531dc968a8
- Add Logto OIDC integration (app/core/logto.py): CookieStorage adapter, create/decode session token helpers, sync_logto_user upsert - New auth endpoints (/api/v1/auth): sign-in, callback, sign-out, me - AuthRedirectMiddleware: protects HTML pages, redirects to /setup when Logto is unconfigured, to /login otherwise - Update require_admin_auth: accepts dmarq_session cookie JWT first, then API key, then Bearer JWT (fully backward compatible) - Update User model: add logto_id, username, picture, created_at, updated_at; make hashed_password nullable for Logto-only users; is_superuser default=True - New Alembic migration d4e5f6a7b8c9 for the above schema changes - Add LOGTO_ENDPOINT / LOGTO_APP_ID / LOGTO_APP_SECRET / LOGTO_REDIRECT_URI settings with logto_configured property - Create login.html (Sign in with Logto button) and setup.html (step-by-step configuration guide) - Update base.html: user menu with avatar/name and sign-out via Alpine.js fetch to /api/v1/auth/me - Update settings.html: remove localStorage adminApiKey; session cookie is sent automatically by browser; add 401 → /login redirect - Update requirements.txt: replace fastapi-users additions with logto + aiohttp - Add test_auth.py: 18 new tests covering session tokens, CookieStorage, sync_logto_user, /me, /sign-in (503), /sign-out cookie clearing - Fix test_security_extra.py: pass Request mock to require_admin_auth; add new test_valid_session_cookie_returns_auth_context Agent-Logs-Url: https://github.com/christianlouis/dmarq/sessions/b448f585-7646-40f8-ae2d-9986c361e3fd Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
112 lines
4.9 KiB
Python
112 lines
4.9 KiB
Python
"""
|
|
Tests for the /api/v1/stats endpoints.
|
|
|
|
Covers dashboard statistics and per-domain statistics with cache refresh.
|
|
"""
|
|
|
|
from unittest.mock import MagicMock, patch
|
|
|
|
from fastapi.testclient import TestClient
|
|
|
|
|
|
class TestDashboardStatistics:
|
|
"""Tests for GET /api/v1/stats/dashboard"""
|
|
|
|
def test_dashboard_returns_200(self, client: TestClient):
|
|
response = client.get("/api/v1/stats/dashboard")
|
|
assert response.status_code == 200
|
|
|
|
def test_dashboard_response_contains_api_version(self, client: TestClient):
|
|
response = client.get("/api/v1/stats/dashboard")
|
|
data = response.json()
|
|
assert data["api_version"] == "1.0"
|
|
|
|
def test_dashboard_response_contains_period_days(self, client: TestClient):
|
|
response = client.get("/api/v1/stats/dashboard")
|
|
data = response.json()
|
|
assert data["period_days"] == 30
|
|
|
|
def test_dashboard_period_days_query_param(self, client: TestClient):
|
|
response = client.get("/api/v1/stats/dashboard?period_days=7")
|
|
assert response.status_code == 200
|
|
data = response.json()
|
|
assert data["period_days"] == 7
|
|
|
|
def test_dashboard_force_refresh(self, client: TestClient):
|
|
"""force_refresh=true should trigger cache invalidation without error."""
|
|
response = client.get("/api/v1/stats/dashboard?force_refresh=true")
|
|
assert response.status_code == 200
|
|
data = response.json()
|
|
assert "api_version" in data
|
|
|
|
def test_dashboard_force_refresh_calls_invalidate_cache(self, client: TestClient):
|
|
"""Verify StatsSummarizer.invalidate_cache is called when force_refresh is set."""
|
|
with patch("app.api.api_v1.endpoints.stats.StatsSummarizer") as MockSummarizer:
|
|
mock_instance = MagicMock()
|
|
mock_instance.calculate_summary_statistics.return_value = {"total": 0}
|
|
MockSummarizer.return_value = mock_instance
|
|
|
|
response = client.get("/api/v1/stats/dashboard?force_refresh=true")
|
|
assert response.status_code == 200
|
|
mock_instance.invalidate_cache.assert_called_once()
|
|
|
|
def test_dashboard_no_force_refresh_skips_invalidate(self, client: TestClient):
|
|
"""Without force_refresh, invalidate_cache should NOT be called."""
|
|
with patch("app.api.api_v1.endpoints.stats.StatsSummarizer") as MockSummarizer:
|
|
mock_instance = MagicMock()
|
|
mock_instance.calculate_summary_statistics.return_value = {"total": 0}
|
|
MockSummarizer.return_value = mock_instance
|
|
|
|
response = client.get("/api/v1/stats/dashboard")
|
|
assert response.status_code == 200
|
|
mock_instance.invalidate_cache.assert_not_called()
|
|
|
|
|
|
class TestDomainStatistics:
|
|
"""Tests for GET /api/v1/stats/domain/{domain_id}"""
|
|
|
|
def test_domain_stats_returns_200(self, client: TestClient):
|
|
response = client.get("/api/v1/stats/domain/example.com")
|
|
assert response.status_code == 200
|
|
|
|
def test_domain_stats_contains_api_version(self, client: TestClient):
|
|
response = client.get("/api/v1/stats/domain/example.com")
|
|
data = response.json()
|
|
assert data["api_version"] == "1.0"
|
|
|
|
def test_domain_stats_contains_period_days(self, client: TestClient):
|
|
response = client.get("/api/v1/stats/domain/example.com")
|
|
data = response.json()
|
|
assert data["period_days"] == 30
|
|
|
|
def test_domain_stats_custom_period(self, client: TestClient):
|
|
response = client.get("/api/v1/stats/domain/example.com?period_days=14")
|
|
assert response.status_code == 200
|
|
data = response.json()
|
|
assert data["period_days"] == 14
|
|
|
|
def test_domain_stats_force_refresh(self, client: TestClient):
|
|
response = client.get("/api/v1/stats/domain/example.com?force_refresh=true")
|
|
assert response.status_code == 200
|
|
|
|
def test_domain_stats_force_refresh_calls_invalidate_with_domain(self, client: TestClient):
|
|
"""Verify invalidate_cache is called with the domain ID."""
|
|
with patch("app.api.api_v1.endpoints.stats.StatsSummarizer") as MockSummarizer:
|
|
mock_instance = MagicMock()
|
|
mock_instance.calculate_summary_statistics.return_value = {"total": 0}
|
|
MockSummarizer.return_value = mock_instance
|
|
|
|
response = client.get("/api/v1/stats/domain/example.com?force_refresh=true")
|
|
assert response.status_code == 200
|
|
mock_instance.invalidate_cache.assert_called_once_with("example.com")
|
|
|
|
def test_domain_stats_no_force_refresh_skips_invalidate(self, client: TestClient):
|
|
with patch("app.api.api_v1.endpoints.stats.StatsSummarizer") as MockSummarizer:
|
|
mock_instance = MagicMock()
|
|
mock_instance.calculate_summary_statistics.return_value = {"total": 0}
|
|
MockSummarizer.return_value = mock_instance
|
|
|
|
response = client.get("/api/v1/stats/domain/example.com")
|
|
assert response.status_code == 200
|
|
mock_instance.invalidate_cache.assert_not_called()
|