Added Oscar-Compatible Receipt Page
This commit is contained in:
committed by
Clinton Blackburn
parent
270ac747ea
commit
1a1fe56b29
@@ -271,6 +271,10 @@ class EnrollmentTest(EnrollmentTestMixin, ModuleStoreTestCase, APITestCase):
|
||||
self.assertEqual(resp.status_code, status.HTTP_200_OK)
|
||||
|
||||
def test_user_does_not_match_param(self):
|
||||
"""
|
||||
The view should return status 404 if the enrollment username does not match the username of the user
|
||||
making the request, unless the request is made by a superuser or with a server API key.
|
||||
"""
|
||||
CourseModeFactory.create(
|
||||
course_id=self.course.id,
|
||||
mode_slug=CourseMode.HONOR,
|
||||
@@ -279,13 +283,19 @@ class EnrollmentTest(EnrollmentTestMixin, ModuleStoreTestCase, APITestCase):
|
||||
url = reverse('courseenrollment',
|
||||
kwargs={'username': self.other_user.username, "course_id": unicode(self.course.id)})
|
||||
|
||||
resp = self.client.get(url)
|
||||
response = self.client.get(url)
|
||||
self.assertEqual(response.status_code, status.HTTP_404_NOT_FOUND)
|
||||
|
||||
# Verify that the server still has access to this endpoint.
|
||||
self.assertEqual(resp.status_code, status.HTTP_404_NOT_FOUND)
|
||||
self.client.logout()
|
||||
resp = self.client.get(url, **{'HTTP_X_EDX_API_KEY': self.API_KEY})
|
||||
self.assertEqual(resp.status_code, status.HTTP_200_OK)
|
||||
response = self.client.get(url, **{'HTTP_X_EDX_API_KEY': self.API_KEY})
|
||||
self.assertEqual(response.status_code, status.HTTP_200_OK)
|
||||
|
||||
# Verify superusers have access to this endpoint
|
||||
superuser = UserFactory.create(password=self.PASSWORD, is_superuser=True)
|
||||
self.client.login(username=superuser.username, password=self.PASSWORD)
|
||||
response = self.client.get(url)
|
||||
self.assertEqual(response.status_code, status.HTTP_200_OK)
|
||||
|
||||
def test_get_course_details(self):
|
||||
CourseModeFactory.create(
|
||||
|
||||
@@ -135,7 +135,9 @@ class EnrollmentView(APIView, ApiKeyPermissionMixIn):
|
||||
"""
|
||||
username = username or request.user.username
|
||||
|
||||
if request.user.username != username and not self.has_api_key_permissions(request):
|
||||
# TODO Implement proper permissions
|
||||
if request.user.username != username and not self.has_api_key_permissions(request) \
|
||||
and not request.user.is_superuser:
|
||||
# Return a 404 instead of a 403 (Unauthorized). If one user is looking up
|
||||
# other users, do not let them deduce the existence of an enrollment.
|
||||
return Response(status=status.HTTP_404_NOT_FOUND)
|
||||
|
||||
Reference in New Issue
Block a user