11 changed files with 228 additions and 16 deletions
@ -0,0 +1,33 @@
|
||||
<% content_for :title, "Reset your password" %> |
||||
|
||||
<% content_for :before_content do %> |
||||
<%= govuk_back_link( |
||||
text: 'Back', |
||||
href: :back, |
||||
) %> |
||||
<% end %> |
||||
|
||||
<%= form_for(@admin_user, as: :admin_user, url: password_path(AdminUser), html: { method: :put }) do |f| %> |
||||
<%= f.hidden_field :reset_password_token %> |
||||
<div class="govuk-grid-row"> |
||||
<div class="govuk-grid-column-two-thirds"> |
||||
<%= f.govuk_error_summary %> |
||||
|
||||
<h1 class="govuk-heading-l"> |
||||
<%= content_for(:title) %> |
||||
</h1> |
||||
|
||||
<%= f.govuk_password_field :password, |
||||
label: { text: "New password" }, |
||||
hint: @minimum_password_length ? { text: "Your password must be at least #{@minimum_password_length} characters and hard to guess." } : nil, |
||||
autocomplete: "new-password" |
||||
%> |
||||
|
||||
<%= f.govuk_password_field :password_confirmation, |
||||
label: { text: "Confirm new password" } |
||||
%> |
||||
|
||||
<%= f.govuk_submit "Update" %> |
||||
</div> |
||||
</div> |
||||
<% end %> |
@ -0,0 +1,13 @@
|
||||
class AddTrackableToAdminUser < ActiveRecord::Migration[7.0] |
||||
def change |
||||
change_table :admin_users, bulk: true do |t| |
||||
t.string :name |
||||
## Trackable |
||||
t.integer :sign_in_count, default: 0, null: false |
||||
t.datetime :current_sign_in_at |
||||
t.datetime :last_sign_in_at |
||||
t.string :current_sign_in_ip |
||||
t.string :last_sign_in_ip |
||||
end |
||||
end |
||||
end |
@ -0,0 +1,55 @@
|
||||
require "rails_helper" |
||||
|
||||
RSpec.describe "Admin Features" do |
||||
let!(:admin_user) { FactoryBot.create(:admin_user, last_sign_in_at: Time.zone.now) } |
||||
let(:notify_client) { instance_double(Notifications::Client) } |
||||
let(:reset_password_token) { "MCDH5y6Km-U7CFPgAMVS" } |
||||
let(:devise_notify_mailer) { DeviseNotifyMailer.new } |
||||
|
||||
before do |
||||
allow(DeviseNotifyMailer).to receive(:new).and_return(devise_notify_mailer) |
||||
allow(devise_notify_mailer).to receive(:notify_client).and_return(notify_client) |
||||
allow(notify_client).to receive(:send_email).and_return(true) |
||||
allow(Devise.token_generator).to receive(:generate).and_return(reset_password_token) |
||||
end |
||||
|
||||
context "when the admin has forgotten their password" do |
||||
it " is redirected to the reset password page when they click the reset password link" do |
||||
visit("/admin") |
||||
click_link("Forgot your password?") |
||||
expect(page).to have_current_path("/admin/password/new") |
||||
end |
||||
|
||||
it " is shown an error message if they submit without entering an email address" do |
||||
visit("/admin/password/new") |
||||
click_button("Reset My Password") |
||||
expect(page).to have_selector("#error_explanation") |
||||
expect(page).to have_content("can't be blank") |
||||
end |
||||
|
||||
it " is redirected to admin login page after reset email is sent" do |
||||
visit("/admin/password/new") |
||||
fill_in("admin_user[email]", with: admin_user.email) |
||||
click_button("Reset My Password") |
||||
expect(page).to have_current_path("/admin/login") |
||||
end |
||||
|
||||
it " is sent a reset password email via Notify" do |
||||
expect(notify_client).to receive(:send_email).with( |
||||
{ |
||||
email_address: admin_user.email, |
||||
template_id: admin_user.reset_password_notify_template, |
||||
personalisation: { |
||||
name: admin_user.email, |
||||
email: admin_user.email, |
||||
organisation: "", |
||||
link: "http://localhost:3000/admin/password/edit?reset_password_token=#{reset_password_token}", |
||||
}, |
||||
}, |
||||
) |
||||
visit("/admin/password/new") |
||||
fill_in("admin_user[email]", with: admin_user.email) |
||||
click_button("Reset My Password") |
||||
end |
||||
end |
||||
end |
@ -0,0 +1,33 @@
|
||||
<% content_for :title, "Reset your password" %> |
||||
|
||||
<% content_for :before_content do %> |
||||
<%= govuk_back_link( |
||||
text: 'Back', |
||||
href: :back, |
||||
) %> |
||||
<% end %> |
||||
|
||||
<%= form_for(@user, as: :user, url: password_path(User), html: { method: :put }) do |f| %> |
||||
<%= f.hidden_field :reset_password_token %> |
||||
<div class="govuk-grid-row"> |
||||
<div class="govuk-grid-column-two-thirds"> |
||||
<%= f.govuk_error_summary %> |
||||
|
||||
<h1 class="govuk-heading-l"> |
||||
<%= content_for(:title) %> |
||||
</h1> |
||||
|
||||
<%= f.govuk_password_field :password, |
||||
label: { text: "New password" }, |
||||
hint: @minimum_password_length ? { text: "Your password must be at least #{@minimum_password_length} characters and hard to guess." } : nil, |
||||
autocomplete: "new-password" |
||||
%> |
||||
|
||||
<%= f.govuk_password_field :password_confirmation, |
||||
label: { text: "Confirm new password" } |
||||
%> |
||||
|
||||
<%= f.govuk_submit "Update" %> |
||||
</div> |
||||
</div> |
||||
<% end %> |
@ -0,0 +1,65 @@
|
||||
require "rails_helper" |
||||
|
||||
RSpec.describe ActiveAdmin::Devise::PasswordsController, type: :request do |
||||
let(:admin_user) { FactoryBot.create(:admin_user) } |
||||
let(:headers) { { "Accept" => "text/html" } } |
||||
let(:page) { Capybara::Node::Simple.new(response.body) } |
||||
let(:new_value) { "new-password" } |
||||
let(:notify_client) { instance_double(Notifications::Client) } |
||||
let(:devise_notify_mailer) { DeviseNotifyMailer.new } |
||||
|
||||
before do |
||||
allow(DeviseNotifyMailer).to receive(:new).and_return(devise_notify_mailer) |
||||
allow(devise_notify_mailer).to receive(:notify_client).and_return(notify_client) |
||||
allow(notify_client).to receive(:send_email).and_return(true) |
||||
end |
||||
|
||||
describe "reset password" do |
||||
it "renders the user edit password view" do |
||||
_raw, enc = Devise.token_generator.generate(AdminUser, :reset_password_token) |
||||
get "/admin/password/edit?reset_password_token=#{enc}" |
||||
expect(page).to have_css("h2", text: "DLUHC CORE Change your password") |
||||
end |
||||
|
||||
context "when passwords entered don't match" do |
||||
let(:raw) { admin_user.send_reset_password_instructions } |
||||
let(:params) do |
||||
{ |
||||
id: admin_user.id, |
||||
admin_user: { |
||||
password: new_value, |
||||
password_confirmation: "something_else", |
||||
reset_password_token: raw, |
||||
}, |
||||
} |
||||
end |
||||
|
||||
it "shows an error" do |
||||
put "/admin/password", headers: headers, params: params |
||||
expect(response).to have_http_status(:unprocessable_entity) |
||||
expect(page).to have_content("doesn't match Password") |
||||
end |
||||
end |
||||
|
||||
context "when passwords is reset" do |
||||
let(:raw) { admin_user.send_reset_password_instructions } |
||||
let(:params) do |
||||
{ |
||||
id: admin_user.id, |
||||
admin_user: { |
||||
password: new_value, |
||||
password_confirmation: new_value, |
||||
reset_password_token: raw, |
||||
}, |
||||
} |
||||
end |
||||
|
||||
it "updates the password" do |
||||
expect { |
||||
put "/admin/password", headers: headers, params: params |
||||
admin_user.reload |
||||
}.to change(admin_user, :encrypted_password) |
||||
end |
||||
end |
||||
end |
||||
end |
Loading…
Reference in new issue