fix: use https base_url in test client so Secure cookies propagate automatically

httpx's cookie jar only auto-attaches Secure cookies to https:// requests.
Switching the ASGITransport client fixture's base_url from http://test to
https://test (no real socket is opened either way) makes it behave like a
browser talking to the Cloudflare-Tunnel-terminated HTTPS edge in
production, eliminating the need for manual client.cookies.set(...)
re-injection workarounds in test_auth.py.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013PphXq1s43DNRj1uWKGXof
This commit is contained in:
Indiana
2026-07-20 15:44:01 +00:00
parent 3758594896
commit 10ac364a90
2 changed files with 2 additions and 12 deletions

View File

@@ -35,5 +35,5 @@ app.dependency_overrides[get_db] = _override_get_db
@pytest_asyncio.fixture @pytest_asyncio.fixture
async def client(): async def client():
transport = ASGITransport(app=app) transport = ASGITransport(app=app)
async with AsyncClient(transport=transport, base_url="http://test") as ac: async with AsyncClient(transport=transport, base_url="https://test") as ac:
yield ac yield ac

View File

@@ -28,11 +28,6 @@ async def test_login_sets_cookie_and_me_returns_user(client):
assert login_resp.status_code == 200 assert login_resp.status_code == 200
assert "qm_session" in login_resp.cookies assert "qm_session" in login_resp.cookies
# secure=True cookies are only auto-attached by httpx's cookie jar to https
# requests; the test transport uses base_url="http://test", so re-inject
# the cookie manually to simulate what a browser talking to the real
# Cloudflare-Tunnel-terminated HTTPS endpoint would do automatically.
client.cookies.set("qm_session", login_resp.cookies["qm_session"])
me_resp = await client.get("/auth/me") me_resp = await client.get("/auth/me")
assert me_resp.status_code == 200 assert me_resp.status_code == 200
assert me_resp.json()["username"] == "medium2" assert me_resp.json()["username"] == "medium2"
@@ -60,13 +55,8 @@ async def test_login_nonexistent_username_rejected(client):
@pytest.mark.asyncio @pytest.mark.asyncio
async def test_logout_revokes_session_server_side(client): async def test_logout_revokes_session_server_side(client):
await client.post("/auth/register", json={"username": "medium4", "password": "spookyspooky"}) await client.post("/auth/register", json={"username": "medium4", "password": "spookyspooky"})
login_resp = await client.post("/auth/login", json={"username": "medium4", "password": "spookyspooky"}) await client.post("/auth/login", json={"username": "medium4", "password": "spookyspooky"})
raw_token = login_resp.cookies["qm_session"]
# secure=True cookies aren't auto-attached over the test transport's plain
# http://test base_url (see note above), so re-inject the cookie before
# the logout call itself, otherwise the server never sees a session to revoke.
client.cookies.set("qm_session", raw_token)
logout_resp = await client.post("/auth/logout") logout_resp = await client.post("/auth/logout")
assert logout_resp.status_code == 204 assert logout_resp.status_code == 204