/me Viewing current user profile
/profile/:id Viewing a specified user's profile
/profile Updating own profile
/profile/delete Deleting profile
Purpose: Displaying currently logged in user's profile.
Steps:
- Log in as a user
- Go to profile page
- Expect:
- Status: 200 OK
- JSON payload with correct fields
- User's profile information rendered in UI
Edge Cases:
- No session:
401 Unauthorized -> Redirected to login page
- User not found:
404 Not found -> Show error page
Purpose: View a public profile, or if an admin, any profile
Steps:
- Go to
/users/<UUID> route
- Expect:
- Status: 200 OK
- JSON payload with correct fields
- User's profile information rendered in UI
Edge Cases:
- Invalid or non-existent UUID:
404 Not found -> Show error page
- DB Error:
500 -> Show internal error page
Purpose: Allow users to update their own profile, such as name and email.
Steps:
- Log in as a user
- Navigate to the profile edit page
- Edit fields
- Make sure fields properly sanitize input for injection prevention
- Submit the form
- Expect:
- Status:
200 OK
- Message such as "Profile Has Been Updated"
- New profile information is correctly rendered
Purpose: Allow users to delete their own account, with a credentials check to confirm
Steps:
- Log in as a user
- Navigate to the delete account section of the profile page
- Enter password to confirm account deletion
- Expect:
- Status:
200 OK
- Redirect to login/register page
Edge Cases:
- Wrong password:
401 Unauthorized -> Show invalid password error
- No password (OAuth users): ???
- Would be a good idea to have multiple accounts for testing purposes, such as one regular user, and one OAuth user
- These might have to be recreated each time the deletion function is tested