Files
qtalker---/backend/tests/test_cookie_scheme.py
Indiana c372427ced feat: matrix/graph data views, wire-generated anomalies, http cookie fix
- auth: session cookie Secure only over https — plain-http LAN access was
  silently dropping the cookie, killing WS auth ('connection unstable')
- wire ghost: server-side spike detection on jitter baseline (3σ + 2.5×mean,
  20KB/s floor, 20s throttle) — wire anomalies now flood every session with
  zero hardware, pushed to clients as {type:'anomaly'} frames
- telemetry cadence 3-5s for live graphs; ambient whispers unchanged
- frontend: MATRIX view (data-rain interleaved with live utterances/anomaly/
  telemetry strings), GRAPHS view (scrolling jitter/variance/dns lines +
  anomaly markers + counters), BOARD/MATRIX/GRAPHS switcher
- connection banner: 'connecting' is now neutral 'tuning the veil…', only
  unstable/closed warns
- db: recreated quantumancy(+_test) as UTF8 (was SQL_ASCII — crashed on
  non-ASCII spirit text); README quickstart updated
- i18n: seance.views.* EN/ES
2026-07-21 00:02:41 +00:00

25 lines
943 B
Python

import pytest
from httpx import ASGITransport, AsyncClient
from app.main import app
@pytest.mark.asyncio
async def test_login_cookie_secure_only_over_https(client):
await client.post("/auth/register", json={"username": "schemer", "password": "spookyspooky"})
https_login = await client.post(
"/auth/login", json={"username": "schemer", "password": "spookyspooky"}
)
assert "secure" in https_login.headers["set-cookie"].lower()
# Plain-http (LAN) access: a Secure cookie would be dropped by the
# browser and silently break the séance socket.
async with AsyncClient(transport=ASGITransport(app=app), base_url="http://test") as http_client:
http_login = await http_client.post(
"/auth/login", json={"username": "schemer", "password": "spookyspooky"}
)
cookie = http_login.headers["set-cookie"].lower()
assert "qm_session=" in cookie
assert "secure" not in cookie