62 lines
2.1 KiB
Python
62 lines
2.1 KiB
Python
from fastapi.testclient import TestClient
|
|
|
|
from tests.conftest import csrf_headers
|
|
|
|
|
|
def test_tokens_are_retrievable_and_revocable(initialized_client: TestClient) -> None:
|
|
client = initialized_client
|
|
response = client.post(
|
|
"/api/v1/tokens",
|
|
json={"name": "Codex", "access_mode": "read_write"},
|
|
headers=csrf_headers(client),
|
|
)
|
|
assert response.status_code == 201
|
|
created = response.json()
|
|
assert created["token"].startswith("mcp_")
|
|
|
|
listed = client.get("/api/v1/tokens").json()
|
|
assert len(listed) == 1
|
|
assert listed[0]["token"] is None
|
|
|
|
revealed = client.get(f"/api/v1/tokens/{created['id']}/reveal").json()
|
|
assert revealed["token"] == created["token"]
|
|
|
|
assert client.post(f"/api/v1/tokens/{created['id']}/revoke").status_code == 403
|
|
revoked = client.post(f"/api/v1/tokens/{created['id']}/revoke", headers=csrf_headers(client))
|
|
assert revoked.status_code == 200
|
|
assert revoked.json()["revoked"] is True
|
|
|
|
|
|
def test_token_creation_requires_session_and_csrf(client: TestClient) -> None:
|
|
assert client.post("/api/v1/tokens", json={"name": "No session"}).status_code == 401
|
|
|
|
|
|
def test_all_profiles_token_is_explicit_and_exclusive(initialized_client: TestClient) -> None:
|
|
client = initialized_client
|
|
created = client.post(
|
|
"/api/v1/tokens",
|
|
json={"name": "Personal archive", "access_mode": "read_write", "all_profiles": True},
|
|
headers=csrf_headers(client),
|
|
)
|
|
assert created.status_code == 201
|
|
assert created.json()["all_profiles"] is True
|
|
assert created.json()["usage_profile_id"] is None
|
|
assert client.get("/api/v1/tokens").json()[0]["all_profiles"] is True
|
|
|
|
profile = client.post(
|
|
"/api/v1/curation/profiles",
|
|
json={"name": "Focused"},
|
|
headers=csrf_headers(client),
|
|
).json()
|
|
invalid = client.post(
|
|
"/api/v1/tokens",
|
|
json={
|
|
"name": "Invalid scope",
|
|
"access_mode": "read_write",
|
|
"all_profiles": True,
|
|
"usage_profile_id": profile["id"],
|
|
},
|
|
headers=csrf_headers(client),
|
|
)
|
|
assert invalid.status_code == 422
|