test: address chunk-context review comments
- Rename test_chunk_context_endpoint_handles_missing_app_password to test_chunk_context_endpoint_rejects_invalid_bearer so it reflects what is actually exercised: an invalid bearer is rejected upfront at validate_token_and_get_user, not at the NotProvisionedError branch. The NotProvisionedError path is covered by the corresponding unit test in test_management_chunk_context_endpoint.py. - Hoist `import base64` to module level per PEP 8. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.7
parent
bea5c3f5ee
commit
06d871ce22
@@ -19,6 +19,7 @@ so a regression to from_token-style auth would surface as a 500/404 from
|
|||||||
Astrolabe instead of a 200 with chunk_text.
|
Astrolabe instead of a 200 with chunk_text.
|
||||||
"""
|
"""
|
||||||
|
|
||||||
|
import base64
|
||||||
import json
|
import json
|
||||||
import logging
|
import logging
|
||||||
import re
|
import re
|
||||||
@@ -39,8 +40,6 @@ pytestmark = [pytest.mark.integration, pytest.mark.multi_user_basic]
|
|||||||
|
|
||||||
|
|
||||||
def _build_basic_auth_header(username: str, password: str) -> str:
|
def _build_basic_auth_header(username: str, password: str) -> str:
|
||||||
import base64
|
|
||||||
|
|
||||||
credentials = base64.b64encode(f"{username}:{password}".encode()).decode("utf-8")
|
credentials = base64.b64encode(f"{username}:{password}".encode()).decode("utf-8")
|
||||||
return f"Basic {credentials}"
|
return f"Basic {credentials}"
|
||||||
|
|
||||||
@@ -227,14 +226,14 @@ async def test_chunk_context_endpoint_requires_authentication():
|
|||||||
|
|
||||||
|
|
||||||
@pytest.mark.timeout(60)
|
@pytest.mark.timeout(60)
|
||||||
async def test_chunk_context_endpoint_handles_missing_app_password():
|
async def test_chunk_context_endpoint_rejects_invalid_bearer():
|
||||||
"""Bearer token for a user with no provisioned app password must produce a
|
"""A syntactically-valid-but-unverifiable bearer must not 500.
|
||||||
clean 401 (NotProvisionedError path), not a 500 or opaque upstream error.
|
|
||||||
|
|
||||||
We simulate "user has not provisioned" by sending a syntactically valid
|
The NotProvisionedError path (handler reached but no stored app password)
|
||||||
bearer that the token verifier will reject. The exact error class doesn't
|
is covered by the corresponding unit test. This check guards the other
|
||||||
matter for this check — what matters is the handler never 500s on the
|
rejection path: token validation fails upfront at
|
||||||
missing-credential path.
|
`validate_token_and_get_user`, which must turn into a clean 401/404 from
|
||||||
|
the HTTP layer, not an opaque 500.
|
||||||
"""
|
"""
|
||||||
import httpx
|
import httpx
|
||||||
|
|
||||||
@@ -249,7 +248,6 @@ async def test_chunk_context_endpoint_handles_missing_app_password():
|
|||||||
},
|
},
|
||||||
headers={"Authorization": "Bearer invalid.token.value"},
|
headers={"Authorization": "Bearer invalid.token.value"},
|
||||||
)
|
)
|
||||||
# Must be 401 (unauthorized) or 404 (route guard), not 500.
|
|
||||||
assert response.status_code in (401, 404), (
|
assert response.status_code in (401, 404), (
|
||||||
f"Expected 401/404 for invalid bearer, got {response.status_code}: "
|
f"Expected 401/404 for invalid bearer, got {response.status_code}: "
|
||||||
f"{response.text}"
|
f"{response.text}"
|
||||||
|
|||||||
Reference in New Issue
Block a user