, str(parent.id))
  5859. self.assertEqual(
  5860. select.first_selected_option.get_attribute("value"), str(parent.id)
  5861. )
  5862. def test_inline_uuid_pk_add_with_popup(self):
  5863. from selenium.webdriver.common.by import By
  5864. from selenium.webdriver.support.ui import Select
  5865. self.admin_login(
  5866. username="super", password="secret", login_url=reverse("admin:index")
  5867. )
  5868. self.selenium.get(
  5869. self.live_server_url
  5870. + reverse("admin:admin_views_relatedwithuuidpkmodel_add")
  5871. )
  5872. self.selenium.find_element(By.ID, "add_id_parent").click()
  5873. self.wait_for_and_switch_to_popup()
  5874. self.selenium.find_element(By.ID, "id_title").send_keys("test")
  5875. self.selenium.find_element(By.XPATH, '//input[@value="Save"]').click()
  5876. self.wait_until(lambda d: len(d.window_handles) == 1, 1)
  5877. self.selenium.switch_to.window(self.selenium.window_handles[0])
  5878. select = Select(self.selenium.find_element(By.ID, "id_parent"))
  5879. uuid_id = str(ParentWithUUIDPK.objects.first().id)
  5880. self.assertEqual(select.first_selected_option.text, uuid_id)
  5881. self.assertEqual(select.first_selected_option.get_attribute("value"), uuid_id)
  5882. def test_inline_uuid_pk_delete_with_popup(self):
  5883. from selenium.webdriver import ActionChains
  5884. from selenium.webdriver.common.by import By
  5885. from selenium.webdriver.support.ui import Select
  5886. parent = ParentWithUUIDPK.objects.create(title="test")
  5887. related_with_parent = RelatedWithUUIDPKModel.objects.create(parent=parent)
  5888. self.admin_login(
  5889. username="super", password="secret", login_url=reverse("admin:index")
  5890. )
  5891. change_url = reverse(
  5892. "admin:admin_views_relatedwithuuidpkmodel_change",
  5893. args=(related_with_parent.id,),
  5894. )
  5895. with self.wait_page_loaded():
  5896. self.selenium.get(self.live_server_url + change_url)
  5897. delete_parent = self.selenium.find_element(By.ID, "delete_id_parent")
  5898. ActionChains(self.selenium).move_to_element(delete_parent).click().perform()
  5899. self.wait_for_and_switch_to_popup()
  5900. self.selenium.find_element(By.XPATH, '//input[@value="Yes, I’m sure"]').click()
  5901. self.selenium.switch_to.window(self.selenium.window_handles[0])
  5902. select = Select(self.selenium.find_element(By.ID, "id_parent"))
  5903. self.assertEqual(ParentWithUUIDPK.objects.count(), 0)
  5904. self.assertEqual(select.first_selected_option.text, "---------")
  5905. self.assertEqual(select.first_selected_option.get_attribute("value"), "")
  5906. def test_inline_with_popup_cancel_delete(self):
  5907. """Clicking ""No, take me back" on a delete popup closes the window."""
  5908. from selenium.webdriver import ActionChains
  5909. from selenium.webdriver.common.by import By
  5910. parent = ParentWithUUIDPK.objects.create(title="test")
  5911. related_with_parent = RelatedWithUUIDPKModel.objects.create(parent=parent)
  5912. self.admin_login(
  5913. username="super", password="secret", login_url=reverse("admin:index")
  5914. )
  5915. change_url = reverse(
  5916. "admin:admin_views_relatedwithuuidpkmodel_change",
  5917. args=(related_with_parent.id,),
  5918. )
  5919. with self.wait_page_loaded():
  5920. self.selenium.get(self.live_server_url + change_url)
  5921. delete_parent = self.selenium.find_element(By.ID, "delete_id_parent")
  5922. ActionChains(self.selenium).move_to_element(delete_parent).click().perform()
  5923. self.wait_for_and_switch_to_popup()
  5924. self.selenium.find_element(By.XPATH, '//a[text()="No, take me back"]').click()
  5925. self.selenium.switch_to.window(self.selenium.window_handles[0])
  5926. self.assertEqual(len(self.selenium.window_handles), 1)
  5927. def test_list_editable_raw_id_fields(self):
  5928. from selenium.webdriver.common.by import By
  5929. parent = ParentWithUUIDPK.objects.create(title="test")
  5930. parent2 = ParentWithUUIDPK.objects.create(title="test2")
  5931. RelatedWithUUIDPKModel.objects.create(parent=parent)
  5932. self.admin_login(
  5933. username="super", password="secret", login_url=reverse("admin:index")
  5934. )
  5935. change_url = reverse(
  5936. "admin:admin_views_relatedwithuuidpkmodel_changelist",
  5937. current_app=site2.name,
  5938. )
  5939. self.selenium.get(self.live_server_url + change_url)
  5940. self.selenium.find_element(By.ID, "lookup_id_form-0-parent").click()
  5941. self.wait_for_and_switch_to_popup()
  5942. # Select "parent2" in the popup.
  5943. self.selenium.find_element(By.LINK_TEXT, str(parent2.pk)).click()
  5944. self.selenium.switch_to.window(self.selenium.window_handles[0])
  5945. # The newly selected pk should appear in the raw id input.
  5946. value = self.selenium.find_element(By.ID, "id_form-0-parent").get_attribute(
  5947. "value"
  5948. )
  5949. self.assertEqual(value, str(parent2.pk))
  5950. def test_input_element_font(self):
  5951. """
  5952. Browsers' default stylesheets override the font of inputs. The admin
  5953. adds additional CSS to handle this.
  5954. """
  5955. from selenium.webdriver.common.by import By
  5956. self.selenium.get(self.live_server_url + reverse("admin:login"))
  5957. element = self.selenium.find_element(By.ID, "id_username")
  5958. # Some browsers quotes the fonts, some don't.
  5959. fonts = [
  5960. font.strip().strip('"')
  5961. for font in element.value_of_css_property("font-family").split(",")
  5962. ]
  5963. self.assertEqual(
  5964. fonts,
  5965. [
  5966. "Segoe UI",
  5967. "system-ui",
  5968. "Roboto",
  5969. "Helvetica Neue",
  5970. "Arial",
  5971. "sans-serif",
  5972. "Apple Color Emoji",
  5973. "Segoe UI Emoji",
  5974. "Segoe UI Symbol",
  5975. "Noto Color Emoji",
  5976. ],
  5977. )
  5978. def test_search_input_filtered_page(self):
  5979. from selenium.webdriver.common.by import By
  5980. Person.objects.create(name="Guido van Rossum", gender=1, alive=True)
  5981. Person.objects.create(name="Grace Hopper", gender=1, alive=False)
  5982. self.admin_login(
  5983. username="super", password="secret", login_url=reverse("admin:index")
  5984. )
  5985. person_url = reverse("admin:admin_views_person_changelist") + "?q=Gui"
  5986. self.selenium.get(self.live_server_url + person_url)
  5987. # Hide sidebar.
  5988. toggle_button = self.selenium.find_element(
  5989. By.CSS_SELECTOR, "#toggle-nav-sidebar"
  5990. )
  5991. toggle_button.click()
  5992. self.addCleanup(_clean_sidebar_state, self.selenium)
  5993. self.assertGreater(
  5994. self.selenium.find_element(By.ID, "searchbar").rect["width"],
  5995. 50,
  5996. )
  5997. def test_related_popup_index(self):
  5998. """
  5999. Create a chain of 'self' related objects via popups.
  6000. """
  6001. from selenium.webdriver.common.by import By
  6002. from selenium.webdriver.support.ui import Select
  6003. self.admin_login(
  6004. username="super", password="secret", login_url=reverse("admin:index")
  6005. )
  6006. add_url = reverse("admin:admin_views_box_add", current_app=site.name)
  6007. self.selenium.get(self.live_server_url + add_url)
  6008. base_window = self.selenium.current_window_handle
  6009. self.selenium.find_element(By.ID, "add_id_next_box").click()
  6010. self.wait_for_and_switch_to_popup()
  6011. popup_window_test = self.selenium.current_window_handle
  6012. self.selenium.find_element(By.ID, "id_title").send_keys("test")
  6013. self.selenium.find_element(By.ID, "add_id_next_box").click()
  6014. self.wait_for_and_switch_to_popup(num_windows=3)
  6015. popup_window_test2 = self.selenium.current_window_handle
  6016. self.selenium.find_element(By.ID, "id_title").send_keys("test2")
  6017. self.selenium.find_element(By.ID, "add_id_next_box").click()
  6018. self.wait_for_and_switch_to_popup(num_windows=4)
  6019. self.selenium.find_element(By.ID, "id_title").send_keys("test3")
  6020. self.selenium.find_element(By.XPATH, '//input[@value="Save"]').click()
  6021. self.selenium.switch_to.window(popup_window_test2)
  6022. select = Select(self.selenium.find_element(By.ID, "id_next_box"))
  6023. next_box_id = str(Box.objects.get(title="test3").id)
  6024. self.assertEqual(
  6025. select.first_selected_option.get_attribute("value"), next_box_id
  6026. )
  6027. self.selenium.find_element(By.XPATH, '//input[@value="Save"]').click()
  6028. self.selenium.switch_to.window(popup_window_test)
  6029. select = Select(self.selenium.find_element(By.ID, "id_next_box"))
  6030. next_box_id = str(Box.objects.get(title="test2").id)
  6031. self.assertEqual(
  6032. select.first_selected_option.get_attribute("value"), next_box_id
  6033. )
  6034. self.selenium.find_element(By.XPATH, '//input[@value="Save"]').click()
  6035. self.selenium.switch_to.window(base_window)
  6036. select = Select(self.selenium.find_element(By.ID, "id_next_box"))
  6037. next_box_id = str(Box.objects.get(title="test").id)
  6038. self.assertEqual(
  6039. select.first_selected_option.get_attribute("value"), next_box_id
  6040. )
  6041. def test_related_popup_incorrect_close(self):
  6042. """
  6043. Cleanup child popups when closing a parent popup.
  6044. """
  6045. from selenium.webdriver.common.by import By
  6046. self.admin_login(
  6047. username="super", password="secret", login_url=reverse("admin:index")
  6048. )
  6049. add_url = reverse("admin:admin_views_box_add", current_app=site.name)
  6050. self.selenium.get(self.live_server_url + add_url)
  6051. self.selenium.find_element(By.ID, "add_id_next_box").click()
  6052. self.wait_for_and_switch_to_popup()
  6053. test_window = self.selenium.current_window_handle
  6054. self.selenium.find_element(By.ID, "id_title").send_keys("test")
  6055. self.selenium.find_element(By.ID, "add_id_next_box").click()
  6056. self.wait_for_and_switch_to_popup(num_windows=3)
  6057. test2_window = self.selenium.current_window_handle
  6058. self.selenium.find_element(By.ID, "id_title").send_keys("test2")
  6059. self.selenium.find_element(By.ID, "add_id_next_box").click()
  6060. self.wait_for_and_switch_to_popup(num_windows=4)
  6061. self.assertEqual(len(self.selenium.window_handles), 4)
  6062. self.selenium.switch_to.window(test2_window)
  6063. self.selenium.find_element(By.XPATH, '//input[@value="Save"]').click()
  6064. self.wait_until(lambda d: len(d.window_handles) == 2, 1)
  6065. self.assertEqual(len(self.selenium.window_handles), 2)
  6066. # Close final popup to clean up test.
  6067. self.selenium.switch_to.window(test_window)
  6068. self.selenium.find_element(By.XPATH, '//input[@value="Save"]').click()
  6069. self.wait_until(lambda d: len(d.window_handles) == 1, 1)
  6070. self.selenium.switch_to.window(self.selenium.window_handles[-1])
  6071. def test_hidden_fields_small_window(self):
  6072. from selenium.webdriver.common.by import By
  6073. self.admin_login(
  6074. username="super",
  6075. password="secret",
  6076. login_url=reverse("admin:index"),
  6077. )
  6078. self.selenium.get(self.live_server_url + reverse("admin:admin_views_story_add"))
  6079. field_title = self.selenium.find_element(By.CLASS_NAME, "field-title")
  6080. with self.small_screen_size():
  6081. self.assertIs(field_title.is_displayed(), False)
  6082. with self.mobile_size():
  6083. self.assertIs(field_title.is_displayed(), False)
  6084. def test_updating_related_objects_updates_fk_selects_except_autocompletes(self):
  6085. from selenium.webdriver import ActionChains
  6086. from selenium.webdriver.common.by import By
  6087. from selenium.webdriver.support.ui import Select
  6088. born_country_select_id = "id_born_country"
  6089. living_country_select_id = "id_living_country"
  6090. living_country_select2_textbox_id = "select2-id_living_country-container"
  6091. favorite_country_to_vacation_select_id = "id_favorite_country_to_vacation"
  6092. continent_select_id = "id_continent"
  6093. def _get_HTML_inside_element_by_id(id_):
  6094. return self.selenium.find_element(By.ID, id_).get_attribute("innerHTML")
  6095. def _get_text_inside_element_by_selector(selector):
  6096. return self.selenium.find_element(By.CSS_SELECTOR, selector).get_attribute(
  6097. "innerText"
  6098. )
  6099. self.admin_login(
  6100. username="super", password="secret", login_url=reverse("admin:index")
  6101. )
  6102. add_url = reverse("admin:admin_views_traveler_add")
  6103. self.selenium.get(self.live_server_url + add_url)
  6104. # Add new Country from the born_country select.
  6105. self.selenium.find_element(By.ID, f"add_{born_country_select_id}").click()
  6106. self.wait_for_and_switch_to_popup()
  6107. self.selenium.find_element(By.ID, "id_name").send_keys("Argentina")
  6108. continent_select = Select(
  6109. self.selenium.find_element(By.ID, continent_select_id)
  6110. )
  6111. continent_select.select_by_visible_text("South America")
  6112. self.selenium.find_element(By.CSS_SELECTOR, '[type="submit"]').click()
  6113. self.wait_until(lambda d: len(d.window_handles) == 1, 1)
  6114. self.selenium.switch_to.window(self.selenium.window_handles[0])
  6115. self.assertHTMLEqual(
  6116. _get_HTML_inside_element_by_id(born_country_select_id),
  6117. """
  6118. <option value="" selected="">---------</option>
  6119. <option value="1" selected="">Argentina</option>
  6120. """,
  6121. )
  6122. # Argentina isn't added to the living_country select nor selected by
  6123. # the select2 widget.
  6124. self.assertEqual(
  6125. _get_text_inside_element_by_selector(f"#{living_country_select_id}"), ""
  6126. )
  6127. self.assertEqual(
  6128. _get_text_inside_element_by_selector(
  6129. f"#{living_country_select2_textbox_id}"
  6130. ),
  6131. "",
  6132. )
  6133. # Argentina won't appear because favorite_country_to_vacation field has
  6134. # limit_choices_to.
  6135. self.assertHTMLEqual(
  6136. _get_HTML_inside_element_by_id(favorite_country_to_vacation_select_id),
  6137. '<option value="" selected="">---------</option>',
  6138. )
  6139. # Add new Country from the living_country select.
  6140. element = self.selenium.find_element(By.ID, f"add_{living_country_select_id}")
  6141. ActionChains(self.selenium).move_to_element(element).click(element).perform()
  6142. self.wait_for_and_switch_to_popup()
  6143. self.selenium.find_element(By.ID, "id_name").send_keys("Spain")
  6144. continent_select = Select(
  6145. self.selenium.find_element(By.ID, continent_select_id)
  6146. )
  6147. continent_select.select_by_visible_text("Europe")
  6148. self.selenium.find_element(By.CSS_SELECTOR, '[type="submit"]').click()
  6149. self.wait_until(lambda d: len(d.window_handles) == 1, 1)
  6150. self.selenium.switch_to.window(self.selenium.window_handles[0])
  6151. self.assertHTMLEqual(
  6152. _get_HTML_inside_element_by_id(born_country_select_id),
  6153. """
  6154. <option value="" selected="">---------</option>
  6155. <option value="1" selected="">Argentina</option>
  6156. <option value="2">Spain</option>
  6157. """,
  6158. )
  6159. # Spain is added to the living_country select and it's also selected by
  6160. # the select2 widget.
  6161. self.assertEqual(
  6162. _get_text_inside_element_by_selector(f"#{living_country_select_id} option"),
  6163. "Spain",
  6164. )
  6165. self.assertEqual(
  6166. _get_text_inside_element_by_selector(
  6167. f"#{living_country_select2_textbox_id}"
  6168. ),
  6169. "Spain",
  6170. )
  6171. # Spain won't appear because favorite_country_to_vacation field has
  6172. # limit_choices_to.
  6173. self.assertHTMLEqual(
  6174. _get_HTML_inside_element_by_id(favorite_country_to_vacation_select_id),
  6175. '<option value="" selected="">---------</option>',
  6176. )
  6177. # Edit second Country created from living_country select.
  6178. favorite_select = Select(
  6179. self.selenium.find_element(By.ID, living_country_select_id)
  6180. )
  6181. favorite_select.select_by_visible_text("Spain")
  6182. self.selenium.find_element(By.ID, f"change_{living_country_select_id}").click()
  6183. self.wait_for_and_switch_to_popup()
  6184. favorite_name_input = self.selenium.find_element(By.ID, "id_name")
  6185. favorite_name_input.clear()
  6186. favorite_name_input.send_keys("Italy")
  6187. self.selenium.find_element(By.CSS_SELECTOR, '[type="submit"]').click()
  6188. self.wait_until(lambda d: len(d.window_handles) == 1, 1)
  6189. self.selenium.switch_to.window(self.selenium.window_handles[0])
  6190. self.assertHTMLEqual(
  6191. _get_HTML_inside_element_by_id(born_country_select_id),
  6192. """
  6193. <option value="" selected="">---------</option>
  6194. <option value="1" selected="">Argentina</option>
  6195. <option value="2">Italy</option>
  6196. """,
  6197. )
  6198. # Italy is added to the living_country select and it's also selected by
  6199. # the select2 widget.
  6200. self.assertEqual(
  6201. _get_text_inside_element_by_selector(f"#{living_country_select_id} option"),
  6202. "Italy",
  6203. )
  6204. self.assertEqual(
  6205. _get_text_inside_element_by_selector(
  6206. f"#{living_country_select2_textbox_id}"
  6207. ),
  6208. "Italy",
  6209. )
  6210. # favorite_country_to_vacation field has no options.
  6211. self.assertHTMLEqual(
  6212. _get_HTML_inside_element_by_id(favorite_country_to_vacation_select_id),
  6213. '<option value="" selected="">---------</option>',
  6214. )
  6215. # Add a new Asian country.
  6216. self.selenium.find_element(
  6217. By.ID, f"add_{favorite_country_to_vacation_select_id}"
  6218. ).click()
  6219. self.wait_for_and_switch_to_popup()
  6220. favorite_name_input = self.selenium.find_element(By.ID, "id_name")
  6221. favorite_name_input.send_keys("Qatar")
  6222. continent_select = Select(
  6223. self.selenium.find_element(By.ID, continent_select_id)
  6224. )
  6225. continent_select.select_by_visible_text("Asia")
  6226. self.selenium.find_element(By.CSS_SELECTOR, '[type="submit"]').click()
  6227. self.wait_until(lambda d: len(d.window_handles) == 1, 1)
  6228. self.selenium.switch_to.window(self.selenium.window_handles[0])
  6229. # Submit the new Traveler.
  6230. with self.wait_page_loaded():
  6231. self.selenium.find_element(By.CSS_SELECTOR, '[name="_save"]').click()
  6232. traveler = Traveler.objects.get()
  6233. self.assertEqual(traveler.born_country.name, "Argentina")
  6234. self.assertEqual(traveler.living_country.name, "Italy")
  6235. self.assertEqual(traveler.favorite_country_to_vacation.name, "Qatar")
  6236. def test_redirect_on_add_view_add_another_button(self):
  6237. from selenium.webdriver.common.by import By
  6238. self.admin_login(
  6239. username="super", password="secret", login_url=reverse("admin:index")
  6240. )
  6241. add_url = reverse("admin7:admin_views_section_add")
  6242. self.selenium.get(self.live_server_url + add_url)
  6243. name_input = self.selenium.find_element(By.ID, "id_name")
  6244. name_input.send_keys("Test section 1")
  6245. self.selenium.find_element(
  6246. By.XPATH, '//input[@value="Save and add another"]'
  6247. ).click()
  6248. self.assertEqual(Section.objects.count(), 1)
  6249. name_input = self.selenium.find_element(By.ID, "id_name")
  6250. name_input.send_keys("Test section 2")
  6251. self.selenium.find_element(
  6252. By.XPATH, '//input[@value="Save and add another"]'
  6253. ).click()
  6254. self.assertEqual(Section.objects.count(), 2)
  6255. def test_redirect_on_add_view_continue_button(self):
  6256. from selenium.webdriver.common.by import By
  6257. self.admin_login(
  6258. username="super", password="secret", login_url=reverse("admin:index")
  6259. )
  6260. add_url = reverse("admin7:admin_views_section_add")
  6261. self.selenium.get(self.live_server_url + add_url)
  6262. name_input = self.selenium.find_element(By.ID, "id_name")
  6263. name_input.send_keys("Test section 1")
  6264. self.selenium.find_element(
  6265. By.XPATH, '//input[@value="Save and continue editing"]'
  6266. ).click()
  6267. self.assertEqual(Section.objects.count(), 1)
  6268. name_input = self.selenium.find_element(By.ID, "id_name")
  6269. name_input_value = name_input.get_attribute("value")
  6270. self.assertEqual(name_input_value, "Test section 1")
  6271. @override_settings(ROOT_URLCONF="admin_views.urls")
  6272. class ReadonlyTest(AdminFieldExtractionMixin, TestCase):
  6273. @classmethod
  6274. def setUpTestData(cls):
  6275. cls.superuser = User.objects.create_superuser(
  6276. username="super", password="secret", email="super@example.com"
  6277. )
  6278. def setUp(self):
  6279. self.client.force_login(self.superuser)
  6280. @ignore_warnings(category=RemovedInDjango60Warning)
  6281. def test_readonly_get(self):
  6282. response = self.client.get(reverse("admin:admin_views_post_add"))
  6283. self.assertNotContains(response, 'name="posted"')
  6284. # 3 fields + 2 submit buttons + 5 inline management form fields, + 2
  6285. # hidden fields for inlines + 1 field for the inline + 2 empty form
  6286. # + 1 logout form.
  6287. self.assertContains(response, "<input", count=17)
  6288. self.assertContains(response, formats.localize(datetime.date.today()))
  6289. self.assertContains(response, "<label>Awesomeness level:</label>")
  6290. self.assertContains(response, "Very awesome.")
  6291. self.assertContains(response, "Unknown coolness.")
  6292. self.assertContains(response, "foo")
  6293. # Multiline text in a readonly field gets <br> tags
  6294. self.assertContains(response, "Multiline<br>test<br>string")
  6295. self.assertContains(
  6296. response,
  6297. '<div class="readonly">Multiline<br>html<br>content</div>',
  6298. html=True,
  6299. )
  6300. self.assertContains(response, "InlineMultiline<br>test<br>string")
  6301. self.assertContains(
  6302. response,
  6303. formats.localize(datetime.date.today() - datetime.timedelta(days=7)),
  6304. )
  6305. self.assertContains(response, '<div class="form-row field-coolness">')
  6306. self.assertContains(response, '<div class="form-row field-awesomeness_level">')
  6307. self.assertContains(response, '<div class="form-row field-posted">')
  6308. self.assertContains(response, '<div class="form-row field-value">')
  6309. self.assertContains(response, '<div class="form-row">')
  6310. self.assertContains(response, '<div class="help"', 3)
  6311. self.assertContains(
  6312. response,
  6313. '<div class="help" id="id_title_helptext"><div>Some help text for the '
  6314. "title (with Unicode ŠĐĆŽćžšđ)</div></div>",
  6315. html=True,
  6316. )
  6317. self.assertContains(
  6318. response,
  6319. '<div class="help" id="id_content_helptext"><div>Some help text for the '
  6320. "content (with Unicode ŠĐĆŽćžšđ)</div></div>",
  6321. html=True,
  6322. )
  6323. self.assertContains(
  6324. response,
  6325. '<div class="help"><div>Some help text for the date (with Unicode ŠĐĆŽćžšđ)'
  6326. "</div></div>",
  6327. html=True,
  6328. )
  6329. p = Post.objects.create(
  6330. title="I worked on readonly_fields", content="Its good stuff"
  6331. )
  6332. response = self.client.get(
  6333. reverse("admin:admin_views_post_change", args=(p.pk,))
  6334. )
  6335. self.assertContains(response, "%d amount of cool" % p.pk)
  6336. @ignore_warnings(category=RemovedInDjango60Warning)
  6337. def test_readonly_text_field(self):
  6338. p = Post.objects.create(
  6339. title="Readonly test",
  6340. content="test",
  6341. readonly_content="test\r\n\r\ntest\r\n\r\ntest\r\n\r\ntest",
  6342. )
  6343. Link.objects.create(
  6344. url="http://www.djangoproject.com",
  6345. post=p,
  6346. readonly_link_content="test\r\nlink",
  6347. )
  6348. response = self.client.get(
  6349. reverse("admin:admin_views_post_change", args=(p.pk,))
  6350. )
  6351. # Checking readonly field.
  6352. self.assertContains(response, "test<br><br>test<br><br>test<br><br>test")
  6353. # Checking readonly field in inline.
  6354. self.assertContains(response, "test<br>link")
  6355. @ignore_warnings(category=RemovedInDjango60Warning)
  6356. def test_readonly_post(self):
  6357. data = {
  6358. "title": "Django Got Readonly Fields",
  6359. "content": "This is an incredible development.",
  6360. "link_set-TOTAL_FORMS": "1",
  6361. "link_set-INITIAL_FORMS": "0",
  6362. "link_set-MAX_NUM_FORMS": "0",
  6363. }
  6364. response = self.client.post(reverse("admin:admin_views_post_add"), data)
  6365. self.assertEqual(response.status_code, 302)
  6366. self.assertEqual(Post.objects.count(), 1)
  6367. p = Post.objects.get()
  6368. self.assertEqual(p.posted, datetime.date.today())
  6369. data["posted"] = "10-8-1990" # some date that's not today
  6370. response = self.client.post(reverse("admin:admin_views_post_add"), data)
  6371. self.assertEqual(response.status_code, 302)
  6372. self.assertEqual(Post.objects.count(), 2)
  6373. p = Post.objects.order_by("-id")[0]
  6374. self.assertEqual(p.posted, datetime.date.today())
  6375. def test_readonly_manytomany(self):
  6376. "Regression test for #13004"
  6377. response = self.client.get(reverse("admin:admin_views_pizza_add"))
  6378. self.assertEqual(response.status_code, 200)
  6379. def test_user_password_change_limited_queryset(self):
  6380. su = User.objects.filter(is_superuser=True)[0]
  6381. response = self.client.get(
  6382. reverse("admin2:auth_user_password_change", args=(su.pk,))
  6383. )
  6384. self.assertEqual(response.status_code, 404)
  6385. def test_change_form_renders_correct_null_choice_value(self):
  6386. """
  6387. Regression test for #17911.
  6388. """
  6389. choice = Choice.objects.create(choice=None)
  6390. response = self.client.get(
  6391. reverse("admin:admin_views_choice_change", args=(choice.pk,))
  6392. )
  6393. self.assertContains(
  6394. response, '<div class="readonly">No opinion</div>', html=True
  6395. )
  6396. def _test_readonly_foreignkey_links(self, admin_site):
  6397. """
  6398. ForeignKey readonly fields render as links if the target model is
  6399. registered in admin.
  6400. """
  6401. chapter = Chapter.objects.create(
  6402. title="Chapter 1",
  6403. content="content",
  6404. book=Book.objects.create(name="Book 1"),
  6405. )
  6406. language = Language.objects.create(iso="_40", name="Test")
  6407. obj = ReadOnlyRelatedField.objects.create(
  6408. chapter=chapter,
  6409. language=language,
  6410. user=self.superuser,
  6411. )
  6412. response = self.client.get(
  6413. reverse(
  6414. f"{admin_site}:admin_views_readonlyrelatedfield_change", args=(obj.pk,)
  6415. ),
  6416. )
  6417. # Related ForeignKey object registered in admin.
  6418. user_url = reverse(f"{admin_site}:auth_user_change", args=(self.superuser.pk,))
  6419. self.assertContains(
  6420. response,
  6421. '<div class="readonly"><a href="%s">super</a></div>' % user_url,
  6422. html=True,
  6423. )
  6424. # Related ForeignKey with the string primary key registered in admin.
  6425. language_url = reverse(
  6426. f"{admin_site}:admin_views_language_change",
  6427. args=(quote(language.pk),),
  6428. )
  6429. self.assertContains(
  6430. response,
  6431. '<div class="readonly"><a href="%s">_40</a></div>' % language_url,
  6432. html=True,
  6433. )
  6434. # Related ForeignKey object not registered in admin.
  6435. self.assertContains(
  6436. response, '<div class="readonly">Chapter 1</div>', html=True
  6437. )
  6438. def test_readonly_foreignkey_links_default_admin_site(self):
  6439. self._test_readonly_foreignkey_links("admin")
  6440. def test_readonly_foreignkey_links_custom_admin_site(self):
  6441. self._test_readonly_foreignkey_links("namespaced_admin")
  6442. def test_readonly_manytomany_backwards_ref(self):
  6443. """
  6444. Regression test for #16433 - backwards references for related objects
  6445. broke if the related field is read-only due to the help_text attribute
  6446. """
  6447. topping = Topping.objects.create(name="Salami")
  6448. pizza = Pizza.objects.create(name="Americano")
  6449. pizza.toppings.add(topping)
  6450. response = self.client.get(reverse("admin:admin_views_topping_add"))
  6451. self.assertEqual(response.status_code, 200)
  6452. def test_readonly_manytomany_forwards_ref(self):
  6453. topping = Topping.objects.create(name="Salami")
  6454. pizza = Pizza.objects.create(name="Americano")
  6455. pizza.toppings.add(topping)
  6456. response = self.client.get(
  6457. reverse("admin:admin_views_pizza_change", args=(pizza.pk,))
  6458. )
  6459. self.assertContains(response, "<label>Toppings:</label>", html=True)
  6460. self.assertContains(response, '<div class="readonly">Salami</div>', html=True)
  6461. def test_readonly_onetoone_backwards_ref(self):
  6462. """
  6463. Can reference a reverse OneToOneField in ModelAdmin.readonly_fields.
  6464. """
  6465. v1 = Villain.objects.create(name="Adam")
  6466. pl = Plot.objects.create(name="Test Plot", team_leader=v1, contact=v1)
  6467. pd = PlotDetails.objects.create(details="Brand New Plot", plot=pl)
  6468. response = self.client.get(
  6469. reverse("admin:admin_views_plotproxy_change", args=(pl.pk,))
  6470. )
  6471. field = self.get_admin_readonly_field(response, "plotdetails")
  6472. pd_url = reverse("admin:admin_views_plotdetails_change", args=(pd.pk,))
  6473. self.assertEqual(field.contents(), '<a href="%s">Brand New Plot</a>' % pd_url)
  6474. # The reverse relation also works if the OneToOneField is null.
  6475. pd.plot = None
  6476. pd.save()
  6477. response = self.client.get(
  6478. reverse("admin:admin_views_plotproxy_change", args=(pl.pk,))
  6479. )
  6480. field = self.get_admin_readonly_field(response, "plotdetails")
  6481. self.assertEqual(field.contents(), "-") # default empty value
  6482. @skipUnlessDBFeature("supports_stored_generated_columns")
  6483. def test_readonly_unsaved_generated_field(self):
  6484. response = self.client.get(reverse("admin:admin_views_square_add"))
  6485. self.assertContains(response, '<div class="readonly">-</div>')
  6486. @ignore_warnings(category=RemovedInDjango60Warning)
  6487. def test_readonly_field_overrides(self):
  6488. """
  6489. Regression test for #22087 - ModelForm Meta overrides are ignored by
  6490. AdminReadonlyField
  6491. """
  6492. p = FieldOverridePost.objects.create(title="Test Post", content="Test Content")
  6493. response = self.client.get(
  6494. reverse("admin:admin_views_fieldoverridepost_change", args=(p.pk,))
  6495. )
  6496. self.assertContains(
  6497. response,
  6498. '<div class="help"><div>Overridden help text for the date</div></div>',
  6499. html=True,
  6500. )
  6501. self.assertContains(
  6502. response,
  6503. '<label for="id_public">Overridden public label:</label>',
  6504. html=True,
  6505. )
  6506. self.assertNotContains(
  6507. response, "Some help text for the date (with Unicode ŠĐĆŽćžšđ)"
  6508. )
  6509. def test_correct_autoescaping(self):
  6510. """
  6511. Make sure that non-field readonly elements are properly autoescaped (#24461)
  6512. """
  6513. section = Section.objects.create(name="<a>evil</a>")
  6514. response = self.client.get(
  6515. reverse("admin:admin_views_section_change", args=(section.pk,))
  6516. )
  6517. self.assertNotContains(response, "<a>evil</a>", status_code=200)
  6518. self.assertContains(response, "&lt;a&gt;evil&lt;/a&gt;", status_code=200)
  6519. def test_label_suffix_translated(self):
  6520. pizza = Pizza.objects.create(name="Americano")
  6521. url = reverse("admin:admin_views_pizza_change", args=(pizza.pk,))
  6522. with self.settings(LANGUAGE_CODE="fr"):
  6523. response = self.client.get(url)
  6524. self.assertContains(response, "<label>Toppings\u00A0:</label>", html=True)
  6525. @override_settings(ROOT_URLCONF="admin_views.urls")
  6526. class LimitChoicesToInAdminTest(TestCase):
  6527. @classmethod
  6528. def setUpTestData(cls):
  6529. cls.superuser = User.objects.create_superuser(
  6530. username="super", password="secret", email="super@example.com"
  6531. )
  6532. def setUp(self):
  6533. self.client.force_login(self.superuser)
  6534. def test_limit_choices_to_as_callable(self):
  6535. """Test for ticket 2445 changes to admin."""
  6536. threepwood = Character.objects.create(
  6537. username="threepwood",
  6538. last_action=datetime.datetime.today() + datetime.timedelta(days=1),
  6539. )
  6540. marley = Character.objects.create(
  6541. username="marley",
  6542. last_action=datetime.datetime.today() - datetime.timedelta(days=1),
  6543. )
  6544. response = self.client.get(reverse("admin:admin_views_stumpjoke_add"))
  6545. # The allowed option should appear twice; the limited option should not appear.
  6546. self.assertContains(response, threepwood.username, count=2)
  6547. self.assertNotContains(response, marley.username)
  6548. @override_settings(ROOT_URLCONF="admin_views.urls")
  6549. class RawIdFieldsTest(TestCase):
  6550. @classmethod
  6551. def setUpTestData(cls):
  6552. cls.superuser = User.objects.create_superuser(
  6553. username="super", password="secret", email="super@example.com"
  6554. )
  6555. def setUp(self):
  6556. self.client.force_login(self.superuser)
  6557. def test_limit_choices_to(self):
  6558. """Regression test for 14880"""
  6559. actor = Actor.objects.create(name="Palin", age=27)
  6560. Inquisition.objects.create(expected=True, leader=actor, country="England")
  6561. Inquisition.objects.create(expected=False, leader=actor, country="Spain")
  6562. response = self.client.get(reverse("admin:admin_views_sketch_add"))
  6563. # Find the link
  6564. m = re.search(
  6565. rb'<a href="([^"]*)"[^>]* id="lookup_id_inquisition"', response.content
  6566. )
  6567. self.assertTrue(m) # Got a match
  6568. popup_url = m[1].decode().replace("&amp;", "&")
  6569. # Handle relative links
  6570. popup_url = urljoin(response.request["PATH_INFO"], popup_url)
  6571. # Get the popup and verify the correct objects show up in the resulting
  6572. # page. This step also tests integers, strings and booleans in the
  6573. # lookup query string; in model we define inquisition field to have a
  6574. # limit_choices_to option that includes a filter on a string field
  6575. # (inquisition__actor__name), a filter on an integer field
  6576. # (inquisition__actor__age), and a filter on a boolean field
  6577. # (inquisition__expected).
  6578. response2 = self.client.get(popup_url)
  6579. self.assertContains(response2, "Spain")
  6580. self.assertNotContains(response2, "England")
  6581. def test_limit_choices_to_isnull_false(self):
  6582. """Regression test for 20182"""
  6583. Actor.objects.create(name="Palin", age=27)
  6584. Actor.objects.create(name="Kilbraken", age=50, title="Judge")
  6585. response = self.client.get(reverse("admin:admin_views_sketch_add"))
  6586. # Find the link
  6587. m = re.search(
  6588. rb'<a href="([^"]*)"[^>]* id="lookup_id_defendant0"', response.content
  6589. )
  6590. self.assertTrue(m) # Got a match
  6591. popup_url = m[1].decode().replace("&amp;", "&")
  6592. # Handle relative links
  6593. popup_url = urljoin(response.request["PATH_INFO"], popup_url)
  6594. # Get the popup and verify the correct objects show up in the resulting
  6595. # page. This step tests field__isnull=0 gets parsed correctly from the
  6596. # lookup query string; in model we define defendant0 field to have a
  6597. # limit_choices_to option that includes "actor__title__isnull=False".
  6598. response2 = self.client.get(popup_url)
  6599. self.assertContains(response2, "Kilbraken")
  6600. self.assertNotContains(response2, "Palin")
  6601. def test_limit_choices_to_isnull_true(self):
  6602. """Regression test for 20182"""
  6603. Actor.objects.create(name="Palin", age=27)
  6604. Actor.objects.create(name="Kilbraken", age=50, title="Judge")
  6605. response = self.client.get(reverse("admin:admin_views_sketch_add"))
  6606. # Find the link
  6607. m = re.search(
  6608. rb'<a href="([^"]*)"[^>]* id="lookup_id_defendant1"', response.content
  6609. )
  6610. self.assertTrue(m) # Got a match
  6611. popup_url = m[1].decode().replace("&amp;", "&")
  6612. # Handle relative links
  6613. popup_url = urljoin(response.request["PATH_INFO"], popup_url)
  6614. # Get the popup and verify the correct objects show up in the resulting
  6615. # page. This step tests field__isnull=1 gets parsed correctly from the
  6616. # lookup query string; in model we define defendant1 field to have a
  6617. # limit_choices_to option that includes "actor__title__isnull=True".
  6618. response2 = self.client.get(popup_url)
  6619. self.assertNotContains(response2, "Kilbraken")
  6620. self.assertContains(response2, "Palin")
  6621. def test_list_display_method_same_name_as_reverse_accessor(self):
  6622. """
  6623. Should be able to use a ModelAdmin method in list_display that has the
  6624. same name as a reverse model field ("sketch" in this case).
  6625. """
  6626. actor = Actor.objects.create(name="Palin", age=27)
  6627. Inquisition.objects.create(expected=True, leader=actor, country="England")
  6628. response = self.client.get(reverse("admin:admin_views_inquisition_changelist"))
  6629. self.assertContains(response, "list-display-sketch")
  6630. @override_settings(ROOT_URLCONF="admin_views.urls")
  6631. class UserAdminTest(TestCase):
  6632. """
  6633. Tests user CRUD functionality.
  6634. """
  6635. @classmethod
  6636. def setUpTestData(cls):
  6637. cls.superuser = User.objects.create_superuser(
  6638. username="super", password="secret", email="super@example.com"
  6639. )
  6640. cls.adduser = User.objects.create_user(
  6641. username="adduser", password="secret", is_staff=True
  6642. )
  6643. cls.changeuser = User.objects.create_user(
  6644. username="changeuser", password="secret", is_staff=True
  6645. )
  6646. cls.s1 = Section.objects.create(name="Test section")
  6647. cls.a1 = Article.objects.create(
  6648. content="<p>Middle content</p>",
  6649. date=datetime.datetime(2008, 3, 18, 11, 54, 58),
  6650. section=cls.s1,
  6651. )
  6652. cls.a2 = Article.objects.create(
  6653. content="<p>Oldest content</p>",
  6654. date=datetime.datetime(2000, 3, 18, 11, 54, 58),
  6655. section=cls.s1,
  6656. )
  6657. cls.a3 = Article.objects.create(
  6658. content="<p>Newest content</p>",
  6659. date=datetime.datetime(2009, 3, 18, 11, 54, 58),
  6660. section=cls.s1,
  6661. )
  6662. cls.p1 = PrePopulatedPost.objects.create(
  6663. title="A Long Title", published=True, slug="a-long-title"
  6664. )
  6665. cls.per1 = Person.objects.create(name="John Mauchly", gender=1, alive=True)
  6666. cls.per2 = Person.objects.create(name="Grace Hopper", gender=1, alive=False)
  6667. cls.per3 = Person.objects.create(name="Guido van Rossum", gender=1, alive=True)
  6668. def setUp(self):
  6669. self.client.force_login(self.superuser)
  6670. def test_save_button(self):
  6671. user_count = User.objects.count()
  6672. response = self.client.post(
  6673. reverse("admin:auth_user_add"),
  6674. {
  6675. "username": "newuser",
  6676. "password1": "newpassword",
  6677. "password2": "newpassword",
  6678. },
  6679. )
  6680. new_user = User.objects.get(username="newuser")
  6681. self.assertRedirects(
  6682. response, reverse("admin:auth_user_change", args=(new_user.pk,))
  6683. )
  6684. self.assertEqual(User.objects.count(), user_count + 1)
  6685. self.assertTrue(new_user.has_usable_password())
  6686. def test_save_continue_editing_button(self):
  6687. user_count = User.objects.count()
  6688. response = self.client.post(
  6689. reverse("admin:auth_user_add"),
  6690. {
  6691. "username": "newuser",
  6692. "password1": "newpassword",
  6693. "password2": "newpassword",
  6694. "_continue": "1",
  6695. },
  6696. )
  6697. new_user = User.objects.get(username="newuser")
  6698. new_user_url = reverse("admin:auth_user_change", args=(new_user.pk,))
  6699. self.assertRedirects(response, new_user_url, fetch_redirect_response=False)
  6700. self.assertEqual(User.objects.count(), user_count + 1)
  6701. self.assertTrue(new_user.has_usable_password())
  6702. response = self.client.get(new_user_url)
  6703. self.assertContains(
  6704. response,
  6705. '<li class="success">The user “<a href="%s">'
  6706. "%s</a>” was added successfully. You may edit it again below.</li>"
  6707. % (new_user_url, new_user),
  6708. html=True,
  6709. )
  6710. def test_password_mismatch(self):
  6711. response = self.client.post(
  6712. reverse("admin:auth_user_add"),
  6713. {
  6714. "username": "newuser",
  6715. "password1": "newpassword",
  6716. "password2": "mismatch",
  6717. },
  6718. )
  6719. self.assertEqual(response.status_code, 200)
  6720. self.assertFormError(response.context["adminform"], "password1", [])
  6721. self.assertFormError(
  6722. response.context["adminform"],
  6723. "password2",
  6724. ["The two password fields didn’t match."],
  6725. )
  6726. def test_user_fk_add_popup(self):
  6727. """
  6728. User addition through a FK popup should return the appropriate
  6729. JavaScript response.
  6730. """
  6731. response = self.client.get(reverse("admin:admin_views_album_add"))
  6732. self.assertContains(response, reverse("admin:auth_user_add"))
  6733. self.assertContains(
  6734. response,
  6735. 'class="related-widget-wrapper-link add-related" id="add_id_owner"',
  6736. )
  6737. response = self.client.get(
  6738. reverse("admin:auth_user_add") + "?%s=1" % IS_POPUP_VAR
  6739. )
  6740. self.assertNotContains(response, 'name="_continue"')
  6741. self.assertNotContains(response, 'name="_addanother"')
  6742. data = {
  6743. "username": "newuser",
  6744. "password1": "newpassword",
  6745. "password2": "newpassword",
  6746. IS_POPUP_VAR: "1",
  6747. "_save": "1",
  6748. }
  6749. response = self.client.post(
  6750. reverse("admin:auth_user_add") + "?%s=1" % IS_POPUP_VAR, data, follow=True
  6751. )
  6752. self.assertContains(response, "&quot;obj&quot;: &quot;newuser&quot;")
  6753. def test_user_fk_change_popup(self):
  6754. """
  6755. User change through a FK popup should return the appropriate JavaScript
  6756. response.
  6757. """
  6758. response = self.client.get(reverse("admin:admin_views_album_add"))
  6759. self.assertContains(
  6760. response, reverse("admin:auth_user_change", args=("__fk__",))
  6761. )
  6762. self.assertContains(
  6763. response,
  6764. 'class="related-widget-wrapper-link change-related" id="change_id_owner"',
  6765. )
  6766. user = User.objects.get(username="changeuser")
  6767. url = (
  6768. reverse("admin:auth_user_change", args=(user.pk,)) + "?%s=1" % IS_POPUP_VAR
  6769. )
  6770. response = self.client.get(url)
  6771. self.assertNotContains(response, 'name="_continue"')
  6772. self.assertNotContains(response, 'name="_addanother"')
  6773. data = {
  6774. "username": "newuser",
  6775. "password1": "newpassword",
  6776. "password2": "newpassword",
  6777. "last_login_0": "2007-05-30",
  6778. "last_login_1": "13:20:10",
  6779. "date_joined_0": "2007-05-30",
  6780. "date_joined_1": "13:20:10",
  6781. IS_POPUP_VAR: "1",
  6782. "_save": "1",
  6783. }
  6784. response = self.client.post(url, data, follow=True)
  6785. self.assertContains(response, "&quot;obj&quot;: &quot;newuser&quot;")
  6786. self.assertContains(response, "&quot;action&quot;: &quot;change&quot;")
  6787. def test_user_fk_delete_popup(self):
  6788. """
  6789. User deletion through a FK popup should return the appropriate
  6790. JavaScript response.
  6791. """
  6792. response = self.client.get(reverse("admin:admin_views_album_add"))
  6793. self.assertContains(
  6794. response, reverse("admin:auth_user_delete", args=("__fk__",))
  6795. )
  6796. self.assertContains(
  6797. response,
  6798. 'class="related-widget-wrapper-link change-related" id="change_id_owner"',
  6799. )
  6800. user = User.objects.get(username="changeuser")
  6801. url = (
  6802. reverse("admin:auth_user_delete", args=(user.pk,)) + "?%s=1" % IS_POPUP_VAR
  6803. )
  6804. response = self.client.get(url)
  6805. self.assertEqual(response.status_code, 200)
  6806. data = {
  6807. "post": "yes",
  6808. IS_POPUP_VAR: "1",
  6809. }
  6810. response = self.client.post(url, data, follow=True)
  6811. self.assertContains(response, "&quot;action&quot;: &quot;delete&quot;")
  6812. def test_save_add_another_button(self):
  6813. user_count = User.objects.count()
  6814. response = self.client.post(
  6815. reverse("admin:auth_user_add"),
  6816. {
  6817. "username": "newuser",
  6818. "password1": "newpassword",
  6819. "password2": "newpassword",
  6820. "_addanother": "1",
  6821. },
  6822. )
  6823. new_user = User.objects.order_by("-id")[0]
  6824. self.assertRedirects(response, reverse("admin:auth_user_add"))
  6825. self.assertEqual(User.objects.count(), user_count + 1)
  6826. self.assertTrue(new_user.has_usable_password())
  6827. def test_user_permission_performance(self):
  6828. u = User.objects.all()[0]
  6829. # Don't depend on a warm cache, see #17377.
  6830. ContentType.objects.clear_cache()
  6831. expected_num_queries = 8 if connection.features.uses_savepoints else 6
  6832. with self.assertNumQueries(expected_num_queries):
  6833. response = self.client.get(reverse("admin:auth_user_change", args=(u.pk,)))
  6834. self.assertEqual(response.status_code, 200)
  6835. def test_form_url_present_in_context(self):
  6836. u = User.objects.all()[0]
  6837. response = self.client.get(
  6838. reverse("admin3:auth_user_password_change", args=(u.pk,))
  6839. )
  6840. self.assertEqual(response.status_code, 200)
  6841. self.assertEqual(response.context["form_url"], "pony")
  6842. @override_settings(ROOT_URLCONF="admin_views.urls")
  6843. class GroupAdminTest(TestCase):
  6844. """
  6845. Tests group CRUD functionality.
  6846. """
  6847. @classmethod
  6848. def setUpTestData(cls):
  6849. cls.superuser = User.objects.create_superuser(
  6850. username="super", password="secret", email="super@example.com"
  6851. )
  6852. def setUp(self):
  6853. self.client.force_login(self.superuser)
  6854. def test_save_button(self):
  6855. group_count = Group.objects.count()
  6856. response = self.client.post(
  6857. reverse("admin:auth_group_add"),
  6858. {
  6859. "name": "newgroup",
  6860. },
  6861. )
  6862. Group.objects.order_by("-id")[0]
  6863. self.assertRedirects(response, reverse("admin:auth_group_changelist"))
  6864. self.assertEqual(Group.objects.count(), group_count + 1)
  6865. def test_group_permission_performance(self):
  6866. g = Group.objects.create(name="test_group")
  6867. # Ensure no queries are skipped due to cached content type for Group.
  6868. ContentType.objects.clear_cache()
  6869. expected_num_queries = 6 if connection.features.uses_savepoints else 4
  6870. with self.assertNumQueries(expected_num_queries):
  6871. response = self.client.get(reverse("admin:auth_group_change", args=(g.pk,)))
  6872. self.assertEqual(response.status_code, 200)
  6873. @override_settings(ROOT_URLCONF="admin_views.urls")
  6874. class CSSTest(TestCase):
  6875. @classmethod
  6876. def setUpTestData(cls):
  6877. cls.superuser = User.objects.create_superuser(
  6878. username="super", password="secret", email="super@example.com"
  6879. )
  6880. cls.s1 = Section.objects.create(name="Test section")
  6881. cls.a1 = Article.objects.create(
  6882. content="<p>Middle content</p>",
  6883. date=datetime.datetime(2008, 3, 18, 11, 54, 58),
  6884. section=cls.s1,
  6885. )
  6886. cls.a2 = Article.objects.create(
  6887. content="<p>Oldest content</p>",
  6888. date=datetime.datetime(2000, 3, 18, 11, 54, 58),
  6889. section=cls.s1,
  6890. )
  6891. cls.a3 = Article.objects.create(
  6892. content="<p>Newest content</p>",
  6893. date=datetime.datetime(2009, 3, 18, 11, 54, 58),
  6894. section=cls.s1,
  6895. )
  6896. cls.p1 = PrePopulatedPost.objects.create(
  6897. title="A Long Title", published=True, slug="a-long-title"
  6898. )
  6899. def setUp(self):
  6900. self.client.force_login(self.superuser)
  6901. @ignore_warnings(category=RemovedInDjango60Warning)
  6902. def test_field_prefix_css_classes(self):
  6903. """
  6904. Fields have a CSS class name with a 'field-' prefix.
  6905. """
  6906. response = self.client.get(reverse("admin:admin_views_post_add"))
  6907. # The main form
  6908. self.assertContains(response, 'class="form-row field-title"')
  6909. self.assertContains(response, 'class="form-row field-content"')
  6910. self.assertContains(response, 'class="form-row field-public"')
  6911. self.assertContains(response, 'class="form-row field-awesomeness_level"')
  6912. self.assertContains(response, 'class="form-row field-coolness"')
  6913. self.assertContains(response, 'class="form-row field-value"')
  6914. self.assertContains(response, 'class="form-row"') # The lambda function
  6915. # The tabular inline
  6916. self.assertContains(response, '<td class="field-url">')
  6917. self.assertContains(response, '<td class="field-posted">')
  6918. def test_index_css_classes(self):
  6919. """
  6920. CSS class names are used for each app and model on the admin index
  6921. pages (#17050).
  6922. """
  6923. # General index page
  6924. response = self.client.get(reverse("admin:index"))
  6925. self.assertContains(response, '<div class="app-admin_views module')
  6926. self.assertContains(
  6927. response,
  6928. '<thead class="visually-hidden"><tr><th scope="col">Model name</th>'
  6929. '<th scope="col">Add link</th><th scope="col">Change or view list link</th>'
  6930. "</tr></thead>",
  6931. html=True,
  6932. )
  6933. self.assertContains(response, '<tr class="model-actor">')
  6934. self.assertContains(response, '<tr class="model-album">')
  6935. # App index page
  6936. response = self.client.get(reverse("admin:app_list", args=("admin_views",)))
  6937. self.assertContains(response, '<div class="app-admin_views module')
  6938. self.assertContains(
  6939. response,
  6940. '<thead class="visually-hidden"><tr><th scope="col">Model name</th>'
  6941. '<th scope="col">Add link</th><th scope="col">Change or view list link</th>'
  6942. "</tr></thead>",
  6943. html=True,
  6944. )
  6945. self.assertContains(response, '<tr class="model-actor">')
  6946. self.assertContains(response, '<tr class="model-album">')
  6947. def test_app_model_in_form_body_class(self):
  6948. """
  6949. Ensure app and model tag are correctly read by change_form template
  6950. """
  6951. response = self.client.get(reverse("admin:admin_views_section_add"))
  6952. self.assertContains(response, '<body class=" app-admin_views model-section ')
  6953. def test_app_model_in_list_body_class(self):
  6954. """
  6955. Ensure app and model tag are correctly read by change_list template
  6956. """
  6957. response = self.client.get(reverse("admin:admin_views_section_changelist"))
  6958. self.assertContains(response, '<body class=" app-admin_views model-section ')
  6959. def test_app_model_in_delete_confirmation_body_class(self):
  6960. """
  6961. Ensure app and model tag are correctly read by delete_confirmation
  6962. template
  6963. """
  6964. response = self.client.get(
  6965. reverse("admin:admin_views_section_delete", args=(self.s1.pk,))
  6966. )
  6967. self.assertContains(response, '<body class=" app-admin_views model-section ')
  6968. def test_app_model_in_app_index_body_class(self):
  6969. """
  6970. Ensure app and model tag are correctly read by app_index template
  6971. """
  6972. response = self.client.get(reverse("admin:app_list", args=("admin_views",)))
  6973. self.assertContains(response, '<body class=" dashboard app-admin_views')
  6974. def test_app_model_in_delete_selected_confirmation_body_class(self):
  6975. """
  6976. Ensure app and model tag are correctly read by
  6977. delete_selected_confirmation template
  6978. """
  6979. action_data = {
  6980. ACTION_CHECKBOX_NAME: [self.s1.pk],
  6981. "action": "delete_selected",
  6982. "index": 0,
  6983. }
  6984. response = self.client.post(
  6985. reverse("admin:admin_views_section_changelist"), action_data
  6986. )
  6987. self.assertContains(response, '<body class=" app-admin_views model-section ')
  6988. def test_changelist_field_classes(self):
  6989. """
  6990. Cells of the change list table should contain the field name in their
  6991. class attribute.
  6992. """
  6993. Podcast.objects.create(name="Django Dose", release_date=datetime.date.today())
  6994. response = self.client.get(reverse("admin:admin_views_podcast_changelist"))
  6995. self.assertContains(response, '<th class="field-name">')
  6996. self.assertContains(response, '<td class="field-release_date nowrap">')
  6997. self.assertContains(response, '<td class="action-checkbox">')
  6998. try:
  6999. import docutils
  7000. except ImportError:
  7001. docutils = None
  7002. @unittest.skipUnless(docutils, "no docutils installed.")
  7003. @override_settings(ROOT_URLCONF="admin_views.urls")
  7004. @modify_settings(
  7005. INSTALLED_APPS={"append": ["django.contrib.admindocs", "django.contrib.flatpages"]}
  7006. )
  7007. class AdminDocsTest(TestCase):
  7008. @classmethod
  7009. def setUpTestData(cls):
  7010. cls.superuser = User.objects.create_superuser(
  7011. username="super", password="secret", email="super@example.com"
  7012. )
  7013. def setUp(self):
  7014. self.client.force_login(self.superuser)
  7015. def test_tags(self):
  7016. response = self.client.get(reverse("django-admindocs-tags"))
  7017. # The builtin tag group exists
  7018. self.assertContains(response, "<h2>Built-in tags</h2>", count=2, html=True)
  7019. # A builtin tag exists in both the index and detail
  7020. self.assertContains(
  7021. response, '<h3 id="built_in-autoescape">autoescape</h3>', html=True
  7022. )
  7023. self.assertContains(
  7024. response,
  7025. '<li><a href="#built_in-autoescape">autoescape</a></li>',
  7026. html=True,
  7027. )
  7028. # An app tag exists in both the index and detail
  7029. self.assertContains(
  7030. response, '<h3 id="flatpages-get_flatpages">get_flatpages</h3>', html=True
  7031. )
  7032. self.assertContains(
  7033. response,
  7034. '<li><a href="#flatpages-get_flatpages">get_flatpages</a></li>',
  7035. html=True,
  7036. )
  7037. # The admin list tag group exists
  7038. self.assertContains(response, "<h2>admin_list</h2>", count=2, html=True)
  7039. # An admin list tag exists in both the index and detail
  7040. self.assertContains(
  7041. response, '<h3 id="admin_list-admin_actions">admin_actions</h3>', html=True
  7042. )
  7043. self.assertContains(
  7044. response,
  7045. '<li><a href="#admin_list-admin_actions">admin_actions</a></li>',
  7046. html=True,
  7047. )
  7048. def test_filters(self):
  7049. response = self.client.get(reverse("django-admindocs-filters"))
  7050. # The builtin filter group exists
  7051. self.assertContains(response, "<h2>Built-in filters</h2>", count=2, html=True)
  7052. # A builtin filter exists in both the index and detail
  7053. self.assertContains(response, '<h3 id="built_in-add">add</h3>', html=True)
  7054. self.assertContains(
  7055. response, '<li><a href="#built_in-add">add</a></li>', html=True
  7056. )
  7057. def test_index_headers(self):
  7058. response = self.client.get(reverse("django-admindocs-docroot"))
  7059. self.assertContains(response, "<h1>Documentation</h1>")
  7060. self.assertContains(response, '<h2><a href="tags/">Tags</a></h2>')
  7061. self.assertContains(response, '<h2><a href="filters/">Filters</a></h2>')
  7062. self.assertContains(response, '<h2><a href="models/">Models</a></h2>')
  7063. self.assertContains(response, '<h2><a href="views/">Views</a></h2>')
  7064. self.assertContains(
  7065. response, '<h2><a href="bookmarklets/">Bookmarklets</a></h2>'
  7066. )
  7067. @override_settings(
  7068. ROOT_URLCONF="admin_views.urls",
  7069. TEMPLATES=[
  7070. {
  7071. "BACKEND": "django.template.backends.django.DjangoTemplates",
  7072. "APP_DIRS": True,
  7073. "OPTIONS": {
  7074. "context_processors": [
  7075. "django.template.context_processors.request",
  7076. "django.contrib.auth.context_processors.auth",
  7077. "django.contrib.messages.context_processors.messages",
  7078. ],
  7079. },
  7080. }
  7081. ],
  7082. )
  7083. class ValidXHTMLTests(TestCase):
  7084. @classmethod
  7085. def setUpTestData(cls):
  7086. cls.superuser = User.objects.create_superuser(
  7087. username="super", password="secret", email="super@example.com"
  7088. )
  7089. def setUp(self):
  7090. self.client.force_login(self.superuser)
  7091. def test_lang_name_present(self):
  7092. with translation.override(None):
  7093. response = self.client.get(reverse("admin:app_list", args=("admin_views",)))
  7094. self.assertNotContains(response, ' lang=""')
  7095. self.assertNotContains(response, ' xml:lang=""')
  7096. @override_settings(ROOT_URLCONF="admin_views.urls", USE_THOUSAND_SEPARATOR=True)
  7097. class DateHierarchyTests(TestCase):
  7098. @classmethod
  7099. def setUpTestData(cls):
  7100. cls.superuser = User.objects.create_superuser(
  7101. username="super", password="secret", email="super@example.com"
  7102. )
  7103. def setUp(self):
  7104. self.client.force_login(self.superuser)
  7105. def assert_non_localized_year(self, response, year):
  7106. """
  7107. The year is not localized with USE_THOUSAND_SEPARATOR (#15234).
  7108. """
  7109. self.assertNotContains(response, formats.number_format(year))
  7110. def assert_contains_year_link(self, response, date):
  7111. self.assertContains(response, '?release_date__year=%d"' % date.year)
  7112. def assert_contains_month_link(self, response, date):
  7113. self.assertContains(
  7114. response,
  7115. '?release_date__month=%d&amp;release_date__year=%d"'
  7116. % (date.month, date.year),
  7117. )
  7118. def assert_contains_day_link(self, response, date):
  7119. self.assertContains(
  7120. response,
  7121. "?release_date__day=%d&amp;"
  7122. 'release_date__month=%d&amp;release_date__year=%d"'
  7123. % (date.day, date.month, date.year),
  7124. )
  7125. def test_empty(self):
  7126. """
  7127. No date hierarchy links display with empty changelist.
  7128. """
  7129. response = self.client.get(reverse("admin:admin_views_podcast_changelist"))
  7130. self.assertNotContains(response, "release_date__year=")
  7131. self.assertNotContains(response, "release_date__month=")
  7132. self.assertNotContains(response, "release_date__day=")
  7133. def test_single(self):
  7134. """
  7135. Single day-level date hierarchy appears for single object.
  7136. """
  7137. DATE = datetime.date(2000, 6, 30)
  7138. Podcast.objects.create(release_date=DATE)
  7139. url = reverse("admin:admin_views_podcast_changelist")
  7140. response = self.client.get(url)
  7141. self.assert_contains_day_link(response, DATE)
  7142. self.assert_non_localized_year(response, 2000)
  7143. def test_within_month(self):
  7144. """
  7145. day-level links appear for changelist within single month.
  7146. """
  7147. DATES = (
  7148. datetime.date(2000, 6, 30),
  7149. datetime.date(2000, 6, 15),
  7150. datetime.date(2000, 6, 3),
  7151. )
  7152. for date in DATES:
  7153. Podcast.objects.create(release_date=date)
  7154. url = reverse("admin:admin_views_podcast_changelist")
  7155. response = self.client.get(url)
  7156. for date in DATES:
  7157. self.assert_contains_day_link(response, date)
  7158. self.assert_non_localized_year(response, 2000)
  7159. def test_within_year(self):
  7160. """
  7161. month-level links appear for changelist within single year.
  7162. """
  7163. DATES = (
  7164. datetime.date(2000, 1, 30),
  7165. datetime.date(2000, 3, 15),
  7166. datetime.date(2000, 5, 3),
  7167. )
  7168. for date in DATES:
  7169. Podcast.objects.create(release_date=date)
  7170. url = reverse("admin:admin_views_podcast_changelist")
  7171. response = self.client.get(url)
  7172. # no day-level links
  7173. self.assertNotContains(response, "release_date__day=")
  7174. for date in DATES:
  7175. self.assert_contains_month_link(response, date)
  7176. self.assert_non_localized_year(response, 2000)
  7177. def test_multiple_years(self):
  7178. """
  7179. year-level links appear for year-spanning changelist.
  7180. """
  7181. DATES = (
  7182. datetime.date(2001, 1, 30),
  7183. datetime.date(2003, 3, 15),
  7184. datetime.date(2005, 5, 3),
  7185. )
  7186. for date in DATES:
  7187. Podcast.objects.create(release_date=date)
  7188. response = self.client.get(reverse("admin:admin_views_podcast_changelist"))
  7189. # no day/month-level links
  7190. self.assertNotContains(response, "release_date__day=")
  7191. self.assertNotContains(response, "release_date__month=")
  7192. for date in DATES:
  7193. self.assert_contains_year_link(response, date)
  7194. # and make sure GET parameters still behave correctly
  7195. for date in DATES:
  7196. url = "%s?release_date__year=%d" % (
  7197. reverse("admin:admin_views_podcast_changelist"),
  7198. date.year,
  7199. )
  7200. response = self.client.get(url)
  7201. self.assert_contains_month_link(response, date)
  7202. self.assert_non_localized_year(response, 2000)
  7203. self.assert_non_localized_year(response, 2003)
  7204. self.assert_non_localized_year(response, 2005)
  7205. url = "%s?release_date__year=%d&release_date__month=%d" % (
  7206. reverse("admin:admin_views_podcast_changelist"),
  7207. date.year,
  7208. date.month,
  7209. )
  7210. response = self.client.get(url)
  7211. self.assert_contains_day_link(response, date)
  7212. self.assert_non_localized_year(response, 2000)
  7213. self.assert_non_localized_year(response, 2003)
  7214. self.assert_non_localized_year(response, 2005)
  7215. def test_related_field(self):
  7216. questions_data = (
  7217. # (posted data, number of answers),
  7218. (datetime.date(2001, 1, 30), 0),
  7219. (datetime.date(2003, 3, 15), 1),
  7220. (datetime.date(2005, 5, 3), 2),
  7221. )
  7222. for date, answer_count in questions_data:
  7223. question = Question.objects.create(posted=date)
  7224. for i in range(answer_count):
  7225. question.answer_set.create()
  7226. response = self.client.get(reverse("admin:admin_views_answer_changelist"))
  7227. for date, answer_count in questions_data:
  7228. link = '?question__posted__year=%d"' % date.year
  7229. if answer_count > 0:
  7230. self.assertContains(response, link)
  7231. else:
  7232. self.assertNotContains(response, link)
  7233. @override_settings(ROOT_URLCONF="admin_views.urls")
  7234. class AdminCustomSaveRelatedTests(TestCase):
  7235. """
  7236. One can easily customize the way related objects are saved.
  7237. Refs #16115.
  7238. """
  7239. @classmethod
  7240. def setUpTestData(cls):
  7241. cls.superuser = User.objects.create_superuser(
  7242. username="super", password="secret", email="super@example.com"
  7243. )
  7244. def setUp(self):
  7245. self.client.force_login(self.superuser)
  7246. def test_should_be_able_to_edit_related_objects_on_add_view(self):
  7247. post = {
  7248. "child_set-TOTAL_FORMS": "3",
  7249. "child_set-INITIAL_FORMS": "0",
  7250. "name": "Josh Stone",
  7251. "child_set-0-name": "Paul",
  7252. "child_set-1-name": "Catherine",
  7253. }
  7254. self.client.post(reverse("admin:admin_views_parent_add"), post)
  7255. self.assertEqual(1, Parent.objects.count())
  7256. self.assertEqual(2, Child.objects.count())
  7257. children_names = list(
  7258. Child.objects.order_by("name").values_list("name", flat=True)
  7259. )
  7260. self.assertEqual("Josh Stone", Parent.objects.latest("id").name)
  7261. self.assertEqual(["Catherine Stone", "Paul Stone"], children_names)
  7262. def test_should_be_able_to_edit_related_objects_on_change_view(self):
  7263. parent = Parent.objects.create(name="Josh Stone")
  7264. paul = Child.objects.create(parent=parent, name="Paul")
  7265. catherine = Child.objects.create(parent=parent, name="Catherine")
  7266. post = {
  7267. "child_set-TOTAL_FORMS": "5",
  7268. "child_set-INITIAL_FORMS": "2",
  7269. "name": "Josh Stone",
  7270. "child_set-0-name": "Paul",
  7271. "child_set-0-id": paul.id,
  7272. "child_set-1-name": "Catherine",
  7273. "child_set-1-id": catherine.id,
  7274. }
  7275. self.client.post(
  7276. reverse("admin:admin_views_parent_change", args=(parent.id,)), post
  7277. )
  7278. children_names = list(
  7279. Child.objects.order_by("name").values_list("name", flat=True)
  7280. )
  7281. self.assertEqual("Josh Stone", Parent.objects.latest("id").name)
  7282. self.assertEqual(["Catherine Stone", "Paul Stone"], children_names)
  7283. def test_should_be_able_to_edit_related_objects_on_changelist_view(self):
  7284. parent = Parent.objects.create(name="Josh Rock")
  7285. Child.objects.create(parent=parent, name="Paul")
  7286. Child.objects.create(parent=parent, name="Catherine")
  7287. post = {
  7288. "form-TOTAL_FORMS": "1",
  7289. "form-INITIAL_FORMS": "1",
  7290. "form-MAX_NUM_FORMS": "0",
  7291. "form-0-id": parent.id,
  7292. "form-0-name": "Josh Stone",
  7293. "_save": "Save",
  7294. }
  7295. self.client.post(reverse("admin:admin_views_parent_changelist"), post)
  7296. children_names = list(
  7297. Child.objects.order_by("name").values_list("name", flat=True)
  7298. )
  7299. self.assertEqual("Josh Stone", Parent.objects.latest("id").name)
  7300. self.assertEqual(["Catherine Stone", "Paul Stone"], children_names)
  7301. @override_settings(ROOT_URLCONF="admin_views.urls")
  7302. class AdminViewLogoutTests(TestCase):
  7303. @classmethod
  7304. def setUpTestData(cls):
  7305. cls.superuser = User.objects.create_superuser(
  7306. username="super", password="secret", email="super@example.com"
  7307. )
  7308. def test_logout(self):
  7309. self.client.force_login(self.superuser)
  7310. response = self.client.post(reverse("admin:logout"))
  7311. self.assertEqual(response.status_code, 200)
  7312. self.assertTemplateUsed(response, "registration/logged_out.html")
  7313. self.assertEqual(response.request["PATH_INFO"], reverse("admin:logout"))
  7314. self.assertFalse(response.context["has_permission"])
  7315. self.assertNotContains(
  7316. response, "user-tools"
  7317. ) # user-tools div shouldn't visible.
  7318. def test_client_logout_url_can_be_used_to_login(self):
  7319. response = self.client.post(reverse("admin:logout"))
  7320. self.assertEqual(
  7321. response.status_code, 302
  7322. ) # we should be redirected to the login page.
  7323. # follow the redirect and test results.
  7324. response = self.client.post(reverse("admin:logout"), follow=True)
  7325. self.assertContains(
  7326. response,
  7327. '<input type="hidden" name="next" value="%s">' % reverse("admin:index"),
  7328. )
  7329. self.assertTemplateUsed(response, "admin/login.html")
  7330. self.assertEqual(response.request["PATH_INFO"], reverse("admin:login"))
  7331. @override_settings(ROOT_URLCONF="admin_views.urls")
  7332. class AdminUserMessageTest(TestCase):
  7333. @classmethod
  7334. def setUpTestData(cls):
  7335. cls.superuser = User.objects.create_superuser(
  7336. username="super", password="secret", email="super@example.com"
  7337. )
  7338. def setUp(self):
  7339. self.client.force_login(self.superuser)
  7340. def send_message(self, level):
  7341. """
  7342. Helper that sends a post to the dummy test methods and asserts that a
  7343. message with the level has appeared in the response.
  7344. """
  7345. action_data = {
  7346. ACTION_CHECKBOX_NAME: [1],
  7347. "action": "message_%s" % level,
  7348. "index": 0,
  7349. }
  7350. response = self.client.post(
  7351. reverse("admin:admin_views_usermessenger_changelist"),
  7352. action_data,
  7353. follow=True,
  7354. )
  7355. self.assertContains(
  7356. response, '<li class="%s">Test %s</li>' % (level, level), html=True
  7357. )
  7358. @override_settings(MESSAGE_LEVEL=10) # Set to DEBUG for this request
  7359. def test_message_debug(self):
  7360. self.send_message("debug")
  7361. def test_message_info(self):
  7362. self.send_message("info")
  7363. def test_message_success(self):
  7364. self.send_message("success")
  7365. def test_message_warning(self):
  7366. self.send_message("warning")
  7367. def test_message_error(self):
  7368. self.send_message("error")
  7369. def test_message_extra_tags(self):
  7370. action_data = {
  7371. ACTION_CHECKBOX_NAME: [1],
  7372. "action": "message_extra_tags",
  7373. "index": 0,
  7374. }
  7375. response = self.client.post(
  7376. reverse("admin:admin_views_usermessenger_changelist"),
  7377. action_data,
  7378. follow=True,
  7379. )
  7380. self.assertContains(
  7381. response, '<li class="extra_tag info">Test tags</li>', html=True
  7382. )
  7383. @override_settings(ROOT_URLCONF="admin_views.urls")
  7384. class AdminKeepChangeListFiltersTests(TestCase):
  7385. admin_site = site
  7386. @classmethod
  7387. def setUpTestData(cls):
  7388. cls.superuser = User.objects.create_superuser(
  7389. username="super", password="secret", email="super@example.com"
  7390. )
  7391. cls.joepublicuser = User.objects.create_user(
  7392. username="joepublic", password="secret"
  7393. )
  7394. def setUp(self):
  7395. self.client.force_login(self.superuser)
  7396. def assertURLEqual(self, url1, url2, msg_prefix=""):
  7397. """
  7398. Assert that two URLs are equal despite the ordering
  7399. of their querystring. Refs #22360.
  7400. """
  7401. parsed_url1 = urlsplit(url1)
  7402. path1 = parsed_url1.path
  7403. parsed_qs1 = dict(parse_qsl(parsed_url1.query))
  7404. parsed_url2 = urlsplit(url2)
  7405. path2 = parsed_url2.path
  7406. parsed_qs2 = dict(parse_qsl(parsed_url2.query))
  7407. for parsed_qs in [parsed_qs1, parsed_qs2]:
  7408. if "_changelist_filters" in parsed_qs:
  7409. changelist_filters = parsed_qs["_changelist_filters"]
  7410. parsed_filters = dict(parse_qsl(changelist_filters))
  7411. parsed_qs["_changelist_filters"] = parsed_filters
  7412. self.assertEqual(path1, path2)
  7413. self.assertEqual(parsed_qs1, parsed_qs2)
  7414. def test_assert_url_equal(self):
  7415. # Test equality.
  7416. change_user_url = reverse(
  7417. "admin:auth_user_change", args=(self.joepublicuser.pk,)
  7418. )
  7419. self.assertURLEqual(
  7420. "http://testserver{}?_changelist_filters="
  7421. "is_staff__exact%3D0%26is_superuser__exact%3D0".format(change_user_url),
  7422. "http://testserver{}?_changelist_filters="
  7423. "is_staff__exact%3D0%26is_superuser__exact%3D0".format(change_user_url),
  7424. )
  7425. # Test inequality.
  7426. with self.assertRaises(AssertionError):
  7427. self.assertURLEqual(
  7428. "http://testserver{}?_changelist_filters="
  7429. "is_staff__exact%3D0%26is_superuser__exact%3D0".format(change_user_url),
  7430. "http://testserver{}?_changelist_filters="
  7431. "is_staff__exact%3D1%26is_superuser__exact%3D1".format(change_user_url),
  7432. )
  7433. # Ignore scheme and host.
  7434. self.assertURLEqual(
  7435. "http://testserver{}?_changelist_filters="
  7436. "is_staff__exact%3D0%26is_superuser__exact%3D0".format(change_user_url),
  7437. "{}?_changelist_filters="
  7438. "is_staff__exact%3D0%26is_superuser__exact%3D0".format(change_user_url),
  7439. )
  7440. # Ignore ordering of querystring.
  7441. self.assertURLEqual(
  7442. "{}?is_staff__exact=0&is_superuser__exact=0".format(
  7443. reverse("admin:auth_user_changelist")
  7444. ),
  7445. "{}?is_superuser__exact=0&is_staff__exact=0".format(
  7446. reverse("admin:auth_user_changelist")
  7447. ),
  7448. )
  7449. # Ignore ordering of _changelist_filters.
  7450. self.assertURLEqual(
  7451. "{}?_changelist_filters="
  7452. "is_staff__exact%3D0%26is_superuser__exact%3D0".format(change_user_url),
  7453. "{}?_changelist_filters="
  7454. "is_superuser__exact%3D0%26is_staff__exact%3D0".format(change_user_url),
  7455. )
  7456. def get_changelist_filters(self):
  7457. return {
  7458. "is_superuser__exact": 0,
  7459. "is_staff__exact": 0,
  7460. }
  7461. def get_changelist_filters_querystring(self):
  7462. return urlencode(self.get_changelist_filters())
  7463. def get_preserved_filters_querystring(self):
  7464. return urlencode(
  7465. {"_changelist_filters": self.get_changelist_filters_querystring()}
  7466. )
  7467. def get_sample_user_id(self):
  7468. return self.joepublicuser.pk
  7469. def get_changelist_url(self):
  7470. return "%s?%s" % (
  7471. reverse("admin:auth_user_changelist", current_app=self.admin_site.name),
  7472. self.get_changelist_filters_querystring(),
  7473. )
  7474. def get_add_url(self, add_preserved_filters=True):
  7475. url = reverse("admin:auth_user_add", current_app=self.admin_site.name)
  7476. if add_preserved_filters:
  7477. url = "%s?%s" % (url, self.get_preserved_filters_querystring())
  7478. return url
  7479. def get_change_url(self, user_id=None, add_preserved_filters=True):
  7480. if user_id is None:
  7481. user_id = self.get_sample_user_id()
  7482. url = reverse(
  7483. "admin:auth_user_change", args=(user_id,), current_app=self.admin_site.name
  7484. )
  7485. if add_preserved_filters:
  7486. url = "%s?%s" % (url, self.get_preserved_filters_querystring())
  7487. return url
  7488. def get_history_url(self, user_id=None):
  7489. if user_id is None:
  7490. user_id = self.get_sample_user_id()
  7491. return "%s?%s" % (
  7492. reverse(
  7493. "admin:auth_user_history",
  7494. args=(user_id,),
  7495. current_app=self.admin_site.name,
  7496. ),
  7497. self.get_preserved_filters_querystring(),
  7498. )
  7499. def get_delete_url(self, user_id=None):
  7500. if user_id is None:
  7501. user_id = self.get_sample_user_id()
  7502. return "%s?%s" % (
  7503. reverse(
  7504. "admin:auth_user_delete",
  7505. args=(user_id,),
  7506. current_app=self.admin_site.name,
  7507. ),
  7508. self.get_preserved_filters_querystring(),
  7509. )
  7510. def test_changelist_view(self):
  7511. response = self.client.get(self.get_changelist_url())
  7512. self.assertEqual(response.status_code, 200)
  7513. # Check the `change_view` link has the correct querystring.
  7514. detail_link = re.search(
  7515. '<a href="(.*?)">{}</a>'.format(self.joepublicuser.username),
  7516. response.text,
  7517. )
  7518. self.assertURLEqual(detail_link[1], self.get_change_url())
  7519. def test_change_view(self):
  7520. # Get the `change_view`.
  7521. response = self.client.get(self.get_change_url())
  7522. self.assertEqual(response.status_code, 200)
  7523. # Check the form action.
  7524. form_action = re.search(
  7525. '<form action="(.*?)" method="post" id="user_form" novalidate>',
  7526. response.text,
  7527. )
  7528. self.assertURLEqual(
  7529. form_action[1], "?%s" % self.get_preserved_filters_querystring()
  7530. )
  7531. # Check the history link.
  7532. history_link = re.search(
  7533. '<a href="(.*?)" class="historylink">History</a>', response.text
  7534. )
  7535. self.assertURLEqual(history_link[1], self.get_history_url())
  7536. # Check the delete link.
  7537. delete_link = re.search(
  7538. '<a href="(.*?)" class="deletelink">Delete</a>', response.text
  7539. )
  7540. self.assertURLEqual(delete_link[1], self.get_delete_url())
  7541. # Test redirect on "Save".
  7542. post_data = {
  7543. "username": "joepublic",
  7544. "last_login_0": "2007-05-30",
  7545. "last_login_1": "13:20:10",
  7546. "date_joined_0": "2007-05-30",
  7547. "date_joined_1": "13:20:10",
  7548. }
  7549. post_data["_save"] = 1
  7550. response = self.client.post(self.get_change_url(), data=post_data)
  7551. self.assertRedirects(response, self.get_changelist_url())
  7552. post_data.pop("_save")
  7553. # Test redirect on "Save and continue".
  7554. post_data["_continue"] = 1
  7555. response = self.client.post(self.get_change_url(), data=post_data)
  7556. self.assertRedirects(response, self.get_change_url())
  7557. post_data.pop("_continue")
  7558. # Test redirect on "Save and add new".
  7559. post_data["_addanother"] = 1
  7560. response = self.client.post(self.get_change_url(), data=post_data)
  7561. self.assertRedirects(response, self.get_add_url())
  7562. post_data.pop("_addanother")
  7563. def test_change_view_close_link(self):
  7564. viewuser = User.objects.create_user(
  7565. username="view", password="secret", is_staff=True
  7566. )
  7567. viewuser.user_permissions.add(
  7568. get_perm(User, get_permission_codename("view", User._meta))
  7569. )
  7570. self.client.force_login(viewuser)
  7571. response = self.client.get(self.get_change_url())
  7572. close_link = re.search(
  7573. '<a href="(.*?)" class="closelink">Close</a>', response.text
  7574. )
  7575. close_link = close_link[1].replace("&amp;", "&")
  7576. self.assertURLEqual(close_link, self.get_changelist_url())
  7577. def test_change_view_without_preserved_filters(self):
  7578. response = self.client.get(self.get_change_url(add_preserved_filters=False))
  7579. # The action attribute is omitted.
  7580. self.assertContains(response, '<form method="post" id="user_form" novalidate>')
  7581. def test_add_view(self):
  7582. # Get the `add_view`.
  7583. response = self.client.get(self.get_add_url())
  7584. self.assertEqual(response.status_code, 200)
  7585. # Check the form action.
  7586. form_action = re.search(
  7587. '<form action="(.*?)" method="post" id="user_form" novalidate>',
  7588. response.text,
  7589. )
  7590. self.assertURLEqual(
  7591. form_action[1], "?%s" % self.get_preserved_filters_querystring()
  7592. )
  7593. post_data = {
  7594. "username": "dummy",
  7595. "password1": "test",
  7596. "password2": "test",
  7597. }
  7598. # Test redirect on "Save".
  7599. post_data["_save"] = 1
  7600. response = self.client.post(self.get_add_url(), data=post_data)
  7601. self.assertRedirects(
  7602. response, self.get_change_url(User.objects.get(username="dummy").pk)
  7603. )
  7604. post_data.pop("_save")
  7605. # Test redirect on "Save and continue".
  7606. post_data["username"] = "dummy2"
  7607. post_data["_continue"] = 1
  7608. response = self.client.post(self.get_add_url(), data=post_data)
  7609. self.assertRedirects(
  7610. response, self.get_change_url(User.objects.get(username="dummy2").pk)
  7611. )
  7612. post_data.pop("_continue")
  7613. # Test redirect on "Save and add new".
  7614. post_data["username"] = "dummy3"
  7615. post_data["_addanother"] = 1
  7616. response = self.client.post(self.get_add_url(), data=post_data)
  7617. self.assertRedirects(response, self.get_add_url())
  7618. post_data.pop("_addanother")
  7619. def test_add_view_without_preserved_filters(self):
  7620. response = self.client.get(self.get_add_url(add_preserved_filters=False))
  7621. # The action attribute is omitted.
  7622. self.assertContains(response, '<form method="post" id="user_form" novalidate>')
  7623. def test_delete_view(self):
  7624. # Test redirect on "Delete".
  7625. response = self.client.post(self.get_delete_url(), {"post": "yes"})
  7626. self.assertRedirects(response, self.get_changelist_url())
  7627. def test_url_prefix(self):
  7628. context = {
  7629. "preserved_filters": self.get_preserved_filters_querystring(),
  7630. "opts": User._meta,
  7631. }
  7632. prefixes = ("", "/prefix/", "/後台/")
  7633. for prefix in prefixes:
  7634. with self.subTest(prefix=prefix), override_script_prefix(prefix):
  7635. url = reverse(
  7636. "admin:auth_user_changelist", current_app=self.admin_site.name
  7637. )
  7638. self.assertURLEqual(
  7639. self.get_changelist_url(),
  7640. add_preserved_filters(context, url),
  7641. )
  7642. class NamespacedAdminKeepChangeListFiltersTests(AdminKeepChangeListFiltersTests):
  7643. admin_site = site2
  7644. @override_settings(ROOT_URLCONF="admin_views.urls")
  7645. class TestLabelVisibility(TestCase):
  7646. """#11277 -Labels of hidden fields in admin were not hidden."""
  7647. @classmethod
  7648. def setUpTestData(cls):
  7649. cls.superuser = User.objects.create_superuser(
  7650. username="super", password="secret", email="super@example.com"
  7651. )
  7652. def setUp(self):
  7653. self.client.force_login(self.superuser)
  7654. def test_all_fields_visible(self):
  7655. response = self.client.get(reverse("admin:admin_views_emptymodelvisible_add"))
  7656. self.assert_fieldline_visible(response)
  7657. self.assert_field_visible(response, "first")
  7658. self.assert_field_visible(response, "second")
  7659. def test_all_fields_hidden(self):
  7660. response = self.client.get(reverse("admin:admin_views_emptymodelhidden_add"))
  7661. self.assert_fieldline_hidden(response)
  7662. self.assert_field_hidden(response, "first")
  7663. self.assert_field_hidden(response, "second")
  7664. def test_mixin(self):
  7665. response = self.client.get(reverse("admin:admin_views_emptymodelmixin_add"))
  7666. self.assert_fieldline_visible(response)
  7667. self.assert_field_hidden(response, "first")
  7668. self.assert_field_visible(response, "second")
  7669. def assert_field_visible(self, response, field_name):
  7670. self.assertContains(
  7671. response, f'<div class="flex-container fieldBox field-{field_name}">'
  7672. )
  7673. def assert_field_hidden(self, response, field_name):
  7674. self.assertContains(
  7675. response, f'<div class="flex-container fieldBox field-{field_name} hidden">'
  7676. )
  7677. def assert_fieldline_visible(self, response):
  7678. self.assertContains(response, '<div class="form-row field-first field-second">')
  7679. def assert_fieldline_hidden(self, response):
  7680. self.assertContains(response, '<div class="form-row hidden')
  7681. @override_settings(ROOT_URLCONF="admin_views.urls")
  7682. class AdminViewOnSiteTests(TestCase):
  7683. @classmethod
  7684. def setUpTestData(cls):
  7685. cls.superuser = User.objects.create_superuser(
  7686. username="super", password="secret", email="super@example.com"
  7687. )
  7688. cls.s1 = State.objects.create(name="New York")
  7689. cls.s2 = State.objects.create(name="Illinois")
  7690. cls.s3 = State.objects.create(name="California")
  7691. cls.c1 = City.objects.create(state=cls.s1, name="New York")
  7692. cls.c2 = City.objects.create(state=cls.s2, name="Chicago")
  7693. cls.c3 = City.objects.create(state=cls.s3, name="San Francisco")
  7694. cls.r1 = Restaurant.objects.create(city=cls.c1, name="Italian Pizza")
  7695. cls.r2 = Restaurant.objects.create(city=cls.c1, name="Boulevard")
  7696. cls.r3 = Restaurant.objects.create(city=cls.c2, name="Chinese Dinner")
  7697. cls.r4 = Restaurant.objects.create(city=cls.c2, name="Angels")
  7698. cls.r5 = Restaurant.objects.create(city=cls.c2, name="Take Away")
  7699. cls.r6 = Restaurant.objects.create(city=cls.c3, name="The Unknown Restaurant")
  7700. cls.w1 = Worker.objects.create(work_at=cls.r1, name="Mario", surname="Rossi")
  7701. cls.w2 = Worker.objects.create(
  7702. work_at=cls.r1, name="Antonio", surname="Bianchi"
  7703. )
  7704. cls.w3 = Worker.objects.create(work_at=cls.r1, name="John", surname="Doe")
  7705. def setUp(self):
  7706. self.client.force_login(self.superuser)
  7707. def test_add_view_form_and_formsets_run_validation(self):
  7708. """
  7709. Issue #20522
  7710. Verifying that if the parent form fails validation, the inlines also
  7711. run validation even if validation is contingent on parent form data.
  7712. Also, assertFormError() and assertFormSetError() is usable for admin
  7713. forms and formsets.
  7714. """
  7715. # The form validation should fail because 'some_required_info' is
  7716. # not included on the parent form, and the family_name of the parent
  7717. # does not match that of the child
  7718. post_data = {
  7719. "family_name": "Test1",
  7720. "dependentchild_set-TOTAL_FORMS": "1",
  7721. "dependentchild_set-INITIAL_FORMS": "0",
  7722. "dependentchild_set-MAX_NUM_FORMS": "1",
  7723. "dependentchild_set-0-id": "",
  7724. "dependentchild_set-0-parent": "",
  7725. "dependentchild_set-0-family_name": "Test2",
  7726. }
  7727. response = self.client.post(
  7728. reverse("admin:admin_views_parentwithdependentchildren_add"), post_data
  7729. )
  7730. self.assertFormError(
  7731. response.context["adminform"],
  7732. "some_required_info",
  7733. ["This field is required."],
  7734. )
  7735. self.assertFormError(response.context["adminform"], None, [])
  7736. self.assertFormSetError(
  7737. response.context["inline_admin_formset"],
  7738. 0,
  7739. None,
  7740. [
  7741. "Children must share a family name with their parents in this "
  7742. "contrived test case"
  7743. ],
  7744. )
  7745. self.assertFormSetError(
  7746. response.context["inline_admin_formset"], None, None, []
  7747. )
  7748. def test_change_view_form_and_formsets_run_validation(self):
  7749. """
  7750. Issue #20522
  7751. Verifying that if the parent form fails validation, the inlines also
  7752. run validation even if validation is contingent on parent form data
  7753. """
  7754. pwdc = ParentWithDependentChildren.objects.create(
  7755. some_required_info=6, family_name="Test1"
  7756. )
  7757. # The form validation should fail because 'some_required_info' is
  7758. # not included on the parent form, and the family_name of the parent
  7759. # does not match that of the child
  7760. post_data = {
  7761. "family_name": "Test2",
  7762. "dependentchild_set-TOTAL_FORMS": "1",
  7763. "dependentchild_set-INITIAL_FORMS": "0",
  7764. "dependentchild_set-MAX_NUM_FORMS": "1",
  7765. "dependentchild_set-0-id": "",
  7766. "dependentchild_set-0-parent": str(pwdc.id),
  7767. "dependentchild_set-0-family_name": "Test1",
  7768. }
  7769. response = self.client.post(
  7770. reverse(
  7771. "admin:admin_views_parentwithdependentchildren_change", args=(pwdc.id,)
  7772. ),
  7773. post_data,
  7774. )
  7775. self.assertFormError(
  7776. response.context["adminform"],
  7777. "some_required_info",
  7778. ["This field is required."],
  7779. )
  7780. self.assertFormSetError(
  7781. response.context["inline_admin_formset"],
  7782. 0,
  7783. None,
  7784. [
  7785. "Children must share a family name with their parents in this "
  7786. "contrived test case"
  7787. ],
  7788. )
  7789. def test_check(self):
  7790. "The view_on_site value is either a boolean or a callable"
  7791. try:
  7792. admin = CityAdmin(City, AdminSite())
  7793. CityAdmin.view_on_site = True
  7794. self.assertEqual(admin.check(), [])
  7795. CityAdmin.view_on_site = False
  7796. self.assertEqual(admin.check(), [])
  7797. CityAdmin.view_on_site = lambda obj: obj.get_absolute_url()
  7798. self.assertEqual(admin.check(), [])
  7799. CityAdmin.view_on_site = []
  7800. self.assertEqual(
  7801. admin.check(),
  7802. [
  7803. Error(
  7804. "The value of 'view_on_site' must be a callable or a boolean "
  7805. "value.",
  7806. obj=CityAdmin,
  7807. id="admin.E025",
  7808. ),
  7809. ],
  7810. )
  7811. finally:
  7812. # Restore the original values for the benefit of other tests.
  7813. CityAdmin.view_on_site = True
  7814. def test_false(self):
  7815. "The 'View on site' button is not displayed if view_on_site is False"
  7816. response = self.client.get(
  7817. reverse("admin:admin_views_restaurant_change", args=(self.r1.pk,))
  7818. )
  7819. content_type_pk = ContentType.objects.get_for_model(Restaurant).pk
  7820. self.assertNotContains(
  7821. response, reverse("admin:view_on_site", args=(content_type_pk, 1))
  7822. )
  7823. def test_true(self):
  7824. "The default behavior is followed if view_on_site is True"
  7825. response = self.client.get(
  7826. reverse("admin:admin_views_city_change", args=(self.c1.pk,))
  7827. )
  7828. content_type_pk = ContentType.objects.get_for_model(City).pk
  7829. self.assertContains(
  7830. response, reverse("admin:view_on_site", args=(content_type_pk, self.c1.pk))
  7831. )
  7832. def test_callable(self):
  7833. "The right link is displayed if view_on_site is a callable"
  7834. response = self.client.get(
  7835. reverse("admin:admin_views_worker_change", args=(self.w1.pk,))
  7836. )
  7837. self.assertContains(
  7838. response, '"/worker/%s/%s/"' % (self.w1.surname, self.w1.name)
  7839. )
  7840. def test_missing_get_absolute_url(self):
  7841. "None is returned if model doesn't have get_absolute_url"
  7842. model_admin = ModelAdmin(Worker, None)
  7843. self.assertIsNone(model_admin.get_view_on_site_url(Worker()))
  7844. def test_custom_admin_site(self):
  7845. model_admin = ModelAdmin(City, customadmin.site)
  7846. content_type_pk = ContentType.objects.get_for_model(City).pk
  7847. redirect_url = model_admin.get_view_on_site_url(self.c1)
  7848. self.assertEqual(
  7849. redirect_url,
  7850. reverse(
  7851. f"{customadmin.site.name}:view_on_site",
  7852. kwargs={
  7853. "content_type_id": content_type_pk,
  7854. "object_id": self.c1.pk,
  7855. },
  7856. ),
  7857. )
  7858. def test_view_on_site_url_non_integer_ids(self):
  7859. """The view_on_site URL accepts non-integer ids."""
  7860. self.assertEqual(
  7861. reverse(
  7862. "admin:view_on_site",
  7863. kwargs={
  7864. "content_type_id": "37156b6a-8a82",
  7865. "object_id": "37156b6a-8a83",
  7866. },
  7867. ),
  7868. "/test_admin/admin/r/37156b6a-8a82/37156b6a-8a83/",
  7869. )
  7870. @override_settings(ROOT_URLCONF="admin_views.urls")
  7871. class InlineAdminViewOnSiteTest(TestCase):
  7872. @classmethod
  7873. def setUpTestData(cls):
  7874. cls.superuser = User.objects.create_superuser(
  7875. username="super", password="secret", email="super@example.com"
  7876. )
  7877. cls.s1 = State.objects.create(name="New York")
  7878. cls.s2 = State.objects.create(name="Illinois")
  7879. cls.s3 = State.objects.create(name="California")
  7880. cls.c1 = City.objects.create(state=cls.s1, name="New York")
  7881. cls.c2 = City.objects.create(state=cls.s2, name="Chicago")
  7882. cls.c3 = City.objects.create(state=cls.s3, name="San Francisco")
  7883. cls.r1 = Restaurant.objects.create(city=cls.c1, name="Italian Pizza")
  7884. cls.r2 = Restaurant.objects.create(city=cls.c1, name="Boulevard")
  7885. cls.r3 = Restaurant.objects.create(city=cls.c2, name="Chinese Dinner")
  7886. cls.r4 = Restaurant.objects.create(city=cls.c2, name="Angels")
  7887. cls.r5 = Restaurant.objects.create(city=cls.c2, name="Take Away")
  7888. cls.r6 = Restaurant.objects.create(city=cls.c3, name="The Unknown Restaurant")
  7889. cls.w1 = Worker.objects.create(work_at=cls.r1, name="Mario", surname="Rossi")
  7890. cls.w2 = Worker.objects.create(
  7891. work_at=cls.r1, name="Antonio", surname="Bianchi"
  7892. )
  7893. cls.w3 = Worker.objects.create(work_at=cls.r1, name="John", surname="Doe")
  7894. def setUp(self):
  7895. self.client.force_login(self.superuser)
  7896. def test_false(self):
  7897. "The 'View on site' button is not displayed if view_on_site is False"
  7898. response = self.client.get(
  7899. reverse("admin:admin_views_state_change", args=(self.s1.pk,))
  7900. )
  7901. content_type_pk = ContentType.objects.get_for_model(City).pk
  7902. self.assertNotContains(
  7903. response, reverse("admin:view_on_site", args=(content_type_pk, self.c1.pk))
  7904. )
  7905. def test_true(self):
  7906. "The 'View on site' button is displayed if view_on_site is True"
  7907. response = self.client.get(
  7908. reverse("admin:admin_views_city_change", args=(self.c1.pk,))
  7909. )
  7910. content_type_pk = ContentType.objects.get_for_model(Restaurant).pk
  7911. self.assertContains(
  7912. response, reverse("admin:view_on_site", args=(content_type_pk, self.r1.pk))
  7913. )
  7914. def test_callable(self):
  7915. "The right link is displayed if view_on_site is a callable"
  7916. response = self.client.get(
  7917. reverse("admin:admin_views_restaurant_change", args=(self.r1.pk,))
  7918. )
  7919. self.assertContains(
  7920. response, '"/worker_inline/%s/%s/"' % (self.w1.surname, self.w1.name)
  7921. )
  7922. @override_settings(ROOT_URLCONF="admin_views.urls")
  7923. class GetFormsetsWithInlinesArgumentTest(TestCase):
  7924. """
  7925. #23934 - When adding a new model instance in the admin, the 'obj' argument
  7926. of get_formsets_with_inlines() should be None. When changing, it should be
  7927. equal to the existing model instance.
  7928. The GetFormsetsArgumentCheckingAdmin ModelAdmin throws an exception
  7929. if obj is not None during add_view or obj is None during change_view.
  7930. """
  7931. @classmethod
  7932. def setUpTestData(cls):
  7933. cls.superuser = User.objects.create_superuser(
  7934. username="super", password="secret", email="super@example.com"
  7935. )
  7936. def setUp(self):
  7937. self.client.force_login(self.superuser)
  7938. def test_explicitly_provided_pk(self):
  7939. post_data = {"name": "1"}
  7940. response = self.client.post(
  7941. reverse("admin:admin_views_explicitlyprovidedpk_add"), post_data
  7942. )
  7943. self.assertEqual(response.status_code, 302)
  7944. post_data = {"name": "2"}
  7945. response = self.client.post(
  7946. reverse("admin:admin_views_explicitlyprovidedpk_change", args=(1,)),
  7947. post_data,
  7948. )
  7949. self.assertEqual(response.status_code, 302)
  7950. def test_implicitly_generated_pk(self):
  7951. post_data = {"name": "1"}
  7952. response = self.client.post(
  7953. reverse("admin:admin_views_implicitlygeneratedpk_add"), post_data
  7954. )
  7955. self.assertEqual(response.status_code, 302)
  7956. post_data = {"name": "2"}
  7957. response = self.client.post(
  7958. reverse("admin:admin_views_implicitlygeneratedpk_change", args=(1,)),
  7959. post_data,
  7960. )
  7961. self.assertEqual(response.status_code, 302)
  7962. @override_settings(ROOT_URLCONF="admin_views.urls")
  7963. class AdminSiteFinalCatchAllPatternTests(TestCase):
  7964. """
  7965. Verifies the behaviour of the admin catch-all view.
  7966. * Anonynous/non-staff users are redirected to login for all URLs, whether
  7967. otherwise valid or not.
  7968. * APPEND_SLASH is applied for staff if needed.
  7969. * Otherwise Http404.
  7970. * Catch-all view disabled via AdminSite.final_catch_all_view.
  7971. """
  7972. @classmethod
  7973. def setUpTestData(cls):
  7974. cls.staff_user = User.objects.create_user(
  7975. username="staff",
  7976. password="secret",
  7977. email="staff@example.com",
  7978. is_staff=True,
  7979. )
  7980. cls.non_staff_user = User.objects.create_user(
  7981. username="user",
  7982. password="secret",
  7983. email="user@example.com",
  7984. is_staff=False,
  7985. )
  7986. def test_unknown_url_redirects_login_if_not_authenticated(self):
  7987. unknown_url = "/test_admin/admin/unknown/"
  7988. response = self.client.get(unknown_url)
  7989. self.assertRedirects(
  7990. response, "%s?next=%s" % (reverse("admin:login"), unknown_url)
  7991. )
  7992. def test_unknown_url_404_if_authenticated(self):
  7993. self.client.force_login(self.staff_user)
  7994. unknown_url = "/test_admin/admin/unknown/"
  7995. response = self.client.get(unknown_url)
  7996. self.assertEqual(response.status_code, 404)
  7997. def test_known_url_redirects_login_if_not_authenticated(self):
  7998. known_url = reverse("admin:admin_views_article_changelist")
  7999. response = self.client.get(known_url)
  8000. self.assertRedirects(
  8001. response, "%s?next=%s" % (reverse("admin:login"), known_url)
  8002. )
  8003. def test_known_url_missing_slash_redirects_login_if_not_authenticated(self):
  8004. known_url = reverse("admin:admin_views_article_changelist")[:-1]
  8005. response = self.client.get(known_url)
  8006. # Redirects with the next URL also missing the slash.
  8007. self.assertRedirects(
  8008. response, "%s?next=%s" % (reverse("admin:login"), known_url)
  8009. )
  8010. def test_non_admin_url_shares_url_prefix(self):
  8011. url = reverse("non_admin")[:-1]
  8012. response = self.client.get(url)
  8013. # Redirects with the next URL also missing the slash.
  8014. self.assertRedirects(response, "%s?next=%s" % (reverse("admin:login"), url))
  8015. def test_url_without_trailing_slash_if_not_authenticated(self):
  8016. url = reverse("admin:article_extra_json")
  8017. response = self.client.get(url)
  8018. self.assertRedirects(response, "%s?next=%s" % (reverse("admin:login"), url))
  8019. def test_unkown_url_without_trailing_slash_if_not_authenticated(self):
  8020. url = reverse("admin:article_extra_json")[:-1]
  8021. response = self.client.get(url)
  8022. self.assertRedirects(response, "%s?next=%s" % (reverse("admin:login"), url))
  8023. @override_settings(APPEND_SLASH=True)
  8024. def test_missing_slash_append_slash_true_unknown_url(self):
  8025. self.client.force_login(self.staff_user)
  8026. unknown_url = "/test_admin/admin/unknown/"
  8027. response = self.client.get(unknown_url[:-1])
  8028. self.assertEqual(response.status_code, 404)
  8029. @override_settings(APPEND_SLASH=True)
  8030. def test_missing_slash_append_slash_true(self):
  8031. self.client.force_login(self.staff_user)
  8032. known_url = reverse("admin:admin_views_article_changelist")
  8033. response = self.client.get(known_url[:-1])
  8034. self.assertRedirects(
  8035. response, known_url, status_code=301, target_status_code=403
  8036. )
  8037. @override_settings(APPEND_SLASH=True)
  8038. def test_missing_slash_append_slash_true_query_string(self):
  8039. self.client.force_login(self.staff_user)
  8040. known_url = reverse("admin:admin_views_article_changelist")
  8041. response = self.client.get("%s?id=1" % known_url[:-1])
  8042. self.assertRedirects(
  8043. response,
  8044. f"{known_url}?id=1",
  8045. status_code=301,
  8046. fetch_redirect_response=False,
  8047. )
  8048. @override_settings(APPEND_SLASH=True)
  8049. def test_missing_slash_append_slash_true_script_name(self):
  8050. self.client.force_login(self.staff_user)
  8051. known_url = reverse("admin:admin_views_article_changelist")
  8052. response = self.client.get(known_url[:-1], SCRIPT_NAME="/prefix/")
  8053. self.assertRedirects(
  8054. response,
  8055. "/prefix" + known_url,
  8056. status_code=301,
  8057. fetch_redirect_response=False,
  8058. )
  8059. @override_settings(APPEND_SLASH=True)
  8060. def test_missing_slash_append_slash_true_script_name_query_string(self):
  8061. self.client.force_login(self.staff_user)
  8062. known_url = reverse("admin:admin_views_article_changelist")
  8063. response = self.client.get("%s?id=1" % known_url[:-1], SCRIPT_NAME="/prefix/")
  8064. self.assertRedirects(
  8065. response,
  8066. f"/prefix{known_url}?id=1",
  8067. status_code=301,
  8068. fetch_redirect_response=False,
  8069. )
  8070. @override_settings(APPEND_SLASH=True, FORCE_SCRIPT_NAME="/prefix/")
  8071. def test_missing_slash_append_slash_true_force_script_name(self):
  8072. self.client.force_login(self.staff_user)
  8073. known_url = reverse("admin:admin_views_article_changelist")
  8074. response = self.client.get(known_url[:-1])
  8075. self.assertRedirects(
  8076. response,
  8077. "/prefix" + known_url,
  8078. status_code=301,
  8079. fetch_redirect_response=False,
  8080. )
  8081. @override_settings(APPEND_SLASH=True)
  8082. def test_missing_slash_append_slash_true_non_staff_user(self):
  8083. self.client.force_login(self.non_staff_user)
  8084. known_url = reverse("admin:admin_views_article_changelist")
  8085. response = self.client.get(known_url[:-1])
  8086. self.assertRedirects(
  8087. response,
  8088. "/test_admin/admin/login/?next=/test_admin/admin/admin_views/article",
  8089. )
  8090. @override_settings(APPEND_SLASH=True)
  8091. def test_missing_slash_append_slash_true_non_staff_user_query_string(self):
  8092. self.client.force_login(self.non_staff_user)
  8093. known_url = reverse("admin:admin_views_article_changelist")
  8094. response = self.client.get("%s?id=1" % known_url[:-1])
  8095. self.assertRedirects(
  8096. response,
  8097. "/test_admin/admin/login/?next=/test_admin/admin/admin_views/article"
  8098. "%3Fid%3D1",
  8099. )
  8100. @override_settings(APPEND_SLASH=False)
  8101. def test_missing_slash_append_slash_false(self):
  8102. self.client.force_login(self.staff_user)
  8103. known_url = reverse("admin:admin_views_article_changelist")
  8104. response = self.client.get(known_url[:-1])
  8105. self.assertEqual(response.status_code, 404)
  8106. @override_settings(APPEND_SLASH=True)
  8107. def test_single_model_no_append_slash(self):
  8108. self.client.force_login(self.staff_user)
  8109. known_url = reverse("admin9:admin_views_actor_changelist")
  8110. response = self.client.get(known_url[:-1])
  8111. self.assertEqual(response.status_code, 404)
  8112. # Same tests above with final_catch_all_view=False.
  8113. def test_unknown_url_404_if_not_authenticated_without_final_catch_all_view(self):
  8114. unknown_url = "/test_admin/admin10/unknown/"
  8115. response = self.client.get(unknown_url)
  8116. self.assertEqual(response.status_code, 404)
  8117. def test_unknown_url_404_if_authenticated_without_final_catch_all_view(self):
  8118. self.client.force_login(self.staff_user)
  8119. unknown_url = "/test_admin/admin10/unknown/"
  8120. response = self.client.get(unknown_url)
  8121. self.assertEqual(response.status_code, 404)
  8122. def test_known_url_redirects_login_if_not_auth_without_final_catch_all_view(
  8123. self,
  8124. ):
  8125. known_url = reverse("admin10:admin_views_article_changelist")
  8126. response = self.client.get(known_url)
  8127. self.assertRedirects(
  8128. response, "%s?next=%s" % (reverse("admin10:login"), known_url)
  8129. )
  8130. def test_known_url_missing_slash_redirects_with_slash_if_not_auth_no_catch_all_view(
  8131. self,
  8132. ):
  8133. known_url = reverse("admin10:admin_views_article_changelist")
  8134. response = self.client.get(known_url[:-1])
  8135. self.assertRedirects(
  8136. response, known_url, status_code=301, fetch_redirect_response=False
  8137. )
  8138. def test_non_admin_url_shares_url_prefix_without_final_catch_all_view(self):
  8139. url = reverse("non_admin10")
  8140. response = self.client.get(url[:-1])
  8141. self.assertRedirects(response, url, status_code=301)
  8142. def test_url_no_trailing_slash_if_not_auth_without_final_catch_all_view(
  8143. self,
  8144. ):
  8145. url = reverse("admin10:article_extra_json")
  8146. response = self.client.get(url)
  8147. self.assertRedirects(response, "%s?next=%s" % (reverse("admin10:login"), url))
  8148. def test_unknown_url_no_trailing_slash_if_not_auth_without_final_catch_all_view(
  8149. self,
  8150. ):
  8151. url = reverse("admin10:article_extra_json")[:-1]
  8152. response = self.client.get(url)
  8153. # Matches test_admin/admin10/admin_views/article/<path:object_id>/
  8154. self.assertRedirects(
  8155. response, url + "/", status_code=301, fetch_redirect_response=False
  8156. )
  8157. @override_settings(APPEND_SLASH=True)
  8158. def test_missing_slash_append_slash_true_unknown_url_without_final_catch_all_view(
  8159. self,
  8160. ):
  8161. self.client.force_login(self.staff_user)
  8162. unknown_url = "/test_admin/admin10/unknown/"
  8163. response = self.client.get(unknown_url[:-1])
  8164. self.assertEqual(response.status_code, 404)
  8165. @override_settings(APPEND_SLASH=True)
  8166. def test_missing_slash_append_slash_true_without_final_catch_all_view(self):
  8167. self.client.force_login(self.staff_user)
  8168. known_url = reverse("admin10:admin_views_article_changelist")
  8169. response = self.client.get(known_url[:-1])
  8170. self.assertRedirects(
  8171. response, known_url, status_code=301, target_status_code=403
  8172. )
  8173. @override_settings(APPEND_SLASH=True)
  8174. def test_missing_slash_append_slash_true_query_without_final_catch_all_view(self):
  8175. self.client.force_login(self.staff_user)
  8176. known_url = reverse("admin10:admin_views_article_changelist")
  8177. response = self.client.get("%s?id=1" % known_url[:-1])
  8178. self.assertRedirects(
  8179. response,
  8180. f"{known_url}?id=1",
  8181. status_code=301,
  8182. fetch_redirect_response=False,
  8183. )
  8184. @override_settings(APPEND_SLASH=False)
  8185. def test_missing_slash_append_slash_false_without_final_catch_all_view(self):
  8186. self.client.force_login(self.staff_user)
  8187. known_url = reverse("admin10:admin_views_article_changelist")
  8188. response = self.client.get(known_url[:-1])
  8189. self.assertEqual(response.status_code, 404)
  8190. # Outside admin.
  8191. def test_non_admin_url_404_if_not_authenticated(self):
  8192. unknown_url = "/unknown/"
  8193. response = self.client.get(unknown_url)
  8194. # Does not redirect to the admin login.
  8195. self.assertEqual(response.status_code, 404)