CI & Build / Python lint (push) Successful in 2s
CI & Build / Build now, or wait for Android? (push) Successful in 2s
Android / Build, or is the channel already serving this? (push) Successful in 3s
Desktop (Tauri) / Build, or is the channel already serving this? (push) Successful in 2s
CI & Build / TypeScript typecheck (push) Successful in 7s
CI & Build / Python tests (push) Successful in 15s
CI & Build / integration (push) Successful in 45s
CI & Build / Build & push image (push) Skipped
Desktop (Tauri) / Windows installer (cross-compiled) (push) Successful in 4m17s
Desktop (Tauri) / Tauri desktop (Linux) (push) Successful in 7m33s
Desktop (Tauri) / Update manifest (push) Successful in 7s
Android / Kotlin + Rust (APK) (push) Successful in 11m25s
Step 2 of milestone 481. The operator chose a full rename (Scribe note 5071), so this goes past the display strings into the identities: - src/thoughtsync → src/inkwell; every import, the Dockerfile and both compose commands, alembic env, pyproject - THOUGHTSYNC_* → INKWELL_* (database URL, secret key, log level, tag/port/bind) - container data dir /var/thoughtsync → /var/inkwell - image git.fabledsword.com/bvandeusen/inkwell; Postgres user/db default inkwell; CI's integration service follows - the files the image serves are inkwell.*. fetch-clients.sh still fetches the thoughtsync-named release assets, because the lanes that publish them are renamed in steps 3 and 4 - exports are written with app "inkwell" Two deliberate exceptions, both because data rides on them: - compose volumes are now named explicitly and overridable (INKWELL_DB_VOLUME, INKWELL_DATA_VOLUME), so a deployment installed as ThoughtSync points at the volumes and DB identity it already has. .env.example says exactly what to set - import still accepts app "thoughtsync", because exports written before the rename are backups. Tested both ways Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
31 lines
1017 B
Python
31 lines
1017 B
Python
from inkwell.security import generate_token, hash_password, hash_token, verify_password
|
|
|
|
|
|
def test_password_roundtrip():
|
|
h = hash_password("correct horse battery staple")
|
|
assert verify_password("correct horse battery staple", h)
|
|
assert not verify_password("wrong password", h)
|
|
|
|
|
|
def test_hash_token_deterministic():
|
|
t = generate_token()
|
|
# Lookup hash is deterministic (same token → same hash) and SHA-256 hex (64 chars).
|
|
assert hash_token(t) == hash_token(t)
|
|
assert len(hash_token(t)) == 64
|
|
# Different tokens hash differently.
|
|
assert hash_token(t) != hash_token(generate_token())
|
|
|
|
|
|
def test_generate_token_unique():
|
|
assert generate_token() != generate_token()
|
|
assert len(generate_token()) >= 32
|
|
|
|
|
|
def test_password_hash_is_salted():
|
|
# Same input hashes differently each time (random salt).
|
|
assert hash_password("same-input") != hash_password("same-input")
|
|
|
|
|
|
def test_verify_rejects_garbage_hash():
|
|
assert not verify_password("whatever", "not-a-bcrypt-hash")
|