light-heart-labs--dreamserver
9e8f1bbeed
Dashboard / frontend (push) Failing after 0s
Dashboard / api (push) Failing after 0s
Lint PowerShell / powershell-lint (ubuntu-latest) (push) Failing after 1s
Python Lint / Lint Python with Ruff (push) Failing after 1s
ShellCheck / Lint shell scripts (push) Failing after 1s
Matrix Smoke / linux-smoke (push) Failing after 1s
Matrix Smoke / distro: cachyos (push) Failing after 15s
Matrix Smoke / distro: linux-mint-21.3 (push) Failing after 15s
Matrix Smoke / distro: debian-12 (push) Failing after 5m21s
Matrix Smoke / distro: fedora-41 (push) Failing after 4m56s
Matrix Smoke / distro: ubuntu-24.04 (push) Failing after 2m13s
Matrix Smoke / distro: rocky-9 (push) Failing after 10m39s
Matrix Smoke / distro: manjaro (push) Failing after 12m11s
Matrix Smoke / distro: opensuse-tw (push) Failing after 11m53s
Matrix Smoke / distro: archlinux (push) Failing after 20m3s
Matrix Smoke / distro: ubuntu-22.04 (push) Failing after 13m49s
Validate .env Schema / tier-1-env-validation (push) Successful in 52s
Validate .env Schema / tier-2-env-validation (push) Successful in 44s
Validate .env Schema / tier-3-env-validation (push) Successful in 52s
Validate .env Schema / tier-4-env-validation (push) Successful in 51s
Validate Extensions Catalog / Check catalog is up-to-date (push) Failing after 9m47s
Secret Scan / Scan for secrets (push) Failing after 21m4s
Validate Docker Compose / Validate Docker Compose files (push) Has been cancelled
Python Type Check / Type check with mypy (push) Has been cancelled
Validate .env Schema / tier-0-env-validation (push) Has been cancelled
Test Linux / integration-smoke (push) Has been cancelled
Lint PowerShell / powershell-lint (windows-latest) (push) Has been cancelled
Matrix Smoke / macos-smoke (push) Has been cancelled
36 行
1.2 KiB
Python
36 行
1.2 KiB
Python
"""Tests for security.py — API key authentication."""
|
|
|
|
import pytest
|
|
|
|
from fastapi import HTTPException
|
|
from fastapi.security import HTTPAuthorizationCredentials
|
|
|
|
import security
|
|
|
|
|
|
class TestVerifyApiKey:
|
|
|
|
@pytest.fixture(autouse=True)
|
|
def _set_key(self, monkeypatch):
|
|
"""Pin the API key to a known value for testing."""
|
|
monkeypatch.setattr(security, "DASHBOARD_API_KEY", "test-secret-key-12345")
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_valid_key_returns_key(self):
|
|
creds = HTTPAuthorizationCredentials(scheme="Bearer", credentials="test-secret-key-12345")
|
|
result = await security.verify_api_key(creds)
|
|
assert result == "test-secret-key-12345"
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_invalid_key_raises_403(self):
|
|
creds = HTTPAuthorizationCredentials(scheme="Bearer", credentials="wrong-key")
|
|
with pytest.raises(HTTPException) as exc_info:
|
|
await security.verify_api_key(creds)
|
|
assert exc_info.value.status_code == 403
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_missing_credentials_raises_401(self):
|
|
with pytest.raises(HTTPException) as exc_info:
|
|
await security.verify_api_key(None)
|
|
assert exc_info.value.status_code == 401
|