🐛 fix(users.py): assign the hashed new password to a variable before updating the user's password to ensure consistency

✅ test(test_user.py): add test to verify if the new password works after resetting it
This commit is contained in:
Gabriel Luiz Freitas Almeida 2023-09-08 14:28:32 -03:00
commit 01a289dd9a
2 changed files with 6 additions and 2 deletions

View file

@ -121,8 +121,8 @@ def reset_password(
if not user:
raise HTTPException(status_code=404, detail="User not found")
user.password = get_password_hash(user_update.password)
new_password = get_password_hash(user_update.password)
user.password = new_password
session.commit()
session.refresh(user)

View file

@ -185,6 +185,10 @@ def test_patch_reset_password(client, active_user, logged_in_headers):
headers=logged_in_headers,
)
assert response.status_code == 200, response.json()
# Now we need to test if the new password works
login_data = {"username": active_user.username, "password": "newpassword"}
response = client.post("/api/v1/login", data=login_data)
assert response.status_code == 200
def test_patch_user_wrong_id(client, active_user, logged_in_headers):