Files
flowdeck/tests/test_db_advanced.py
T
bruno d125eb399e
FlowDeck CI / lint (push) Successful in 1m49s
FlowDeck CI / test (push) Successful in 21m47s
FlowDeck CI / docker (push) Successful in 1m45s
fix: A3–A8 — bloc « fallback admin » de l'audit sécurité (401 sans session, ACL, CSRF)
- A3 : helper `_require_user_id()` (401 sans session) sur profile/password/token/forge ; `PUT /api/user/password` exige `current_password` vérifié ; `/api/user` sorti de la liste CSRF exemptée
- A4 : `POST /api/v1/token` → 401 sans session, chemin legacy `user_id=0` supprimé
- A5 : CRUD membres d'espace (POST/PUT/DELETE) : session + rôle admin de l'espace (ou admin global), placeholder user créé en `is_admin=0`, GET membres sans session → 401
- A6 : `_require_view` → 404 et `_require_edit` → 401 quand il n'y a pas de session (fin du legacy single-user sur les collections)
- A7 : création ET lecture de page → 401 sans session (PermissionManager conservé) ; `/board/api/pages` sorti de `EXCLUDED_PATHS` ; header CSRF manquant ajouté sur setItemIcon (local_workspace)
- A8 : seed admin sans mot de passe codé en dur — aléatoire au premier boot loggé une fois, ou `FLOWDECK_ADMIN_PASSWORD` ; re-seed seulement si absent
- tests : client connecté par défaut via `_TestSessionAuth` (session + CSRF injectés à la volée, jamais dans le cookie jar → plus de CookieConflict), helper `anon()` sur les 40 tests d'anonymat ; 1016/1016 verts, `ruff check app tests` OK
2026-09-30 22:04:13 -04:00

164 lines
5.9 KiB
Python

"""FlowDeck — v5.3.0 tests: inline databases, database templates, property validation."""
import json
import os
import tempfile
import pytest
from conftest import login_test_client
from fastapi.testclient import TestClient
@pytest.fixture
def client():
db_file = tempfile.NamedTemporaryFile(suffix=".db", delete=False)
db_path = db_file.name
db_file.close()
os.environ["DATABASE_URL"] = f"sqlite:///{db_path}"
os.environ["APP_SECRET_KEY"] = "test-secret-for-tests"
os.environ["RATE_LIMIT_ENABLED"] = "false"
os.environ["PUBLIC_API_INSECURE_OK"] = "true"
# Point the process-wide settings singleton at OUR temp DB (xdist-safe).
from app.config import settings
settings.database_url = f"sqlite:///{db_path}"
settings.rate_limit_enabled = False
settings.public_api_insecure_ok = True
from app.db import init_db
from app.main import app
init_db()
yield login_test_client(TestClient(app))
os.unlink(db_path)
# ── Database templates ──
def test_seed_templates_available(client):
resp = client.get("/workspace/templates/database")
assert resp.status_code == 200
templates = resp.json()["templates"]
names = {t["name"] for t in templates}
assert "Project tracker" in names
assert "CRM / Contacts" in names
for t in templates:
assert t.get("icon")
def _props(client, cid):
return client.get(f"/db/{cid}/properties/api").json()["properties"]
def test_create_collection_from_template_materializes_properties(client):
resp = client.post("/db/api", json={"name": "My CRM", "template": "CRM / Contacts"})
assert resp.status_code == 200
cid = resp.json()["id"]
# Properties materialized (status + person/email etc.), title skipped
props = _props(client, cid)
names = {p["name"]: p for p in props}
assert "Email" in names
assert "Stage" in names
assert names["Stage"]["prop_type"] == "status"
assert "Title" not in names # title is the row title, not a column
def test_create_inline_database_from_template(client):
resp = client.post("/db/inline/api", json={"name": "Tasks", "template": "Task list", "parent_page_id": 1})
assert resp.status_code == 200
cid = resp.json()["id"]
assert resp.json()["is_inline"] is True
props = _props(client, cid)
names = {p["name"] for p in props}
assert {"Status", "Priority", "Due date"} <= names
def test_apply_db_template_endpoint(client):
resp = client.get("/workspace/templates/database").json()
tpl = next(t for t in resp["templates"] if t["name"] == "Project tracker")
r = client.post(f"/workspace/templates/database/{tpl['id']}/apply", json={"name": "Proj"})
assert r.status_code == 200
cid = r.json()["collection_id"]
props = _props(client, cid)
names = {p["name"] for p in props}
assert {"Status", "Priority", "Assignee"} <= names
# ── Property validation ──
def _add_collection(client, name="V"):
return client.post("/db/api", json={"name": name}).json()["id"]
def test_required_property_validation(client):
cid = _add_collection(client)
client.post(f"/db/{cid}/properties/api", json={"name": "Email", "prop_type": "email",
"validation": {"required": True}})
# Missing required → 400
r = client.post(f"/db/{cid}/pages/api", json={"title": "Row", "properties": {}})
assert r.status_code == 400
assert "required" in r.json()["detail"].lower()
# With value → ok
r = client.post(f"/db/{cid}/pages/api", json={"title": "Row", "properties": {"Email": "[email protected]"}})
assert r.status_code == 200
def test_unique_property_validation(client):
cid = _add_collection(client)
client.post(f"/db/{cid}/properties/api", json={"name": "Code", "prop_type": "text",
"validation": {"unique": True}})
client.post(f"/db/{cid}/pages/api", json={"title": "R1", "properties": {"Code": "abc"}})
# Duplicate → 400
r = client.post(f"/db/{cid}/pages/api", json={"title": "R2", "properties": {"Code": "abc"}})
assert r.status_code == 400
assert "unique" in r.json()["detail"].lower()
# Update to a duplicate also fails
pid = client.post(f"/db/{cid}/pages/api", json={"title": "R3", "properties": {"Code": "xyz"}}).json()["id"]
r = client.put(f"/db/pages/{pid}/api", json={"properties": {"Code": "abc"}})
assert r.status_code == 400
# Same row keeping its own value is allowed
r = client.put(f"/db/pages/{pid}/api", json={"properties": {"Code": "xyz"}})
assert r.status_code == 200
def test_min_max_validation(client):
cid = _add_collection(client)
client.post(f"/db/{cid}/properties/api", json={"name": "Score", "prop_type": "number",
"validation": {"min": 0, "max": 100}})
r = client.post(f"/db/{cid}/pages/api", json={"title": "R", "properties": {"Score": -5}})
assert r.status_code == 400
r = client.post(f"/db/{cid}/pages/api", json={"title": "R", "properties": {"Score": 150}})
assert r.status_code == 400
r = client.post(f"/db/{cid}/pages/api", json={"title": "R", "properties": {"Score": 50}})
assert r.status_code == 200
def test_property_validation_persisted_and_readable(client):
cid = _add_collection(client)
r = client.post(f"/db/{cid}/properties/api", json={"name": "P", "prop_type": "number",
"validation": {"min": 1, "max": 9}})
pid = r.json()["id"]
props = _props(client, cid)
p = next(x for x in props if x["id"] == pid)
assert json.loads(p["validation_json"]) == {"min": 1, "max": 9}
# ── Inline database block data (via /db collection payload) ──
def test_inline_db_collection_payload(client):
cid = _add_collection(client)
r = client.get(f"/db/{cid}/api")
assert r.status_code == 200
data = r.json()
assert data["collection"]["id"] == cid
assert "views" in data