CI & Build / Python lint (push) Successful in 2s
CI & Build / Build now, or wait for Android? (push) Successful in 2s
Android / Build, or is the channel already serving this? (push) Successful in 3s
Desktop (Tauri) / Build, or is the channel already serving this? (push) Successful in 2s
CI & Build / TypeScript typecheck (push) Successful in 7s
CI & Build / Python tests (push) Successful in 15s
CI & Build / integration (push) Successful in 45s
CI & Build / Build & push image (push) Skipped
Desktop (Tauri) / Windows installer (cross-compiled) (push) Successful in 4m17s
Desktop (Tauri) / Tauri desktop (Linux) (push) Successful in 7m33s
Desktop (Tauri) / Update manifest (push) Successful in 7s
Android / Kotlin + Rust (APK) (push) Successful in 11m25s
Step 2 of milestone 481. The operator chose a full rename (Scribe note 5071), so this goes past the display strings into the identities: - src/thoughtsync → src/inkwell; every import, the Dockerfile and both compose commands, alembic env, pyproject - THOUGHTSYNC_* → INKWELL_* (database URL, secret key, log level, tag/port/bind) - container data dir /var/thoughtsync → /var/inkwell - image git.fabledsword.com/bvandeusen/inkwell; Postgres user/db default inkwell; CI's integration service follows - the files the image serves are inkwell.*. fetch-clients.sh still fetches the thoughtsync-named release assets, because the lanes that publish them are renamed in steps 3 and 4 - exports are written with app "inkwell" Two deliberate exceptions, both because data rides on them: - compose volumes are now named explicitly and overridable (INKWELL_DB_VOLUME, INKWELL_DATA_VOLUME), so a deployment installed as ThoughtSync points at the volumes and DB identity it already has. .env.example says exactly what to set - import still accepts app "thoughtsync", because exports written before the rename are backups. Tested both ways Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
54 lines
1.8 KiB
Python
54 lines
1.8 KiB
Python
import pytest
|
|
|
|
from inkwell.app import create_app
|
|
|
|
|
|
@pytest.fixture
|
|
def app():
|
|
return create_app()
|
|
|
|
|
|
async def test_create_device_requires_auth(app):
|
|
# No session cookie and no bearer header → 401 before any DB access.
|
|
client = app.test_client()
|
|
resp = await client.post("/api/auth/devices", json={"name": "phone"})
|
|
assert resp.status_code == 401
|
|
|
|
|
|
async def test_list_devices_requires_auth(app):
|
|
client = app.test_client()
|
|
resp = await client.get("/api/auth/devices")
|
|
assert resp.status_code == 401
|
|
|
|
|
|
async def test_revoke_device_requires_auth(app):
|
|
client = app.test_client()
|
|
resp = await client.delete("/api/auth/devices/00000000-0000-0000-0000-000000000000")
|
|
assert resp.status_code == 401
|
|
|
|
|
|
async def test_revoke_self_requires_auth(app):
|
|
client = app.test_client()
|
|
resp = await client.delete("/api/auth/devices/self")
|
|
assert resp.status_code == 401
|
|
|
|
|
|
async def test_revoke_self_without_a_bearer_token_is_a_bad_request(app):
|
|
# Doubles as the routing check: a session-authenticated caller presents no
|
|
# device token, so the self-revoke view answers 400 BEFORE any DB access. A 404
|
|
# here would mean "self" fell through to the id-keyed route as a malformed UUID
|
|
# — i.e. that the static rule stopped winning.
|
|
client = app.test_client()
|
|
async with client.session_transaction() as sess:
|
|
sess["user_id"] = "00000000-0000-0000-0000-000000000001"
|
|
resp = await client.delete("/api/auth/devices/self")
|
|
assert resp.status_code == 400
|
|
|
|
|
|
async def test_device_login_validates_input(app):
|
|
# Missing credentials → 400 BEFORE any DB access, so it's checkable in the
|
|
# DB-free unit lane (invalid-cred and success paths are operator-verified).
|
|
client = app.test_client()
|
|
resp = await client.post("/api/auth/device-login", json={})
|
|
assert resp.status_code == 400
|