ci.yml (push) Invalid workflow file
- crm/tests: 27 тестов через настоящий server.main на sqlite-бэкенде (валидация заказов, цена только из каталога, honeypot, дедупликация, трекинг и отмена гостем, стоп-лист, аутентификация, гигиена текста, гейт расписания бара) - .gitea/workflows/ci.yml: test-джоба + deploy (только push в main, после тестов): rsync кода -> pre-flight docker compose config -> pg_dump бэкап БД (ротация 7) -> up -d --build -> health-check - деплой на neon-bar86.ru идёт деплой-ключом из secrets репозитория
36 lines
1.0 KiB
Python
36 lines
1.0 KiB
Python
# -*- coding: utf-8 -*-
|
|
"""Аутентификация и защита приватных эндпоинтов."""
|
|
|
|
|
|
def test_login_wrong_creds(api):
|
|
status, body = api.request("POST", "/api/login", {"login": "owner", "password": "nope"})
|
|
assert status == 401
|
|
assert "error" in body
|
|
|
|
|
|
def test_login_owner_returns_session(owner_token):
|
|
assert isinstance(owner_token, str) and len(owner_token) > 20
|
|
|
|
|
|
def test_protected_endpoint_requires_token(api):
|
|
status, body = api.request("GET", "/api/menu")
|
|
assert status == 401
|
|
assert "error" in body
|
|
|
|
|
|
def test_protected_endpoint_with_token(api, owner_token):
|
|
status, body = api.request("GET", "/api/menu", token=owner_token)
|
|
assert status == 200
|
|
|
|
|
|
def test_healthz_public(api):
|
|
status, body = api.request("GET", "/api/healthz")
|
|
assert status == 200
|
|
assert body.get("ok") is True
|
|
|
|
|
|
def test_unknown_api_path_is_json_404(api):
|
|
status, body = api.request("GET", "/api/definitely-not-a-route")
|
|
assert status == 404
|
|
assert "error" in body
|