tests.py 130 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526252725282529253025312532253325342535253625372538253925402541254225432544254525462547254825492550255125522553255425552556255725582559256025612562256325642565256625672568256925702571257225732574257525762577257825792580258125822583258425852586258725882589259025912592259325942595259625972598259926002601260226032604260526062607260826092610261126122613261426152616261726182619262026212622262326242625262626272628262926302631263226332634263526362637263826392640264126422643264426452646264726482649265026512652265326542655265626572658265926602661266226632664266526662667266826692670267126722673267426752676267726782679268026812682268326842685268626872688268926902691269226932694269526962697269826992700270127022703270427052706270727082709271027112712271327142715271627172718271927202721272227232724272527262727272827292730273127322733273427352736273727382739274027412742274327442745274627472748274927502751275227532754275527562757275827592760276127622763276427652766276727682769277027712772277327742775277627772778277927802781278227832784278527862787278827892790279127922793279427952796279727982799280028012802280328042805280628072808280928102811281228132814281528162817281828192820282128222823282428252826282728282829283028312832283328342835283628372838283928402841284228432844284528462847284828492850285128522853285428552856285728582859286028612862286328642865286628672868286928702871287228732874287528762877287828792880288128822883288428852886288728882889289028912892289328942895289628972898289929002901290229032904290529062907290829092910291129122913291429152916291729182919292029212922292329242925292629272928292929302931293229332934293529362937293829392940294129422943294429452946294729482949295029512952295329542955
  1. # coding: utf-8
  2. import re
  3. import datetime
  4. import urlparse
  5. from django.conf import settings
  6. from django.core import mail
  7. from django.core.exceptions import SuspiciousOperation
  8. from django.core.files import temp as tempfile
  9. from django.core.urlresolvers import reverse
  10. # Register auth models with the admin.
  11. from django.contrib.auth import REDIRECT_FIELD_NAME, admin
  12. from django.contrib.auth.models import User, Permission, UNUSABLE_PASSWORD
  13. from django.contrib.contenttypes.models import ContentType
  14. from django.contrib.admin.models import LogEntry, DELETION
  15. from django.contrib.admin.sites import LOGIN_FORM_KEY
  16. from django.contrib.admin.util import quote
  17. from django.contrib.admin.helpers import ACTION_CHECKBOX_NAME
  18. from django.contrib.admin.views.main import IS_POPUP_VAR
  19. from django.forms.util import ErrorList
  20. import django.template.context
  21. from django.test import TestCase
  22. from django.utils import formats
  23. from django.utils.cache import get_max_age
  24. from django.utils.encoding import iri_to_uri
  25. from django.utils.html import escape
  26. from django.utils.http import urlencode
  27. from django.utils.translation import activate, deactivate
  28. from django.utils import unittest
  29. # local test models
  30. from models import (Article, BarAccount, CustomArticle, EmptyModel,
  31. FooAccount, Gallery, ModelWithStringPrimaryKey,
  32. Person, Persona, Picture, Podcast, Section, Subscriber, Vodcast,
  33. Language, Collector, Widget, Grommet, DooHickey, FancyDoodad, Whatsit,
  34. Category, Post, Plot, FunkyTag, Chapter, Book, Promo, WorkHour, Employee,
  35. Question, Answer, Inquisition, Actor, FoodDelivery,
  36. RowLevelChangePermissionModel, Paper, CoverLetter, Story, OtherStory)
  37. class AdminViewBasicTest(TestCase):
  38. fixtures = ['admin-views-users.xml', 'admin-views-colors.xml',
  39. 'admin-views-fabrics.xml', 'admin-views-books.xml']
  40. # Store the bit of the URL where the admin is registered as a class
  41. # variable. That way we can test a second AdminSite just by subclassing
  42. # this test case and changing urlbit.
  43. urlbit = 'admin'
  44. def setUp(self):
  45. self.old_USE_I18N = settings.USE_I18N
  46. self.old_USE_L10N = settings.USE_L10N
  47. self.old_LANGUAGE_CODE = settings.LANGUAGE_CODE
  48. self.client.login(username='super', password='secret')
  49. settings.USE_I18N = True
  50. def tearDown(self):
  51. settings.USE_I18N = self.old_USE_I18N
  52. settings.USE_L10N = self.old_USE_L10N
  53. settings.LANGUAGE_CODE = self.old_LANGUAGE_CODE
  54. self.client.logout()
  55. formats.reset_format_cache()
  56. def testTrailingSlashRequired(self):
  57. """
  58. If you leave off the trailing slash, app should redirect and add it.
  59. """
  60. request = self.client.get('/test_admin/%s/admin_views/article/add' % self.urlbit)
  61. self.assertRedirects(request,
  62. '/test_admin/%s/admin_views/article/add/' % self.urlbit, status_code=301
  63. )
  64. def testBasicAddGet(self):
  65. """
  66. A smoke test to ensure GET on the add_view works.
  67. """
  68. response = self.client.get('/test_admin/%s/admin_views/section/add/' % self.urlbit)
  69. self.assertEqual(response.status_code, 200)
  70. def testAddWithGETArgs(self):
  71. response = self.client.get('/test_admin/%s/admin_views/section/add/' % self.urlbit, {'name': 'My Section'})
  72. self.assertEqual(response.status_code, 200)
  73. self.assertTrue(
  74. 'value="My Section"' in response.content,
  75. "Couldn't find an input with the right value in the response."
  76. )
  77. def testBasicEditGet(self):
  78. """
  79. A smoke test to ensure GET on the change_view works.
  80. """
  81. response = self.client.get('/test_admin/%s/admin_views/section/1/' % self.urlbit)
  82. self.assertEqual(response.status_code, 200)
  83. def testBasicEditGetStringPK(self):
  84. """
  85. A smoke test to ensure GET on the change_view works (returns an HTTP
  86. 404 error, see #11191) when passing a string as the PK argument for a
  87. model with an integer PK field.
  88. """
  89. response = self.client.get('/test_admin/%s/admin_views/section/abc/' % self.urlbit)
  90. self.assertEqual(response.status_code, 404)
  91. def testBasicAddPost(self):
  92. """
  93. A smoke test to ensure POST on add_view works.
  94. """
  95. post_data = {
  96. "name": u"Another Section",
  97. # inline data
  98. "article_set-TOTAL_FORMS": u"3",
  99. "article_set-INITIAL_FORMS": u"0",
  100. "article_set-MAX_NUM_FORMS": u"0",
  101. }
  102. response = self.client.post('/test_admin/%s/admin_views/section/add/' % self.urlbit, post_data)
  103. self.assertEqual(response.status_code, 302) # redirect somewhere
  104. def testPopupAddPost(self):
  105. """
  106. Ensure http response from a popup is properly escaped.
  107. """
  108. post_data = {
  109. '_popup': u'1',
  110. 'title': u'title with a new\nline',
  111. 'content': u'some content',
  112. 'date_0': u'2010-09-10',
  113. 'date_1': u'14:55:39',
  114. }
  115. response = self.client.post('/test_admin/%s/admin_views/article/add/' % self.urlbit, post_data)
  116. self.failUnlessEqual(response.status_code, 200)
  117. self.assertContains(response, 'dismissAddAnotherPopup')
  118. self.assertContains(response, 'title with a new\u000Aline')
  119. # Post data for edit inline
  120. inline_post_data = {
  121. "name": u"Test section",
  122. # inline data
  123. "article_set-TOTAL_FORMS": u"6",
  124. "article_set-INITIAL_FORMS": u"3",
  125. "article_set-MAX_NUM_FORMS": u"0",
  126. "article_set-0-id": u"1",
  127. # there is no title in database, give one here or formset will fail.
  128. "article_set-0-title": u"Norske bostaver æøå skaper problemer",
  129. "article_set-0-content": u"<p>Middle content</p>",
  130. "article_set-0-date_0": u"2008-03-18",
  131. "article_set-0-date_1": u"11:54:58",
  132. "article_set-0-section": u"1",
  133. "article_set-1-id": u"2",
  134. "article_set-1-title": u"Need a title.",
  135. "article_set-1-content": u"<p>Oldest content</p>",
  136. "article_set-1-date_0": u"2000-03-18",
  137. "article_set-1-date_1": u"11:54:58",
  138. "article_set-2-id": u"3",
  139. "article_set-2-title": u"Need a title.",
  140. "article_set-2-content": u"<p>Newest content</p>",
  141. "article_set-2-date_0": u"2009-03-18",
  142. "article_set-2-date_1": u"11:54:58",
  143. "article_set-3-id": u"",
  144. "article_set-3-title": u"",
  145. "article_set-3-content": u"",
  146. "article_set-3-date_0": u"",
  147. "article_set-3-date_1": u"",
  148. "article_set-4-id": u"",
  149. "article_set-4-title": u"",
  150. "article_set-4-content": u"",
  151. "article_set-4-date_0": u"",
  152. "article_set-4-date_1": u"",
  153. "article_set-5-id": u"",
  154. "article_set-5-title": u"",
  155. "article_set-5-content": u"",
  156. "article_set-5-date_0": u"",
  157. "article_set-5-date_1": u"",
  158. }
  159. def testBasicEditPost(self):
  160. """
  161. A smoke test to ensure POST on edit_view works.
  162. """
  163. response = self.client.post('/test_admin/%s/admin_views/section/1/' % self.urlbit, self.inline_post_data)
  164. self.assertEqual(response.status_code, 302) # redirect somewhere
  165. def testEditSaveAs(self):
  166. """
  167. Test "save as".
  168. """
  169. post_data = self.inline_post_data.copy()
  170. post_data.update({
  171. '_saveasnew': u'Save+as+new',
  172. "article_set-1-section": u"1",
  173. "article_set-2-section": u"1",
  174. "article_set-3-section": u"1",
  175. "article_set-4-section": u"1",
  176. "article_set-5-section": u"1",
  177. })
  178. response = self.client.post('/test_admin/%s/admin_views/section/1/' % self.urlbit, post_data)
  179. self.assertEqual(response.status_code, 302) # redirect somewhere
  180. def testChangeListSortingCallable(self):
  181. """
  182. Ensure we can sort on a list_display field that is a callable
  183. (column 2 is callable_year in ArticleAdmin)
  184. """
  185. response = self.client.get('/test_admin/%s/admin_views/article/' % self.urlbit, {'ot': 'asc', 'o': 2})
  186. self.assertEqual(response.status_code, 200)
  187. self.assertTrue(
  188. response.content.index('Oldest content') < response.content.index('Middle content') and
  189. response.content.index('Middle content') < response.content.index('Newest content'),
  190. "Results of sorting on callable are out of order."
  191. )
  192. def testChangeListSortingModel(self):
  193. """
  194. Ensure we can sort on a list_display field that is a Model method
  195. (colunn 3 is 'model_year' in ArticleAdmin)
  196. """
  197. response = self.client.get('/test_admin/%s/admin_views/article/' % self.urlbit, {'ot': 'dsc', 'o': 3})
  198. self.assertEqual(response.status_code, 200)
  199. self.assertTrue(
  200. response.content.index('Newest content') < response.content.index('Middle content') and
  201. response.content.index('Middle content') < response.content.index('Oldest content'),
  202. "Results of sorting on Model method are out of order."
  203. )
  204. def testChangeListSortingModelAdmin(self):
  205. """
  206. Ensure we can sort on a list_display field that is a ModelAdmin method
  207. (colunn 4 is 'modeladmin_year' in ArticleAdmin)
  208. """
  209. response = self.client.get('/test_admin/%s/admin_views/article/' % self.urlbit, {'ot': 'asc', 'o': 4})
  210. self.assertEqual(response.status_code, 200)
  211. self.assertTrue(
  212. response.content.index('Oldest content') < response.content.index('Middle content') and
  213. response.content.index('Middle content') < response.content.index('Newest content'),
  214. "Results of sorting on ModelAdmin method are out of order."
  215. )
  216. def testLimitedFilter(self):
  217. """Ensure admin changelist filters do not contain objects excluded via limit_choices_to.
  218. This also tests relation-spanning filters (e.g. 'color__value').
  219. """
  220. response = self.client.get('/test_admin/%s/admin_views/thing/' % self.urlbit)
  221. self.assertEqual(response.status_code, 200)
  222. self.assertTrue(
  223. '<div id="changelist-filter">' in response.content,
  224. "Expected filter not found in changelist view."
  225. )
  226. self.assertFalse(
  227. '<a href="?color__id__exact=3">Blue</a>' in response.content,
  228. "Changelist filter not correctly limited by limit_choices_to."
  229. )
  230. def testRelationSpanningFilters(self):
  231. response = self.client.get('/test_admin/%s/admin_views/chapterxtra1/' %
  232. self.urlbit)
  233. self.assertEqual(response.status_code, 200)
  234. self.assertContains(response, '<div id="changelist-filter">')
  235. filters = {
  236. 'chap__id__exact': dict(
  237. values=[c.id for c in Chapter.objects.all()],
  238. test=lambda obj, value: obj.chap.id == value),
  239. 'chap__title': dict(
  240. values=[c.title for c in Chapter.objects.all()],
  241. test=lambda obj, value: obj.chap.title == value),
  242. 'chap__book__id__exact': dict(
  243. values=[b.id for b in Book.objects.all()],
  244. test=lambda obj, value: obj.chap.book.id == value),
  245. 'chap__book__name': dict(
  246. values=[b.name for b in Book.objects.all()],
  247. test=lambda obj, value: obj.chap.book.name == value),
  248. 'chap__book__promo__id__exact': dict(
  249. values=[p.id for p in Promo.objects.all()],
  250. test=lambda obj, value:
  251. obj.chap.book.promo_set.filter(id=value).exists()),
  252. 'chap__book__promo__name': dict(
  253. values=[p.name for p in Promo.objects.all()],
  254. test=lambda obj, value:
  255. obj.chap.book.promo_set.filter(name=value).exists()),
  256. }
  257. for filter_path, params in filters.items():
  258. for value in params['values']:
  259. query_string = urlencode({filter_path: value})
  260. # ensure filter link exists
  261. self.assertContains(response, '<a href="?%s">' % query_string)
  262. # ensure link works
  263. filtered_response = self.client.get(
  264. '/test_admin/%s/admin_views/chapterxtra1/?%s' % (
  265. self.urlbit, query_string))
  266. self.assertEqual(filtered_response.status_code, 200)
  267. # ensure changelist contains only valid objects
  268. for obj in filtered_response.context['cl'].query_set.all():
  269. self.assertTrue(params['test'](obj, value))
  270. def testIncorrectLookupParameters(self):
  271. """Ensure incorrect lookup parameters are handled gracefully."""
  272. response = self.client.get('/test_admin/%s/admin_views/thing/' % self.urlbit, {'notarealfield': '5'})
  273. self.assertRedirects(response, '/test_admin/%s/admin_views/thing/?e=1' % self.urlbit)
  274. response = self.client.get('/test_admin/%s/admin_views/thing/' % self.urlbit, {'color__id__exact': 'StringNotInteger!'})
  275. self.assertRedirects(response, '/test_admin/%s/admin_views/thing/?e=1' % self.urlbit)
  276. def testIsNullLookups(self):
  277. """Ensure is_null is handled correctly."""
  278. Article.objects.create(title="I Could Go Anywhere", content="Versatile", date=datetime.datetime.now())
  279. response = self.client.get('/test_admin/%s/admin_views/article/' % self.urlbit)
  280. self.assertTrue('4 articles' in response.content, '"4 articles" missing from response')
  281. response = self.client.get('/test_admin/%s/admin_views/article/' % self.urlbit, {'section__isnull': 'false'})
  282. self.assertTrue('3 articles' in response.content, '"3 articles" missing from response')
  283. response = self.client.get('/test_admin/%s/admin_views/article/' % self.urlbit, {'section__isnull': 'true'})
  284. self.assertTrue('1 article' in response.content, '"1 article" missing from response')
  285. def testLogoutAndPasswordChangeURLs(self):
  286. response = self.client.get('/test_admin/%s/admin_views/article/' % self.urlbit)
  287. self.assertFalse('<a href="/test_admin/%s/logout/">' % self.urlbit not in response.content)
  288. self.assertFalse('<a href="/test_admin/%s/password_change/">' % self.urlbit not in response.content)
  289. def testNamedGroupFieldChoicesChangeList(self):
  290. """
  291. Ensures the admin changelist shows correct values in the relevant column
  292. for rows corresponding to instances of a model in which a named group
  293. has been used in the choices option of a field.
  294. """
  295. response = self.client.get('/test_admin/%s/admin_views/fabric/' % self.urlbit)
  296. self.assertEqual(response.status_code, 200)
  297. self.assertTrue(
  298. '<a href="1/">Horizontal</a>' in response.content and
  299. '<a href="2/">Vertical</a>' in response.content,
  300. "Changelist table isn't showing the right human-readable values set by a model field 'choices' option named group."
  301. )
  302. def testNamedGroupFieldChoicesFilter(self):
  303. """
  304. Ensures the filter UI shows correctly when at least one named group has
  305. been used in the choices option of a model field.
  306. """
  307. response = self.client.get('/test_admin/%s/admin_views/fabric/' % self.urlbit)
  308. self.assertEqual(response.status_code, 200)
  309. self.assertTrue(
  310. '<div id="changelist-filter">' in response.content,
  311. "Expected filter not found in changelist view."
  312. )
  313. self.assertTrue(
  314. '<a href="?surface__exact=x">Horizontal</a>' in response.content and
  315. '<a href="?surface__exact=y">Vertical</a>' in response.content,
  316. "Changelist filter isn't showing options contained inside a model field 'choices' option named group."
  317. )
  318. def testChangeListNullBooleanDisplay(self):
  319. Post.objects.create(public=None)
  320. # This hard-codes the URl because it'll fail if it runs
  321. # against the 'admin2' custom admin (which doesn't have the
  322. # Post model).
  323. response = self.client.get("/test_admin/admin/admin_views/post/")
  324. self.assertTrue('icon-unknown.gif' in response.content)
  325. def testI18NLanguageNonEnglishDefault(self):
  326. """
  327. Check if the Javascript i18n view returns an empty language catalog
  328. if the default language is non-English but the selected language
  329. is English. See #13388 and #3594 for more details.
  330. """
  331. try:
  332. settings.LANGUAGE_CODE = 'fr'
  333. activate('en-us')
  334. response = self.client.get('/test_admin/admin/jsi18n/')
  335. self.assertNotContains(response, 'Choisir une heure')
  336. finally:
  337. deactivate()
  338. def testI18NLanguageNonEnglishFallback(self):
  339. """
  340. Makes sure that the fallback language is still working properly
  341. in cases where the selected language cannot be found.
  342. """
  343. try:
  344. settings.LANGUAGE_CODE = 'fr'
  345. activate('none')
  346. response = self.client.get('/test_admin/admin/jsi18n/')
  347. self.assertContains(response, 'Choisir une heure')
  348. finally:
  349. deactivate()
  350. def testL10NDeactivated(self):
  351. """
  352. Check if L10N is deactivated, the Javascript i18n view doesn't
  353. return localized date/time formats. Refs #14824.
  354. """
  355. try:
  356. settings.LANGUAGE_CODE = 'ru'
  357. settings.USE_L10N = False
  358. activate('ru')
  359. response = self.client.get('/test_admin/admin/jsi18n/')
  360. self.assertNotContains(response, '%d.%m.%Y %H:%M:%S')
  361. self.assertContains(response, '%Y-%m-%d %H:%M:%S')
  362. finally:
  363. deactivate()
  364. def test_disallowed_filtering(self):
  365. self.assertRaises(SuspiciousOperation,
  366. self.client.get, "/test_admin/admin/admin_views/album/?owner__email__startswith=fuzzy"
  367. )
  368. try:
  369. self.client.get("/test_admin/admin/admin_views/thing/?color__value__startswith=red")
  370. self.client.get("/test_admin/admin/admin_views/thing/?color__value=red")
  371. except SuspiciousOperation:
  372. self.fail("Filters are allowed if explicitly included in list_filter")
  373. try:
  374. self.client.get("/test_admin/admin/admin_views/person/?age__gt=30")
  375. except SuspiciousOperation:
  376. self.fail("Filters should be allowed if they involve a local field without the need to whitelist them in list_filter or date_hierarchy.")
  377. e1 = Employee.objects.create(name='Anonymous', gender=1, age=22, alive=True, code='123')
  378. e2 = Employee.objects.create(name='Visitor', gender=2, age=19, alive=True, code='124')
  379. WorkHour.objects.create(datum=datetime.datetime.now(), employee=e1)
  380. WorkHour.objects.create(datum=datetime.datetime.now(), employee=e2)
  381. response = self.client.get("/test_admin/admin/admin_views/workhour/")
  382. self.assertEqual(response.status_code, 200)
  383. self.assertContains(response, 'employee__person_ptr__exact')
  384. response = self.client.get("/test_admin/admin/admin_views/workhour/?employee__person_ptr__exact=%d" % e1.pk)
  385. self.assertEqual(response.status_code, 200)
  386. def test_allowed_filtering_15103(self):
  387. """
  388. Regressions test for ticket 15103 - filtering on fields defined in a
  389. ForeignKey 'limit_choices_to' should be allowed, otherwise raw_id_fields
  390. can break.
  391. """
  392. try:
  393. self.client.get("/test_admin/admin/admin_views/inquisition/?leader__name=Palin&leader__age=27")
  394. except SuspiciousOperation:
  395. self.fail("Filters should be allowed if they are defined on a ForeignKey pointing to this model")
  396. class AdminJavaScriptTest(AdminViewBasicTest):
  397. def testSingleWidgetFirsFieldFocus(self):
  398. """
  399. JavaScript-assisted auto-focus on first field.
  400. """
  401. response = self.client.get('/test_admin/%s/admin_views/picture/add/' % self.urlbit)
  402. self.assertContains(
  403. response,
  404. '<script type="text/javascript">document.getElementById("id_name").focus();</script>'
  405. )
  406. def testMultiWidgetFirsFieldFocus(self):
  407. """
  408. JavaScript-assisted auto-focus should work if a model/ModelAdmin setup
  409. is such that the first form field has a MultiWidget.
  410. """
  411. response = self.client.get('/test_admin/%s/admin_views/reservation/add/' % self.urlbit)
  412. self.assertContains(
  413. response,
  414. '<script type="text/javascript">document.getElementById("id_start_date_0").focus();</script>'
  415. )
  416. class SaveAsTests(TestCase):
  417. fixtures = ['admin-views-users.xml','admin-views-person.xml']
  418. def setUp(self):
  419. self.client.login(username='super', password='secret')
  420. def tearDown(self):
  421. self.client.logout()
  422. def test_save_as_duplication(self):
  423. """Ensure save as actually creates a new person"""
  424. post_data = {'_saveasnew':'', 'name':'John M', 'gender':1, 'age': 42}
  425. response = self.client.post('/test_admin/admin/admin_views/person/1/', post_data)
  426. self.assertEqual(len(Person.objects.filter(name='John M')), 1)
  427. self.assertEqual(len(Person.objects.filter(id=1)), 1)
  428. def test_save_as_display(self):
  429. """
  430. Ensure that 'save as' is displayed when activated and after submitting
  431. invalid data aside save_as_new will not show us a form to overwrite the
  432. initial model.
  433. """
  434. response = self.client.get('/test_admin/admin/admin_views/person/1/')
  435. self.assertTrue(response.context['save_as'])
  436. post_data = {'_saveasnew':'', 'name':'John M', 'gender':3, 'alive':'checked'}
  437. response = self.client.post('/test_admin/admin/admin_views/person/1/', post_data)
  438. self.assertEqual(response.context['form_url'], '../add/')
  439. class CustomModelAdminTest(AdminViewBasicTest):
  440. urlbit = "admin2"
  441. def testCustomAdminSiteLoginForm(self):
  442. self.client.logout()
  443. request = self.client.get('/test_admin/admin2/')
  444. self.assertEqual(request.status_code, 200)
  445. login = self.client.post('/test_admin/admin2/', {
  446. REDIRECT_FIELD_NAME: '/test_admin/admin2/',
  447. LOGIN_FORM_KEY: 1,
  448. 'username': 'customform',
  449. 'password': 'secret',
  450. })
  451. self.assertEqual(login.status_code, 200)
  452. self.assertContains(login, 'custom form error')
  453. def testCustomAdminSiteLoginTemplate(self):
  454. self.client.logout()
  455. request = self.client.get('/test_admin/admin2/')
  456. self.assertTemplateUsed(request, 'custom_admin/login.html')
  457. self.assertTrue('Hello from a custom login template' in request.content)
  458. def testCustomAdminSiteLogoutTemplate(self):
  459. request = self.client.get('/test_admin/admin2/logout/')
  460. self.assertTemplateUsed(request, 'custom_admin/logout.html')
  461. self.assertTrue('Hello from a custom logout template' in request.content)
  462. def testCustomAdminSiteIndexViewAndTemplate(self):
  463. request = self.client.get('/test_admin/admin2/')
  464. self.assertTemplateUsed(request, 'custom_admin/index.html')
  465. self.assertTrue('Hello from a custom index template *bar*' in request.content)
  466. def testCustomAdminSitePasswordChangeTemplate(self):
  467. request = self.client.get('/test_admin/admin2/password_change/')
  468. self.assertTemplateUsed(request, 'custom_admin/password_change_form.html')
  469. self.assertTrue('Hello from a custom password change form template' in request.content)
  470. def testCustomAdminSitePasswordChangeDoneTemplate(self):
  471. request = self.client.get('/test_admin/admin2/password_change/done/')
  472. self.assertTemplateUsed(request, 'custom_admin/password_change_done.html')
  473. self.assertTrue('Hello from a custom password change done template' in request.content)
  474. def testCustomAdminSiteView(self):
  475. self.client.login(username='super', password='secret')
  476. response = self.client.get('/test_admin/%s/my_view/' % self.urlbit)
  477. self.assertTrue(response.content == "Django is a magical pony!", response.content)
  478. def get_perm(Model, perm):
  479. """Return the permission object, for the Model"""
  480. ct = ContentType.objects.get_for_model(Model)
  481. return Permission.objects.get(content_type=ct, codename=perm)
  482. class AdminViewPermissionsTest(TestCase):
  483. """Tests for Admin Views Permissions."""
  484. fixtures = ['admin-views-users.xml']
  485. def setUp(self):
  486. """Test setup."""
  487. # Setup permissions, for our users who can add, change, and delete.
  488. # We can't put this into the fixture, because the content type id
  489. # and the permission id could be different on each run of the test.
  490. opts = Article._meta
  491. # User who can add Articles
  492. add_user = User.objects.get(username='adduser')
  493. add_user.user_permissions.add(get_perm(Article,
  494. opts.get_add_permission()))
  495. # User who can change Articles
  496. change_user = User.objects.get(username='changeuser')
  497. change_user.user_permissions.add(get_perm(Article,
  498. opts.get_change_permission()))
  499. # User who can delete Articles
  500. delete_user = User.objects.get(username='deleteuser')
  501. delete_user.user_permissions.add(get_perm(Article,
  502. opts.get_delete_permission()))
  503. delete_user.user_permissions.add(get_perm(Section,
  504. Section._meta.get_delete_permission()))
  505. # login POST dicts
  506. self.super_login = {
  507. REDIRECT_FIELD_NAME: '/test_admin/admin/',
  508. LOGIN_FORM_KEY: 1,
  509. 'username': 'super',
  510. 'password': 'secret',
  511. }
  512. self.super_email_login = {
  513. REDIRECT_FIELD_NAME: '/test_admin/admin/',
  514. LOGIN_FORM_KEY: 1,
  515. 'username': 'super@example.com',
  516. 'password': 'secret',
  517. }
  518. self.super_email_bad_login = {
  519. REDIRECT_FIELD_NAME: '/test_admin/admin/',
  520. LOGIN_FORM_KEY: 1,
  521. 'username': 'super@example.com',
  522. 'password': 'notsecret',
  523. }
  524. self.adduser_login = {
  525. REDIRECT_FIELD_NAME: '/test_admin/admin/',
  526. LOGIN_FORM_KEY: 1,
  527. 'username': 'adduser',
  528. 'password': 'secret',
  529. }
  530. self.changeuser_login = {
  531. REDIRECT_FIELD_NAME: '/test_admin/admin/',
  532. LOGIN_FORM_KEY: 1,
  533. 'username': 'changeuser',
  534. 'password': 'secret',
  535. }
  536. self.deleteuser_login = {
  537. REDIRECT_FIELD_NAME: '/test_admin/admin/',
  538. LOGIN_FORM_KEY: 1,
  539. 'username': 'deleteuser',
  540. 'password': 'secret',
  541. }
  542. self.joepublic_login = {
  543. REDIRECT_FIELD_NAME: '/test_admin/admin/',
  544. LOGIN_FORM_KEY: 1,
  545. 'username': 'joepublic',
  546. 'password': 'secret',
  547. }
  548. self.no_username_login = {
  549. REDIRECT_FIELD_NAME: '/test_admin/admin/',
  550. LOGIN_FORM_KEY: 1,
  551. 'password': 'secret',
  552. }
  553. def testLogin(self):
  554. """
  555. Make sure only staff members can log in.
  556. Successful posts to the login page will redirect to the orignal url.
  557. Unsuccessfull attempts will continue to render the login page with
  558. a 200 status code.
  559. """
  560. # Super User
  561. request = self.client.get('/test_admin/admin/')
  562. self.assertEqual(request.status_code, 200)
  563. login = self.client.post('/test_admin/admin/', self.super_login)
  564. self.assertRedirects(login, '/test_admin/admin/')
  565. self.assertFalse(login.context)
  566. self.client.get('/test_admin/admin/logout/')
  567. # Test if user enters e-mail address
  568. request = self.client.get('/test_admin/admin/')
  569. self.assertEqual(request.status_code, 200)
  570. login = self.client.post('/test_admin/admin/', self.super_email_login)
  571. self.assertContains(login, "Your e-mail address is not your username")
  572. # only correct passwords get a username hint
  573. login = self.client.post('/test_admin/admin/', self.super_email_bad_login)
  574. self.assertContains(login, "Please enter a correct username and password.")
  575. new_user = User(username='jondoe', password='secret', email='super@example.com')
  576. new_user.save()
  577. # check to ensure if there are multiple e-mail addresses a user doesn't get a 500
  578. login = self.client.post('/test_admin/admin/', self.super_email_login)
  579. self.assertContains(login, "Please enter a correct username and password.")
  580. # Add User
  581. request = self.client.get('/test_admin/admin/')
  582. self.assertEqual(request.status_code, 200)
  583. login = self.client.post('/test_admin/admin/', self.adduser_login)
  584. self.assertRedirects(login, '/test_admin/admin/')
  585. self.assertFalse(login.context)
  586. self.client.get('/test_admin/admin/logout/')
  587. # Change User
  588. request = self.client.get('/test_admin/admin/')
  589. self.assertEqual(request.status_code, 200)
  590. login = self.client.post('/test_admin/admin/', self.changeuser_login)
  591. self.assertRedirects(login, '/test_admin/admin/')
  592. self.assertFalse(login.context)
  593. self.client.get('/test_admin/admin/logout/')
  594. # Delete User
  595. request = self.client.get('/test_admin/admin/')
  596. self.assertEqual(request.status_code, 200)
  597. login = self.client.post('/test_admin/admin/', self.deleteuser_login)
  598. self.assertRedirects(login, '/test_admin/admin/')
  599. self.assertFalse(login.context)
  600. self.client.get('/test_admin/admin/logout/')
  601. # Regular User should not be able to login.
  602. request = self.client.get('/test_admin/admin/')
  603. self.assertEqual(request.status_code, 200)
  604. login = self.client.post('/test_admin/admin/', self.joepublic_login)
  605. self.assertEqual(login.status_code, 200)
  606. self.assertContains(login, "Please enter a correct username and password.")
  607. # Requests without username should not return 500 errors.
  608. request = self.client.get('/test_admin/admin/')
  609. self.assertEqual(request.status_code, 200)
  610. login = self.client.post('/test_admin/admin/', self.no_username_login)
  611. self.assertEqual(login.status_code, 200)
  612. form = login.context[0].get('form')
  613. self.assertEqual(form.errors['username'][0], 'This field is required.')
  614. def testLoginSuccessfullyRedirectsToOriginalUrl(self):
  615. request = self.client.get('/test_admin/admin/')
  616. self.assertEqual(request.status_code, 200)
  617. query_string = 'the-answer=42'
  618. redirect_url = '/test_admin/admin/?%s' % query_string
  619. new_next = {REDIRECT_FIELD_NAME: redirect_url}
  620. login = self.client.post('/test_admin/admin/', dict(self.super_login, **new_next), QUERY_STRING=query_string)
  621. self.assertRedirects(login, redirect_url)
  622. def testAddView(self):
  623. """Test add view restricts access and actually adds items."""
  624. add_dict = {'title' : 'Døm ikke',
  625. 'content': '<p>great article</p>',
  626. 'date_0': '2008-03-18', 'date_1': '10:54:39',
  627. 'section': 1}
  628. # Change User should not have access to add articles
  629. self.client.get('/test_admin/admin/')
  630. self.client.post('/test_admin/admin/', self.changeuser_login)
  631. # make sure the view removes test cookie
  632. self.assertEqual(self.client.session.test_cookie_worked(), False)
  633. request = self.client.get('/test_admin/admin/admin_views/article/add/')
  634. self.assertEqual(request.status_code, 403)
  635. # Try POST just to make sure
  636. post = self.client.post('/test_admin/admin/admin_views/article/add/', add_dict)
  637. self.assertEqual(post.status_code, 403)
  638. self.assertEqual(Article.objects.all().count(), 3)
  639. self.client.get('/test_admin/admin/logout/')
  640. # Add user may login and POST to add view, then redirect to admin root
  641. self.client.get('/test_admin/admin/')
  642. self.client.post('/test_admin/admin/', self.adduser_login)
  643. addpage = self.client.get('/test_admin/admin/admin_views/article/add/')
  644. self.assertEqual(addpage.status_code, 200)
  645. change_list_link = '<a href="../">Articles</a> &rsaquo;'
  646. self.assertFalse(change_list_link in addpage.content,
  647. 'User restricted to add permission is given link to change list view in breadcrumbs.')
  648. post = self.client.post('/test_admin/admin/admin_views/article/add/', add_dict)
  649. self.assertRedirects(post, '/test_admin/admin/')
  650. self.assertEqual(Article.objects.all().count(), 4)
  651. self.assertEqual(len(mail.outbox), 1)
  652. self.assertEqual(mail.outbox[0].subject, 'Greetings from a created object')
  653. self.client.get('/test_admin/admin/logout/')
  654. # Super can add too, but is redirected to the change list view
  655. self.client.get('/test_admin/admin/')
  656. self.client.post('/test_admin/admin/', self.super_login)
  657. addpage = self.client.get('/test_admin/admin/admin_views/article/add/')
  658. self.assertEqual(addpage.status_code, 200)
  659. self.assertFalse(change_list_link not in addpage.content,
  660. 'Unrestricted user is not given link to change list view in breadcrumbs.')
  661. post = self.client.post('/test_admin/admin/admin_views/article/add/', add_dict)
  662. self.assertRedirects(post, '/test_admin/admin/admin_views/article/')
  663. self.assertEqual(Article.objects.all().count(), 5)
  664. self.client.get('/test_admin/admin/logout/')
  665. # 8509 - if a normal user is already logged in, it is possible
  666. # to change user into the superuser without error
  667. login = self.client.login(username='joepublic', password='secret')
  668. # Check and make sure that if user expires, data still persists
  669. self.client.get('/test_admin/admin/')
  670. self.client.post('/test_admin/admin/', self.super_login)
  671. # make sure the view removes test cookie
  672. self.assertEqual(self.client.session.test_cookie_worked(), False)
  673. def testChangeView(self):
  674. """Change view should restrict access and allow users to edit items."""
  675. change_dict = {'title' : 'Ikke fordømt',
  676. 'content': '<p>edited article</p>',
  677. 'date_0': '2008-03-18', 'date_1': '10:54:39',
  678. 'section': 1}
  679. # add user shoud not be able to view the list of article or change any of them
  680. self.client.get('/test_admin/admin/')
  681. self.client.post('/test_admin/admin/', self.adduser_login)
  682. request = self.client.get('/test_admin/admin/admin_views/article/')
  683. self.assertEqual(request.status_code, 403)
  684. request = self.client.get('/test_admin/admin/admin_views/article/1/')
  685. self.assertEqual(request.status_code, 403)
  686. post = self.client.post('/test_admin/admin/admin_views/article/1/', change_dict)
  687. self.assertEqual(post.status_code, 403)
  688. self.client.get('/test_admin/admin/logout/')
  689. # change user can view all items and edit them
  690. self.client.get('/test_admin/admin/')
  691. self.client.post('/test_admin/admin/', self.changeuser_login)
  692. request = self.client.get('/test_admin/admin/admin_views/article/')
  693. self.assertEqual(request.status_code, 200)
  694. request = self.client.get('/test_admin/admin/admin_views/article/1/')
  695. self.assertEqual(request.status_code, 200)
  696. post = self.client.post('/test_admin/admin/admin_views/article/1/', change_dict)
  697. self.assertRedirects(post, '/test_admin/admin/admin_views/article/')
  698. self.assertEqual(Article.objects.get(pk=1).content, '<p>edited article</p>')
  699. # one error in form should produce singular error message, multiple errors plural
  700. change_dict['title'] = ''
  701. post = self.client.post('/test_admin/admin/admin_views/article/1/', change_dict)
  702. self.assertEqual(request.status_code, 200)
  703. self.assertTrue('Please correct the error below.' in post.content,
  704. 'Singular error message not found in response to post with one error.')
  705. change_dict['content'] = ''
  706. post = self.client.post('/test_admin/admin/admin_views/article/1/', change_dict)
  707. self.assertEqual(request.status_code, 200)
  708. self.assertTrue('Please correct the errors below.' in post.content,
  709. 'Plural error message not found in response to post with multiple errors.')
  710. self.client.get('/test_admin/admin/logout/')
  711. # Test redirection when using row-level change permissions. Refs #11513.
  712. RowLevelChangePermissionModel.objects.create(name="odd id")
  713. RowLevelChangePermissionModel.objects.create(name="even id")
  714. for login_dict in [self.super_login, self.changeuser_login, self.adduser_login, self.deleteuser_login]:
  715. self.client.post('/test_admin/admin/', login_dict)
  716. request = self.client.get('/test_admin/admin/admin_views/rowlevelchangepermissionmodel/1/')
  717. self.assertEqual(request.status_code, 403)
  718. request = self.client.post('/test_admin/admin/admin_views/rowlevelchangepermissionmodel/1/', {'name': 'changed'})
  719. self.assertEqual(RowLevelChangePermissionModel.objects.get(id=1).name, 'odd id')
  720. self.assertEqual(request.status_code, 403)
  721. request = self.client.get('/test_admin/admin/admin_views/rowlevelchangepermissionmodel/2/')
  722. self.assertEqual(request.status_code, 200)
  723. request = self.client.post('/test_admin/admin/admin_views/rowlevelchangepermissionmodel/2/', {'name': 'changed'})
  724. self.assertEqual(RowLevelChangePermissionModel.objects.get(id=2).name, 'changed')
  725. self.assertRedirects(request, '/test_admin/admin/')
  726. self.client.get('/test_admin/admin/logout/')
  727. for login_dict in [self.joepublic_login, self.no_username_login]:
  728. self.client.post('/test_admin/admin/', login_dict)
  729. request = self.client.get('/test_admin/admin/admin_views/rowlevelchangepermissionmodel/1/')
  730. self.assertEqual(request.status_code, 200)
  731. self.assertContains(request, 'login-form')
  732. request = self.client.post('/test_admin/admin/admin_views/rowlevelchangepermissionmodel/1/', {'name': 'changed'})
  733. self.assertEqual(RowLevelChangePermissionModel.objects.get(id=1).name, 'odd id')
  734. self.assertEqual(request.status_code, 200)
  735. self.assertContains(request, 'login-form')
  736. request = self.client.get('/test_admin/admin/admin_views/rowlevelchangepermissionmodel/2/')
  737. self.assertEqual(request.status_code, 200)
  738. self.assertContains(request, 'login-form')
  739. request = self.client.post('/test_admin/admin/admin_views/rowlevelchangepermissionmodel/2/', {'name': 'changed again'})
  740. self.assertEqual(RowLevelChangePermissionModel.objects.get(id=2).name, 'changed')
  741. self.assertEqual(request.status_code, 200)
  742. self.assertContains(request, 'login-form')
  743. self.client.get('/test_admin/admin/logout/')
  744. def testConditionallyShowAddSectionLink(self):
  745. """
  746. The foreign key widget should only show the "add related" button if the
  747. user has permission to add that related item.
  748. """
  749. # Set up and log in user.
  750. url = '/test_admin/admin/admin_views/article/add/'
  751. add_link_text = ' class="add-another"'
  752. self.client.get('/test_admin/admin/')
  753. self.client.post('/test_admin/admin/', self.adduser_login)
  754. # The add user can't add sections yet, so they shouldn't see the "add
  755. # section" link.
  756. response = self.client.get(url)
  757. self.assertNotContains(response, add_link_text)
  758. # Allow the add user to add sections too. Now they can see the "add
  759. # section" link.
  760. add_user = User.objects.get(username='adduser')
  761. perm = get_perm(Section, Section._meta.get_add_permission())
  762. add_user.user_permissions.add(perm)
  763. response = self.client.get(url)
  764. self.assertContains(response, add_link_text)
  765. def testCustomModelAdminTemplates(self):
  766. self.client.get('/test_admin/admin/')
  767. self.client.post('/test_admin/admin/', self.super_login)
  768. # Test custom change list template with custom extra context
  769. request = self.client.get('/test_admin/admin/admin_views/customarticle/')
  770. self.assertEqual(request.status_code, 200)
  771. self.assertTrue("var hello = 'Hello!';" in request.content)
  772. self.assertTemplateUsed(request, 'custom_admin/change_list.html')
  773. # Test custom add form template
  774. request = self.client.get('/test_admin/admin/admin_views/customarticle/add/')
  775. self.assertTemplateUsed(request, 'custom_admin/add_form.html')
  776. # Add an article so we can test delete, change, and history views
  777. post = self.client.post('/test_admin/admin/admin_views/customarticle/add/', {
  778. 'content': '<p>great article</p>',
  779. 'date_0': '2008-03-18',
  780. 'date_1': '10:54:39'
  781. })
  782. self.assertRedirects(post, '/test_admin/admin/admin_views/customarticle/')
  783. self.assertEqual(CustomArticle.objects.all().count(), 1)
  784. # Test custom delete, change, and object history templates
  785. # Test custom change form template
  786. request = self.client.get('/test_admin/admin/admin_views/customarticle/1/')
  787. self.assertTemplateUsed(request, 'custom_admin/change_form.html')
  788. request = self.client.get('/test_admin/admin/admin_views/customarticle/1/delete/')
  789. self.assertTemplateUsed(request, 'custom_admin/delete_confirmation.html')
  790. request = self.client.post('/test_admin/admin/admin_views/customarticle/', data={
  791. 'index': 0,
  792. 'action': ['delete_selected'],
  793. '_selected_action': ['1'],
  794. })
  795. self.assertTemplateUsed(request, 'custom_admin/delete_selected_confirmation.html')
  796. request = self.client.get('/test_admin/admin/admin_views/customarticle/1/history/')
  797. self.assertTemplateUsed(request, 'custom_admin/object_history.html')
  798. self.client.get('/test_admin/admin/logout/')
  799. def testDeleteView(self):
  800. """Delete view should restrict access and actually delete items."""
  801. delete_dict = {'post': 'yes'}
  802. # add user shoud not be able to delete articles
  803. self.client.get('/test_admin/admin/')
  804. self.client.post('/test_admin/admin/', self.adduser_login)
  805. request = self.client.get('/test_admin/admin/admin_views/article/1/delete/')
  806. self.assertEqual(request.status_code, 403)
  807. post = self.client.post('/test_admin/admin/admin_views/article/1/delete/', delete_dict)
  808. self.assertEqual(post.status_code, 403)
  809. self.assertEqual(Article.objects.all().count(), 3)
  810. self.client.get('/test_admin/admin/logout/')
  811. # Delete user can delete
  812. self.client.get('/test_admin/admin/')
  813. self.client.post('/test_admin/admin/', self.deleteuser_login)
  814. response = self.client.get('/test_admin/admin/admin_views/section/1/delete/')
  815. # test response contains link to related Article
  816. self.assertContains(response, "admin_views/article/1/")
  817. response = self.client.get('/test_admin/admin/admin_views/article/1/delete/')
  818. self.assertEqual(response.status_code, 200)
  819. post = self.client.post('/test_admin/admin/admin_views/article/1/delete/', delete_dict)
  820. self.assertRedirects(post, '/test_admin/admin/')
  821. self.assertEqual(Article.objects.all().count(), 2)
  822. self.assertEqual(len(mail.outbox), 1)
  823. self.assertEqual(mail.outbox[0].subject, 'Greetings from a deleted object')
  824. article_ct = ContentType.objects.get_for_model(Article)
  825. logged = LogEntry.objects.get(content_type=article_ct, action_flag=DELETION)
  826. self.assertEqual(logged.object_id, u'1')
  827. self.client.get('/test_admin/admin/logout/')
  828. def testDisabledPermissionsWhenLoggedIn(self):
  829. self.client.login(username='super', password='secret')
  830. superuser = User.objects.get(username='super')
  831. superuser.is_active = False
  832. superuser.save()
  833. response = self.client.get('/test_admin/admin/')
  834. self.assertContains(response, 'id="login-form"')
  835. self.assertNotContains(response, 'Log out')
  836. response = self.client.get('/test_admin/admin/secure-view/')
  837. self.assertContains(response, 'id="login-form"')
  838. class AdminViewDeletedObjectsTest(TestCase):
  839. fixtures = ['admin-views-users.xml', 'deleted-objects.xml']
  840. def setUp(self):
  841. self.client.login(username='super', password='secret')
  842. def tearDown(self):
  843. self.client.logout()
  844. def test_nesting(self):
  845. """
  846. Objects should be nested to display the relationships that
  847. cause them to be scheduled for deletion.
  848. """
  849. pattern = re.compile(r"""<li>Plot: <a href=".+/admin_views/plot/1/">World Domination</a>\s*<ul>\s*<li>Plot details: <a href=".+/admin_views/plotdetails/1/">almost finished</a>""")
  850. response = self.client.get('/test_admin/admin/admin_views/villain/%s/delete/' % quote(1))
  851. self.assertTrue(pattern.search(response.content))
  852. def test_cyclic(self):
  853. """
  854. Cyclic relationships should still cause each object to only be
  855. listed once.
  856. """
  857. one = """<li>Cyclic one: <a href="/test_admin/admin/admin_views/cyclicone/1/">I am recursive</a>"""
  858. two = """<li>Cyclic two: <a href="/test_admin/admin/admin_views/cyclictwo/1/">I am recursive too</a>"""
  859. response = self.client.get('/test_admin/admin/admin_views/cyclicone/%s/delete/' % quote(1))
  860. self.assertContains(response, one, 1)
  861. self.assertContains(response, two, 1)
  862. def test_perms_needed(self):
  863. self.client.logout()
  864. delete_user = User.objects.get(username='deleteuser')
  865. delete_user.user_permissions.add(get_perm(Plot,
  866. Plot._meta.get_delete_permission()))
  867. self.assertTrue(self.client.login(username='deleteuser',
  868. password='secret'))
  869. response = self.client.get('/test_admin/admin/admin_views/plot/%s/delete/' % quote(1))
  870. self.assertContains(response, "your account doesn't have permission to delete the following types of objects")
  871. self.assertContains(response, "<li>plot details</li>")
  872. def test_protected(self):
  873. q = Question.objects.create(question="Why?")
  874. a1 = Answer.objects.create(question=q, answer="Because.")
  875. a2 = Answer.objects.create(question=q, answer="Yes.")
  876. response = self.client.get("/test_admin/admin/admin_views/question/%s/delete/" % quote(q.pk))
  877. self.assertContains(response, "would require deleting the following protected related objects")
  878. self.assertContains(response, '<li>Answer: <a href="/test_admin/admin/admin_views/answer/%s/">Because.</a></li>' % a1.pk)
  879. self.assertContains(response, '<li>Answer: <a href="/test_admin/admin/admin_views/answer/%s/">Yes.</a></li>' % a2.pk)
  880. def test_not_registered(self):
  881. should_contain = """<li>Secret hideout: underground bunker"""
  882. response = self.client.get('/test_admin/admin/admin_views/villain/%s/delete/' % quote(1))
  883. self.assertContains(response, should_contain, 1)
  884. def test_multiple_fkeys_to_same_model(self):
  885. """
  886. If a deleted object has two relationships from another model,
  887. both of those should be followed in looking for related
  888. objects to delete.
  889. """
  890. should_contain = """<li>Plot: <a href="/test_admin/admin/admin_views/plot/1/">World Domination</a>"""
  891. response = self.client.get('/test_admin/admin/admin_views/villain/%s/delete/' % quote(1))
  892. self.assertContains(response, should_contain)
  893. response = self.client.get('/test_admin/admin/admin_views/villain/%s/delete/' % quote(2))
  894. self.assertContains(response, should_contain)
  895. def test_multiple_fkeys_to_same_instance(self):
  896. """
  897. If a deleted object has two relationships pointing to it from
  898. another object, the other object should still only be listed
  899. once.
  900. """
  901. should_contain = """<li>Plot: <a href="/test_admin/admin/admin_views/plot/2/">World Peace</a></li>"""
  902. response = self.client.get('/test_admin/admin/admin_views/villain/%s/delete/' % quote(2))
  903. self.assertContains(response, should_contain, 1)
  904. def test_inheritance(self):
  905. """
  906. In the case of an inherited model, if either the child or
  907. parent-model instance is deleted, both instances are listed
  908. for deletion, as well as any relationships they have.
  909. """
  910. should_contain = [
  911. """<li>Villain: <a href="/test_admin/admin/admin_views/villain/3/">Bob</a>""",
  912. """<li>Super villain: <a href="/test_admin/admin/admin_views/supervillain/3/">Bob</a>""",
  913. """<li>Secret hideout: floating castle""",
  914. """<li>Super secret hideout: super floating castle!"""
  915. ]
  916. response = self.client.get('/test_admin/admin/admin_views/villain/%s/delete/' % quote(3))
  917. for should in should_contain:
  918. self.assertContains(response, should, 1)
  919. response = self.client.get('/test_admin/admin/admin_views/supervillain/%s/delete/' % quote(3))
  920. for should in should_contain:
  921. self.assertContains(response, should, 1)
  922. def test_generic_relations(self):
  923. """
  924. If a deleted object has GenericForeignKeys pointing to it,
  925. those objects should be listed for deletion.
  926. """
  927. plot = Plot.objects.get(pk=3)
  928. tag = FunkyTag.objects.create(content_object=plot, name='hott')
  929. should_contain = """<li>Funky tag: hott"""
  930. response = self.client.get('/test_admin/admin/admin_views/plot/%s/delete/' % quote(3))
  931. self.assertContains(response, should_contain)
  932. class AdminViewStringPrimaryKeyTest(TestCase):
  933. fixtures = ['admin-views-users.xml', 'string-primary-key.xml']
  934. def __init__(self, *args):
  935. super(AdminViewStringPrimaryKeyTest, self).__init__(*args)
  936. self.pk = """abcdefghijklmnopqrstuvwxyz ABCDEFGHIJKLMNOPQRSTUVWXYZ 1234567890 -_.!~*'() ;/?:@&=+$, <>#%" {}|\^[]`"""
  937. def setUp(self):
  938. self.client.login(username='super', password='secret')
  939. content_type_pk = ContentType.objects.get_for_model(ModelWithStringPrimaryKey).pk
  940. LogEntry.objects.log_action(100, content_type_pk, self.pk, self.pk, 2, change_message='')
  941. def tearDown(self):
  942. self.client.logout()
  943. def test_get_history_view(self):
  944. "Retrieving the history for the object using urlencoded form of primary key should work"
  945. response = self.client.get('/test_admin/admin/admin_views/modelwithstringprimarykey/%s/history/' % quote(self.pk))
  946. self.assertContains(response, escape(self.pk))
  947. self.assertEqual(response.status_code, 200)
  948. def test_get_change_view(self):
  949. "Retrieving the object using urlencoded form of primary key should work"
  950. response = self.client.get('/test_admin/admin/admin_views/modelwithstringprimarykey/%s/' % quote(self.pk))
  951. self.assertContains(response, escape(self.pk))
  952. self.assertEqual(response.status_code, 200)
  953. def test_changelist_to_changeform_link(self):
  954. "The link from the changelist referring to the changeform of the object should be quoted"
  955. response = self.client.get('/test_admin/admin/admin_views/modelwithstringprimarykey/')
  956. should_contain = """<th><a href="%s/">%s</a></th></tr>""" % (quote(self.pk), escape(self.pk))
  957. self.assertContains(response, should_contain)
  958. def test_recentactions_link(self):
  959. "The link from the recent actions list referring to the changeform of the object should be quoted"
  960. response = self.client.get('/test_admin/admin/')
  961. should_contain = """<a href="admin_views/modelwithstringprimarykey/%s/">%s</a>""" % (quote(self.pk), escape(self.pk))
  962. self.assertContains(response, should_contain)
  963. def test_recentactions_without_content_type(self):
  964. "If a LogEntry is missing content_type it will not display it in span tag under the hyperlink."
  965. response = self.client.get('/test_admin/admin/')
  966. should_contain = """<a href="admin_views/modelwithstringprimarykey/%s/">%s</a>""" % (quote(self.pk), escape(self.pk))
  967. self.assertContains(response, should_contain)
  968. should_contain = "Model with string primary key" # capitalized in Recent Actions
  969. self.assertContains(response, should_contain)
  970. logentry = LogEntry.objects.get(content_type__name__iexact=should_contain)
  971. # http://code.djangoproject.com/ticket/10275
  972. # if the log entry doesn't have a content type it should still be
  973. # possible to view the Recent Actions part
  974. logentry.content_type = None
  975. logentry.save()
  976. counted_presence_before = response.content.count(should_contain)
  977. response = self.client.get('/test_admin/admin/')
  978. counted_presence_after = response.content.count(should_contain)
  979. self.assertEqual(counted_presence_before - 1,
  980. counted_presence_after)
  981. def test_deleteconfirmation_link(self):
  982. "The link from the delete confirmation page referring back to the changeform of the object should be quoted"
  983. response = self.client.get('/test_admin/admin/admin_views/modelwithstringprimarykey/%s/delete/' % quote(self.pk))
  984. # this URL now comes through reverse(), thus iri_to_uri encoding
  985. should_contain = """/%s/">%s</a>""" % (iri_to_uri(quote(self.pk)), escape(self.pk))
  986. self.assertContains(response, should_contain)
  987. def test_url_conflicts_with_add(self):
  988. "A model with a primary key that ends with add should be visible"
  989. add_model = ModelWithStringPrimaryKey(id="i have something to add")
  990. add_model.save()
  991. response = self.client.get('/test_admin/admin/admin_views/modelwithstringprimarykey/%s/' % quote(add_model.pk))
  992. should_contain = """<h1>Change model with string primary key</h1>"""
  993. self.assertContains(response, should_contain)
  994. def test_url_conflicts_with_delete(self):
  995. "A model with a primary key that ends with delete should be visible"
  996. delete_model = ModelWithStringPrimaryKey(id="delete")
  997. delete_model.save()
  998. response = self.client.get('/test_admin/admin/admin_views/modelwithstringprimarykey/%s/' % quote(delete_model.pk))
  999. should_contain = """<h1>Change model with string primary key</h1>"""
  1000. self.assertContains(response, should_contain)
  1001. def test_url_conflicts_with_history(self):
  1002. "A model with a primary key that ends with history should be visible"
  1003. history_model = ModelWithStringPrimaryKey(id="history")
  1004. history_model.save()
  1005. response = self.client.get('/test_admin/admin/admin_views/modelwithstringprimarykey/%s/' % quote(history_model.pk))
  1006. should_contain = """<h1>Change model with string primary key</h1>"""
  1007. self.assertContains(response, should_contain)
  1008. class SecureViewTests(TestCase):
  1009. fixtures = ['admin-views-users.xml']
  1010. def setUp(self):
  1011. # login POST dicts
  1012. self.super_login = {
  1013. LOGIN_FORM_KEY: 1,
  1014. REDIRECT_FIELD_NAME: '/test_admin/admin/secure-view/',
  1015. 'username': 'super',
  1016. 'password': 'secret',
  1017. }
  1018. self.super_email_login = {
  1019. LOGIN_FORM_KEY: 1,
  1020. REDIRECT_FIELD_NAME: '/test_admin/admin/secure-view/',
  1021. 'username': 'super@example.com',
  1022. 'password': 'secret',
  1023. }
  1024. self.super_email_bad_login = {
  1025. LOGIN_FORM_KEY: 1,
  1026. REDIRECT_FIELD_NAME: '/test_admin/admin/secure-view/',
  1027. 'username': 'super@example.com',
  1028. 'password': 'notsecret',
  1029. }
  1030. self.adduser_login = {
  1031. LOGIN_FORM_KEY: 1,
  1032. REDIRECT_FIELD_NAME: '/test_admin/admin/secure-view/',
  1033. 'username': 'adduser',
  1034. 'password': 'secret',
  1035. }
  1036. self.changeuser_login = {
  1037. LOGIN_FORM_KEY: 1,
  1038. REDIRECT_FIELD_NAME: '/test_admin/admin/secure-view/',
  1039. 'username': 'changeuser',
  1040. 'password': 'secret',
  1041. }
  1042. self.deleteuser_login = {
  1043. LOGIN_FORM_KEY: 1,
  1044. REDIRECT_FIELD_NAME: '/test_admin/admin/secure-view/',
  1045. 'username': 'deleteuser',
  1046. 'password': 'secret',
  1047. }
  1048. self.joepublic_login = {
  1049. LOGIN_FORM_KEY: 1,
  1050. REDIRECT_FIELD_NAME: '/test_admin/admin/secure-view/',
  1051. 'username': 'joepublic',
  1052. 'password': 'secret',
  1053. }
  1054. def tearDown(self):
  1055. self.client.logout()
  1056. def test_secure_view_shows_login_if_not_logged_in(self):
  1057. "Ensure that we see the login form"
  1058. response = self.client.get('/test_admin/admin/secure-view/' )
  1059. self.assertTemplateUsed(response, 'admin/login.html')
  1060. def test_secure_view_login_successfully_redirects_to_original_url(self):
  1061. request = self.client.get('/test_admin/admin/secure-view/')
  1062. self.assertEqual(request.status_code, 200)
  1063. query_string = 'the-answer=42'
  1064. redirect_url = '/test_admin/admin/secure-view/?%s' % query_string
  1065. new_next = {REDIRECT_FIELD_NAME: redirect_url}
  1066. login = self.client.post('/test_admin/admin/secure-view/', dict(self.super_login, **new_next), QUERY_STRING=query_string)
  1067. self.assertRedirects(login, redirect_url)
  1068. def test_staff_member_required_decorator_works_as_per_admin_login(self):
  1069. """
  1070. Make sure only staff members can log in.
  1071. Successful posts to the login page will redirect to the orignal url.
  1072. Unsuccessfull attempts will continue to render the login page with
  1073. a 200 status code.
  1074. """
  1075. # Super User
  1076. request = self.client.get('/test_admin/admin/secure-view/')
  1077. self.assertEqual(request.status_code, 200)
  1078. login = self.client.post('/test_admin/admin/secure-view/', self.super_login)
  1079. self.assertRedirects(login, '/test_admin/admin/secure-view/')
  1080. self.assertFalse(login.context)
  1081. self.client.get('/test_admin/admin/logout/')
  1082. # make sure the view removes test cookie
  1083. self.assertEqual(self.client.session.test_cookie_worked(), False)
  1084. # Test if user enters e-mail address
  1085. request = self.client.get('/test_admin/admin/secure-view/')
  1086. self.assertEqual(request.status_code, 200)
  1087. login = self.client.post('/test_admin/admin/secure-view/', self.super_email_login)
  1088. self.assertContains(login, "Your e-mail address is not your username")
  1089. # only correct passwords get a username hint
  1090. login = self.client.post('/test_admin/admin/secure-view/', self.super_email_bad_login)
  1091. self.assertContains(login, "Please enter a correct username and password.")
  1092. new_user = User(username='jondoe', password='secret', email='super@example.com')
  1093. new_user.save()
  1094. # check to ensure if there are multiple e-mail addresses a user doesn't get a 500
  1095. login = self.client.post('/test_admin/admin/secure-view/', self.super_email_login)
  1096. self.assertContains(login, "Please enter a correct username and password.")
  1097. # Add User
  1098. request = self.client.get('/test_admin/admin/secure-view/')
  1099. self.assertEqual(request.status_code, 200)
  1100. login = self.client.post('/test_admin/admin/secure-view/', self.adduser_login)
  1101. self.assertRedirects(login, '/test_admin/admin/secure-view/')
  1102. self.assertFalse(login.context)
  1103. self.client.get('/test_admin/admin/logout/')
  1104. # Change User
  1105. request = self.client.get('/test_admin/admin/secure-view/')
  1106. self.assertEqual(request.status_code, 200)
  1107. login = self.client.post('/test_admin/admin/secure-view/', self.changeuser_login)
  1108. self.assertRedirects(login, '/test_admin/admin/secure-view/')
  1109. self.assertFalse(login.context)
  1110. self.client.get('/test_admin/admin/logout/')
  1111. # Delete User
  1112. request = self.client.get('/test_admin/admin/secure-view/')
  1113. self.assertEqual(request.status_code, 200)
  1114. login = self.client.post('/test_admin/admin/secure-view/', self.deleteuser_login)
  1115. self.assertRedirects(login, '/test_admin/admin/secure-view/')
  1116. self.assertFalse(login.context)
  1117. self.client.get('/test_admin/admin/logout/')
  1118. # Regular User should not be able to login.
  1119. request = self.client.get('/test_admin/admin/secure-view/')
  1120. self.assertEqual(request.status_code, 200)
  1121. login = self.client.post('/test_admin/admin/secure-view/', self.joepublic_login)
  1122. self.assertEqual(login.status_code, 200)
  1123. # Login.context is a list of context dicts we just need to check the first one.
  1124. self.assertContains(login, "Please enter a correct username and password.")
  1125. # 8509 - if a normal user is already logged in, it is possible
  1126. # to change user into the superuser without error
  1127. login = self.client.login(username='joepublic', password='secret')
  1128. # Check and make sure that if user expires, data still persists
  1129. self.client.get('/test_admin/admin/secure-view/')
  1130. self.client.post('/test_admin/admin/secure-view/', self.super_login)
  1131. # make sure the view removes test cookie
  1132. self.assertEqual(self.client.session.test_cookie_worked(), False)
  1133. def test_shortcut_view_only_available_to_staff(self):
  1134. """
  1135. Only admin users should be able to use the admin shortcut view.
  1136. """
  1137. user_ctype = ContentType.objects.get_for_model(User)
  1138. user = User.objects.get(username='super')
  1139. shortcut_url = "/test_admin/admin/r/%s/%s/" % (user_ctype.pk, user.pk)
  1140. # Not logged in: we should see the login page.
  1141. response = self.client.get(shortcut_url, follow=False)
  1142. self.assertTemplateUsed(response, 'admin/login.html')
  1143. # Logged in? Redirect.
  1144. self.client.login(username='super', password='secret')
  1145. response = self.client.get(shortcut_url, follow=False)
  1146. # Can't use self.assertRedirects() because User.get_absolute_url() is silly.
  1147. self.assertEqual(response.status_code, 302)
  1148. self.assertEqual(response['Location'], 'http://example.com/users/super/')
  1149. class AdminViewUnicodeTest(TestCase):
  1150. fixtures = ['admin-views-unicode.xml']
  1151. def setUp(self):
  1152. self.client.login(username='super', password='secret')
  1153. def tearDown(self):
  1154. self.client.logout()
  1155. def testUnicodeEdit(self):
  1156. """
  1157. A test to ensure that POST on edit_view handles non-ascii characters.
  1158. """
  1159. post_data = {
  1160. "name": u"Test lærdommer",
  1161. # inline data
  1162. "chapter_set-TOTAL_FORMS": u"6",
  1163. "chapter_set-INITIAL_FORMS": u"3",
  1164. "chapter_set-MAX_NUM_FORMS": u"0",
  1165. "chapter_set-0-id": u"1",
  1166. "chapter_set-0-title": u"Norske bostaver æøå skaper problemer",
  1167. "chapter_set-0-content": u"&lt;p&gt;Svært frustrerende med UnicodeDecodeError&lt;/p&gt;",
  1168. "chapter_set-1-id": u"2",
  1169. "chapter_set-1-title": u"Kjærlighet.",
  1170. "chapter_set-1-content": u"&lt;p&gt;La kjærligheten til de lidende seire.&lt;/p&gt;",
  1171. "chapter_set-2-id": u"3",
  1172. "chapter_set-2-title": u"Need a title.",
  1173. "chapter_set-2-content": u"&lt;p&gt;Newest content&lt;/p&gt;",
  1174. "chapter_set-3-id": u"",
  1175. "chapter_set-3-title": u"",
  1176. "chapter_set-3-content": u"",
  1177. "chapter_set-4-id": u"",
  1178. "chapter_set-4-title": u"",
  1179. "chapter_set-4-content": u"",
  1180. "chapter_set-5-id": u"",
  1181. "chapter_set-5-title": u"",
  1182. "chapter_set-5-content": u"",
  1183. }
  1184. response = self.client.post('/test_admin/admin/admin_views/book/1/', post_data)
  1185. self.assertEqual(response.status_code, 302) # redirect somewhere
  1186. def testUnicodeDelete(self):
  1187. """
  1188. Ensure that the delete_view handles non-ascii characters
  1189. """
  1190. delete_dict = {'post': 'yes'}
  1191. response = self.client.get('/test_admin/admin/admin_views/book/1/delete/')
  1192. self.assertEqual(response.status_code, 200)
  1193. response = self.client.post('/test_admin/admin/admin_views/book/1/delete/', delete_dict)
  1194. self.assertRedirects(response, '/test_admin/admin/admin_views/book/')
  1195. class AdminViewListEditable(TestCase):
  1196. fixtures = ['admin-views-users.xml', 'admin-views-person.xml']
  1197. def setUp(self):
  1198. self.client.login(username='super', password='secret')
  1199. def tearDown(self):
  1200. self.client.logout()
  1201. def test_inheritance(self):
  1202. Podcast.objects.create(name="This Week in Django",
  1203. release_date=datetime.date.today())
  1204. response = self.client.get('/test_admin/admin/admin_views/podcast/')
  1205. self.assertEqual(response.status_code, 200)
  1206. def test_inheritance_2(self):
  1207. Vodcast.objects.create(name="This Week in Django", released=True)
  1208. response = self.client.get('/test_admin/admin/admin_views/vodcast/')
  1209. self.assertEqual(response.status_code, 200)
  1210. def test_custom_pk(self):
  1211. Language.objects.create(iso='en', name='English', english_name='English')
  1212. response = self.client.get('/test_admin/admin/admin_views/language/')
  1213. self.assertEqual(response.status_code, 200)
  1214. def test_changelist_input_html(self):
  1215. response = self.client.get('/test_admin/admin/admin_views/person/')
  1216. # 2 inputs per object(the field and the hidden id field) = 6
  1217. # 3 management hidden fields = 3
  1218. # 4 action inputs (3 regular checkboxes, 1 checkbox to select all)
  1219. # main form submit button = 1
  1220. # search field and search submit button = 2
  1221. # CSRF field = 1
  1222. # field to track 'select all' across paginated views = 1
  1223. # 6 + 3 + 4 + 1 + 2 + 1 + 1 = 18 inputs
  1224. self.assertEqual(response.content.count("<input"), 18)
  1225. # 1 select per object = 3 selects
  1226. self.assertEqual(response.content.count("<select"), 4)
  1227. def test_post_messages(self):
  1228. # Ticket 12707: Saving inline editable should not show admin
  1229. # action warnings
  1230. data = {
  1231. "form-TOTAL_FORMS": "3",
  1232. "form-INITIAL_FORMS": "3",
  1233. "form-MAX_NUM_FORMS": "0",
  1234. "form-0-gender": "1",
  1235. "form-0-id": "1",
  1236. "form-1-gender": "2",
  1237. "form-1-id": "2",
  1238. "form-2-alive": "checked",
  1239. "form-2-gender": "1",
  1240. "form-2-id": "3",
  1241. "_save": "Save",
  1242. }
  1243. response = self.client.post('/test_admin/admin/admin_views/person/',
  1244. data, follow=True)
  1245. self.assertEqual(len(response.context['messages']), 1)
  1246. def test_post_submission(self):
  1247. data = {
  1248. "form-TOTAL_FORMS": "3",
  1249. "form-INITIAL_FORMS": "3",
  1250. "form-MAX_NUM_FORMS": "0",
  1251. "form-0-gender": "1",
  1252. "form-0-id": "1",
  1253. "form-1-gender": "2",
  1254. "form-1-id": "2",
  1255. "form-2-alive": "checked",
  1256. "form-2-gender": "1",
  1257. "form-2-id": "3",
  1258. "_save": "Save",
  1259. }
  1260. self.client.post('/test_admin/admin/admin_views/person/', data)
  1261. self.assertEqual(Person.objects.get(name="John Mauchly").alive, False)
  1262. self.assertEqual(Person.objects.get(name="Grace Hopper").gender, 2)
  1263. # test a filtered page
  1264. data = {
  1265. "form-TOTAL_FORMS": "2",
  1266. "form-INITIAL_FORMS": "2",
  1267. "form-MAX_NUM_FORMS": "0",
  1268. "form-0-id": "1",
  1269. "form-0-gender": "1",
  1270. "form-0-alive": "checked",
  1271. "form-1-id": "3",
  1272. "form-1-gender": "1",
  1273. "form-1-alive": "checked",
  1274. "_save": "Save",
  1275. }
  1276. self.client.post('/test_admin/admin/admin_views/person/?gender__exact=1', data)
  1277. self.assertEqual(Person.objects.get(name="John Mauchly").alive, True)
  1278. # test a searched page
  1279. data = {
  1280. "form-TOTAL_FORMS": "1",
  1281. "form-INITIAL_FORMS": "1",
  1282. "form-MAX_NUM_FORMS": "0",
  1283. "form-0-id": "1",
  1284. "form-0-gender": "1",
  1285. "_save": "Save",
  1286. }
  1287. self.client.post('/test_admin/admin/admin_views/person/?q=john', data)
  1288. self.assertEqual(Person.objects.get(name="John Mauchly").alive, False)
  1289. def test_non_field_errors(self):
  1290. ''' Ensure that non field errors are displayed for each of the
  1291. forms in the changelist's formset. Refs #13126.
  1292. '''
  1293. FoodDelivery.objects.create(reference='123', driver='bill', restaurant='thai')
  1294. FoodDelivery.objects.create(reference='456', driver='bill', restaurant='india')
  1295. FoodDelivery.objects.create(reference='789', driver='bill', restaurant='pizza')
  1296. data = {
  1297. "form-TOTAL_FORMS": "3",
  1298. "form-INITIAL_FORMS": "3",
  1299. "form-MAX_NUM_FORMS": "0",
  1300. "form-0-id": "1",
  1301. "form-0-reference": "123",
  1302. "form-0-driver": "bill",
  1303. "form-0-restaurant": "thai",
  1304. # Same data as above: Forbidden because of unique_together!
  1305. "form-1-id": "2",
  1306. "form-1-reference": "456",
  1307. "form-1-driver": "bill",
  1308. "form-1-restaurant": "thai",
  1309. "form-2-id": "3",
  1310. "form-2-reference": "789",
  1311. "form-2-driver": "bill",
  1312. "form-2-restaurant": "pizza",
  1313. "_save": "Save",
  1314. }
  1315. response = self.client.post('/test_admin/admin/admin_views/fooddelivery/', data)
  1316. self.assertContains(response, '<tr><td colspan="4"><ul class="errorlist"><li>Food delivery with this Driver and Restaurant already exists.</li></ul></td></tr>', 1)
  1317. data = {
  1318. "form-TOTAL_FORMS": "3",
  1319. "form-INITIAL_FORMS": "3",
  1320. "form-MAX_NUM_FORMS": "0",
  1321. "form-0-id": "1",
  1322. "form-0-reference": "123",
  1323. "form-0-driver": "bill",
  1324. "form-0-restaurant": "thai",
  1325. # Same data as above: Forbidden because of unique_together!
  1326. "form-1-id": "2",
  1327. "form-1-reference": "456",
  1328. "form-1-driver": "bill",
  1329. "form-1-restaurant": "thai",
  1330. # Same data also.
  1331. "form-2-id": "3",
  1332. "form-2-reference": "789",
  1333. "form-2-driver": "bill",
  1334. "form-2-restaurant": "thai",
  1335. "_save": "Save",
  1336. }
  1337. response = self.client.post('/test_admin/admin/admin_views/fooddelivery/', data)
  1338. self.assertContains(response, '<tr><td colspan="4"><ul class="errorlist"><li>Food delivery with this Driver and Restaurant already exists.</li></ul></td></tr>', 2)
  1339. def test_non_form_errors(self):
  1340. # test if non-form errors are handled; ticket #12716
  1341. data = {
  1342. "form-TOTAL_FORMS": "1",
  1343. "form-INITIAL_FORMS": "1",
  1344. "form-MAX_NUM_FORMS": "0",
  1345. "form-0-id": "2",
  1346. "form-0-alive": "1",
  1347. "form-0-gender": "2",
  1348. # Ensure that the form processing understands this as a list_editable "Save"
  1349. # and not an action "Go".
  1350. "_save": "Save",
  1351. }
  1352. response = self.client.post('/test_admin/admin/admin_views/person/', data)
  1353. self.assertContains(response, "Grace is not a Zombie")
  1354. def test_non_form_errors_is_errorlist(self):
  1355. # test if non-form errors are correctly handled; ticket #12878
  1356. data = {
  1357. "form-TOTAL_FORMS": "1",
  1358. "form-INITIAL_FORMS": "1",
  1359. "form-MAX_NUM_FORMS": "0",
  1360. "form-0-id": "2",
  1361. "form-0-alive": "1",
  1362. "form-0-gender": "2",
  1363. "_save": "Save",
  1364. }
  1365. response = self.client.post('/test_admin/admin/admin_views/person/', data)
  1366. non_form_errors = response.context['cl'].formset.non_form_errors()
  1367. self.assertTrue(isinstance(non_form_errors, ErrorList))
  1368. self.assertEqual(str(non_form_errors), str(ErrorList(["Grace is not a Zombie"])))
  1369. def test_list_editable_ordering(self):
  1370. collector = Collector.objects.create(id=1, name="Frederick Clegg")
  1371. Category.objects.create(id=1, order=1, collector=collector)
  1372. Category.objects.create(id=2, order=2, collector=collector)
  1373. Category.objects.create(id=3, order=0, collector=collector)
  1374. Category.objects.create(id=4, order=0, collector=collector)
  1375. # NB: The order values must be changed so that the items are reordered.
  1376. data = {
  1377. "form-TOTAL_FORMS": "4",
  1378. "form-INITIAL_FORMS": "4",
  1379. "form-MAX_NUM_FORMS": "0",
  1380. "form-0-order": "14",
  1381. "form-0-id": "1",
  1382. "form-0-collector": "1",
  1383. "form-1-order": "13",
  1384. "form-1-id": "2",
  1385. "form-1-collector": "1",
  1386. "form-2-order": "1",
  1387. "form-2-id": "3",
  1388. "form-2-collector": "1",
  1389. "form-3-order": "0",
  1390. "form-3-id": "4",
  1391. "form-3-collector": "1",
  1392. # Ensure that the form processing understands this as a list_editable "Save"
  1393. # and not an action "Go".
  1394. "_save": "Save",
  1395. }
  1396. response = self.client.post('/test_admin/admin/admin_views/category/', data)
  1397. # Successful post will redirect
  1398. self.assertEqual(response.status_code, 302)
  1399. # Check that the order values have been applied to the right objects
  1400. self.assertEqual(Category.objects.get(id=1).order, 14)
  1401. self.assertEqual(Category.objects.get(id=2).order, 13)
  1402. self.assertEqual(Category.objects.get(id=3).order, 1)
  1403. self.assertEqual(Category.objects.get(id=4).order, 0)
  1404. def test_list_editable_action_submit(self):
  1405. # List editable changes should not be executed if the action "Go" button is
  1406. # used to submit the form.
  1407. data = {
  1408. "form-TOTAL_FORMS": "3",
  1409. "form-INITIAL_FORMS": "3",
  1410. "form-MAX_NUM_FORMS": "0",
  1411. "form-0-gender": "1",
  1412. "form-0-id": "1",
  1413. "form-1-gender": "2",
  1414. "form-1-id": "2",
  1415. "form-2-alive": "checked",
  1416. "form-2-gender": "1",
  1417. "form-2-id": "3",
  1418. "index": "0",
  1419. "_selected_action": [u'3'],
  1420. "action": [u'', u'delete_selected'],
  1421. }
  1422. self.client.post('/test_admin/admin/admin_views/person/', data)
  1423. self.assertEqual(Person.objects.get(name="John Mauchly").alive, True)
  1424. self.assertEqual(Person.objects.get(name="Grace Hopper").gender, 1)
  1425. def test_list_editable_action_choices(self):
  1426. # List editable changes should be executed if the "Save" button is
  1427. # used to submit the form - any action choices should be ignored.
  1428. data = {
  1429. "form-TOTAL_FORMS": "3",
  1430. "form-INITIAL_FORMS": "3",
  1431. "form-MAX_NUM_FORMS": "0",
  1432. "form-0-gender": "1",
  1433. "form-0-id": "1",
  1434. "form-1-gender": "2",
  1435. "form-1-id": "2",
  1436. "form-2-alive": "checked",
  1437. "form-2-gender": "1",
  1438. "form-2-id": "3",
  1439. "_save": "Save",
  1440. "_selected_action": [u'1'],
  1441. "action": [u'', u'delete_selected'],
  1442. }
  1443. self.client.post('/test_admin/admin/admin_views/person/', data)
  1444. self.assertEqual(Person.objects.get(name="John Mauchly").alive, False)
  1445. self.assertEqual(Person.objects.get(name="Grace Hopper").gender, 2)
  1446. def test_list_editable_popup(self):
  1447. """
  1448. Fields should not be list-editable in popups.
  1449. """
  1450. response = self.client.get('/test_admin/admin/admin_views/person/')
  1451. self.assertNotEqual(response.context['cl'].list_editable, ())
  1452. response = self.client.get('/test_admin/admin/admin_views/person/?%s' % IS_POPUP_VAR)
  1453. self.assertEqual(response.context['cl'].list_editable, ())
  1454. def test_pk_hidden_fields(self):
  1455. """ Ensure that hidden pk fields aren't displayed in the table body and
  1456. that their corresponding human-readable value is displayed instead.
  1457. Note that the hidden pk fields are in fact be displayed but
  1458. separately (not in the table), and only once.
  1459. Refs #12475.
  1460. """
  1461. Story.objects.create(title='The adventures of Guido', content='Once upon a time in Djangoland...')
  1462. Story.objects.create(title='Crouching Tiger, Hidden Python', content='The Python was sneaking into...')
  1463. response = self.client.get('/test_admin/admin/admin_views/story/')
  1464. self.assertContains(response, 'id="id_form-0-id"', 1) # Only one hidden field, in a separate place than the table.
  1465. self.assertContains(response, 'id="id_form-1-id"', 1)
  1466. self.assertContains(response, '<div class="hiddenfields">\n<input type="hidden" name="form-0-id" value="2" id="id_form-0-id" /><input type="hidden" name="form-1-id" value="1" id="id_form-1-id" />\n</div>')
  1467. self.assertContains(response, '<td>1</td>', 1)
  1468. self.assertContains(response, '<td>2</td>', 1)
  1469. def test_pk_hidden_fields_with_list_display_links(self):
  1470. """ Similarly as test_pk_hidden_fields, but when the hidden pk fields are
  1471. referenced in list_display_links.
  1472. Refs #12475.
  1473. """
  1474. OtherStory.objects.create(title='The adventures of Guido', content='Once upon a time in Djangoland...')
  1475. OtherStory.objects.create(title='Crouching Tiger, Hidden Python', content='The Python was sneaking into...')
  1476. response = self.client.get('/test_admin/admin/admin_views/otherstory/')
  1477. self.assertContains(response, 'id="id_form-0-id"', 1) # Only one hidden field, in a separate place than the table.
  1478. self.assertContains(response, 'id="id_form-1-id"', 1)
  1479. self.assertContains(response, '<div class="hiddenfields">\n<input type="hidden" name="form-0-id" value="2" id="id_form-0-id" /><input type="hidden" name="form-1-id" value="1" id="id_form-1-id" />\n</div>')
  1480. self.assertContains(response, '<th><a href="1/">1</a></th>', 1)
  1481. self.assertContains(response, '<th><a href="2/">2</a></th>', 1)
  1482. class AdminSearchTest(TestCase):
  1483. fixtures = ['admin-views-users', 'multiple-child-classes',
  1484. 'admin-views-person']
  1485. def setUp(self):
  1486. self.client.login(username='super', password='secret')
  1487. def tearDown(self):
  1488. self.client.logout()
  1489. def test_search_on_sibling_models(self):
  1490. "Check that a search that mentions sibling models"
  1491. response = self.client.get('/test_admin/admin/admin_views/recommendation/?q=bar')
  1492. # confirm the search returned 1 object
  1493. self.assertContains(response, "\n1 recommendation\n")
  1494. def test_with_fk_to_field(self):
  1495. """Ensure that the to_field GET parameter is preserved when a search
  1496. is performed. Refs #10918.
  1497. """
  1498. from django.contrib.admin.views.main import TO_FIELD_VAR
  1499. response = self.client.get('/test_admin/admin/auth/user/?q=joe&%s=username' % TO_FIELD_VAR)
  1500. self.assertContains(response, "\n1 user\n")
  1501. self.assertContains(response, '<input type="hidden" name="t" value="username"/>')
  1502. def test_exact_matches(self):
  1503. response = self.client.get('/test_admin/admin/admin_views/recommendation/?q=bar')
  1504. # confirm the search returned one object
  1505. self.assertContains(response, "\n1 recommendation\n")
  1506. response = self.client.get('/test_admin/admin/admin_views/recommendation/?q=ba')
  1507. # confirm the search returned zero objects
  1508. self.assertContains(response, "\n0 recommendations\n")
  1509. def test_beginning_matches(self):
  1510. response = self.client.get('/test_admin/admin/admin_views/person/?q=Gui')
  1511. # confirm the search returned one object
  1512. self.assertContains(response, "\n1 person\n")
  1513. self.assertContains(response, "Guido")
  1514. response = self.client.get('/test_admin/admin/admin_views/person/?q=uido')
  1515. # confirm the search returned zero objects
  1516. self.assertContains(response, "\n0 persons\n")
  1517. self.assertNotContains(response, "Guido")
  1518. class AdminInheritedInlinesTest(TestCase):
  1519. fixtures = ['admin-views-users.xml',]
  1520. def setUp(self):
  1521. self.client.login(username='super', password='secret')
  1522. def tearDown(self):
  1523. self.client.logout()
  1524. def testInline(self):
  1525. "Ensure that inline models which inherit from a common parent are correctly handled by admin."
  1526. foo_user = u"foo username"
  1527. bar_user = u"bar username"
  1528. name_re = re.compile('name="(.*?)"')
  1529. # test the add case
  1530. response = self.client.get('/test_admin/admin/admin_views/persona/add/')
  1531. names = name_re.findall(response.content)
  1532. # make sure we have no duplicate HTML names
  1533. self.assertEqual(len(names), len(set(names)))
  1534. # test the add case
  1535. post_data = {
  1536. "name": u"Test Name",
  1537. # inline data
  1538. "accounts-TOTAL_FORMS": u"1",
  1539. "accounts-INITIAL_FORMS": u"0",
  1540. "accounts-MAX_NUM_FORMS": u"0",
  1541. "accounts-0-username": foo_user,
  1542. "accounts-2-TOTAL_FORMS": u"1",
  1543. "accounts-2-INITIAL_FORMS": u"0",
  1544. "accounts-2-MAX_NUM_FORMS": u"0",
  1545. "accounts-2-0-username": bar_user,
  1546. }
  1547. response = self.client.post('/test_admin/admin/admin_views/persona/add/', post_data)
  1548. self.assertEqual(response.status_code, 302) # redirect somewhere
  1549. self.assertEqual(Persona.objects.count(), 1)
  1550. self.assertEqual(FooAccount.objects.count(), 1)
  1551. self.assertEqual(BarAccount.objects.count(), 1)
  1552. self.assertEqual(FooAccount.objects.all()[0].username, foo_user)
  1553. self.assertEqual(BarAccount.objects.all()[0].username, bar_user)
  1554. self.assertEqual(Persona.objects.all()[0].accounts.count(), 2)
  1555. # test the edit case
  1556. response = self.client.get('/test_admin/admin/admin_views/persona/1/')
  1557. names = name_re.findall(response.content)
  1558. # make sure we have no duplicate HTML names
  1559. self.assertEqual(len(names), len(set(names)))
  1560. post_data = {
  1561. "name": u"Test Name",
  1562. "accounts-TOTAL_FORMS": "2",
  1563. "accounts-INITIAL_FORMS": u"1",
  1564. "accounts-MAX_NUM_FORMS": u"0",
  1565. "accounts-0-username": "%s-1" % foo_user,
  1566. "accounts-0-account_ptr": "1",
  1567. "accounts-0-persona": "1",
  1568. "accounts-2-TOTAL_FORMS": u"2",
  1569. "accounts-2-INITIAL_FORMS": u"1",
  1570. "accounts-2-MAX_NUM_FORMS": u"0",
  1571. "accounts-2-0-username": "%s-1" % bar_user,
  1572. "accounts-2-0-account_ptr": "2",
  1573. "accounts-2-0-persona": "1",
  1574. }
  1575. response = self.client.post('/test_admin/admin/admin_views/persona/1/', post_data)
  1576. self.assertEqual(response.status_code, 302)
  1577. self.assertEqual(Persona.objects.count(), 1)
  1578. self.assertEqual(FooAccount.objects.count(), 1)
  1579. self.assertEqual(BarAccount.objects.count(), 1)
  1580. self.assertEqual(FooAccount.objects.all()[0].username, "%s-1" % foo_user)
  1581. self.assertEqual(BarAccount.objects.all()[0].username, "%s-1" % bar_user)
  1582. self.assertEqual(Persona.objects.all()[0].accounts.count(), 2)
  1583. class AdminActionsTest(TestCase):
  1584. fixtures = ['admin-views-users.xml', 'admin-views-actions.xml']
  1585. def setUp(self):
  1586. self.client.login(username='super', password='secret')
  1587. def tearDown(self):
  1588. self.client.logout()
  1589. def test_model_admin_custom_action(self):
  1590. "Tests a custom action defined in a ModelAdmin method"
  1591. action_data = {
  1592. ACTION_CHECKBOX_NAME: [1],
  1593. 'action' : 'mail_admin',
  1594. 'index': 0,
  1595. }
  1596. response = self.client.post('/test_admin/admin/admin_views/subscriber/', action_data)
  1597. self.assertEqual(len(mail.outbox), 1)
  1598. self.assertEqual(mail.outbox[0].subject, 'Greetings from a ModelAdmin action')
  1599. def test_model_admin_default_delete_action(self):
  1600. "Tests the default delete action defined as a ModelAdmin method"
  1601. action_data = {
  1602. ACTION_CHECKBOX_NAME: [1, 2],
  1603. 'action' : 'delete_selected',
  1604. 'index': 0,
  1605. }
  1606. delete_confirmation_data = {
  1607. ACTION_CHECKBOX_NAME: [1, 2],
  1608. 'action' : 'delete_selected',
  1609. 'post': 'yes',
  1610. }
  1611. confirmation = self.client.post('/test_admin/admin/admin_views/subscriber/', action_data)
  1612. self.assertContains(confirmation, "Are you sure you want to delete the selected subscribers")
  1613. self.assertTrue(confirmation.content.count(ACTION_CHECKBOX_NAME) == 2)
  1614. response = self.client.post('/test_admin/admin/admin_views/subscriber/', delete_confirmation_data)
  1615. self.assertEqual(Subscriber.objects.count(), 0)
  1616. def test_non_localized_pk(self):
  1617. """If USE_THOUSAND_SEPARATOR is set, make sure that the ids for
  1618. the objects selected for deletion are rendered without separators.
  1619. Refs #14895.
  1620. """
  1621. self.old_USE_THOUSAND_SEPARATOR = settings.USE_THOUSAND_SEPARATOR
  1622. self.old_USE_L10N = settings.USE_L10N
  1623. settings.USE_THOUSAND_SEPARATOR = True
  1624. settings.USE_L10N = True
  1625. subscriber = Subscriber.objects.get(id=1)
  1626. subscriber.id = 9999
  1627. subscriber.save()
  1628. action_data = {
  1629. ACTION_CHECKBOX_NAME: [9999, 2],
  1630. 'action' : 'delete_selected',
  1631. 'index': 0,
  1632. }
  1633. response = self.client.post('/test_admin/admin/admin_views/subscriber/', action_data)
  1634. self.assertTemplateUsed(response, 'admin/delete_selected_confirmation.html')
  1635. self.assertTrue('value="9999"' in response.content and 'value="2"' in response.content) # Instead of 9,999
  1636. settings.USE_THOUSAND_SEPARATOR = self.old_USE_THOUSAND_SEPARATOR
  1637. settings.USE_L10N = self.old_USE_L10N
  1638. def test_model_admin_default_delete_action_protected(self):
  1639. """
  1640. Tests the default delete action defined as a ModelAdmin method in the
  1641. case where some related objects are protected from deletion.
  1642. """
  1643. q1 = Question.objects.create(question="Why?")
  1644. a1 = Answer.objects.create(question=q1, answer="Because.")
  1645. a2 = Answer.objects.create(question=q1, answer="Yes.")
  1646. q2 = Question.objects.create(question="Wherefore?")
  1647. action_data = {
  1648. ACTION_CHECKBOX_NAME: [q1.pk, q2.pk],
  1649. 'action' : 'delete_selected',
  1650. 'index': 0,
  1651. }
  1652. response = self.client.post("/test_admin/admin/admin_views/question/", action_data)
  1653. self.assertContains(response, "would require deleting the following protected related objects")
  1654. self.assertContains(response, '<li>Answer: <a href="/test_admin/admin/admin_views/answer/%s/">Because.</a></li>' % a1.pk)
  1655. self.assertContains(response, '<li>Answer: <a href="/test_admin/admin/admin_views/answer/%s/">Yes.</a></li>' % a2.pk)
  1656. def test_custom_function_mail_action(self):
  1657. "Tests a custom action defined in a function"
  1658. action_data = {
  1659. ACTION_CHECKBOX_NAME: [1],
  1660. 'action' : 'external_mail',
  1661. 'index': 0,
  1662. }
  1663. response = self.client.post('/test_admin/admin/admin_views/externalsubscriber/', action_data)
  1664. self.assertEqual(len(mail.outbox), 1)
  1665. self.assertEqual(mail.outbox[0].subject, 'Greetings from a function action')
  1666. def test_custom_function_action_with_redirect(self):
  1667. "Tests a custom action defined in a function"
  1668. action_data = {
  1669. ACTION_CHECKBOX_NAME: [1],
  1670. 'action' : 'redirect_to',
  1671. 'index': 0,
  1672. }
  1673. response = self.client.post('/test_admin/admin/admin_views/externalsubscriber/', action_data)
  1674. self.assertEqual(response.status_code, 302)
  1675. def test_default_redirect(self):
  1676. """
  1677. Test that actions which don't return an HttpResponse are redirected to
  1678. the same page, retaining the querystring (which may contain changelist
  1679. information).
  1680. """
  1681. action_data = {
  1682. ACTION_CHECKBOX_NAME: [1],
  1683. 'action' : 'external_mail',
  1684. 'index': 0,
  1685. }
  1686. url = '/test_admin/admin/admin_views/externalsubscriber/?ot=asc&o=1'
  1687. response = self.client.post(url, action_data)
  1688. self.assertRedirects(response, url)
  1689. def test_model_without_action(self):
  1690. "Tests a ModelAdmin without any action"
  1691. response = self.client.get('/test_admin/admin/admin_views/oldsubscriber/')
  1692. self.assertEqual(response.context["action_form"], None)
  1693. self.assertTrue(
  1694. '<input type="checkbox" class="action-select"' not in response.content,
  1695. "Found an unexpected action toggle checkboxbox in response"
  1696. )
  1697. self.assertTrue('action-checkbox-column' not in response.content,
  1698. "Found unexpected action-checkbox-column class in response")
  1699. def test_model_without_action_still_has_jquery(self):
  1700. "Tests that a ModelAdmin without any actions still gets jQuery included in page"
  1701. response = self.client.get('/test_admin/admin/admin_views/oldsubscriber/')
  1702. self.assertEqual(response.context["action_form"], None)
  1703. self.assertTrue('jquery.min.js' in response.content,
  1704. "jQuery missing from admin pages for model with no admin actions"
  1705. )
  1706. def test_action_column_class(self):
  1707. "Tests that the checkbox column class is present in the response"
  1708. response = self.client.get('/test_admin/admin/admin_views/subscriber/')
  1709. self.assertNotEqual(response.context["action_form"], None)
  1710. self.assertTrue('action-checkbox-column' in response.content,
  1711. "Expected an action-checkbox-column in response")
  1712. def test_multiple_actions_form(self):
  1713. """
  1714. Test that actions come from the form whose submit button was pressed (#10618).
  1715. """
  1716. action_data = {
  1717. ACTION_CHECKBOX_NAME: [1],
  1718. # Two different actions selected on the two forms...
  1719. 'action': ['external_mail', 'delete_selected'],
  1720. # ...but we clicked "go" on the top form.
  1721. 'index': 0
  1722. }
  1723. response = self.client.post('/test_admin/admin/admin_views/externalsubscriber/', action_data)
  1724. # Send mail, don't delete.
  1725. self.assertEqual(len(mail.outbox), 1)
  1726. self.assertEqual(mail.outbox[0].subject, 'Greetings from a function action')
  1727. def test_user_message_on_none_selected(self):
  1728. """
  1729. User should see a warning when 'Go' is pressed and no items are selected.
  1730. """
  1731. action_data = {
  1732. ACTION_CHECKBOX_NAME: [],
  1733. 'action' : 'delete_selected',
  1734. 'index': 0,
  1735. }
  1736. response = self.client.post('/test_admin/admin/admin_views/subscriber/', action_data)
  1737. msg = """Items must be selected in order to perform actions on them. No items have been changed."""
  1738. self.assertContains(response, msg)
  1739. self.assertEqual(Subscriber.objects.count(), 2)
  1740. def test_user_message_on_no_action(self):
  1741. """
  1742. User should see a warning when 'Go' is pressed and no action is selected.
  1743. """
  1744. action_data = {
  1745. ACTION_CHECKBOX_NAME: [1, 2],
  1746. 'action' : '',
  1747. 'index': 0,
  1748. }
  1749. response = self.client.post('/test_admin/admin/admin_views/subscriber/', action_data)
  1750. msg = """No action selected."""
  1751. self.assertContains(response, msg)
  1752. self.assertEqual(Subscriber.objects.count(), 2)
  1753. def test_selection_counter(self):
  1754. """
  1755. Check if the selection counter is there.
  1756. """
  1757. response = self.client.get('/test_admin/admin/admin_views/subscriber/')
  1758. self.assertContains(response, '0 of 2 selected')
  1759. def test_popup_actions(self):
  1760. """ Actions should not be shown in popups. """
  1761. response = self.client.get('/test_admin/admin/admin_views/subscriber/')
  1762. self.assertNotEquals(response.context["action_form"], None)
  1763. response = self.client.get(
  1764. '/test_admin/admin/admin_views/subscriber/?%s' % IS_POPUP_VAR)
  1765. self.assertEqual(response.context["action_form"], None)
  1766. class TestCustomChangeList(TestCase):
  1767. fixtures = ['admin-views-users.xml']
  1768. urlbit = 'admin'
  1769. def setUp(self):
  1770. result = self.client.login(username='super', password='secret')
  1771. self.assertEqual(result, True)
  1772. def tearDown(self):
  1773. self.client.logout()
  1774. def test_custom_changelist(self):
  1775. """
  1776. Validate that a custom ChangeList class can be used (#9749)
  1777. """
  1778. # Insert some data
  1779. post_data = {"name": u"First Gadget"}
  1780. response = self.client.post('/test_admin/%s/admin_views/gadget/add/' % self.urlbit, post_data)
  1781. self.assertEqual(response.status_code, 302) # redirect somewhere
  1782. # Hit the page once to get messages out of the queue message list
  1783. response = self.client.get('/test_admin/%s/admin_views/gadget/' % self.urlbit)
  1784. # Ensure that that data is still not visible on the page
  1785. response = self.client.get('/test_admin/%s/admin_views/gadget/' % self.urlbit)
  1786. self.assertEqual(response.status_code, 200)
  1787. self.assertNotContains(response, 'First Gadget')
  1788. class TestInlineNotEditable(TestCase):
  1789. fixtures = ['admin-views-users.xml']
  1790. def setUp(self):
  1791. result = self.client.login(username='super', password='secret')
  1792. self.assertEqual(result, True)
  1793. def tearDown(self):
  1794. self.client.logout()
  1795. def test(self):
  1796. """
  1797. InlineModelAdmin broken?
  1798. """
  1799. response = self.client.get('/test_admin/admin/admin_views/parent/add/')
  1800. self.assertEqual(response.status_code, 200)
  1801. class AdminCustomQuerysetTest(TestCase):
  1802. fixtures = ['admin-views-users.xml']
  1803. def setUp(self):
  1804. self.client.login(username='super', password='secret')
  1805. self.pks = [EmptyModel.objects.create().id for i in range(3)]
  1806. def test_changelist_view(self):
  1807. response = self.client.get('/test_admin/admin/admin_views/emptymodel/')
  1808. for i in self.pks:
  1809. if i > 1:
  1810. self.assertContains(response, 'Primary key = %s' % i)
  1811. else:
  1812. self.assertNotContains(response, 'Primary key = %s' % i)
  1813. def test_change_view(self):
  1814. for i in self.pks:
  1815. response = self.client.get('/test_admin/admin/admin_views/emptymodel/%s/' % i)
  1816. if i > 1:
  1817. self.assertEqual(response.status_code, 200)
  1818. else:
  1819. self.assertEqual(response.status_code, 404)
  1820. def test_add_model_modeladmin_only_qs(self):
  1821. # only() is used in ModelAdmin.queryset()
  1822. p = Paper.objects.create(title=u"My Paper Title")
  1823. self.assertEqual(Paper.objects.count(), 1)
  1824. response = self.client.get('/test_admin/admin/admin_views/paper/%s/' % p.pk)
  1825. self.assertEqual(response.status_code, 200)
  1826. post_data = {
  1827. "title": u"My Modified Paper Title",
  1828. "_save": "Save",
  1829. }
  1830. response = self.client.post('/test_admin/admin/admin_views/paper/%s/' % p.pk,
  1831. post_data, follow=True)
  1832. self.assertEqual(response.status_code, 200)
  1833. # Message should contain non-ugly model name. Instance representation is set by unicode() (ugly)
  1834. self.assertContains(response, '<li class="info">The paper &quot;Paper_Deferred_author object&quot; was changed successfully.</li>')
  1835. # defer() is used in ModelAdmin.queryset()
  1836. cl = CoverLetter.objects.create(author=u"John Doe")
  1837. self.assertEqual(CoverLetter.objects.count(), 1)
  1838. response = self.client.get('/test_admin/admin/admin_views/coverletter/%s/' % cl.pk)
  1839. self.assertEqual(response.status_code, 200)
  1840. post_data = {
  1841. "author": u"John Doe II",
  1842. "_save": "Save",
  1843. }
  1844. response = self.client.post('/test_admin/admin/admin_views/coverletter/%s/' % cl.pk,
  1845. post_data, follow=True)
  1846. self.assertEqual(response.status_code, 200)
  1847. # Message should contain non-ugly model name. Instance representation is set by model's __unicode__()
  1848. self.assertContains(response, '<li class="info">The cover letter &quot;John Doe II&quot; was changed successfully.</li>')
  1849. class AdminInlineFileUploadTest(TestCase):
  1850. fixtures = ['admin-views-users.xml', 'admin-views-actions.xml']
  1851. urlbit = 'admin'
  1852. def setUp(self):
  1853. self.client.login(username='super', password='secret')
  1854. # Set up test Picture and Gallery.
  1855. # These must be set up here instead of in fixtures in order to allow Picture
  1856. # to use a NamedTemporaryFile.
  1857. tdir = tempfile.gettempdir()
  1858. file1 = tempfile.NamedTemporaryFile(suffix=".file1", dir=tdir)
  1859. file1.write('a' * (2 ** 21))
  1860. filename = file1.name
  1861. file1.close()
  1862. g = Gallery(name="Test Gallery")
  1863. g.save()
  1864. p = Picture(name="Test Picture", image=filename, gallery=g)
  1865. p.save()
  1866. def tearDown(self):
  1867. self.client.logout()
  1868. def test_inline_file_upload_edit_validation_error_post(self):
  1869. """
  1870. Test that inline file uploads correctly display prior data (#10002).
  1871. """
  1872. post_data = {
  1873. "name": u"Test Gallery",
  1874. "pictures-TOTAL_FORMS": u"2",
  1875. "pictures-INITIAL_FORMS": u"1",
  1876. "pictures-MAX_NUM_FORMS": u"0",
  1877. "pictures-0-id": u"1",
  1878. "pictures-0-gallery": u"1",
  1879. "pictures-0-name": "Test Picture",
  1880. "pictures-0-image": "",
  1881. "pictures-1-id": "",
  1882. "pictures-1-gallery": "1",
  1883. "pictures-1-name": "Test Picture 2",
  1884. "pictures-1-image": "",
  1885. }
  1886. response = self.client.post('/test_admin/%s/admin_views/gallery/1/' % self.urlbit, post_data)
  1887. self.assertTrue(response._container[0].find("Currently:") > -1)
  1888. class AdminInlineTests(TestCase):
  1889. fixtures = ['admin-views-users.xml']
  1890. def setUp(self):
  1891. self.post_data = {
  1892. "name": u"Test Name",
  1893. "widget_set-TOTAL_FORMS": "3",
  1894. "widget_set-INITIAL_FORMS": u"0",
  1895. "widget_set-MAX_NUM_FORMS": u"0",
  1896. "widget_set-0-id": "",
  1897. "widget_set-0-owner": "1",
  1898. "widget_set-0-name": "",
  1899. "widget_set-1-id": "",
  1900. "widget_set-1-owner": "1",
  1901. "widget_set-1-name": "",
  1902. "widget_set-2-id": "",
  1903. "widget_set-2-owner": "1",
  1904. "widget_set-2-name": "",
  1905. "doohickey_set-TOTAL_FORMS": "3",
  1906. "doohickey_set-INITIAL_FORMS": u"0",
  1907. "doohickey_set-MAX_NUM_FORMS": u"0",
  1908. "doohickey_set-0-owner": "1",
  1909. "doohickey_set-0-code": "",
  1910. "doohickey_set-0-name": "",
  1911. "doohickey_set-1-owner": "1",
  1912. "doohickey_set-1-code": "",
  1913. "doohickey_set-1-name": "",
  1914. "doohickey_set-2-owner": "1",
  1915. "doohickey_set-2-code": "",
  1916. "doohickey_set-2-name": "",
  1917. "grommet_set-TOTAL_FORMS": "3",
  1918. "grommet_set-INITIAL_FORMS": u"0",
  1919. "grommet_set-MAX_NUM_FORMS": u"0",
  1920. "grommet_set-0-code": "",
  1921. "grommet_set-0-owner": "1",
  1922. "grommet_set-0-name": "",
  1923. "grommet_set-1-code": "",
  1924. "grommet_set-1-owner": "1",
  1925. "grommet_set-1-name": "",
  1926. "grommet_set-2-code": "",
  1927. "grommet_set-2-owner": "1",
  1928. "grommet_set-2-name": "",
  1929. "whatsit_set-TOTAL_FORMS": "3",
  1930. "whatsit_set-INITIAL_FORMS": u"0",
  1931. "whatsit_set-MAX_NUM_FORMS": u"0",
  1932. "whatsit_set-0-owner": "1",
  1933. "whatsit_set-0-index": "",
  1934. "whatsit_set-0-name": "",
  1935. "whatsit_set-1-owner": "1",
  1936. "whatsit_set-1-index": "",
  1937. "whatsit_set-1-name": "",
  1938. "whatsit_set-2-owner": "1",
  1939. "whatsit_set-2-index": "",
  1940. "whatsit_set-2-name": "",
  1941. "fancydoodad_set-TOTAL_FORMS": "3",
  1942. "fancydoodad_set-INITIAL_FORMS": u"0",
  1943. "fancydoodad_set-MAX_NUM_FORMS": u"0",
  1944. "fancydoodad_set-0-doodad_ptr": "",
  1945. "fancydoodad_set-0-owner": "1",
  1946. "fancydoodad_set-0-name": "",
  1947. "fancydoodad_set-0-expensive": "on",
  1948. "fancydoodad_set-1-doodad_ptr": "",
  1949. "fancydoodad_set-1-owner": "1",
  1950. "fancydoodad_set-1-name": "",
  1951. "fancydoodad_set-1-expensive": "on",
  1952. "fancydoodad_set-2-doodad_ptr": "",
  1953. "fancydoodad_set-2-owner": "1",
  1954. "fancydoodad_set-2-name": "",
  1955. "fancydoodad_set-2-expensive": "on",
  1956. "category_set-TOTAL_FORMS": "3",
  1957. "category_set-INITIAL_FORMS": "0",
  1958. "category_set-MAX_NUM_FORMS": "0",
  1959. "category_set-0-order": "",
  1960. "category_set-0-id": "",
  1961. "category_set-0-collector": "1",
  1962. "category_set-1-order": "",
  1963. "category_set-1-id": "",
  1964. "category_set-1-collector": "1",
  1965. "category_set-2-order": "",
  1966. "category_set-2-id": "",
  1967. "category_set-2-collector": "1",
  1968. }
  1969. result = self.client.login(username='super', password='secret')
  1970. self.assertEqual(result, True)
  1971. self.collector = Collector(pk=1,name='John Fowles')
  1972. self.collector.save()
  1973. def tearDown(self):
  1974. self.client.logout()
  1975. def test_simple_inline(self):
  1976. "A simple model can be saved as inlines"
  1977. # First add a new inline
  1978. self.post_data['widget_set-0-name'] = "Widget 1"
  1979. response = self.client.post('/test_admin/admin/admin_views/collector/1/', self.post_data)
  1980. self.assertEqual(response.status_code, 302)
  1981. self.assertEqual(Widget.objects.count(), 1)
  1982. self.assertEqual(Widget.objects.all()[0].name, "Widget 1")
  1983. # Check that the PK link exists on the rendered form
  1984. response = self.client.get('/test_admin/admin/admin_views/collector/1/')
  1985. self.assertContains(response, 'name="widget_set-0-id"')
  1986. # Now resave that inline
  1987. self.post_data['widget_set-INITIAL_FORMS'] = "1"
  1988. self.post_data['widget_set-0-id'] = "1"
  1989. self.post_data['widget_set-0-name'] = "Widget 1"
  1990. response = self.client.post('/test_admin/admin/admin_views/collector/1/', self.post_data)
  1991. self.assertEqual(response.status_code, 302)
  1992. self.assertEqual(Widget.objects.count(), 1)
  1993. self.assertEqual(Widget.objects.all()[0].name, "Widget 1")
  1994. # Now modify that inline
  1995. self.post_data['widget_set-INITIAL_FORMS'] = "1"
  1996. self.post_data['widget_set-0-id'] = "1"
  1997. self.post_data['widget_set-0-name'] = "Widget 1 Updated"
  1998. response = self.client.post('/test_admin/admin/admin_views/collector/1/', self.post_data)
  1999. self.assertEqual(response.status_code, 302)
  2000. self.assertEqual(Widget.objects.count(), 1)
  2001. self.assertEqual(Widget.objects.all()[0].name, "Widget 1 Updated")
  2002. def test_explicit_autofield_inline(self):
  2003. "A model with an explicit autofield primary key can be saved as inlines. Regression for #8093"
  2004. # First add a new inline
  2005. self.post_data['grommet_set-0-name'] = "Grommet 1"
  2006. response = self.client.post('/test_admin/admin/admin_views/collector/1/', self.post_data)
  2007. self.assertEqual(response.status_code, 302)
  2008. self.assertEqual(Grommet.objects.count(), 1)
  2009. self.assertEqual(Grommet.objects.all()[0].name, "Grommet 1")
  2010. # Check that the PK link exists on the rendered form
  2011. response = self.client.get('/test_admin/admin/admin_views/collector/1/')
  2012. self.assertContains(response, 'name="grommet_set-0-code"')
  2013. # Now resave that inline
  2014. self.post_data['grommet_set-INITIAL_FORMS'] = "1"
  2015. self.post_data['grommet_set-0-code'] = "1"
  2016. self.post_data['grommet_set-0-name'] = "Grommet 1"
  2017. response = self.client.post('/test_admin/admin/admin_views/collector/1/', self.post_data)
  2018. self.assertEqual(response.status_code, 302)
  2019. self.assertEqual(Grommet.objects.count(), 1)
  2020. self.assertEqual(Grommet.objects.all()[0].name, "Grommet 1")
  2021. # Now modify that inline
  2022. self.post_data['grommet_set-INITIAL_FORMS'] = "1"
  2023. self.post_data['grommet_set-0-code'] = "1"
  2024. self.post_data['grommet_set-0-name'] = "Grommet 1 Updated"
  2025. response = self.client.post('/test_admin/admin/admin_views/collector/1/', self.post_data)
  2026. self.assertEqual(response.status_code, 302)
  2027. self.assertEqual(Grommet.objects.count(), 1)
  2028. self.assertEqual(Grommet.objects.all()[0].name, "Grommet 1 Updated")
  2029. def test_char_pk_inline(self):
  2030. "A model with a character PK can be saved as inlines. Regression for #10992"
  2031. # First add a new inline
  2032. self.post_data['doohickey_set-0-code'] = "DH1"
  2033. self.post_data['doohickey_set-0-name'] = "Doohickey 1"
  2034. response = self.client.post('/test_admin/admin/admin_views/collector/1/', self.post_data)
  2035. self.assertEqual(response.status_code, 302)
  2036. self.assertEqual(DooHickey.objects.count(), 1)
  2037. self.assertEqual(DooHickey.objects.all()[0].name, "Doohickey 1")
  2038. # Check that the PK link exists on the rendered form
  2039. response = self.client.get('/test_admin/admin/admin_views/collector/1/')
  2040. self.assertContains(response, 'name="doohickey_set-0-code"')
  2041. # Now resave that inline
  2042. self.post_data['doohickey_set-INITIAL_FORMS'] = "1"
  2043. self.post_data['doohickey_set-0-code'] = "DH1"
  2044. self.post_data['doohickey_set-0-name'] = "Doohickey 1"
  2045. response = self.client.post('/test_admin/admin/admin_views/collector/1/', self.post_data)
  2046. self.assertEqual(response.status_code, 302)
  2047. self.assertEqual(DooHickey.objects.count(), 1)
  2048. self.assertEqual(DooHickey.objects.all()[0].name, "Doohickey 1")
  2049. # Now modify that inline
  2050. self.post_data['doohickey_set-INITIAL_FORMS'] = "1"
  2051. self.post_data['doohickey_set-0-code'] = "DH1"
  2052. self.post_data['doohickey_set-0-name'] = "Doohickey 1 Updated"
  2053. response = self.client.post('/test_admin/admin/admin_views/collector/1/', self.post_data)
  2054. self.assertEqual(response.status_code, 302)
  2055. self.assertEqual(DooHickey.objects.count(), 1)
  2056. self.assertEqual(DooHickey.objects.all()[0].name, "Doohickey 1 Updated")
  2057. def test_integer_pk_inline(self):
  2058. "A model with an integer PK can be saved as inlines. Regression for #10992"
  2059. # First add a new inline
  2060. self.post_data['whatsit_set-0-index'] = "42"
  2061. self.post_data['whatsit_set-0-name'] = "Whatsit 1"
  2062. response = self.client.post('/test_admin/admin/admin_views/collector/1/', self.post_data)
  2063. self.assertEqual(response.status_code, 302)
  2064. self.assertEqual(Whatsit.objects.count(), 1)
  2065. self.assertEqual(Whatsit.objects.all()[0].name, "Whatsit 1")
  2066. # Check that the PK link exists on the rendered form
  2067. response = self.client.get('/test_admin/admin/admin_views/collector/1/')
  2068. self.assertContains(response, 'name="whatsit_set-0-index"')
  2069. # Now resave that inline
  2070. self.post_data['whatsit_set-INITIAL_FORMS'] = "1"
  2071. self.post_data['whatsit_set-0-index'] = "42"
  2072. self.post_data['whatsit_set-0-name'] = "Whatsit 1"
  2073. response = self.client.post('/test_admin/admin/admin_views/collector/1/', self.post_data)
  2074. self.assertEqual(response.status_code, 302)
  2075. self.assertEqual(Whatsit.objects.count(), 1)
  2076. self.assertEqual(Whatsit.objects.all()[0].name, "Whatsit 1")
  2077. # Now modify that inline
  2078. self.post_data['whatsit_set-INITIAL_FORMS'] = "1"
  2079. self.post_data['whatsit_set-0-index'] = "42"
  2080. self.post_data['whatsit_set-0-name'] = "Whatsit 1 Updated"
  2081. response = self.client.post('/test_admin/admin/admin_views/collector/1/', self.post_data)
  2082. self.assertEqual(response.status_code, 302)
  2083. self.assertEqual(Whatsit.objects.count(), 1)
  2084. self.assertEqual(Whatsit.objects.all()[0].name, "Whatsit 1 Updated")
  2085. def test_inherited_inline(self):
  2086. "An inherited model can be saved as inlines. Regression for #11042"
  2087. # First add a new inline
  2088. self.post_data['fancydoodad_set-0-name'] = "Fancy Doodad 1"
  2089. response = self.client.post('/test_admin/admin/admin_views/collector/1/', self.post_data)
  2090. self.assertEqual(response.status_code, 302)
  2091. self.assertEqual(FancyDoodad.objects.count(), 1)
  2092. self.assertEqual(FancyDoodad.objects.all()[0].name, "Fancy Doodad 1")
  2093. # Check that the PK link exists on the rendered form
  2094. response = self.client.get('/test_admin/admin/admin_views/collector/1/')
  2095. self.assertContains(response, 'name="fancydoodad_set-0-doodad_ptr"')
  2096. # Now resave that inline
  2097. self.post_data['fancydoodad_set-INITIAL_FORMS'] = "1"
  2098. self.post_data['fancydoodad_set-0-doodad_ptr'] = "1"
  2099. self.post_data['fancydoodad_set-0-name'] = "Fancy Doodad 1"
  2100. response = self.client.post('/test_admin/admin/admin_views/collector/1/', self.post_data)
  2101. self.assertEqual(response.status_code, 302)
  2102. self.assertEqual(FancyDoodad.objects.count(), 1)
  2103. self.assertEqual(FancyDoodad.objects.all()[0].name, "Fancy Doodad 1")
  2104. # Now modify that inline
  2105. self.post_data['fancydoodad_set-INITIAL_FORMS'] = "1"
  2106. self.post_data['fancydoodad_set-0-doodad_ptr'] = "1"
  2107. self.post_data['fancydoodad_set-0-name'] = "Fancy Doodad 1 Updated"
  2108. response = self.client.post('/test_admin/admin/admin_views/collector/1/', self.post_data)
  2109. self.assertEqual(response.status_code, 302)
  2110. self.assertEqual(FancyDoodad.objects.count(), 1)
  2111. self.assertEqual(FancyDoodad.objects.all()[0].name, "Fancy Doodad 1 Updated")
  2112. def test_ordered_inline(self):
  2113. """Check that an inline with an editable ordering fields is
  2114. updated correctly. Regression for #10922"""
  2115. # Create some objects with an initial ordering
  2116. Category.objects.create(id=1, order=1, collector=self.collector)
  2117. Category.objects.create(id=2, order=2, collector=self.collector)
  2118. Category.objects.create(id=3, order=0, collector=self.collector)
  2119. Category.objects.create(id=4, order=0, collector=self.collector)
  2120. # NB: The order values must be changed so that the items are reordered.
  2121. self.post_data.update({
  2122. "name": "Frederick Clegg",
  2123. "category_set-TOTAL_FORMS": "7",
  2124. "category_set-INITIAL_FORMS": "4",
  2125. "category_set-MAX_NUM_FORMS": "0",
  2126. "category_set-0-order": "14",
  2127. "category_set-0-id": "1",
  2128. "category_set-0-collector": "1",
  2129. "category_set-1-order": "13",
  2130. "category_set-1-id": "2",
  2131. "category_set-1-collector": "1",
  2132. "category_set-2-order": "1",
  2133. "category_set-2-id": "3",
  2134. "category_set-2-collector": "1",
  2135. "category_set-3-order": "0",
  2136. "category_set-3-id": "4",
  2137. "category_set-3-collector": "1",
  2138. "category_set-4-order": "",
  2139. "category_set-4-id": "",
  2140. "category_set-4-collector": "1",
  2141. "category_set-5-order": "",
  2142. "category_set-5-id": "",
  2143. "category_set-5-collector": "1",
  2144. "category_set-6-order": "",
  2145. "category_set-6-id": "",
  2146. "category_set-6-collector": "1",
  2147. })
  2148. response = self.client.post('/test_admin/admin/admin_views/collector/1/', self.post_data)
  2149. # Successful post will redirect
  2150. self.assertEqual(response.status_code, 302)
  2151. # Check that the order values have been applied to the right objects
  2152. self.assertEqual(self.collector.category_set.count(), 4)
  2153. self.assertEqual(Category.objects.get(id=1).order, 14)
  2154. self.assertEqual(Category.objects.get(id=2).order, 13)
  2155. self.assertEqual(Category.objects.get(id=3).order, 1)
  2156. self.assertEqual(Category.objects.get(id=4).order, 0)
  2157. class NeverCacheTests(TestCase):
  2158. fixtures = ['admin-views-users.xml', 'admin-views-colors.xml', 'admin-views-fabrics.xml']
  2159. def setUp(self):
  2160. self.client.login(username='super', password='secret')
  2161. def tearDown(self):
  2162. self.client.logout()
  2163. def testAdminIndex(self):
  2164. "Check the never-cache status of the main index"
  2165. response = self.client.get('/test_admin/admin/')
  2166. self.assertEqual(get_max_age(response), 0)
  2167. def testAppIndex(self):
  2168. "Check the never-cache status of an application index"
  2169. response = self.client.get('/test_admin/admin/admin_views/')
  2170. self.assertEqual(get_max_age(response), 0)
  2171. def testModelIndex(self):
  2172. "Check the never-cache status of a model index"
  2173. response = self.client.get('/test_admin/admin/admin_views/fabric/')
  2174. self.assertEqual(get_max_age(response), 0)
  2175. def testModelAdd(self):
  2176. "Check the never-cache status of a model add page"
  2177. response = self.client.get('/test_admin/admin/admin_views/fabric/add/')
  2178. self.assertEqual(get_max_age(response), 0)
  2179. def testModelView(self):
  2180. "Check the never-cache status of a model edit page"
  2181. response = self.client.get('/test_admin/admin/admin_views/section/1/')
  2182. self.assertEqual(get_max_age(response), 0)
  2183. def testModelHistory(self):
  2184. "Check the never-cache status of a model history page"
  2185. response = self.client.get('/test_admin/admin/admin_views/section/1/history/')
  2186. self.assertEqual(get_max_age(response), 0)
  2187. def testModelDelete(self):
  2188. "Check the never-cache status of a model delete page"
  2189. response = self.client.get('/test_admin/admin/admin_views/section/1/delete/')
  2190. self.assertEqual(get_max_age(response), 0)
  2191. def testLogin(self):
  2192. "Check the never-cache status of login views"
  2193. self.client.logout()
  2194. response = self.client.get('/test_admin/admin/')
  2195. self.assertEqual(get_max_age(response), 0)
  2196. def testLogout(self):
  2197. "Check the never-cache status of logout view"
  2198. response = self.client.get('/test_admin/admin/logout/')
  2199. self.assertEqual(get_max_age(response), 0)
  2200. def testPasswordChange(self):
  2201. "Check the never-cache status of the password change view"
  2202. self.client.logout()
  2203. response = self.client.get('/test_admin/password_change/')
  2204. self.assertEqual(get_max_age(response), None)
  2205. def testPasswordChangeDone(self):
  2206. "Check the never-cache status of the password change done view"
  2207. response = self.client.get('/test_admin/admin/password_change/done/')
  2208. self.assertEqual(get_max_age(response), None)
  2209. def testJsi18n(self):
  2210. "Check the never-cache status of the Javascript i18n view"
  2211. response = self.client.get('/test_admin/admin/jsi18n/')
  2212. self.assertEqual(get_max_age(response), None)
  2213. class ReadonlyTest(TestCase):
  2214. fixtures = ['admin-views-users.xml']
  2215. def setUp(self):
  2216. self.client.login(username='super', password='secret')
  2217. def tearDown(self):
  2218. self.client.logout()
  2219. def test_readonly_get(self):
  2220. response = self.client.get('/test_admin/admin/admin_views/post/add/')
  2221. self.assertEqual(response.status_code, 200)
  2222. self.assertNotContains(response, 'name="posted"')
  2223. # 3 fields + 2 submit buttons + 4 inline management form fields, + 2
  2224. # hidden fields for inlines + 1 field for the inline + 2 empty form
  2225. self.assertEqual(response.content.count("<input"), 14)
  2226. self.assertContains(response, formats.localize(datetime.date.today()))
  2227. self.assertContains(response,
  2228. "<label>Awesomeness level:</label>")
  2229. self.assertContains(response, "Very awesome.")
  2230. self.assertContains(response, "Unkown coolness.")
  2231. self.assertContains(response, "foo")
  2232. self.assertContains(response,
  2233. formats.localize(datetime.date.today() - datetime.timedelta(days=7))
  2234. )
  2235. self.assertContains(response, '<div class="form-row coolness">')
  2236. self.assertContains(response, '<div class="form-row awesomeness_level">')
  2237. self.assertContains(response, '<div class="form-row posted">')
  2238. self.assertContains(response, '<div class="form-row value">')
  2239. self.assertContains(response, '<div class="form-row ">')
  2240. self.assertContains(response, '<p class="help">', 3)
  2241. self.assertContains(response, '<p class="help">Some help text for the title (with unicode ŠĐĆŽćžšđ)</p>')
  2242. self.assertContains(response, '<p class="help">Some help text for the content (with unicode ŠĐĆŽćžšđ)</p>')
  2243. self.assertContains(response, '<p class="help">Some help text for the date (with unicode ŠĐĆŽćžšđ)</p>')
  2244. p = Post.objects.create(title="I worked on readonly_fields", content="Its good stuff")
  2245. response = self.client.get('/test_admin/admin/admin_views/post/%d/' % p.pk)
  2246. self.assertContains(response, "%d amount of cool" % p.pk)
  2247. def test_readonly_post(self):
  2248. data = {
  2249. "title": "Django Got Readonly Fields",
  2250. "content": "This is an incredible development.",
  2251. "link_set-TOTAL_FORMS": "1",
  2252. "link_set-INITIAL_FORMS": "0",
  2253. "link_set-MAX_NUM_FORMS": "0",
  2254. }
  2255. response = self.client.post('/test_admin/admin/admin_views/post/add/', data)
  2256. self.assertEqual(response.status_code, 302)
  2257. self.assertEqual(Post.objects.count(), 1)
  2258. p = Post.objects.get()
  2259. self.assertEqual(p.posted, datetime.date.today())
  2260. data["posted"] = "10-8-1990" # some date that's not today
  2261. response = self.client.post('/test_admin/admin/admin_views/post/add/', data)
  2262. self.assertEqual(response.status_code, 302)
  2263. self.assertEqual(Post.objects.count(), 2)
  2264. p = Post.objects.order_by('-id')[0]
  2265. self.assertEqual(p.posted, datetime.date.today())
  2266. def test_readonly_manytomany(self):
  2267. "Regression test for #13004"
  2268. response = self.client.get('/test_admin/admin/admin_views/pizza/add/')
  2269. self.assertEqual(response.status_code, 200)
  2270. class RawIdFieldsTest(TestCase):
  2271. fixtures = ['admin-views-users.xml']
  2272. def setUp(self):
  2273. self.client.login(username='super', password='secret')
  2274. def tearDown(self):
  2275. self.client.logout()
  2276. def test_limit_choices_to(self):
  2277. """Regression test for 14880"""
  2278. # This includes tests integers, strings and booleans in the lookup query string
  2279. actor = Actor.objects.create(name="Palin", age=27)
  2280. inquisition1 = Inquisition.objects.create(expected=True,
  2281. leader=actor,
  2282. country="England")
  2283. inquisition2 = Inquisition.objects.create(expected=False,
  2284. leader=actor,
  2285. country="Spain")
  2286. response = self.client.get('/test_admin/admin/admin_views/sketch/add/')
  2287. # Find the link
  2288. m = re.search(r'<a href="([^"]*)"[^>]* id="lookup_id_inquisition"', response.content)
  2289. self.assertTrue(m) # Got a match
  2290. popup_url = m.groups()[0].replace("&amp;", "&")
  2291. # Handle relative links
  2292. popup_url = urlparse.urljoin(response.request['PATH_INFO'], popup_url)
  2293. # Get the popup
  2294. response2 = self.client.get(popup_url)
  2295. self.assertContains(response2, "Spain")
  2296. self.assertNotContains(response2, "England")
  2297. class UserAdminTest(TestCase):
  2298. """
  2299. Tests user CRUD functionality.
  2300. """
  2301. fixtures = ['admin-views-users.xml']
  2302. def setUp(self):
  2303. self.client.login(username='super', password='secret')
  2304. def tearDown(self):
  2305. self.client.logout()
  2306. def test_save_button(self):
  2307. user_count = User.objects.count()
  2308. response = self.client.post('/test_admin/admin/auth/user/add/', {
  2309. 'username': 'newuser',
  2310. 'password1': 'newpassword',
  2311. 'password2': 'newpassword',
  2312. })
  2313. new_user = User.objects.order_by('-id')[0]
  2314. self.assertRedirects(response, '/test_admin/admin/auth/user/%s/' % new_user.pk)
  2315. self.assertEqual(User.objects.count(), user_count + 1)
  2316. self.assertNotEqual(new_user.password, UNUSABLE_PASSWORD)
  2317. def test_save_continue_editing_button(self):
  2318. user_count = User.objects.count()
  2319. response = self.client.post('/test_admin/admin/auth/user/add/', {
  2320. 'username': 'newuser',
  2321. 'password1': 'newpassword',
  2322. 'password2': 'newpassword',
  2323. '_continue': '1',
  2324. })
  2325. new_user = User.objects.order_by('-id')[0]
  2326. self.assertRedirects(response, '/test_admin/admin/auth/user/%s/' % new_user.pk)
  2327. self.assertEqual(User.objects.count(), user_count + 1)
  2328. self.assertNotEqual(new_user.password, UNUSABLE_PASSWORD)
  2329. def test_password_mismatch(self):
  2330. response = self.client.post('/test_admin/admin/auth/user/add/', {
  2331. 'username': 'newuser',
  2332. 'password1': 'newpassword',
  2333. 'password2': 'mismatch',
  2334. })
  2335. self.assertEqual(response.status_code, 200)
  2336. adminform = response.context['adminform']
  2337. self.assertTrue('password' not in adminform.form.errors)
  2338. self.assertEqual(adminform.form.errors['password2'],
  2339. [u"The two password fields didn't match."])
  2340. def test_user_fk_popup(self):
  2341. """Quick user addition in a FK popup shouldn't invoke view for further user customization"""
  2342. response = self.client.get('/test_admin/admin/admin_views/album/add/')
  2343. self.assertEqual(response.status_code, 200)
  2344. self.assertContains(response, '/test_admin/admin/auth/user/add')
  2345. self.assertContains(response, 'class="add-another" id="add_id_owner" onclick="return showAddAnotherPopup(this);"')
  2346. response = self.client.get('/test_admin/admin/auth/user/add/?_popup=1')
  2347. self.assertEqual(response.status_code, 200)
  2348. self.assertNotContains(response, 'name="_continue"')
  2349. self.assertNotContains(response, 'name="_addanother"')
  2350. data = {
  2351. 'username': 'newuser',
  2352. 'password1': 'newpassword',
  2353. 'password2': 'newpassword',
  2354. '_popup': '1',
  2355. '_save': '1',
  2356. }
  2357. response = self.client.post('/test_admin/admin/auth/user/add/?_popup=1', data, follow=True)
  2358. self.assertEqual(response.status_code, 200)
  2359. self.assertContains(response, 'dismissAddAnotherPopup')
  2360. def test_save_add_another_button(self):
  2361. user_count = User.objects.count()
  2362. response = self.client.post('/test_admin/admin/auth/user/add/', {
  2363. 'username': 'newuser',
  2364. 'password1': 'newpassword',
  2365. 'password2': 'newpassword',
  2366. '_addanother': '1',
  2367. })
  2368. new_user = User.objects.order_by('-id')[0]
  2369. self.assertRedirects(response, '/test_admin/admin/auth/user/add/')
  2370. self.assertEqual(User.objects.count(), user_count + 1)
  2371. self.assertNotEqual(new_user.password, UNUSABLE_PASSWORD)
  2372. try:
  2373. import docutils
  2374. except ImportError:
  2375. docutils = None
  2376. #@unittest.skipUnless(docutils, "no docutils installed.")
  2377. class AdminDocsTest(TestCase):
  2378. fixtures = ['admin-views-users.xml']
  2379. def setUp(self):
  2380. self.client.login(username='super', password='secret')
  2381. def tearDown(self):
  2382. self.client.logout()
  2383. def test_tags(self):
  2384. response = self.client.get('/test_admin/admin/doc/tags/')
  2385. # The builtin tag group exists
  2386. self.assertContains(response, "<h2>Built-in tags</h2>", count=2)
  2387. # A builtin tag exists in both the index and detail
  2388. self.assertContains(response, '<h3 id="built_in-autoescape">autoescape</h3>')
  2389. self.assertContains(response, '<li><a href="#built_in-autoescape">autoescape</a></li>')
  2390. # An app tag exists in both the index and detail
  2391. self.assertContains(response, '<h3 id="flatpages-get_flatpages">get_flatpages</h3>')
  2392. self.assertContains(response, '<li><a href="#flatpages-get_flatpages">get_flatpages</a></li>')
  2393. # The admin list tag group exists
  2394. self.assertContains(response, "<h2>admin_list</h2>", count=2)
  2395. # An admin list tag exists in both the index and detail
  2396. self.assertContains(response, '<h3 id="admin_list-admin_actions">admin_actions</h3>')
  2397. self.assertContains(response, '<li><a href="#admin_list-admin_actions">admin_actions</a></li>')
  2398. def test_filters(self):
  2399. response = self.client.get('/test_admin/admin/doc/filters/')
  2400. # The builtin filter group exists
  2401. self.assertContains(response, "<h2>Built-in filters</h2>", count=2)
  2402. # A builtin filter exists in both the index and detail
  2403. self.assertContains(response, '<h3 id="built_in-add">add</h3>')
  2404. self.assertContains(response, '<li><a href="#built_in-add">add</a></li>')
  2405. AdminDocsTest = unittest.skipUnless(docutils, "no docutils installed.")(AdminDocsTest)
  2406. class ValidXHTMLTests(TestCase):
  2407. fixtures = ['admin-views-users.xml']
  2408. urlbit = 'admin'
  2409. def setUp(self):
  2410. self._context_processors = None
  2411. self._use_i18n, settings.USE_I18N = settings.USE_I18N, False
  2412. if 'django.core.context_processors.i18n' in settings.TEMPLATE_CONTEXT_PROCESSORS:
  2413. self._context_processors = settings.TEMPLATE_CONTEXT_PROCESSORS
  2414. cp = list(settings.TEMPLATE_CONTEXT_PROCESSORS)
  2415. cp.remove('django.core.context_processors.i18n')
  2416. settings.TEMPLATE_CONTEXT_PROCESSORS = tuple(cp)
  2417. # Force re-evaluation of the contex processor list
  2418. django.template.context._standard_context_processors = None
  2419. self.client.login(username='super', password='secret')
  2420. def tearDown(self):
  2421. self.client.logout()
  2422. if self._context_processors is not None:
  2423. settings.TEMPLATE_CONTEXT_PROCESSORS = self._context_processors
  2424. # Force re-evaluation of the contex processor list
  2425. django.template.context._standard_context_processors = None
  2426. settings.USE_I18N = self._use_i18n
  2427. def testLangNamePresent(self):
  2428. response = self.client.get('/test_admin/%s/admin_views/' % self.urlbit)
  2429. self.assertFalse(' lang=""' in response.content)
  2430. self.assertFalse(' xml:lang=""' in response.content)
  2431. class DateHierarchyTests(TestCase):
  2432. fixtures = ['admin-views-users.xml']
  2433. def setUp(self):
  2434. self.client.login(username='super', password='secret')
  2435. self.old_USE_THOUSAND_SEPARATOR = settings.USE_THOUSAND_SEPARATOR
  2436. self.old_USE_L10N = settings.USE_L10N
  2437. settings.USE_THOUSAND_SEPARATOR = True
  2438. settings.USE_L10N = True
  2439. def tearDown(self):
  2440. settings.USE_THOUSAND_SEPARATOR = self.old_USE_THOUSAND_SEPARATOR
  2441. settings.USE_L10N = self.old_USE_L10N
  2442. formats.reset_format_cache()
  2443. def assert_non_localized_year(self, response, year):
  2444. """Ensure that the year is not localized with
  2445. USE_THOUSAND_SEPARATOR. Refs #15234.
  2446. """
  2447. self.assertNotContains(response, formats.number_format(year))
  2448. def assert_contains_year_link(self, response, date):
  2449. self.assertContains(response, '?release_date__year=%d"' % (date.year,))
  2450. def assert_contains_month_link(self, response, date):
  2451. self.assertContains(
  2452. response, '?release_date__year=%d&amp;release_date__month=%d"' % (
  2453. date.year, date.month))
  2454. def assert_contains_day_link(self, response, date):
  2455. self.assertContains(
  2456. response, '?release_date__year=%d&amp;'
  2457. 'release_date__month=%d&amp;release_date__day=%d"' % (
  2458. date.year, date.month, date.day))
  2459. def test_empty(self):
  2460. """
  2461. Ensure that no date hierarchy links display with empty changelist.
  2462. """
  2463. response = self.client.get(
  2464. reverse('admin:admin_views_podcast_changelist'))
  2465. self.assertNotContains(response, 'release_date__year=')
  2466. self.assertNotContains(response, 'release_date__month=')
  2467. self.assertNotContains(response, 'release_date__day=')
  2468. def test_single(self):
  2469. """
  2470. Ensure that single day-level date hierarchy appears for single object.
  2471. """
  2472. DATE = datetime.date(2000, 6, 30)
  2473. Podcast.objects.create(release_date=DATE)
  2474. url = reverse('admin:admin_views_podcast_changelist')
  2475. response = self.client.get(url)
  2476. self.assert_contains_day_link(response, DATE)
  2477. self.assert_non_localized_year(response, 2000)
  2478. def test_within_month(self):
  2479. """
  2480. Ensure that day-level links appear for changelist within single month.
  2481. """
  2482. DATES = (datetime.date(2000, 6, 30),
  2483. datetime.date(2000, 6, 15),
  2484. datetime.date(2000, 6, 3))
  2485. for date in DATES:
  2486. Podcast.objects.create(release_date=date)
  2487. url = reverse('admin:admin_views_podcast_changelist')
  2488. response = self.client.get(url)
  2489. for date in DATES:
  2490. self.assert_contains_day_link(response, date)
  2491. self.assert_non_localized_year(response, 2000)
  2492. def test_within_year(self):
  2493. """
  2494. Ensure that month-level links appear for changelist within single year.
  2495. """
  2496. DATES = (datetime.date(2000, 1, 30),
  2497. datetime.date(2000, 3, 15),
  2498. datetime.date(2000, 5, 3))
  2499. for date in DATES:
  2500. Podcast.objects.create(release_date=date)
  2501. url = reverse('admin:admin_views_podcast_changelist')
  2502. response = self.client.get(url)
  2503. # no day-level links
  2504. self.assertNotContains(response, 'release_date__day=')
  2505. for date in DATES:
  2506. self.assert_contains_month_link(response, date)
  2507. self.assert_non_localized_year(response, 2000)
  2508. def test_multiple_years(self):
  2509. """
  2510. Ensure that year-level links appear for year-spanning changelist.
  2511. """
  2512. DATES = (datetime.date(2001, 1, 30),
  2513. datetime.date(2003, 3, 15),
  2514. datetime.date(2005, 5, 3))
  2515. for date in DATES:
  2516. Podcast.objects.create(release_date=date)
  2517. response = self.client.get(
  2518. reverse('admin:admin_views_podcast_changelist'))
  2519. # no day/month-level links
  2520. self.assertNotContains(response, 'release_date__day=')
  2521. self.assertNotContains(response, 'release_date__month=')
  2522. for date in DATES:
  2523. self.assert_contains_year_link(response, date)
  2524. # and make sure GET parameters still behave correctly
  2525. for date in DATES:
  2526. url = '%s?release_date__year=%d' % (
  2527. reverse('admin:admin_views_podcast_changelist'),
  2528. date.year)
  2529. response = self.client.get(url)
  2530. self.assert_contains_month_link(response, date)
  2531. self.assert_non_localized_year(response, 2000)
  2532. self.assert_non_localized_year(response, 2003)
  2533. self.assert_non_localized_year(response, 2005)
  2534. url = '%s?release_date__year=%d&release_date__month=%d' % (
  2535. reverse('admin:admin_views_podcast_changelist'),
  2536. date.year, date.month)
  2537. response = self.client.get(url)
  2538. self.assert_contains_day_link(response, date)
  2539. self.assert_non_localized_year(response, 2000)
  2540. self.assert_non_localized_year(response, 2003)
  2541. self.assert_non_localized_year(response, 2005)