"""Login state, active sign-in, and allowed memberships stay separate.""" import unittest from test_web import invoke from user_engine.domain import Membership from user_engine.oidc import BrowserSession from user_engine.testing.fixtures import human_actor_claims import test_portal_navigation def _section(body: bytes, element_id: str) -> bytes: marker = f'id="{element_id}"'.encode() start = body.index(marker) end = body.index(b"", start) return body[start:end] class AccountAwarenessTests(unittest.TestCase): setUp = test_portal_navigation.PortalNavigationTests.setUp get = test_portal_navigation.PortalNavigationTests.get def test_signed_out_home_states_only_the_portal_session(self): _, body = invoke(self.app, "/", query="username=forged&tenant=tenant:evil:one") self.assertIn(b"NetKingdom Identity", body) self.assertIn(b"Identity", body) self.assertIn(b"You are not signed in.", body) self.assertIn(b"It is not another sign-in.", body) self.assertNotIn(b"Active now", body) self.assertNotIn(b"Allowed tenants", body) self.assertNotIn(b"forged", body) self.assertNotIn(b"tenant:evil:one", body) def test_token_tenant_without_membership_is_active_and_not_allowed(self): session = self.app.service.me(self.oidc.claims("member"), correlation_id="synthetic") self.assertIsNotNone( self.app.service.store.tenant_account("tenant:trial:demo-company", session.user.user_id) ) _, body = self.get("/onboarding", who="member") active = _section(body, "active-tenant-list") allowed = _section(body, "allowed-tenant-list") self.assertIn(b"tenant:trial:demo-company - Active", active) self.assertNotIn(b"tenant:two", active) self.assertIn(b"No tenant memberships are recorded.", allowed) self.assertNotIn(b"tenant:trial:demo-company", allowed) self.assertIn(b"No workload access is recorded.", body) self.assertIn(b"Workload decisions are not checked.", body) self.assertNotIn(b"Viewing", body) self.assertIn(b"An ordinary sign-in uses one tenant.", body) self.assertIn(b"This session is for the account site.", body) self.assertIn(b"Signed in as", body) def test_allowed_tenant_that_is_not_active_uses_sign_in(self): session = self.app.service.me(self.oidc.claims("member"), correlation_id="synthetic") self.app.service.store.save_membership(Membership( membership_id="mem-other", user_id=session.user.user_id, tenant="tenant:other:company", scope_type="tenant", scope_id="tenant:other:company", kind="user", )) _, body = self.get("/onboarding", who="member") allowed = _section(body, "allowed-tenant-list") active = _section(body, "active-tenant-list") self.assertIn(b"tenant:other:company - user - Inactive.", allowed) self.assertIn(b'href="/login?tenant_hint=tenant%3Aother%3Acompany"', allowed) self.assertNotIn(b"