fix: auto_login=off error on login and editing a user + FE tests (#3471)

* 🐛 (users.py): Fix issue where user password was not being updated correctly
📝 (constants.ts, authContext.tsx, index.tsx): Add LANGFLOW_REFRESH_TOKEN constant and update related code to support refresh token functionality
📝 (userManagementModal/index.tsx): Update form reset logic and handle input values correctly
📝 (LoginPage/index.tsx, LoginAdminPage/index.tsx): Update login function to include refresh token parameter
📝 (components/index.ts, auth.ts): Update inputHandlerEventType to support boolean values

✨ (auto-login-off.spec.ts): Add end-to-end test for user login functionality with auto_login set to false, CRUD operations for users, and verification of user flows visibility based on permissions.

* ✨ (auto-login-off.spec.ts): improve test description for better clarity and understanding
📝 (auto-login-off.spec.ts): add comments to clarify the purpose of intercepting requests and performing CRUD operations

* 🐛 (users.py): fix comparison of password to check for None using 'is not None' instead of '!= None' for better accuracy
This commit is contained in:
Cristhian Zanforlin Lousa 2024-08-21 12:55:47 -03:00 • committed by GitHub
commit 8dd85d98b6
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
11 changed files with 296 additions and 21 deletions

View file

@ -90,17 +90,21 @@ def patch_user(
Update an existing user's data.
"""
update_password = user_update.password is not None and user_update.password != ""
if not user.is_superuser and user_update.is_superuser:
raise HTTPException(status_code=403, detail="Permission denied")
if not user.is_superuser and user.id != user_id:
raise HTTPException(status_code=403, detail="Permission denied")
if user_update.password:
if update_password:
if not user.is_superuser:
raise HTTPException(status_code=400, detail="You can't change your password here")
user_update.password = get_password_hash(user_update.password)
if user_db := get_user_by_id(session, user_id):
if not update_password:
user_update.password = user_db.password
return update_user(user_db, user_update, session)
else:
raise HTTPException(status_code=404, detail="User not found")