Details
-
Task
-
Resolution: Unresolved
-
Major
-
None
-
11.10.13
-
Unknown
-
Description
The manual test is here: Authentication security module disable account
Existing automated coverage
- DisableAccountFailureStrategyTest#resetAuthenticationFailureCounterWhenAccountIsActivated: unit only: the failure counter is reset when the account is re-activated
- DefaultAuthenticationFailureManagerTest#authenticationFailureLimitReached: unit only: strategies are notified when the max attempts are reached
- UserProfileIT#toggleEnableDisable: admin disables then enables an account from the user profile page (not linked to the failure strategy)
Missing automated coverage
- As admin, in Administer Wiki > Users & Rights > Authentication select Failure Strategy "Disable account", set Maximum number of authorized attempts to 4 and Save
- Create user U1, log out, fail to log in as U1 4 times
- Assert the error "This account has been disabled. Please ask the administrator to enable it back." is shown and the correct password is refused
- As admin, enable U1 from its profile page (ProfileUserProfilePage#clickEnable)
- Log out and assert U1 can log in with the correct password
Suggested location: xwiki-platform-core/xwiki-platform-flamingo/xwiki-platform-flamingo-skin/xwiki-platform-flamingo-skin-test/xwiki-platform-flamingo-skin-test-docker/src/test/it/org/xwiki/flamingo/test/docker/LoginProtectionIT.java
Found by comparing the XWiki 18.4.4 manual test runs against the automated tests on master (a0055f10a1a).