Name the account site NetKingdom Identity.
Say "Signed in as" the identity, and describe a one-time code as a higher security level of the NetKingdom sign-in rather than another sign-in. The account site keeps its own session. Assistant: grok Assistant-Session: 01a0d25d-d358-7e13-b84a-d007fbb7e34f
This commit is contained in:
parent
b5c60ab2bd
commit
b987a3de9e
9 changed files with 50 additions and 39 deletions
|
|
@ -103,7 +103,7 @@ class PortalNavigationTests(unittest.TestCase):
|
|||
def test_get_logout_only_confirms_and_bad_csrf_does_not_end_session(self):
|
||||
response, body = self.get('/logout')
|
||||
self.assertEqual('200 OK',response['status'])
|
||||
self.assertIn(b'Log out of this portal?',body)
|
||||
self.assertIn(b'End this account-site session?',body)
|
||||
self.assertIsNotNone(self.oidc.claims('operator'))
|
||||
for token in ['', 'wrong', 'member-csrf']:
|
||||
response,_=invoke(self.app,'/logout',method='POST',cookie='ue_session=operator',form={'csrf_token':token})
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue