Files
conjurer/tests/integration/test_musician_auth.py
T
gitea 491f957315
CI / compile (pull_request) Successful in 11s
CI / unit (pull_request) Successful in 12s
CI / integration (pull_request) Successful in 11s
build / build (push) Failing after 7s
CI / compile (push) Successful in 10s
CI / unit (push) Successful in 14s
CI / integration (push) Successful in 12s
tests: retarget /clear_pr_pls auth tests after the musician/radio split
test_musician_auth.py still probed /clear_pr_pls on the musician, but that
endpoint moved to betoniarka during the split - the musician now 404s it, so
all three tests failed 404 != 401/200. This was pre-existing debt, unrelated to
the AI/share/bridge work; it just kept the integration job red.

Split the coverage to match the current architecture:
* test_musician_auth.py exercises the same auth contract (no key -> 401, key ->
  200, key unset -> open) against /get_share_list, an authenticated endpoint the
  musician still serves, with a valid body so the permitted case is a clean 200
  rather than a 400;
* new test_betoniarka_auth.py covers /clear_pr_pls where it now lives, pointing
  PRIORITY_PLAYLIST_PATH at a tmp file so the authorised case can truncate it,
  and checks /ping stays open;
* conftest.py adds conjurer_betoniarka to sys.path so the service imports.

Verified in a clean venv (pytest flask waitress requests), matching the CI
integration job: 13 passed, up from 3 failed / 6 passed. Unit suite unaffected
(23 passed).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-30 11:41:39 +02:00

48 lines
1.5 KiB
Python

"""Integration: the musician Flask service enforces the shared key on its
authenticated endpoints while leaving the open ones reachable.
/clear_pr_pls used to live here but moved to betoniarka during the
musician/radio split - its auth contract is now covered in
test_betoniarka_auth.py. These tests exercise the same contract against an
endpoint the musician still serves.
"""
import conjurer_musician as m
# An authenticated endpoint the musician still owns. The body passes the
# endpoint's own validation, so a permitted request reaches 200 rather than a
# 400 that would not distinguish auth from a bad payload.
AUTHED_ENDPOINT = "/get_share_list"
VALID_BODY = {"entries": 1, "keywords": ["conjurer"]}
def _client(key="test-secret"):
m.API_KEY = key
return m.app.test_client()
def test_authed_endpoint_rejected_without_key():
client = _client()
assert client.post(AUTHED_ENDPOINT, json=VALID_BODY).status_code == 401
def test_authed_endpoint_accepted_with_key():
client = _client()
resp = client.post(
AUTHED_ENDPOINT,
json=VALID_BODY,
headers={"X-Conjurer-Api-Key": "test-secret"},
)
assert resp.status_code == 200
def test_mp3_list_is_open():
client = _client()
resp = client.get("/mp3")
assert resp.status_code == 200
assert "music_file_list" in resp.get_json()
def test_open_when_key_unset():
client = _client(key=None)
assert client.post(AUTHED_ENDPOINT, json=VALID_BODY).status_code == 200