1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
|
"""
A group name is checked where it is created.
The column is 128 characters wide: a longer name was a database error on
PostgreSQL and a silent truncation on SQLite. And the name is shown to other
people — in their group list, in the invitation mail — so it carries no line
breaks or other control characters, and no bidirectional override that makes it
display as something other than what it is.
"""
import pytest
from test_bundle_pepper import _login, _register
@pytest.mark.asyncio
@pytest.mark.parametrize("name,ok", [
("Photos de famille", True),
("x" * 128, True),
("👨👩👧 Family", True), # a ZWJ sequence is a name, not a trick
("x" * 129, False),
("Films\nClick here", False),
("tab\there", False),
("evilgpj.exe", False),
(" ", False),
])
async def test_a_group_name(client, name, ok):
await _register(client, "group_namer")
token = (await _login(client, "group_namer"))["access_token"]
r = await client.post("/v1/groups", json={"name": name},
headers={"Authorization": f"Bearer {token}"})
assert (r.status_code < 300) is ok, (name, r.status_code, r.text)
if not ok:
assert r.status_code == 422
|