test: address chunk-context review comments

- Rename test_chunk_context_endpoint_handles_missing_app_password to
  test_chunk_context_endpoint_rejects_invalid_bearer so it reflects
  what is actually exercised: an invalid bearer is rejected upfront at
  validate_token_and_get_user, not at the NotProvisionedError branch.
  The NotProvisionedError path is covered by the corresponding unit
  test in test_management_chunk_context_endpoint.py.
- Hoist `import base64` to module level per PEP 8.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
Chris Coutinho
2026-04-22 20:17:34 +02:00
co-authored by Claude Opus 4.7
parent bea5c3f5ee
commit 06d871ce22
@@ -19,6 +19,7 @@ so a regression to from_token-style auth would surface as a 500/404 from
Astrolabe instead of a 200 with chunk_text. Astrolabe instead of a 200 with chunk_text.
""" """
import base64
import json import json
import logging import logging
import re import re
@@ -39,8 +40,6 @@ pytestmark = [pytest.mark.integration, pytest.mark.multi_user_basic]
def _build_basic_auth_header(username: str, password: str) -> str: def _build_basic_auth_header(username: str, password: str) -> str:
import base64
credentials = base64.b64encode(f"{username}:{password}".encode()).decode("utf-8") credentials = base64.b64encode(f"{username}:{password}".encode()).decode("utf-8")
return f"Basic {credentials}" return f"Basic {credentials}"
@@ -227,14 +226,14 @@ async def test_chunk_context_endpoint_requires_authentication():
@pytest.mark.timeout(60) @pytest.mark.timeout(60)
async def test_chunk_context_endpoint_handles_missing_app_password(): async def test_chunk_context_endpoint_rejects_invalid_bearer():
"""Bearer token for a user with no provisioned app password must produce a """A syntactically-valid-but-unverifiable bearer must not 500.
clean 401 (NotProvisionedError path), not a 500 or opaque upstream error.
We simulate "user has not provisioned" by sending a syntactically valid The NotProvisionedError path (handler reached but no stored app password)
bearer that the token verifier will reject. The exact error class doesn't is covered by the corresponding unit test. This check guards the other
matter for this check — what matters is the handler never 500s on the rejection path: token validation fails upfront at
missing-credential path. `validate_token_and_get_user`, which must turn into a clean 401/404 from
the HTTP layer, not an opaque 500.
""" """
import httpx import httpx
@@ -249,7 +248,6 @@ async def test_chunk_context_endpoint_handles_missing_app_password():
}, },
headers={"Authorization": "Bearer invalid.token.value"}, headers={"Authorization": "Bearer invalid.token.value"},
) )
# Must be 401 (unauthorized) or 404 (route guard), not 500.
assert response.status_code in (401, 404), ( assert response.status_code in (401, 404), (
f"Expected 401/404 for invalid bearer, got {response.status_code}: " f"Expected 401/404 for invalid bearer, got {response.status_code}: "
f"{response.text}" f"{response.text}"