Add security secret "last_sign_in"

In order to comply with the security measure for the
ENS: "[op.acc.5.r5.2] The user shall be informed of
the last access made with his identity".

We have added a new secret to display the last
access made to the user on the "My account" page.
This commit is contained in:
taitus
2023-10-09 10:04:14 +02:00
parent 13e9b75d9a
commit 87fc3c572b
7 changed files with 56 additions and 3 deletions

View File

@@ -0,0 +1,26 @@
require "rails_helper"
describe Account::SignInInfoComponent do
let(:account) { create(:user, last_sign_in_at: Date.current, last_sign_in_ip: "1.2.3.4") }
context "Security secret for render last sign in is enabled" do
it "shows a sign in info" do
allow(Rails.application).to receive(:secrets).and_return(ActiveSupport::OrderedOptions.new.merge(
security: { last_sign_in: true }
))
render_inline Account::SignInInfoComponent.new(account)
expect(page).to have_content "Last login:"
expect(page).to have_content "from IP"
end
end
context "Security secret for render last sign in is disabled" do
it "does not show sign in info" do
render_inline Account::SignInInfoComponent.new(account)
expect(page).not_to be_rendered
end
end
end