Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,7 @@
UserOAuthModelView,
UserRemoteUserModelView,
)
from wtforms.validators import DataRequired

from airflow.providers.fab.www.security import permissions

Expand Down Expand Up @@ -186,6 +187,8 @@ class CustomUserDBModelView(MultiResourceUserMixin, UserDBModelView):
"conf_password",
]

validators_columns = {"roles": [DataRequired()]}

base_permissions = [
permissions.ACTION_CAN_CREATE,
permissions.ACTION_CAN_READ,
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -95,6 +95,7 @@ def app_context(self, app):
yield
delete_user(app, "no_access")
delete_user(app, "has_access")
delete_user(app, "test_new_user")

@pytest.mark.parametrize(("url", "_", "expected_text"), PERMISSIONS_TESTS_PARAMS)
def test_user_model_view_without_access(self, url, expected_text, _, app, client):
Expand Down Expand Up @@ -185,6 +186,41 @@ def test_user_model_view_with_delete_access(self, app, client):
client.post(f"/users/delete/{user_to_delete.id}", follow_redirects=False)
assert bool(get_auth_manager().security_manager.get_user_by_id(user_to_delete.id)) is False

def test_user_creation_without_role_shows_validation_error(self, app, client):
"""Regression test for https://github.com/apache/airflow/issues/59963"""
create_user(
app,
username="has_access",
role_name="role_has_access",
permissions=[
(permissions.ACTION_CAN_READ, permissions.RESOURCE_WEBSITE),
(permissions.ACTION_CAN_CREATE, permissions.RESOURCE_USER),
],
)

client = client_with_login(
app,
username="has_access",
password="has_access",
)

response = client.post(
"/users/add",
data={
"first_name": "Test",
"last_name": "User",
"username": "test_new_user",
"email": "test_new_user@example.com",
"password": "test_password",
"conf_password": "test_password",
"active": "y",
},
follow_redirects=True,
)

assert response.status_code == 200
check_content_in_response("This field is required", response)


class TestResetUserSessions:
@pytest.fixture(autouse=True)
Expand Down