tests: the self-revoke routing check reads the URL map; its 400 moves to Postgres
CI & Build / Python lint (push) Successful in 3s
CI & Build / Build now, or wait for Android? (push) Successful in 3s
Android / Build, or is the channel already serving this? (push) Successful in 3s
Android / Kotlin + Rust (APK) (push) Skipped
Desktop (Tauri) / Build, or is the channel already serving this? (push) Successful in 2s
Desktop (Tauri) / Web tests, clippy, Rust tests and rustfmt (push) Skipped
Desktop (Tauri) / Tauri desktop (Linux) (push) Skipped
Desktop (Tauri) / Windows installer (cross-compiled) (push) Skipped
Desktop (Tauri) / Update manifest (push) Skipped
CI & Build / Web typecheck and unit tests (push) Successful in 9s
CI & Build / Python tests (push) Successful in 14s
CI & Build / integration (push) Successful in 51s
CI & Build / Build & push image (push) Successful in 50s
CI & Build / Python lint (push) Successful in 3s
CI & Build / Build now, or wait for Android? (push) Successful in 3s
Android / Build, or is the channel already serving this? (push) Successful in 3s
Android / Kotlin + Rust (APK) (push) Skipped
Desktop (Tauri) / Build, or is the channel already serving this? (push) Successful in 2s
Desktop (Tauri) / Web tests, clippy, Rust tests and rustfmt (push) Skipped
Desktop (Tauri) / Tauri desktop (Linux) (push) Skipped
Desktop (Tauri) / Windows installer (cross-compiled) (push) Skipped
Desktop (Tauri) / Update manifest (push) Skipped
CI & Build / Web typecheck and unit tests (push) Successful in 9s
CI & Build / Python tests (push) Successful in 14s
CI & Build / integration (push) Successful in 51s
CI & Build / Build & push image (push) Successful in 50s
test_devices signed a fake account into a session and relied on
login_required answering without the database. Since 3dd0b44 the session
path reads the account's epoch, so the fake account hit an unreachable
database and 500ed. The routing property (the static /devices/self rule beats
/devices/<device_id>) is now asserted on the URL map, and the view's 400 for a
web session is an integration test with a real account. #5173.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
+8
-10
@@ -33,16 +33,14 @@ async def test_revoke_self_requires_auth(app):
|
||||
assert resp.status_code == 401
|
||||
|
||||
|
||||
async def test_revoke_self_without_a_bearer_token_is_a_bad_request(app):
|
||||
# Doubles as the routing check: a session-authenticated caller presents no
|
||||
# device token, so the self-revoke view answers 400 BEFORE any DB access. A 404
|
||||
# here would mean "self" fell through to the id-keyed route as a malformed UUID
|
||||
# — i.e. that the static rule stopped winning.
|
||||
client = app.test_client()
|
||||
async with client.session_transaction() as sess:
|
||||
sess["user_id"] = "00000000-0000-0000-0000-000000000001"
|
||||
resp = await client.delete("/api/auth/devices/self")
|
||||
assert resp.status_code == 400
|
||||
def test_revoke_self_routes_to_the_self_revoke_view(app):
|
||||
# The static rule must win over `/devices/<device_id>`: if "self" fell through to
|
||||
# the id-keyed route it would be read as a malformed UUID and answer 404. Checked
|
||||
# on the URL map, because every route behind login_required now reads the
|
||||
# account's session epoch (#5173). The view's 400 for a caller with no bearer
|
||||
# token is in test_integration.py.
|
||||
endpoint, _ = app.url_map.bind("localhost").match("/api/auth/devices/self", method="DELETE")
|
||||
assert endpoint == "auth.revoke_own_device"
|
||||
|
||||
|
||||
async def test_device_login_validates_input(app):
|
||||
|
||||
@@ -1170,3 +1170,12 @@ async def test_a_short_password_leaves_the_reset_link_usable(app_client, db):
|
||||
assert short.status_code == 400
|
||||
ok = await client.post("/api/auth/reset-password", json={"token": token, "password": "a-brand-new-password"})
|
||||
assert ok.status_code == 200
|
||||
|
||||
|
||||
async def test_revoking_this_device_from_a_web_session_is_a_bad_request(app_client, db):
|
||||
"""A session-cookie caller holds no device token, so "revoke the one I'm using"
|
||||
has nothing to name. Moved here from the unit lane when the session check began
|
||||
reading the account (#5173)."""
|
||||
await _signed_in(app_client, "web")
|
||||
resp = await app_client.delete("/api/auth/devices/self")
|
||||
assert resp.status_code == 400
|
||||
|
||||
Reference in New Issue
Block a user