Files
gh-christianlouis-docuelevate/tests/test_api_auth_enabled.py
T
2026-03-12 17:03:30 +00:00

149 lines
5.3 KiB
Python

"""
Integration tests for API endpoints with AUTH_ENABLED=True.
These tests verify that authentication properly protects endpoints when enabled.
"""
import pytest
@pytest.mark.integration
class TestAPIWithAuthDisabled:
"""Test API endpoints with authentication disabled (default test configuration)."""
def test_whoami_returns_error_when_no_user(self, client):
"""Test that /whoami returns error dict when user is not in session."""
response = client.get("/api/auth/whoami")
assert response.status_code == 200
data = response.json()
# With auth disabled and no user, returns error dict
assert "error" in data
def test_private_endpoint_accessible_when_auth_disabled(self, client):
"""Test that /private endpoint is accessible when AUTH_ENABLED=False."""
response = client.get("/private")
assert response.status_code == 200
data = response.json()
assert "message" in data
def test_login_page_not_available_when_auth_disabled(self, client):
"""Test that /login returns 404 when auth is disabled."""
response = client.get("/login")
assert response.status_code == 404
@pytest.mark.integration
class TestSessionConfiguration:
"""Test that session configuration is correct for authenticated tests."""
def test_session_secret_configured_in_conftest(self):
"""Test that SESSION_SECRET is configured in conftest.py."""
import os
session_secret = os.environ.get("SESSION_SECRET")
assert session_secret is not None
assert len(session_secret) >= 32, "SESSION_SECRET must be at least 32 characters"
def test_session_secret_meets_requirements_for_auth(self):
"""Test that SESSION_SECRET meets validation requirements."""
from app.config import settings
# Session secret should always be configured (needed even when auth is disabled)
assert settings.session_secret is not None
assert len(settings.session_secret) >= 32
@pytest.mark.unit
class TestAuthEnabledConfiguration:
"""Test authentication configuration handling."""
def test_auth_enabled_defaults_to_false_in_tests(self):
"""Test that AUTH_ENABLED defaults to False in test environment."""
import os
auth_enabled = os.environ.get("AUTH_ENABLED", "False")
assert auth_enabled == "False", "Tests should run with AUTH_ENABLED=False by default"
def test_can_temporarily_enable_auth(self):
"""Test that AUTH_ENABLED can be enabled temporarily with patch."""
import os
from unittest.mock import patch
with patch.dict(os.environ, {"AUTH_ENABLED": "True"}):
assert os.environ.get("AUTH_ENABLED") == "True"
# Should revert after context
assert os.environ.get("AUTH_ENABLED") == "False"
@pytest.mark.integration
class TestProtectedAPIEndpoints:
"""Test API endpoints that can be protected when auth is enabled."""
def test_api_auth_whoami_endpoint_exists(self, client):
"""Test that /api/auth/whoami endpoint exists."""
response = client.get("/api/auth/whoami")
assert response.status_code == 200
def test_api_endpoints_accessible_without_auth_when_disabled(self, client):
"""Test that API endpoints are accessible when AUTH_ENABLED=False."""
# These should all work without authentication when auth is disabled
response = client.get("/")
assert response.status_code in [200, 302, 404] # Valid responses
response = client.get("/api/files")
assert response.status_code == 200
response = client.get("/api/logs")
assert response.status_code == 200
def test_whoami_with_user_in_session(self, client):
"""Test /whoami endpoint returns user data when user is in session."""
# Even with auth disabled, if user is in session, whoami should work
# This tests the endpoint logic itself
# We can't easily set session in TestClient, so we'll test the handler directly
from unittest.mock import MagicMock
from app.api.user import whoami_handler
mock_request = MagicMock()
mock_request.session = {
"user": {
"id": "test123",
"name": "Test User",
"email": "test@example.com",
}
}
# Mock DB: no UserProfile found (no custom avatar)
mock_db = MagicMock()
mock_db.query.return_value.filter.return_value.first.return_value = None
import asyncio
result = asyncio.run(whoami_handler(mock_request, mock_db))
assert result["id"] == "test123"
assert result["email"] == "test@example.com"
assert "picture" in result # Gravatar URL should be added
def test_whoami_raises_401_when_no_user(self):
"""Test /whoami handler raises 401 when no user in session."""
import asyncio
from unittest.mock import MagicMock
from fastapi import HTTPException
from app.api.user import whoami_handler
mock_request = MagicMock()
mock_request.session = {}
mock_db = MagicMock()
with pytest.raises(HTTPException) as exc_info:
asyncio.run(whoami_handler(mock_request, mock_db))
assert exc_info.value.status_code == 401
assert "Not logged in" in exc_info.value.detail