M1.5 backend: admin role + DB-backed settings, DB-URL-only install
- users.is_admin; first registered user becomes admin; registration gated by the allow_registration setting (first account always allowed). is_admin in /api/auth/* responses; require_admin guard (live DB check). - settings table + code registry (site_name, allow_registration, session_ttl_days) with typed defaults — empty table = all defaults (rule 26). get/set/validate service; GET /api/config (public) + GET/PATCH /api/settings (admin), live session-TTL apply with no restart (rule 25). - Cookie-signing secret now persisted in the DB (before_serving load-or-create), so sessions survive restarts with no volume. Config: DATABASE_URL is the only required env; SECRET_KEY + DATA_DIR are optional break-glass items. - Migration 0003; DB-free tests for settings validation + admin guard. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FRgehjoz7Yv8LkUfADxACm
This commit is contained in:
@@ -0,0 +1,21 @@
|
||||
import pytest
|
||||
|
||||
from thoughtsync.app import create_app
|
||||
|
||||
|
||||
@pytest.fixture
|
||||
def app():
|
||||
return create_app()
|
||||
|
||||
|
||||
async def test_settings_requires_auth(app):
|
||||
# require_admin returns 401 before any DB access when unauthenticated.
|
||||
client = app.test_client()
|
||||
resp = await client.get("/api/settings")
|
||||
assert resp.status_code == 401
|
||||
|
||||
|
||||
async def test_settings_patch_requires_auth(app):
|
||||
client = app.test_client()
|
||||
resp = await client.patch("/api/settings", json={"site_name": "x"})
|
||||
assert resp.status_code == 401
|
||||
Reference in New Issue
Block a user