from fastapi.testclient import TestClient from tests.conftest import csrf_headers def test_tokens_are_retrievable_and_revocable(initialized_client: TestClient) -> None: client = initialized_client response = client.post( "/api/v1/tokens", json={"name": "Codex", "access_mode": "read_write"}, headers=csrf_headers(client), ) assert response.status_code == 201 created = response.json() assert created["token"].startswith("mcp_") listed = client.get("/api/v1/tokens").json() assert len(listed) == 1 assert listed[0]["token"] is None revealed = client.get(f"/api/v1/tokens/{created['id']}/reveal").json() assert revealed["token"] == created["token"] assert client.post(f"/api/v1/tokens/{created['id']}/revoke").status_code == 403 revoked = client.post(f"/api/v1/tokens/{created['id']}/revoke", headers=csrf_headers(client)) assert revoked.status_code == 200 assert revoked.json()["revoked"] is True def test_token_creation_requires_session_and_csrf(client: TestClient) -> None: assert client.post("/api/v1/tokens", json={"name": "No session"}).status_code == 401 def test_all_profiles_token_is_explicit_and_exclusive(initialized_client: TestClient) -> None: client = initialized_client created = client.post( "/api/v1/tokens", json={"name": "Personal archive", "access_mode": "read_write", "all_profiles": True}, headers=csrf_headers(client), ) assert created.status_code == 201 assert created.json()["all_profiles"] is True assert created.json()["usage_profile_id"] is None assert client.get("/api/v1/tokens").json()[0]["all_profiles"] is True profile = client.post( "/api/v1/curation/profiles", json={"name": "Focused"}, headers=csrf_headers(client), ).json() invalid = client.post( "/api/v1/tokens", json={ "name": "Invalid scope", "access_mode": "read_write", "all_profiles": True, "usage_profile_id": profile["id"], }, headers=csrf_headers(client), ) assert invalid.status_code == 422