Onboarding guidé systématique + tableau de bord simplifié
Comportement SYSTÉMATIQUE à chaque création de jeu (admin compris), pas une formalité réservée à l'inscription : /onboarding (routes/onboarding/) devient le point d'entrée unique — 4 cartes retournables (survol = explication au dos), défilement horizontal animé vers le nom du jeu. Un admin y repasse à volonté (pas de project_slug dédié, jamais bloqué/ redirigé vers un projet précédent) ; un compte "user" n'en a plus qu'un créé d'office (routes/auth/register_2fa.py), guidé ici à la place. - db/games/game_type_catalog.py : catalogue des 4 types (Quiz/ Embranchement-escape game/RPG/Créer mon jeu de A à Z), _meta['onboarding_type'] décide du "kind" du premier écran créé et si le tableau de bord complet reste accessible. - routes/games/game_dashboard.py, templates/game_dashboard_simple.html : un type restreint (quiz/embranchement/rpg) voit désormais SON tableau de bord (même route que "custom"), rendu en version simplifiée — juste ses écrans en cartes avec un aperçu RÉEL du contenu (scène mise à l'échelle par container query CSS, adaptée à la largeur réelle de la carte). "+ Ajouter un écran" n'y propose pas de choix de type : imposé par le projet (routes/screens/screens_new.py), verrouillé aussi côté serveur. - core/auth_guard.py : plus de blocage de game_dashboard par type — la restriction se fait au rendu, pas à l'accès à la route. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
0f23024882
commit
76a50fa87a
+45
-9
@@ -34,19 +34,41 @@ def _register(client, email, prenom="Alice", nom="Test", password="Sup3r$ecret!"
|
||||
def _confirm_2fa(client):
|
||||
"""Récupère la clé TOTP affichée sur la page de confirmation et
|
||||
soumet le code du moment — comme un humain qui vient de scanner le
|
||||
QR code avec son application."""
|
||||
QR code avec son application. Un compte "user" n'a plus de projet
|
||||
créé d'office ici (voir routes/onboarding/onboarding_new.py) — la
|
||||
redirection renvoie désormais vers /onboarding, pas /game/<slug> ;
|
||||
voir _complete_onboarding ci-dessous pour les tests qui ont besoin
|
||||
d'un vrai projet ensuite."""
|
||||
html = client.get("/register/2fa").get_data(as_text=True)
|
||||
secret = re.search(r"<code>([A-Z0-9]+)</code>", html).group(1)
|
||||
code = pyotp.TOTP(secret).now()
|
||||
return client.post("/register/2fa", data={"code": code}, follow_redirects=False), secret
|
||||
|
||||
|
||||
def _complete_onboarding(client, name="Mon jeu", onboarding_type="custom"):
|
||||
"""Termine l'onboarding guidé (voir routes/onboarding/onboarding_new.py)
|
||||
— la plupart des tests de ce fichier n'ont pas besoin de tester
|
||||
l'onboarding lui-même (voir test_onboarding.py), juste d'obtenir un
|
||||
project_slug réel pour la suite ; "custom" est le choix le plus proche
|
||||
du comportement historique (tableau de bord complet)."""
|
||||
return client.post(
|
||||
"/onboarding", data={"onboarding_type": onboarding_type, "name": name}, follow_redirects=False
|
||||
)
|
||||
|
||||
|
||||
def _cleanup_project(email):
|
||||
game_dir = db.game_dir(db.slugify(email))
|
||||
import os
|
||||
import shutil
|
||||
if os.path.isdir(game_dir):
|
||||
shutil.rmtree(game_dir)
|
||||
user = auth.get_user_by_email(email)
|
||||
if user and user.get("project_slug"):
|
||||
if os.path.isdir(db.game_dir(user["project_slug"])):
|
||||
# db.delete_game (voir db/games/project_slug.py — structure de
|
||||
# dossiers par utilisateur) nettoie aussi le dossier
|
||||
# propriétaire s'il devient vide, contrairement à un simple
|
||||
# shutil.rmtree(game_dir) — sans ça, des dossiers propriétaires
|
||||
# vides s'accumulent sous projects/ d'un run de tests à l'autre
|
||||
# (déjà observé : ça a fini par provoquer une collision de nom
|
||||
# dans db.move_game, un dossier vide comptant comme "occupé").
|
||||
db.delete_game(user["project_slug"])
|
||||
|
||||
|
||||
def test_anonymous_request_redirects_to_login(anon_client):
|
||||
@@ -100,13 +122,23 @@ def test_full_registration_flow_requires_totp_before_account_is_usable(anon_clie
|
||||
user = auth.get_user_by_email("flow@example.com")
|
||||
assert user["totp_confirmed"] == 1
|
||||
assert user["role"] == "user" # jamais le premier compte de la session de tests
|
||||
assert user["project_slug"] == db.slugify("flow@example.com")
|
||||
# Onboarding guidé (voir routes/onboarding/onboarding_new.py) : plus
|
||||
# de projet créé d'office ici — connecté mais sans project_slug tant
|
||||
# qu'il n'a pas choisi un type de jeu.
|
||||
assert user["project_slug"] is None
|
||||
try:
|
||||
assert resp.headers["Location"] == "/game/" + user["project_slug"]
|
||||
# Connecté pour de vrai maintenant.
|
||||
assert resp.headers["Location"] == "/onboarding"
|
||||
# Connecté pour de vrai maintenant, mais renvoyé vers l'onboarding
|
||||
# tant qu'aucun projet n'existe (voir core/auth_guard.py).
|
||||
resp2 = anon_client.get("/", follow_redirects=False)
|
||||
assert resp2.status_code == 302
|
||||
assert resp2.headers["Location"] == "/game/" + user["project_slug"]
|
||||
assert resp2.headers["Location"] == "/onboarding"
|
||||
|
||||
onboard_resp = _complete_onboarding(anon_client)
|
||||
assert onboard_resp.status_code == 302
|
||||
user = auth.get_user_by_email("flow@example.com")
|
||||
assert user["project_slug"] is not None
|
||||
assert onboard_resp.headers["Location"] == "/game/" + user["project_slug"]
|
||||
finally:
|
||||
_cleanup_project("flow@example.com")
|
||||
|
||||
@@ -123,6 +155,7 @@ def test_wrong_totp_code_is_rejected(anon_client):
|
||||
def test_login_requires_correct_password_then_totp(anon_client):
|
||||
_register(anon_client, "login@example.com")
|
||||
resp, secret = _confirm_2fa(anon_client)
|
||||
_complete_onboarding(anon_client)
|
||||
slug = auth.get_user_by_email("login@example.com")["project_slug"]
|
||||
try:
|
||||
anon_client.post("/logout")
|
||||
@@ -146,6 +179,7 @@ def test_login_requires_correct_password_then_totp(anon_client):
|
||||
def test_non_admin_user_is_isolated_to_their_own_project(anon_client):
|
||||
_register(anon_client, "isolated@example.com")
|
||||
_confirm_2fa(anon_client)
|
||||
_complete_onboarding(anon_client)
|
||||
user = auth.get_user_by_email("isolated@example.com")
|
||||
try:
|
||||
# Un autre projet (celui de l'admin partagé par conftest.py, ou
|
||||
@@ -173,6 +207,7 @@ def test_non_admin_user_cannot_delete_their_only_project(anon_client):
|
||||
retour — bloqué plutôt que risqué."""
|
||||
_register(anon_client, "nodelete@example.com")
|
||||
_confirm_2fa(anon_client)
|
||||
_complete_onboarding(anon_client)
|
||||
user = auth.get_user_by_email("nodelete@example.com")
|
||||
try:
|
||||
resp = anon_client.post(f"/game/{user['project_slug']}/delete")
|
||||
@@ -281,6 +316,7 @@ def test_recovery_codes_are_shown_once_after_confirming_2fa(anon_client):
|
||||
def test_login_with_a_recovery_code_instead_of_totp(anon_client):
|
||||
_register(anon_client, "recoverylogin@example.com")
|
||||
_confirm_2fa(anon_client)
|
||||
_complete_onboarding(anon_client)
|
||||
user = auth.get_user_by_email("recoverylogin@example.com")
|
||||
slug = user["project_slug"]
|
||||
codes = auth.generate_recovery_codes(user["id"])
|
||||
|
||||
@@ -0,0 +1,171 @@
|
||||
"""Onboarding guidé (routes/onboarding/onboarding_new.py) : un compte
|
||||
"user" fraîchement inscrit choisit un type de jeu (Quiz/Embranchement/
|
||||
RPG/Créer mon jeu de A à Z) avant d'avoir accès à quoi que ce soit — voir
|
||||
le plan "Fusion des deux moteurs + structure de dossiers + onboarding
|
||||
guidé". Réutilise les fixtures de test_auth.py (inscription/2FA)."""
|
||||
import os
|
||||
|
||||
import auth
|
||||
import db
|
||||
import screens
|
||||
|
||||
from tests.test_auth import _register, _confirm_2fa, _complete_onboarding, _cleanup_project, anon_client # noqa: F401
|
||||
|
||||
|
||||
def test_account_without_a_project_is_redirected_to_onboarding(anon_client):
|
||||
_register(anon_client, "needsonboarding@example.com")
|
||||
_confirm_2fa(anon_client)
|
||||
try:
|
||||
resp = anon_client.get("/", follow_redirects=False)
|
||||
assert resp.status_code == 302
|
||||
assert resp.headers["Location"] == "/onboarding"
|
||||
|
||||
resp = anon_client.get("/onboarding")
|
||||
assert resp.status_code == 200
|
||||
assert "Quiz" in resp.get_data(as_text=True)
|
||||
finally:
|
||||
_cleanup_project("needsonboarding@example.com")
|
||||
|
||||
|
||||
def test_quiz_lands_on_simplified_dashboard_with_one_document_screen(anon_client):
|
||||
"""Le dashboard simplifié (routes/games/game_dashboard.py) — un compte
|
||||
restreint (quiz/embranchement/rpg) atterrit maintenant sur SON
|
||||
tableau de bord (même route que "custom"), juste rendu en version
|
||||
simplifiée : que des écrans en cartes, pas d'onglets Objets/Éléments
|
||||
de jeu/Variables (réservés à "Créer mon jeu de A à Z")."""
|
||||
_register(anon_client, "quizuser@example.com")
|
||||
_confirm_2fa(anon_client)
|
||||
try:
|
||||
resp = _complete_onboarding(anon_client, name="Mon Quiz", onboarding_type="quiz")
|
||||
assert resp.status_code == 302
|
||||
user = auth.get_user_by_email("quizuser@example.com")
|
||||
slug = user["project_slug"]
|
||||
assert resp.headers["Location"] == f"/game/{slug}"
|
||||
assert db.get_onboarding_type(slug) == "quiz"
|
||||
|
||||
screen_list = screens.list_screens(slug)
|
||||
assert len(screen_list) == 1
|
||||
assert screen_list[0]["kind"] == "document"
|
||||
|
||||
html = anon_client.get(f"/game/{slug}").get_data(as_text=True)
|
||||
assert "screenCardGrid" in html
|
||||
assert "+ Ajouter un écran" in html
|
||||
assert 'name="kind"' not in html # pas de choix de type à l'ajout
|
||||
assert "openNewObjectPanel" not in html # onglet Objets du dashboard complet absent
|
||||
|
||||
# L'éditeur de l'écran, lui, reste atteignable comme avant.
|
||||
edit_html = anon_client.get(f"/game/{slug}/screens/{screen_list[0]['id']}/edit").get_data(as_text=True)
|
||||
assert "scene-editor.js" not in edit_html
|
||||
finally:
|
||||
_cleanup_project("quizuser@example.com")
|
||||
|
||||
|
||||
def test_rpg_dashboard_shows_scene_preview_and_forces_jeu2d_on_new_screens(anon_client):
|
||||
_register(anon_client, "rpguser@example.com")
|
||||
_confirm_2fa(anon_client)
|
||||
try:
|
||||
resp = _complete_onboarding(anon_client, name="Mon RPG", onboarding_type="rpg")
|
||||
slug = auth.get_user_by_email("rpguser@example.com")["project_slug"]
|
||||
assert resp.headers["Location"] == f"/game/{slug}"
|
||||
screen_list = screens.list_screens(slug)
|
||||
assert screen_list[0]["kind"] == "jeu_2d"
|
||||
|
||||
html = anon_client.get(f"/game/{slug}").get_data(as_text=True)
|
||||
assert "screenPreviewScene" in html
|
||||
assert 'name="kind"' not in html
|
||||
|
||||
# "+ Ajouter un écran" ne propose pas de choix de type — imposé
|
||||
# jeu_2d par le projet, même en tentant de forcer "document" via
|
||||
# un POST direct (défense en profondeur, pas seulement l'UI).
|
||||
anon_client.post(f"/game/{slug}/screens/new", data={"name": "Scène 2", "kind": "document"}, follow_redirects=False)
|
||||
new_screen_list = screens.list_screens(slug)
|
||||
assert len(new_screen_list) == 2
|
||||
assert new_screen_list[1]["kind"] == "jeu_2d"
|
||||
|
||||
edit_html = anon_client.get(f"/game/{slug}/screens/{screen_list[0]['id']}/edit").get_data(as_text=True)
|
||||
assert "scene-editor.js" in edit_html
|
||||
finally:
|
||||
_cleanup_project("rpguser@example.com")
|
||||
|
||||
|
||||
def test_custom_keeps_todays_full_dashboard_behavior(anon_client):
|
||||
_register(anon_client, "customuser@example.com")
|
||||
_confirm_2fa(anon_client)
|
||||
try:
|
||||
resp = _complete_onboarding(anon_client, name="Mon jeu complet", onboarding_type="custom")
|
||||
assert resp.status_code == 302
|
||||
|
||||
slug = auth.get_user_by_email("customuser@example.com")["project_slug"]
|
||||
assert resp.headers["Location"] == f"/game/{slug}"
|
||||
|
||||
html = anon_client.get(f"/game/{slug}").get_data(as_text=True)
|
||||
assert "Tableau de bord" in html or "gameNavLink" in html
|
||||
finally:
|
||||
_cleanup_project("customuser@example.com")
|
||||
|
||||
|
||||
def test_onboarding_rejects_unknown_type(anon_client):
|
||||
_register(anon_client, "badtype@example.com")
|
||||
_confirm_2fa(anon_client)
|
||||
try:
|
||||
resp = anon_client.post("/onboarding", data={"onboarding_type": "n_importe_quoi", "name": "Test"})
|
||||
assert resp.status_code == 200
|
||||
assert auth.get_user_by_email("badtype@example.com")["project_slug"] is None
|
||||
finally:
|
||||
_cleanup_project("badtype@example.com")
|
||||
|
||||
|
||||
def test_revisiting_onboarding_after_completion_redirects_without_recreating(anon_client):
|
||||
_register(anon_client, "revisit@example.com")
|
||||
_confirm_2fa(anon_client)
|
||||
try:
|
||||
first = _complete_onboarding(anon_client, name="Premier jeu", onboarding_type="custom")
|
||||
first_slug = auth.get_user_by_email("revisit@example.com")["project_slug"]
|
||||
|
||||
resp = anon_client.get("/onboarding", follow_redirects=False)
|
||||
assert resp.status_code == 302
|
||||
assert resp.headers["Location"] == first.headers["Location"]
|
||||
|
||||
again = anon_client.post("/onboarding", data={"onboarding_type": "quiz", "name": "Second jeu"}, follow_redirects=False)
|
||||
assert auth.get_user_by_email("revisit@example.com")["project_slug"] == first_slug
|
||||
assert again.headers["Location"] == first.headers["Location"]
|
||||
finally:
|
||||
_cleanup_project("revisit@example.com")
|
||||
|
||||
|
||||
def test_admin_is_never_redirected_to_onboarding(client, game):
|
||||
resp = client.get("/", follow_redirects=False)
|
||||
assert resp.status_code == 200
|
||||
|
||||
|
||||
def test_admin_can_create_several_games_of_different_types_via_onboarding(client):
|
||||
"""Comportement systématique à CHAQUE création de jeu, pas une
|
||||
formalité réservée à la toute première inscription (voir le plan) —
|
||||
un admin, illimité (pas de project_slug dédié), doit pouvoir repasser
|
||||
par /onboarding autant de fois qu'il crée un nouveau jeu, sans jamais
|
||||
être bloqué/redirigé vers un projet précédent."""
|
||||
resp1 = _complete_onboarding(client, name="Jeu Quiz Admin", onboarding_type="quiz")
|
||||
assert resp1.status_code == 302
|
||||
slug1 = resp1.headers["Location"].split("/game/", 1)[1].split("/", 1)[0]
|
||||
slug2 = None
|
||||
try:
|
||||
# project_slug reste NON posé sur le compte admin (voir
|
||||
# auth/create_user.py — colonne réservée à un compte "user" à
|
||||
# projet unique) : repasser sur /onboarding ne redirige PAS vers
|
||||
# le premier projet créé, la page de choix s'affiche à nouveau.
|
||||
resp = client.get("/onboarding")
|
||||
assert resp.status_code == 200
|
||||
assert "Quiz" in resp.get_data(as_text=True)
|
||||
|
||||
resp2 = _complete_onboarding(client, name="Jeu RPG Admin", onboarding_type="rpg")
|
||||
assert resp2.status_code == 302
|
||||
slug2 = resp2.headers["Location"].split("/game/", 1)[1].split("/", 1)[0]
|
||||
assert slug2 != slug1
|
||||
|
||||
slugs = {g["slug"] for g in db.list_games()}
|
||||
assert slug1 in slugs
|
||||
assert slug2 in slugs
|
||||
finally:
|
||||
for slug in (slug1, slug2):
|
||||
if slug and os.path.isdir(db.game_dir(slug)):
|
||||
db.delete_game(slug)
|
||||
@@ -5,8 +5,9 @@ import pyotp
|
||||
|
||||
import auth
|
||||
import db
|
||||
from db.games.project_slug import build_slug, split_slug
|
||||
|
||||
from tests.test_auth import _register, _confirm_2fa, _cleanup_project, anon_client # noqa: F401
|
||||
from tests.test_auth import _register, _confirm_2fa, _complete_onboarding, _cleanup_project, anon_client # noqa: F401
|
||||
|
||||
|
||||
def test_profile_page_shows_current_user_info(anon_client):
|
||||
@@ -122,6 +123,7 @@ def test_delete_account_requires_the_confirmation_phrase(anon_client):
|
||||
def test_delete_account_removes_user_and_their_project(anon_client):
|
||||
_register(anon_client, "deleteforreal@example.com")
|
||||
_confirm_2fa(anon_client)
|
||||
_complete_onboarding(anon_client)
|
||||
user = auth.get_user_by_email("deleteforreal@example.com")
|
||||
slug = user["project_slug"]
|
||||
import os
|
||||
@@ -218,6 +220,7 @@ def test_update_email_renames_the_user_project_folder(anon_client):
|
||||
|
||||
_register(anon_client, "oldmail@example.com")
|
||||
_confirm_2fa(anon_client)
|
||||
_complete_onboarding(anon_client)
|
||||
old_user = auth.get_user_by_email("oldmail@example.com")
|
||||
old_slug = old_user["project_slug"]
|
||||
assert os.path.isdir(db.game_dir(old_slug))
|
||||
@@ -229,7 +232,10 @@ def test_update_email_renames_the_user_project_folder(anon_client):
|
||||
new_user = auth.get_user_by_email("newmail@example.com")
|
||||
assert new_user is not None
|
||||
new_slug = new_user["project_slug"]
|
||||
assert new_slug == db.slugify("newmail@example.com")
|
||||
# Structure de dossiers par utilisateur (voir db/games/
|
||||
# project_slug.py) : seul le dossier PROPRIÉTAIRE change de nom,
|
||||
# le dossier projet (project_part) reste le même.
|
||||
assert new_slug == build_slug(db.slugify("newmail@example.com"), split_slug(old_slug)[1])
|
||||
assert not os.path.isdir(db.game_dir(old_slug))
|
||||
assert os.path.isdir(db.game_dir(new_slug))
|
||||
|
||||
|
||||
@@ -80,10 +80,11 @@ def test_publish_route_is_isolated_like_other_game_routes(fake_vendor, anon_clie
|
||||
code supplémentaire — un compte non-admin ne doit pas pouvoir publier
|
||||
le projet d'un autre (même vérification que /game/<slug> lui-même,
|
||||
voir tests/test_auth.py::test_non_admin_user_is_isolated_to_their_own_project)."""
|
||||
from tests.test_auth import _register, _confirm_2fa, _cleanup_project
|
||||
from tests.test_auth import _register, _confirm_2fa, _complete_onboarding, _cleanup_project
|
||||
|
||||
_register(anon_client, "publishisolation@example.com")
|
||||
_confirm_2fa(anon_client)
|
||||
_complete_onboarding(anon_client)
|
||||
try:
|
||||
resp = anon_client.post("/game/un-projet-qui-nest-pas-le-sien/publish")
|
||||
assert resp.status_code == 403
|
||||
|
||||
Reference in New Issue
Block a user