diff --git a/backend/tests/conftest.py b/backend/tests/conftest.py index df46c59..5f91353 100644 --- a/backend/tests/conftest.py +++ b/backend/tests/conftest.py @@ -35,5 +35,5 @@ app.dependency_overrides[get_db] = _override_get_db @pytest_asyncio.fixture async def client(): transport = ASGITransport(app=app) - async with AsyncClient(transport=transport, base_url="http://test") as ac: + async with AsyncClient(transport=transport, base_url="https://test") as ac: yield ac diff --git a/backend/tests/test_auth.py b/backend/tests/test_auth.py index ed99473..a8c3a41 100644 --- a/backend/tests/test_auth.py +++ b/backend/tests/test_auth.py @@ -28,11 +28,6 @@ async def test_login_sets_cookie_and_me_returns_user(client): assert login_resp.status_code == 200 assert "qm_session" in login_resp.cookies - # secure=True cookies are only auto-attached by httpx's cookie jar to https - # requests; the test transport uses base_url="http://test", so re-inject - # the cookie manually to simulate what a browser talking to the real - # Cloudflare-Tunnel-terminated HTTPS endpoint would do automatically. - client.cookies.set("qm_session", login_resp.cookies["qm_session"]) me_resp = await client.get("/auth/me") assert me_resp.status_code == 200 assert me_resp.json()["username"] == "medium2" @@ -60,13 +55,8 @@ async def test_login_nonexistent_username_rejected(client): @pytest.mark.asyncio async def test_logout_revokes_session_server_side(client): await client.post("/auth/register", json={"username": "medium4", "password": "spookyspooky"}) - login_resp = await client.post("/auth/login", json={"username": "medium4", "password": "spookyspooky"}) - raw_token = login_resp.cookies["qm_session"] + await client.post("/auth/login", json={"username": "medium4", "password": "spookyspooky"}) - # secure=True cookies aren't auto-attached over the test transport's plain - # http://test base_url (see note above), so re-inject the cookie before - # the logout call itself, otherwise the server never sees a session to revoke. - client.cookies.set("qm_session", raw_token) logout_resp = await client.post("/auth/logout") assert logout_resp.status_code == 204