Requests: Various fixes and improvements (#617)

- Refactored activity backend for full user-level management, using the
db file
- Revamped the activity sidebar UX and categorisation
- Added download history and user filtering
- Added User Preferences modal, giving limited configuration for
non-admins - replaces the "restrict settings" config option.
- Many many bug fixes
- Many many new tests
This commit is contained in:
Alex
2026-02-14 18:24:28 +00:00
committed by GitHub
parent 68608b6162
commit b7bee132a1
42 changed files with 5118 additions and 467 deletions
+5 -3
View File
@@ -191,7 +191,7 @@ class TestLoginRequiredDecorator:
assert resp[0]["success"] is True
def test_settings_access_not_restricted_when_global_toggle_off(self, main_module, view):
def test_settings_access_requires_admin_even_when_legacy_toggle_off(self, main_module, view):
with patch.object(main_module, "get_auth_mode", return_value="builtin"):
with patch(
"shelfmark.core.settings_registry.load_config_file",
@@ -201,9 +201,11 @@ class TestLoginRequiredDecorator:
main_module.session["user_id"] = "user"
main_module.session["is_admin"] = False
decorated = main_module.login_required(view)
resp = decorated()
resp = _as_response(decorated())
data = resp.get_json()
assert resp[0]["success"] is True
assert resp.status_code == 403
assert "Admin access required" in (data.get("error") or "")
def test_security_tab_always_blocks_non_admin_even_when_toggle_off(self, main_module, view):
with patch.object(main_module, "get_auth_mode", return_value="builtin"):