diff --git a/changedetectionio/blueprint/ui/__init__.py b/changedetectionio/blueprint/ui/__init__.py index 6fc247fe0..e3a2b020c 100644 --- a/changedetectionio/blueprint/ui/__init__.py +++ b/changedetectionio/blueprint/ui/__init__.py @@ -1,7 +1,7 @@ import time import threading from blinker import signal -from flask import Blueprint, request, redirect, url_for, flash, render_template, session, current_app +from flask import Blueprint, request, redirect, url_for, flash, render_template, session, current_app, abort from flask_babel import gettext from loguru import logger @@ -406,10 +406,12 @@ def construct_blueprint(datastore: ChangeDetectionStore, update_q, worker_pool, return redirect(url_for('watchlist.index')) - @ui_blueprint.route("/share-url/", methods=['POST']) @login_optionally_required def form_share_put_watch(uuid): + if not datastore.data['settings']['application']['ui'].get('use_share_watch'): + abort(403, description="Access denied") + """Given a watch UUID, upload the info and return a share-link the share-link can be imported/added""" import requests diff --git a/changedetectionio/tests/test_share_watch.py b/changedetectionio/tests/test_share_watch.py index e308d5b93..a4a56fca6 100644 --- a/changedetectionio/tests/test_share_watch.py +++ b/changedetectionio/tests/test_share_watch.py @@ -9,8 +9,17 @@ import re def test_share_watch(client, live_server, measure_memory_usage, datastore_path): set_original_response(datastore_path=datastore_path) - # live_server_setup(live_server) # Setup on conftest per function + # Turn it on + res = client.post( + url_for('settings.settings_page'), + data={ + 'application-ui-use_share_watch': '1', + 'requests-timeout': '60', + }, + follow_redirects=True, + ) + assert res.status_code == 200 test_url = url_for('test_endpoint', _external=True) include_filters = ".nice-filter" @@ -72,4 +81,21 @@ def test_share_watch(client, live_server, measure_memory_usage, datastore_path): res = client.get(url_for("watchlist.index")) assert bytes(test_url.encode('utf-8')) in res.data + # Turn it off + res = client.post( + url_for('settings.settings_page'), + data={ + 'application-ui-use_share_watch': '', + 'requests-timeout': '60', + }, + follow_redirects=True, + ) + + # click share the link + res = client.post( + url_for("ui.form_share_put_watch", uuid=uuid), + follow_redirects=True + ) + assert res.status_code == 403 + delete_all_watches(client) \ No newline at end of file