All checks were successful
Build and deploy / Validate source (push) Successful in 6s
Build and deploy / Integration suite on a real stack (push) Successful in 3m7s
Build and deploy / Secret scan and release gate (push) Successful in 10s
Build and deploy / Publish images (push) Successful in 1m6s
The order page becomes the customer's area, one page at four addresses: - /conta/entrar: sign in or create an account, side by side. "Esqueci minha senha" points to the Dropstar WhatsApp until e-mail can be sent. - /conta: the counts of orders waiting for payment, in production, in correction and finished, and the latest one. - /conta/pedidos: every order and the cart waiting for payment in one list, newest first, filtered by group, order number and period, ten per page. The cart shows "Aguardando pagamento" and its "Pagar" goes to the PIX page when a PIX code is open. An order opens in place with its progress, items, delivery, history, files and the correction form. A guest sees the orders paid in this browser. - /conta/dados: WhatsApp and a saved delivery address (the CNPJ is locked), e-mail and password changes, both confirmed with the current password; a password change signs the other devices out. The cart fills in the account's details and saved address. New API routes for the details, and the order list takes filters and pages and returns the counts; only the newest unpaid quote whose files still exist is listed. The Site's "Minha conta" and "Ver meus pedidos" point to the new addresses. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
95 lines
7.0 KiB
Python
95 lines
7.0 KiB
Python
"""Customer identity, correction and final-file trust boundaries against local stack."""
|
|
from uuid import uuid4
|
|
from urllib.request import urlopen
|
|
from tests.smoke_test import Client, approved_quote, upload_bytes, item_spec
|
|
|
|
def run():
|
|
customer=Client();other=Client();customer.call('/session');other.call('/session')
|
|
uid=upload_bytes(customer,b'LOCAL ORIGINAL ONLY')
|
|
item=item_spec('file','1.01',0,uid)
|
|
profile={'cnpj':'11222333000181','zap':'11999999999','mail':'workflow-'+uuid4().hex[:8]+'@example.test'}
|
|
q=customer.call('/quotes',{'request_key':str(uuid4()),'customer':profile,'items':[item],'freight':{'service':'pickup'}})
|
|
approved_quote(customer,q,[item])
|
|
order=customer.call('/orders/dev-paid',{'quote_id':q['id']});oid=order['id']
|
|
before=list(customer.jar)[0].value
|
|
password='local-test-password-'+uuid4().hex
|
|
customer.call('/account/register',{'customer':profile,'password':password})
|
|
assert customer.call('/account/me')['customer']['mail']==profile['mail']
|
|
assert [e['id'] for e in customer.call('/customer/orders')['items'] if e['kind']=='order'][0]==oid
|
|
# The list filters, pages and counts by group.
|
|
listing=customer.call('/customer/orders?status=prod&page=1&size=1')
|
|
assert listing['counts']['prod']>=1 and listing['total']==listing['counts']['prod'] and len(listing['items'])==1, listing
|
|
assert customer.call('/customer/orders?status=fin')['items']==[]
|
|
assert customer.call('/customer/orders?number='+str(order['number']))['items'][0]['id']==oid
|
|
# The account's details change; the CNPJ does not, and e-mail and password need the password.
|
|
address={'recipient':'Workflow Ltda','street':'Rua de Teste','number':'10','complement':'',
|
|
'district':'Centro','city':'Franca','state':'SP','postal_code':'14400000'}
|
|
saved=customer.call('/account/profile',{'zap':'(16) 98888-7777','address':address})['customer']
|
|
assert saved['zap']=='16988887777' and saved['cnpj']==profile['cnpj'] and saved['address']['city']=='Franca'
|
|
assert customer.call('/account/me')['customer']['address']['postal_code']=='14400000'
|
|
customer.call('/account/profile',{'zap':'16988887777','cnpj':'00000000000000'},expected=422)
|
|
customer.call('/account/email',{'email':'x-'+profile['mail'],'password':'wrong-password'},expected=401)
|
|
customer.call('/account/password',{'current':'wrong-password','new':'another-password-123'},expected=401)
|
|
other.call('/account/profile',{'zap':'16988887777'},expected=401)
|
|
print('PASS: customer order list filters and pages; account details change, CNPJ does not')
|
|
# Email/CNPJ do not grant ownership; only current guest session is migrated.
|
|
other.call('/customer/orders/'+oid,expected=404)
|
|
other.call('/account/login',{'email':profile['mail'],'password':'wrong-password'},expected=401)
|
|
revoked=Client()
|
|
import http.cookiejar
|
|
cookie=http.cookiejar.Cookie(0,'dtf_session',before,None,False,'localhost.local',False,False,'/',True,False,None,True,None,None,{},False)
|
|
revoked.jar.set_cookie(cookie)
|
|
revoked.call('/customer/orders',expected=401)
|
|
account_scope=customer.call('/session')['cart_scope']
|
|
cookie.value=account_scope;revoked.jar.set_cookie(cookie)
|
|
revoked.call('/customer/orders',expected=401)
|
|
other.call('/account/login',{'email':profile['mail'],'password':password})
|
|
assert other.call('/customer/orders/'+oid)['id']==oid
|
|
print('PASS: registration claims only current guest records, cross-session account login, revoked sessions, owner UUID is not a credential')
|
|
|
|
def move(state,version):
|
|
return customer.call('/operator/orders/'+oid+'/move',{'state':state,'version':version,'reason':'Please replace the artwork' if state=='cor' else ''},operator=True)['version']
|
|
version=move('tra',0)
|
|
customer.call('/operator/orders/'+oid+'/move',{'state':'fil','version':version},operator=True,expected=409)
|
|
final_id=upload_bytes(customer,b'LOCAL FINAL VERSION ONE',order_id=oid)
|
|
customer.call('/uploads/'+final_id,expected=404)
|
|
body={'version':version,'files':[{'item_index':0,'upload_id':final_id}],'note':'Manually checked final'}
|
|
customer.call('/operator/orders/'+oid+'/final-files',body,expected=401)
|
|
version=customer.call('/operator/orders/'+oid+'/final-files',body,operator=True)['version']
|
|
detail=customer.call('/customer/orders/'+oid)
|
|
final=detail['files'][0]
|
|
link=customer.call('/customer/orders/'+oid+'/files/'+final['id']+'/download')
|
|
assert urlopen(link['url']).read()==b'LOCAL FINAL VERSION ONE'
|
|
guest=Client();guest.call('/session');guest.call('/customer/orders/'+oid+'/files/'+final['id']+'/download',expected=404)
|
|
version=move('fil',version);version=move('imp',version);version=move('cor',version)
|
|
customer.call('/customer/orders/'+oid+'/files/'+final['id']+'/download',expected=404)
|
|
premature_final=upload_bytes(customer,b'FINAL BEFORE CUSTOMER CORRECTION',order_id=oid)
|
|
version=customer.call('/operator/orders/'+oid+'/final-files',
|
|
{'version':version,'files':[{'item_index':0,'upload_id':premature_final}],
|
|
'note':'Prepared before customer sent the new correction'},operator=True)['version']
|
|
correction_id=upload_bytes(customer,b'LOCAL CORRECTED ORIGINAL')
|
|
payload={'version':version,'files':[{'item_index':0,'upload_id':correction_id}],'note':'Replaced the artwork as requested'}
|
|
guest.call('/customer/orders/'+oid+'/corrections',payload,expected=404)
|
|
customer.call('/customer/orders/'+oid+'/corrections',{**payload,'version':0},expected=409)
|
|
version=customer.call('/customer/orders/'+oid+'/corrections',payload)['version']
|
|
files=customer.call('/operator/orders/'+oid+'/files',operator=True)
|
|
assert any(f['kind']=='correction' and f['active'] and f['upload_id']==correction_id for f in files)
|
|
assert not any(f['kind']=='final' and f['active'] for f in files), 'new correction kept a stale final active'
|
|
version=move('tra',version)
|
|
customer.call('/operator/orders/'+oid+'/move',{'state':'fil','version':version},operator=True,expected=409)
|
|
new_final=upload_bytes(customer,b'LOCAL FINAL VERSION TWO',order_id=oid)
|
|
version=customer.call('/operator/orders/'+oid+'/final-files',{'version':version,'files':[{'item_index':0,'upload_id':new_final}],'note':'Checked corrected final'},operator=True)['version']
|
|
for state in ('fil','imp','fin'):version=move(state,version)
|
|
detail=other.call('/customer/orders/'+oid)
|
|
assert detail['state']=='fin'
|
|
assert sum(f['active'] and f['kind']=='final' for f in detail['files'])==1
|
|
assert any(h['reason']=='Please replace the artwork' for h in detail['history'])
|
|
print('PASS: final-file gate, final revisions, secure customer downloads, correction history/uploads, old final invalidation and reapproval')
|
|
old_cookie=list(other.jar)[0].value
|
|
other.call('/account/logout',{})
|
|
cookie.value=old_cookie;revoked.jar.set_cookie(cookie);revoked.call('/customer/orders',expected=401)
|
|
other.call('/session');assert other.call('/customer/orders')['items']==[]
|
|
print('PASS: logout revokes server session and signed-out visitors cannot see account orders')
|
|
|
|
if __name__=='__main__':run()
|