- billboard.views.search_buds(GET /billboard/buds/search?q=...) — top-3 prefix match against request.user.buds via Q(username__istartswith) | Q(email__istartswith). Returns {buds: [{id, username, email}]}. Privacy: only the user's own buds are searched, no leak of strangers.
- _resolve_recipient(raw) helper resolves a free-form recipient (email if "@" present, else username, both case-insensitive). Wired into add_bud + share_post so #id_recipient accepts either form.
- share_post implicit auto-add (per-spec): when recipient is registered + first-time-shared, both directions of buds M2M get the link — request.user.buds.add(recipient) AND recipient.buds.add(request.user). Idempotent, no auto-add on reshare/self/unregistered.
- new bud-autocomplete.js shared module (apps/billboard/static/apps/billboard/) — bindBudAutocomplete(input, suggestionsEl, {searchUrl}). Mirrors sky.html birth-place picker: 250ms debounced fetch from MIN_CHARS=1, click-to-fill, Escape closes, click-outside closes, late-response drop. e.stopPropagation on suggestion-click so the bud-panel's outside-click handler doesn't fire and clear the input.
- SCSS .bud-suggestions / .bud-suggestion-item mirrors .sky-suggestions but position:fixed bottom:4rem (aligned above the bud panel, with overflow:hidden on the panel forcing the dropdown to live as a sibling rather than a child). Landscape breakpoints clear the navbar/footer 4rem sidebars, 8rem at min-width 1800px.
- both _bud_panel.html (post share) + _bud_add_panel.html (my_buds add) get the suggestions div sibling + script tags. Each panel's existing document click-outside handler now skips the suggestions container so a click inside doesn't close+clear. type="email" → type="text" since usernames are accepted; placeholder "friend@example.com or username".
- new test classes in test_buds.py: SearchBudsViewTest (6 — prefix match, cap-3, email prefix, non-bud leakproof, empty-q, anon redirect) + SharePostImplicitAutoAddTest (4 — sharer.buds += recipient, recipient.buds += sharer, username-typed share, unregistered no-add) + AddBudViewTest.test_add_resolves_username_too. test_my_buds.py FT adds test_autocomplete_suggests_buds_by_username_prefix. test_sharing.py placeholder assertion updated to "friend@example.com or username".
- 852 ITs (+11) + 5 my_buds FTs green.
Code architected by Disco DeDisco <discodedisco@outlook.com>
Git commit message Co-Authored-By:
Claude Opus 4.7 (1M context) <noreply@anthropic.com>
77 lines
2.5 KiB
Python
77 lines
2.5 KiB
Python
import os
|
|
|
|
from django.conf import settings
|
|
from django.test import tag
|
|
from selenium import webdriver
|
|
from selenium.webdriver.common.by import By
|
|
|
|
from .base import FunctionalTest
|
|
from .post_page import PostPage
|
|
from .my_posts_page import MyPostsPage
|
|
|
|
|
|
# Helper fns
|
|
def quit_if_possible(browser):
|
|
try:
|
|
browser.quit()
|
|
except:
|
|
pass
|
|
|
|
|
|
# Test mdls
|
|
class SharingTest(FunctionalTest):
|
|
@tag("two-browser")
|
|
def test_can_share_a_post_with_another_user(self):
|
|
self.create_pre_authenticated_session("disco@test.io")
|
|
disco_browser = self.browser
|
|
self.addCleanup(lambda: quit_if_possible(disco_browser))
|
|
|
|
options = webdriver.FirefoxOptions()
|
|
if os.environ.get("HEADLESS"):
|
|
options.add_argument("--headless")
|
|
ali_browser = webdriver.Firefox(options=options)
|
|
self.addCleanup(lambda: quit_if_possible(ali_browser))
|
|
self.browser = ali_browser
|
|
self.create_pre_authenticated_session("alice@test.io")
|
|
|
|
self.browser = disco_browser
|
|
self.browser.get(self.live_server_url + '/billboard/')
|
|
post_page = PostPage(self).add_post_line("Send help")
|
|
|
|
share_box = post_page.get_share_box()
|
|
self.assertEqual(
|
|
share_box.get_attribute("placeholder"),
|
|
"friend@example.com or username",
|
|
)
|
|
|
|
post_page.share_post_with("alice@test.io")
|
|
|
|
self.browser = ali_browser
|
|
MyPostsPage(self).go_to_my_posts_page("alice@test.io")
|
|
|
|
self.browser.find_element(By.LINK_TEXT, "Send help").click()
|
|
|
|
self.wait_for(
|
|
lambda: self.assertEqual(post_page.get_post_owner(), "disco@test.io")
|
|
)
|
|
|
|
post_page.add_post_line("At your command, Disco King")
|
|
|
|
self.browser = disco_browser
|
|
self.browser.refresh()
|
|
# Line numbering: 1) "Send help" 2) "Shared with alice@test.io …"
|
|
# (auto-appended by share_post in C3.b) 3) Alice's reply.
|
|
post_page.wait_for_row_in_post_table("At your command, Disco King", 3)
|
|
|
|
class PostAccessTest(FunctionalTest):
|
|
def test_stranger_cannot_access_owned_post(self):
|
|
self.create_pre_authenticated_session("disco@test.io")
|
|
self.browser.get(self.live_server_url + '/billboard/')
|
|
PostPage(self).add_post_line("private eye")
|
|
post_url = self.browser.current_url
|
|
|
|
self.browser.delete_cookie(settings.SESSION_COOKIE_NAME)
|
|
self.browser.get(post_url)
|
|
|
|
self.assertNotEqual(self.browser.current_url, post_url)
|