httpx's cookie jar only auto-attaches Secure cookies to https:// requests. Switching the ASGITransport client fixture's base_url from http://test to https://test (no real socket is opened either way) makes it behave like a browser talking to the Cloudflare-Tunnel-terminated HTTPS edge in production, eliminating the need for manual client.cookies.set(...) re-injection workarounds in test_auth.py. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013PphXq1s43DNRj1uWKGXof
65 lines
2.3 KiB
Python
65 lines
2.3 KiB
Python
import pytest
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_register_creates_user(client):
|
|
response = await client.post(
|
|
"/auth/register",
|
|
json={"username": "medium1", "password": "spookyspooky"},
|
|
)
|
|
assert response.status_code == 201
|
|
body = response.json()
|
|
assert body["username"] == "medium1"
|
|
assert "id" in body
|
|
assert "password" not in body
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_register_duplicate_username_rejected(client):
|
|
await client.post("/auth/register", json={"username": "medium1", "password": "spookyspooky"})
|
|
response = await client.post("/auth/register", json={"username": "medium1", "password": "anotherpass"})
|
|
assert response.status_code == 409
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_login_sets_cookie_and_me_returns_user(client):
|
|
await client.post("/auth/register", json={"username": "medium2", "password": "spookyspooky"})
|
|
login_resp = await client.post("/auth/login", json={"username": "medium2", "password": "spookyspooky"})
|
|
assert login_resp.status_code == 200
|
|
assert "qm_session" in login_resp.cookies
|
|
|
|
me_resp = await client.get("/auth/me")
|
|
assert me_resp.status_code == 200
|
|
assert me_resp.json()["username"] == "medium2"
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_login_wrong_password_rejected(client):
|
|
await client.post("/auth/register", json={"username": "medium3", "password": "spookyspooky"})
|
|
response = await client.post("/auth/login", json={"username": "medium3", "password": "wrongpass"})
|
|
assert response.status_code == 401
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_me_without_cookie_rejected(client):
|
|
response = await client.get("/auth/me")
|
|
assert response.status_code == 401
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_login_nonexistent_username_rejected(client):
|
|
response = await client.post("/auth/login", json={"username": "nosuchmedium", "password": "whatever123"})
|
|
assert response.status_code == 401
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_logout_revokes_session_server_side(client):
|
|
await client.post("/auth/register", json={"username": "medium4", "password": "spookyspooky"})
|
|
await client.post("/auth/login", json={"username": "medium4", "password": "spookyspooky"})
|
|
|
|
logout_resp = await client.post("/auth/logout")
|
|
assert logout_resp.status_code == 204
|
|
|
|
me_resp = await client.get("/auth/me")
|
|
assert me_resp.status_code == 401
|