/api/user/set-account-username (PATCH)
Account information like email addresses is generated with faker-js it is not real user information.
await global.api.user.SetAccountUsername.patch(req)Returns object
{
"accountid": "acct_44459632c25a2971",
"object": "account",
"appid": "tests_1656038582",
"profileid": "prof_4af629079046c56f",
"sessionKeyNumber": 1,
"lastSignedInAt": "2022-06-24T02:43:02.000Z",
"owner": true,
"ownerSince": "2022-06-24T02:43:02.000Z",
"administrator": true,
"administratorSince": "2022-06-24T02:43:02.000Z",
"usernameLastChangedAt": "2022-06-24T02:43:02.000Z",
"createdAt": "2022-06-24T02:43:02.326Z",
"updatedAt": "2022-06-24T02:43:02.360Z"
}
Exceptions
These exceptions are thrown (NodeJS) or returned as JSON (HTTP) if you provide incorrect data or do not meet the requirements:
Exception | Circumstances |
---|---|
invalid-account | ineligible accessing account |
invalid-accountid | missing querystring accountid |
invalid querystring accountid | |
invalid-new-username | missing posted new-username |
invalid-new-username-length | posted new-username too short |
posted new-username too long | |
invalid-password | missing posted password |
invalid posted password |
NodeJS source (view on github)
const dashboard = require('../../../../index.js')
module.exports = {
patch: async (req) => {
if (!req.query || !req.query.accountid) {
throw new Error('invalid-accountid')
}
let accountInfo
try {
accountInfo = await dashboard.Storage.Account.findOne({
where: {
accountid: req.query.accountid,
appid: req.appid || global.appid
}
})
} catch (error) {
}
if (!accountInfo) {
throw new Error('invalid-accountid')
}
if (accountInfo.dataValues.accountid !== req.account.accountid) {
throw new Error('invalid-account')
}
if (!req.body || !req.body['new-username']) {
throw new Error('invalid-new-username')
}
if (global.minimumUsernameLength > req.body['new-username'].length ||
global.maximumUsernameLength < req.body['new-username'].length) {
throw new Error('invalid-new-username-length')
}
if (!req.body.password || !req.body.password.length) {
throw new Error('invalid-password')
}
let dashboardEncryptionKey = global.dashboardEncryptionKey
if (req.server) {
dashboardEncryptionKey = req.server.dashboardEncryptionKey || dashboardEncryptionKey
}
const validPassword = await dashboard.Hash.bcryptHashCompare(req.body.password, accountInfo.dataValues.passwordHash, dashboardEncryptionKey)
if (!validPassword) {
throw new Error('invalid-password')
}
const usernameHash = await dashboard.Hash.sha512Hash(req.body['new-username'], dashboardEncryptionKey)
await dashboard.Storage.Account.update({
usernameHash,
usernameLastChangedAt: new Date()
}, {
where: {
accountid: req.query.accountid,
appid: req.appid || global.appid
}
})
await dashboard.StorageCache.remove(req.query.accountid)
return global.api.user.Account.get(req)
}
}
Test source (view on github)
/* eslint-env mocha */
const assert = require('assert')
const TestHelper = require('../../../../test-helper.js')
describe('/api/user/set-account-username', () => {
describe('exceptions', () => {
describe('invalid-accountid', () => {
it('missing querystring accountid', async () => {
const user = await TestHelper.createUser()
const req = TestHelper.createRequest('/api/user/set-account-username')
req.account = user.account
req.session = user.session
let errorMessage
try {
await req.patch()
} catch (error) {
errorMessage = error.message
}
assert.strictEqual(errorMessage, 'invalid-accountid')
})
it('invalid querystring accountid', async () => {
const user = await TestHelper.createUser()
const req = TestHelper.createRequest('/api/user/set-account-username?accountid=invalid')
req.account = user.account
req.session = user.session
let errorMessage
try {
await req.patch()
} catch (error) {
errorMessage = error.message
}
assert.strictEqual(errorMessage, 'invalid-accountid')
})
})
describe('invalid-account', () => {
it('ineligible accessing account', async () => {
const user = await TestHelper.createUser()
const user2 = await TestHelper.createUser()
const req = TestHelper.createRequest(`/api/user/set-account-username?accountid=${user2.account.accountid}`)
req.account = user.account
req.session = user.session
let errorMessage
try {
await req.patch()
} catch (error) {
errorMessage = error.message
}
assert.strictEqual(errorMessage, 'invalid-account')
})
})
describe('invalid-password', () => {
it('missing posted password', async () => {
const user = await TestHelper.createUser()
const req = TestHelper.createRequest(`/api/user/set-account-username?accountid=${user.account.accountid}`)
req.account = user.account
req.session = user.session
req.body = {
'new-username': '1234567890',
password: ''
}
let errorMessage
try {
await req.patch(req)
} catch (error) {
errorMessage = error.message
}
assert.strictEqual(errorMessage, 'invalid-password')
})
it('invalid posted password', async () => {
const user = await TestHelper.createUser()
const req = TestHelper.createRequest(`/api/user/set-account-username?accountid=${user.account.accountid}`)
req.account = user.account
req.session = user.session
req.body = {
'new-username': '1234567890',
password: 'invalid'
}
let errorMessage
try {
await req.patch(req)
} catch (error) {
errorMessage = error.message
}
assert.strictEqual(errorMessage, 'invalid-password')
})
})
describe('invalid-new-username', () => {
it('missing posted new-username', async () => {
const user = await TestHelper.createUser()
const req = TestHelper.createRequest(`/api/user/set-account-username?accountid=${user.account.accountid}`)
req.account = user.account
req.session = user.session
req.body = {
'new-username': '',
password: '1234567890'
}
let errorMessage
try {
await req.patch(req)
} catch (error) {
errorMessage = error.message
}
assert.strictEqual(errorMessage, 'invalid-new-username')
})
})
describe('invalid-new-username-length', () => {
it('posted new-username too short', async () => {
const user = await TestHelper.createUser()
const req = TestHelper.createRequest(`/api/user/set-account-username?accountid=${user.account.accountid}`)
req.account = user.account
req.session = user.session
req.body = {
'new-username': '1',
password: user.account.password
}
global.minimumUsernameLength = 100
let errorMessage
try {
await req.patch(req)
} catch (error) {
errorMessage = error.message
}
assert.strictEqual(errorMessage, 'invalid-new-username-length')
})
it('posted new-username too long', async () => {
const user = await TestHelper.createUser()
const req = TestHelper.createRequest(`/api/user/set-account-username?accountid=${user.account.accountid}`)
req.account = user.account
req.session = user.session
req.body = {
'new-username': '12345678',
password: user.account.password
}
global.maximumUsernameLength = 1
let errorMessage
try {
await req.patch(req)
} catch (error) {
errorMessage = error.message
}
assert.strictEqual(errorMessage, 'invalid-new-username-length')
})
})
})
describe('returns', () => {
it('object', async () => {
const user = await TestHelper.createUser()
const req = TestHelper.createRequest(`/api/user/set-account-username?accountid=${user.account.accountid}`)
req.account = user.account
req.session = user.session
req.body = {
'new-username': 'a1234567890',
password: user.account.password
}
req.filename = __filename
req.saveResponse = true
const account = await req.patch()
assert.strictEqual(account.object, 'account')
})
})
})