feat: matrix/graph data views, wire-generated anomalies, http cookie fix
- auth: session cookie Secure only over https — plain-http LAN access was
silently dropping the cookie, killing WS auth ('connection unstable')
- wire ghost: server-side spike detection on jitter baseline (3σ + 2.5×mean,
20KB/s floor, 20s throttle) — wire anomalies now flood every session with
zero hardware, pushed to clients as {type:'anomaly'} frames
- telemetry cadence 3-5s for live graphs; ambient whispers unchanged
- frontend: MATRIX view (data-rain interleaved with live utterances/anomaly/
telemetry strings), GRAPHS view (scrolling jitter/variance/dns lines +
anomaly markers + counters), BOARD/MATRIX/GRAPHS switcher
- connection banner: 'connecting' is now neutral 'tuning the veil…', only
unstable/closed warns
- db: recreated quantumancy(+_test) as UTF8 (was SQL_ASCII — crashed on
non-ASCII spirit text); README quickstart updated
- i18n: seance.views.* EN/ES
This commit is contained in:
24
backend/tests/test_cookie_scheme.py
Normal file
24
backend/tests/test_cookie_scheme.py
Normal file
@@ -0,0 +1,24 @@
|
||||
import pytest
|
||||
from httpx import ASGITransport, AsyncClient
|
||||
|
||||
from app.main import app
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_login_cookie_secure_only_over_https(client):
|
||||
await client.post("/auth/register", json={"username": "schemer", "password": "spookyspooky"})
|
||||
|
||||
https_login = await client.post(
|
||||
"/auth/login", json={"username": "schemer", "password": "spookyspooky"}
|
||||
)
|
||||
assert "secure" in https_login.headers["set-cookie"].lower()
|
||||
|
||||
# Plain-http (LAN) access: a Secure cookie would be dropped by the
|
||||
# browser and silently break the séance socket.
|
||||
async with AsyncClient(transport=ASGITransport(app=app), base_url="http://test") as http_client:
|
||||
http_login = await http_client.post(
|
||||
"/auth/login", json={"username": "schemer", "password": "spookyspooky"}
|
||||
)
|
||||
cookie = http_login.headers["set-cookie"].lower()
|
||||
assert "qm_session=" in cookie
|
||||
assert "secure" not in cookie
|
||||
Reference in New Issue
Block a user