tests: the self-revoke routing check reads the URL map; its 400 moves to Postgres
CI & Build / Python lint (push) Successful in 3s
CI & Build / Build now, or wait for Android? (push) Successful in 3s
Android / Build, or is the channel already serving this? (push) Successful in 3s
Android / Kotlin + Rust (APK) (push) Skipped
Desktop (Tauri) / Build, or is the channel already serving this? (push) Successful in 2s
Desktop (Tauri) / Web tests, clippy, Rust tests and rustfmt (push) Skipped
Desktop (Tauri) / Tauri desktop (Linux) (push) Skipped
Desktop (Tauri) / Windows installer (cross-compiled) (push) Skipped
Desktop (Tauri) / Update manifest (push) Skipped
CI & Build / Web typecheck and unit tests (push) Successful in 9s
CI & Build / Python tests (push) Successful in 14s
CI & Build / integration (push) Successful in 51s
CI & Build / Build & push image (push) Successful in 50s
CI & Build / Python lint (push) Successful in 3s
CI & Build / Build now, or wait for Android? (push) Successful in 3s
Android / Build, or is the channel already serving this? (push) Successful in 3s
Android / Kotlin + Rust (APK) (push) Skipped
Desktop (Tauri) / Build, or is the channel already serving this? (push) Successful in 2s
Desktop (Tauri) / Web tests, clippy, Rust tests and rustfmt (push) Skipped
Desktop (Tauri) / Tauri desktop (Linux) (push) Skipped
Desktop (Tauri) / Windows installer (cross-compiled) (push) Skipped
Desktop (Tauri) / Update manifest (push) Skipped
CI & Build / Web typecheck and unit tests (push) Successful in 9s
CI & Build / Python tests (push) Successful in 14s
CI & Build / integration (push) Successful in 51s
CI & Build / Build & push image (push) Successful in 50s
test_devices signed a fake account into a session and relied on
login_required answering without the database. Since 3dd0b44 the session
path reads the account's epoch, so the fake account hit an unreachable
database and 500ed. The routing property (the static /devices/self rule beats
/devices/<device_id>) is now asserted on the URL map, and the view's 400 for a
web session is an integration test with a real account. #5173.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
+8
-10
@@ -33,16 +33,14 @@ async def test_revoke_self_requires_auth(app):
|
|||||||
assert resp.status_code == 401
|
assert resp.status_code == 401
|
||||||
|
|
||||||
|
|
||||||
async def test_revoke_self_without_a_bearer_token_is_a_bad_request(app):
|
def test_revoke_self_routes_to_the_self_revoke_view(app):
|
||||||
# Doubles as the routing check: a session-authenticated caller presents no
|
# The static rule must win over `/devices/<device_id>`: if "self" fell through to
|
||||||
# device token, so the self-revoke view answers 400 BEFORE any DB access. A 404
|
# the id-keyed route it would be read as a malformed UUID and answer 404. Checked
|
||||||
# here would mean "self" fell through to the id-keyed route as a malformed UUID
|
# on the URL map, because every route behind login_required now reads the
|
||||||
# — i.e. that the static rule stopped winning.
|
# account's session epoch (#5173). The view's 400 for a caller with no bearer
|
||||||
client = app.test_client()
|
# token is in test_integration.py.
|
||||||
async with client.session_transaction() as sess:
|
endpoint, _ = app.url_map.bind("localhost").match("/api/auth/devices/self", method="DELETE")
|
||||||
sess["user_id"] = "00000000-0000-0000-0000-000000000001"
|
assert endpoint == "auth.revoke_own_device"
|
||||||
resp = await client.delete("/api/auth/devices/self")
|
|
||||||
assert resp.status_code == 400
|
|
||||||
|
|
||||||
|
|
||||||
async def test_device_login_validates_input(app):
|
async def test_device_login_validates_input(app):
|
||||||
|
|||||||
@@ -1170,3 +1170,12 @@ async def test_a_short_password_leaves_the_reset_link_usable(app_client, db):
|
|||||||
assert short.status_code == 400
|
assert short.status_code == 400
|
||||||
ok = await client.post("/api/auth/reset-password", json={"token": token, "password": "a-brand-new-password"})
|
ok = await client.post("/api/auth/reset-password", json={"token": token, "password": "a-brand-new-password"})
|
||||||
assert ok.status_code == 200
|
assert ok.status_code == 200
|
||||||
|
|
||||||
|
|
||||||
|
async def test_revoking_this_device_from_a_web_session_is_a_bad_request(app_client, db):
|
||||||
|
"""A session-cookie caller holds no device token, so "revoke the one I'm using"
|
||||||
|
has nothing to name. Moved here from the unit lane when the session check began
|
||||||
|
reading the account (#5173)."""
|
||||||
|
await _signed_in(app_client, "web")
|
||||||
|
resp = await app_client.delete("/api/auth/devices/self")
|
||||||
|
assert resp.status_code == 400
|
||||||
|
|||||||
Reference in New Issue
Block a user