- auth: session cookie Secure only over https — plain-http LAN access was
silently dropping the cookie, killing WS auth ('connection unstable')
- wire ghost: server-side spike detection on jitter baseline (3σ + 2.5×mean,
20KB/s floor, 20s throttle) — wire anomalies now flood every session with
zero hardware, pushed to clients as {type:'anomaly'} frames
- telemetry cadence 3-5s for live graphs; ambient whispers unchanged
- frontend: MATRIX view (data-rain interleaved with live utterances/anomaly/
telemetry strings), GRAPHS view (scrolling jitter/variance/dns lines +
anomaly markers + counters), BOARD/MATRIX/GRAPHS switcher
- connection banner: 'connecting' is now neutral 'tuning the veil…', only
unstable/closed warns
- db: recreated quantumancy(+_test) as UTF8 (was SQL_ASCII — crashed on
non-ASCII spirit text); README quickstart updated
- i18n: seance.views.* EN/ES
25 lines
943 B
Python
25 lines
943 B
Python
import pytest
|
|
from httpx import ASGITransport, AsyncClient
|
|
|
|
from app.main import app
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_login_cookie_secure_only_over_https(client):
|
|
await client.post("/auth/register", json={"username": "schemer", "password": "spookyspooky"})
|
|
|
|
https_login = await client.post(
|
|
"/auth/login", json={"username": "schemer", "password": "spookyspooky"}
|
|
)
|
|
assert "secure" in https_login.headers["set-cookie"].lower()
|
|
|
|
# Plain-http (LAN) access: a Secure cookie would be dropped by the
|
|
# browser and silently break the séance socket.
|
|
async with AsyncClient(transport=ASGITransport(app=app), base_url="http://test") as http_client:
|
|
http_login = await http_client.post(
|
|
"/auth/login", json={"username": "schemer", "password": "spookyspooky"}
|
|
)
|
|
cookie = http_login.headers["set-cookie"].lower()
|
|
assert "qm_session=" in cookie
|
|
assert "secure" not in cookie
|