• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

kobotoolbox / kpi / 36737726384
83%
master: 76%

Build:
Build:
LAST BUILD BRANCH: hugo/dev-2513-order-catch-all-counter-locks
DEFAULT BRANCH: master
Ran 30 Sep 2026 03:39PM UTC
Jobs 10
Files 920
Run time 4min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

30 Sep 2026 03:34PM UTC coverage: 83.06% (-0.02%) from 83.083%
36737726384

push

github

web-flow
feat(accounts): expose `validated_password` on the session endpoint DEV-2948 (#7649)

### 📣 Summary
Adds `has_validated_password` to the allauth session endpoint so the
frontend can read the invalidated-password signal there instead of
`/me`.

### 📖 Description
An administrator can invalidate a user's password from the admin, which
locks them out of KPI until they reset it. The SPA shows a blocker for
this, and today it reads the flag from `/me`, which is why `/me` is
exempt from the permission
class that enforces it.

We settled that `/me` is a profile endpoint and the session endpoint
owns authentication state. This flag was the one thing still breaking
that rule.

This PR adds `data.user.has_validated_password` to `GET
/api/v2/allauth/browser/v1/auth/session`, via a `HeadlessAdapter` wired
up through allauth's documented `HEADLESS_ADAPTER` setting. Declaring it
on the
user dataclass (rather than overriding `serialize_user()`) is what
allauth's docs prescribe, and it means the field lands in the OpenAPI
schema and the generated orval types automatically.

Nothing about how the flag is set or enforced changes. `/me` keeps
returning `validated_password` for API back-compat.

### 💭 Notes
- The value comes from `ExtraUserDetail.validated_password`, which is
what KPI's permission class reads, so the flag can never disagree with
the 403s a user actually gets. The KoboCAT copy on `UserProfile` is
synced from it.
- It is a separate field from allauth's `has_usable_password`, which is
`false` for every SSO account and means something unrelated.

10446 of 13813 branches covered (75.62%)

9 of 21 new or added lines in 2 files covered. (42.86%)

33346 of 40147 relevant lines covered (83.06%)

4.92 hits per line

Uncovered Changes

Lines Coverage ∆ File
12
65.09
-5.84% kobo/apps/accounts/adapter.py
Jobs
ID Job ID Ran Files Coverage
1 36737726384.1 30 Sep 2026 03:39PM UTC 917
50.88
2 36737726384.2 30 Sep 2026 03:39PM UTC 915
49.63
3 36737726384.3 30 Sep 2026 03:39PM UTC 915
43.58
4 36737726384.4 30 Sep 2026 03:39PM UTC 915
52.67
5 36737726384.5 30 Sep 2026 03:41PM UTC 917
53.91
6 36737726384.6 30 Sep 2026 03:43PM UTC 917
59.55
7 36737726384.7 30 Sep 2026 03:43PM UTC 918
67.97
8 36737726384.8 30 Sep 2026 03:47PM UTC 920
70.3
9 36737726384.9 30 Sep 2026 03:50PM UTC 917
44.86
10 36737726384.10 30 Sep 2026 03:55PM UTC 915
58.47
Source Files on build 36737726384
  • Tree
  • List 920
  • Changed 3
  • Source Changed 0
  • Coverage Changed 3
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • 660aa29e on github
  • Prev Build on main (#36734187808)
  • Next Build on main (#36748844994)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc