forked from retoor/devplacepy
ticket #88 attempt 2
This commit is contained in:
@@ -177,3 +177,23 @@ def test_prestige_below_level_returns_400(app_server, seeded_db):
|
||||
_reset_farm(name)
|
||||
response = session.post(f"{BASE_URL}/game/prestige", headers=JSON)
|
||||
assert response.status_code == 400
|
||||
|
||||
|
||||
def test_rate_limit_blocks_excess_requests(app_server, seeded_db):
|
||||
session, name = _signup()
|
||||
_reset_farm(name)
|
||||
responses = []
|
||||
for _ in range(31):
|
||||
responses.append(
|
||||
session.post(f"{BASE_URL}/game/buy-plot", headers=JSON)
|
||||
)
|
||||
success_count = sum(1 for r in responses[:30] if r.status_code != 429)
|
||||
assert success_count >= 1, "expected at least one successful request"
|
||||
assert responses[-1].status_code == 429, f"expected 429 on 31st request, got {responses[-1].status_code}"
|
||||
assert "Rate limit exceeded" in responses[-1].json().get("detail", "")
|
||||
# Verify the rate limit log stored entries for the test user
|
||||
from devplacepy.database import get_table
|
||||
user = get_table("users").find_one(username=name)
|
||||
table = get_table("rate_limit_log")
|
||||
entries = list(table.find(user_uid=user["uid"]))
|
||||
assert len(entries) >= 2, f"expected rate log entries, got {len(entries)}"
|
||||
|
||||
@@ -212,3 +212,28 @@ def test_steal_cooldown_blocks_second_raid(app_server, seeded_db):
|
||||
f"{BASE_URL}/game/farm/{owner}/steal", data={"slot": 0}, headers=JSON
|
||||
)
|
||||
assert second.status_code == 400
|
||||
|
||||
|
||||
def test_harvest_plant_cooldown_blocks_rapid_replant(app_server, seeded_db):
|
||||
session, name = _signup()
|
||||
_reset_farm(name)
|
||||
# Plant and ripen a crop on slot 0
|
||||
plant = session.post(
|
||||
f"{BASE_URL}/game/plant", data={"slot": 0, "crop": "shell"}, headers=JSON
|
||||
)
|
||||
assert plant.status_code == 200
|
||||
_ripen_owner_plot(name)
|
||||
# Harvest it — this sets a 5-second cooldown on the plot
|
||||
harvest = session.post(f"{BASE_URL}/game/harvest", data={"slot": 0}, headers=JSON)
|
||||
assert harvest.status_code == 200
|
||||
# Immediately replant on the same slot — must fail
|
||||
replant = session.post(
|
||||
f"{BASE_URL}/game/plant", data={"slot": 0, "crop": "shell"}, headers=JSON
|
||||
)
|
||||
assert replant.status_code == 400
|
||||
assert "cooldown" in replant.text.lower()
|
||||
# A different slot should still work
|
||||
other = session.post(
|
||||
f"{BASE_URL}/game/plant", data={"slot": 1, "crop": "shell"}, headers=JSON
|
||||
)
|
||||
assert other.status_code == 200
|
||||
|
||||
@@ -119,3 +119,23 @@ def test_game_actions_registered_with_correct_auth():
|
||||
def test_game_read_actions_are_read_only():
|
||||
for name in ("game_state", "game_leaderboard", "game_view_farm"):
|
||||
assert BY_NAME[name].is_read_only is True
|
||||
|
||||
|
||||
def test_all_game_post_actions_require_confirm():
|
||||
mutating_game_actions = {
|
||||
"game_plant",
|
||||
"game_harvest",
|
||||
"game_buy_plot",
|
||||
"game_upgrade_ci",
|
||||
"game_water",
|
||||
"game_steal",
|
||||
"game_fertilize",
|
||||
"game_daily",
|
||||
"game_upgrade_perk",
|
||||
"game_claim_quest",
|
||||
"game_prestige",
|
||||
"game_upgrade_legacy",
|
||||
}
|
||||
for name in mutating_game_actions:
|
||||
assert name in BY_NAME, f"{name} missing from catalog"
|
||||
assert name in CONFIRM_REQUIRED, f"{name} missing from CONFIRM_REQUIRED"
|
||||
|
||||
Reference in New Issue
Block a user