Files
inkwell/tests/test_settings.py
bvandeusenandClaude Opus 5.5 2e2d8667dd
Android / Build, or is the channel already serving this? (push) Successful in 4s
Android / Kotlin + Rust (APK) (push) Skipped
CI & Build / Build now, or wait for Android? (push) Successful in 2s
CI & Build / Web typecheck and unit tests (push) Successful in 11s
CI & Build / Python lint (push) Successful in 2s
CI & Build / Python tests (push) Successful in 15s
Desktop (Tauri) / Build, or is the channel already serving this? (push) Successful in 3s
CI & Build / integration (push) Successful in 1m16s
CI & Build / Build & push image (push) Successful in 1m15s
Desktop (Tauri) / Web tests, clippy, Rust tests and rustfmt (push) Successful in 2m49s
Desktop (Tauri) / Windows installer (cross-compiled) (push) Successful in 3m26s
Desktop (Tauri) / Tauri desktop (Linux) (push) Successful in 4m26s
Desktop (Tauri) / Update manifest (push) Successful in 4s
password reset by email: Settings → Email, Forgot password?, and a test-email button
The operator asked for self-service reset over SMTP. It reuses #5173's
password_resets table, /reset-password page, one-hour single-use token and
sign-out-everywhere.

- Settings (rule 25, not env): a new Email group (SMTP server, port,
  encryption as a choice, username, password, from), General → Public
  address, and Security → Reset emails per account. The registry gains
  `choices`, `secret` (the value is never sent back, `is_set` says one is
  saved, an empty save keeps it) and `url` (http(s), trailing slash
  stripped).
- mailer.py: stdlib smtplib on a worker thread, 20 s timeout,
  starttls | tls | none. mail_settings() is None until a server, a sender
  and the public address are set. Links are built from the public address
  because the Host header can be forged.
- POST /api/auth/forgot-password: the same answer at the same speed for
  any address. The link is made and mailed off the request (send_later).
  It is throttled like a sign-in per visitor address, and capped per typed
  email by reset_emails_per_account; past the cap it answers the same and
  sends nothing.
- POST /api/settings/test-email: mails the admin with the saved settings
  and shows the server's error if it fails.
- Public config `password_reset_by_email`. Sign-in shows "Forgot
  password?" only then, linking to a new /forgot-password page.
- docs/public-hosting.md: an "Email and forgotten passwords" section.

Tests: the secret stays server-side; emailed link → reset; the same
answer for unknown addresses; the cap; test email success and failure;
validation units. #5266.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-07 15:15:43 -04:00

48 lines
1.6 KiB
Python

from inkwell.settings import REGISTRY, validate_updates
def test_registry_has_expected_keys():
keys = {d.key for d in REGISTRY}
assert {"site_name", "allow_registration", "session_ttl_days"} <= keys
def test_validate_rejects_unknown_key():
clean, error = validate_updates({"nope": 1})
assert error is not None
assert clean == {}
def test_validate_coerces_bool_and_int():
clean, error = validate_updates({"allow_registration": "true", "session_ttl_days": "45"})
assert error is None
assert clean["allow_registration"] is True
assert clean["session_ttl_days"] == 45
def test_validate_rejects_bad_int():
clean, error = validate_updates({"session_ttl_days": "not-a-number"})
assert error is not None
assert clean == {}
def test_an_empty_secret_keeps_what_is_saved():
clean, error = validate_updates({"smtp_password": "", "smtp_host": "smtp.example.test"})
assert error is None
assert clean == {"smtp_host": "smtp.example.test"}
def test_a_choice_must_be_one_of_its_values():
assert validate_updates({"smtp_security": "tls"}) == ({"smtp_security": "tls"}, None)
clean, error = validate_updates({"smtp_security": "ssl"})
assert clean == {} and error
def test_the_public_address_is_an_http_url_without_a_trailing_slash():
assert validate_updates({"public_url": "https://notes.example.test/"}) == (
{"public_url": "https://notes.example.test"},
None,
)
assert validate_updates({"public_url": ""}) == ({"public_url": ""}, None)
clean, error = validate_updates({"public_url": "javascript:alert(1)"})
assert clean == {} and error