Skip to content
GitLab
Projects Groups Topics Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
  • Register
  • Sign in
  • erp5 erp5
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributor statistics
    • Graph
    • Compare revisions
  • Merge requests 142
    • Merge requests 142
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Repository
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Jobs
  • Commits
Collapse sidebar
  • nexedinexedi
  • erp5erp5
  • Merge requests
  • !771

Passwords in ERP5 tests

  • Review changes

  • Download
  • Patches
  • Plain diff
Merged Jérome Perrin requested to merge jerome/erp5:feat/passwords-in-tests into master Oct 12, 2018
  • Overview 2
  • Commits 1
  • Pipelines 0
  • Changes 52

It's a security problem that runUnitTest starts a webserver without password for manager user.

The general idea:

  • ERP5TypeTestCase user gets a random password.
  • every time test create user we give them a random password.
  • by default there's a manager user whose login and password are set as manager_username and manager_password class attributes. Many tests where creating a new manager user, but they should be able to use this existing user.
  • maybe we don't need this patch to allow empty passwords in publish method anymore.
  • Zelenium is more complex, the tests start logged in as manager for most tests it's enough, but some tests needs to login again as manager. For these, the username and password is set in cookies before starting tests.
Edited May 28, 2024 by Jérome Perrin
Assignee
Assign to
Reviewers
Request review from
Time tracking
Source branch: feat/passwords-in-tests
GitLab Nexedi Edition | About GitLab | About Nexedi | 沪ICP备2021021310号-2 | 沪ICP备2021021310号-7