Files
bvandeusenandClaude Opus 5.5 f100e5ef85
CI & Build / Python lint (push) Successful in 3s
CI & Build / Build now, or wait for Android? (push) Successful in 3s
Android / Build, or is the channel already serving this? (push) Successful in 3s
Android / Kotlin + Rust (APK) (push) Skipped
Desktop (Tauri) / Build, or is the channel already serving this? (push) Successful in 2s
Desktop (Tauri) / Web tests, clippy, Rust tests and rustfmt (push) Skipped
Desktop (Tauri) / Tauri desktop (Linux) (push) Skipped
Desktop (Tauri) / Windows installer (cross-compiled) (push) Skipped
Desktop (Tauri) / Update manifest (push) Skipped
CI & Build / Web typecheck and unit tests (push) Successful in 9s
CI & Build / Python tests (push) Successful in 14s
CI & Build / integration (push) Successful in 51s
CI & Build / Build & push image (push) Successful in 50s
tests: the self-revoke routing check reads the URL map; its 400 moves to Postgres
test_devices signed a fake account into a session and relied on
login_required answering without the database. Since 3dd0b44 the session
path reads the account's epoch, so the fake account hit an unreachable
database and 500ed. The routing property (the static /devices/self rule beats
/devices/<device_id>) is now asserted on the URL map, and the view's 400 for a
web session is an integration test with a real account. #5173.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-07 14:41:44 -04:00

52 lines
1.8 KiB
Python

import pytest
from inkwell.app import create_app
@pytest.fixture
def app():
return create_app()
async def test_create_device_requires_auth(app):
# No session cookie and no bearer header → 401 before any DB access.
client = app.test_client()
resp = await client.post("/api/auth/devices", json={"name": "phone"})
assert resp.status_code == 401
async def test_list_devices_requires_auth(app):
client = app.test_client()
resp = await client.get("/api/auth/devices")
assert resp.status_code == 401
async def test_revoke_device_requires_auth(app):
client = app.test_client()
resp = await client.delete("/api/auth/devices/00000000-0000-0000-0000-000000000000")
assert resp.status_code == 401
async def test_revoke_self_requires_auth(app):
client = app.test_client()
resp = await client.delete("/api/auth/devices/self")
assert resp.status_code == 401
def test_revoke_self_routes_to_the_self_revoke_view(app):
# The static rule must win over `/devices/<device_id>`: if "self" fell through to
# the id-keyed route it would be read as a malformed UUID and answer 404. Checked
# on the URL map, because every route behind login_required now reads the
# account's session epoch (#5173). The view's 400 for a caller with no bearer
# token is in test_integration.py.
endpoint, _ = app.url_map.bind("localhost").match("/api/auth/devices/self", method="DELETE")
assert endpoint == "auth.revoke_own_device"
async def test_device_login_validates_input(app):
# Missing credentials → 400 BEFORE any DB access, so it's checkable in the
# DB-free unit lane (invalid-cred and success paths are operator-verified).
client = app.test_client()
resp = await client.post("/api/auth/device-login", json={})
assert resp.status_code == 400