CI & Build / Python lint (push) Successful in 3s
CI & Build / Build now, or wait for Android? (push) Successful in 3s
Android / Build, or is the channel already serving this? (push) Successful in 3s
Android / Kotlin + Rust (APK) (push) Skipped
Desktop (Tauri) / Build, or is the channel already serving this? (push) Successful in 2s
Desktop (Tauri) / Web tests, clippy, Rust tests and rustfmt (push) Skipped
Desktop (Tauri) / Tauri desktop (Linux) (push) Skipped
Desktop (Tauri) / Windows installer (cross-compiled) (push) Skipped
Desktop (Tauri) / Update manifest (push) Skipped
CI & Build / Web typecheck and unit tests (push) Successful in 9s
CI & Build / Python tests (push) Successful in 14s
CI & Build / integration (push) Successful in 51s
CI & Build / Build & push image (push) Successful in 50s
test_devices signed a fake account into a session and relied on
login_required answering without the database. Since 3dd0b44 the session
path reads the account's epoch, so the fake account hit an unreachable
database and 500ed. The routing property (the static /devices/self rule beats
/devices/<device_id>) is now asserted on the URL map, and the view's 400 for a
web session is an integration test with a real account. #5173.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
52 lines
1.8 KiB
Python
52 lines
1.8 KiB
Python
import pytest
|
|
|
|
from inkwell.app import create_app
|
|
|
|
|
|
@pytest.fixture
|
|
def app():
|
|
return create_app()
|
|
|
|
|
|
async def test_create_device_requires_auth(app):
|
|
# No session cookie and no bearer header → 401 before any DB access.
|
|
client = app.test_client()
|
|
resp = await client.post("/api/auth/devices", json={"name": "phone"})
|
|
assert resp.status_code == 401
|
|
|
|
|
|
async def test_list_devices_requires_auth(app):
|
|
client = app.test_client()
|
|
resp = await client.get("/api/auth/devices")
|
|
assert resp.status_code == 401
|
|
|
|
|
|
async def test_revoke_device_requires_auth(app):
|
|
client = app.test_client()
|
|
resp = await client.delete("/api/auth/devices/00000000-0000-0000-0000-000000000000")
|
|
assert resp.status_code == 401
|
|
|
|
|
|
async def test_revoke_self_requires_auth(app):
|
|
client = app.test_client()
|
|
resp = await client.delete("/api/auth/devices/self")
|
|
assert resp.status_code == 401
|
|
|
|
|
|
def test_revoke_self_routes_to_the_self_revoke_view(app):
|
|
# The static rule must win over `/devices/<device_id>`: if "self" fell through to
|
|
# the id-keyed route it would be read as a malformed UUID and answer 404. Checked
|
|
# on the URL map, because every route behind login_required now reads the
|
|
# account's session epoch (#5173). The view's 400 for a caller with no bearer
|
|
# token is in test_integration.py.
|
|
endpoint, _ = app.url_map.bind("localhost").match("/api/auth/devices/self", method="DELETE")
|
|
assert endpoint == "auth.revoke_own_device"
|
|
|
|
|
|
async def test_device_login_validates_input(app):
|
|
# Missing credentials → 400 BEFORE any DB access, so it's checkable in the
|
|
# DB-free unit lane (invalid-cred and success paths are operator-verified).
|
|
client = app.test_client()
|
|
resp = await client.post("/api/auth/device-login", json={})
|
|
assert resp.status_code == 400
|