generated from bisco/codex-bootstrap
fix(api): add basic booking throttling
This commit is contained in:
@@ -1,4 +1,5 @@
|
||||
from datetime import timedelta
|
||||
from unittest.mock import patch
|
||||
|
||||
from django.core import mail
|
||||
from django.urls import reverse
|
||||
@@ -9,6 +10,7 @@ from rest_framework.test import APITestCase
|
||||
|
||||
from bookings.models import Reservation
|
||||
from bookings.services import generate_confirmation_token
|
||||
from bookings.views import ReservationConfirmThrottle, ReservationCreateThrottle
|
||||
from shows.models import Performance, Show, Venue
|
||||
|
||||
|
||||
@@ -104,6 +106,32 @@ class BookingApiTests(APITestCase):
|
||||
self.assertEqual(len(callbacks), 1)
|
||||
self.assertEqual(len(mail.outbox), 0)
|
||||
|
||||
def test_reservation_creation_is_throttled(self):
|
||||
with patch.dict(ReservationCreateThrottle.THROTTLE_RATES, {"reservation_create": "1/minute"}, clear=False):
|
||||
with self.captureOnCommitCallbacks(execute=True):
|
||||
first_response = self.client.post(
|
||||
reverse("api-reservation-create", kwargs={"performance_id": self.performance.id}),
|
||||
{
|
||||
"name": "Maria Rossi",
|
||||
"email": "maria@example.com",
|
||||
"party_size": 1,
|
||||
},
|
||||
format="json",
|
||||
)
|
||||
|
||||
second_response = self.client.post(
|
||||
reverse("api-reservation-create", kwargs={"performance_id": self.performance.id}),
|
||||
{
|
||||
"name": "Maria Rossi",
|
||||
"email": "maria@example.com",
|
||||
"party_size": 1,
|
||||
},
|
||||
format="json",
|
||||
)
|
||||
|
||||
self.assertEqual(first_response.status_code, status.HTTP_201_CREATED)
|
||||
self.assertEqual(second_response.status_code, status.HTTP_429_TOO_MANY_REQUESTS)
|
||||
|
||||
def test_reservation_creation_with_insufficient_seats(self):
|
||||
response = self.client.post(
|
||||
reverse("api-reservation-create", kwargs={"performance_id": self.performance.id}),
|
||||
@@ -188,6 +216,27 @@ class BookingApiTests(APITestCase):
|
||||
self.assertEqual(second_response.status_code, status.HTTP_409_CONFLICT)
|
||||
self.assertEqual(second_response.data["status"], "already_confirmed")
|
||||
|
||||
def test_confirmation_is_throttled(self):
|
||||
with patch.dict(ReservationConfirmThrottle.THROTTLE_RATES, {"reservation_confirm": "1/minute"}, clear=False):
|
||||
first_reservation = self.create_reservation(email="first@example.com")
|
||||
_, first_raw_token = generate_confirmation_token(first_reservation)
|
||||
second_reservation = self.create_reservation(email="second@example.com")
|
||||
_, second_raw_token = generate_confirmation_token(second_reservation)
|
||||
|
||||
first_response = self.client.post(
|
||||
reverse("api-reservation-confirm"),
|
||||
{"token": first_raw_token},
|
||||
format="json",
|
||||
)
|
||||
second_response = self.client.post(
|
||||
reverse("api-reservation-confirm"),
|
||||
{"token": second_raw_token},
|
||||
format="json",
|
||||
)
|
||||
|
||||
self.assertEqual(first_response.status_code, status.HTTP_200_OK)
|
||||
self.assertEqual(second_response.status_code, status.HTTP_429_TOO_MANY_REQUESTS)
|
||||
|
||||
@override_settings(SITE_BASE_URL="https://tickets.azionelab.example")
|
||||
def test_qr_retrieval_success_for_confirmed_reservation(self):
|
||||
reservation = self.create_reservation()
|
||||
|
||||
Reference in New Issue
Block a user