-
Notifications
You must be signed in to change notification settings - Fork 100
add a new method to remove an entry #3
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -144,6 +144,53 @@ def test_show_entries(self): | |
| # the database state is not guaranteed. In a real-world scenario, | ||
| # you might want to set up a known database state before running this test. | ||
|
|
||
| def test_delete_entry_unauthorized(self): | ||
| """ | ||
| Test that an unauthorized user cannot delete an entry. | ||
| """ | ||
| with app.test_client() as client: | ||
| # Try to delete an entry without being logged in | ||
| response = client.post('/delete/1', follow_redirects=True) | ||
|
|
||
| # Should get a 401 Unauthorized response | ||
| assert response.status_code == 401 | ||
|
|
||
| def test_delete_entry_authorized(self): | ||
|
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Description: The test_delete_entry_authorized function is quite long and performs multiple operations. Consider breaking down the function into smaller, more focused test functions or using setup and teardown methods. Severity: Low
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Sorry, I'm not able to suggest a fix for this review finding. Request ID : 1d7a21f3-17b7-40fa-8f5c-94f691fe9b33 |
||
| """ | ||
| Test that an authorized user can delete an entry. | ||
| """ | ||
| with app.test_client() as client: | ||
| # First login | ||
| client.post('/login', data={ | ||
| 'username': app.config['USERNAME'], | ||
| 'password': app.config['PASSWORD'] | ||
| }) | ||
|
|
||
| # Add an entry to delete | ||
| client.post('/add', data={ | ||
| 'title': 'Test Entry to Delete', | ||
| 'text': 'This entry will be deleted' | ||
| }) | ||
|
|
||
| # Get the entries to find the ID of the one we just added | ||
| with app.app_context(): | ||
| db = get_db() | ||
| entry = db.execute('SELECT id FROM entries WHERE title = ?', | ||
| ['Test Entry to Delete']).fetchone() | ||
|
|
||
| if entry: | ||
| # Delete the entry | ||
| response = client.post(f'/delete/{entry["id"]}', follow_redirects=True) | ||
|
|
||
| # Check if deletion was successful | ||
| assert response.status_code == 200 | ||
| assert b'Entry was successfully deleted' in response.data | ||
|
|
||
| # Verify the entry is no longer in the database | ||
| check = db.execute('SELECT * FROM entries WHERE id = ?', | ||
| [entry["id"]]).fetchone() | ||
| assert check is None | ||
|
|
||
|
|
||
|
|
||
| class AuthActions(object): | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Warning
Description: The show_entries() function doesn't handle potential database errors, which could lead to unhandled exceptions. Wrap the database operations in a try-except block to catch and handle potential SQLite errors.
Severity: High
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The fix addresses the comment by wrapping the database operations in the show_entries() function within a try-except block. This modification handles potential SQLite errors, preventing unhandled exceptions. If a database error occurs, it logs the error and returns an error page or message, improving the application's robustness and user experience.