Files
ad/tests/api/test_auth_truth.py
T

31 lines
1.1 KiB
Python
Raw Normal View History

2026-10-05 09:36:20 +02:00
# retoor <retoor@molodetz.nl>
import pytest
from molodetz.docs_api import all_endpoints
ENDPOINTS = [item for item in all_endpoints() if "logout" not in item["path"]]
JSON = {"Accept": "application/json"}
def _call(client, item):
path = item["probe_path"]
if item["method"] == "GET":
return client.get(path, headers=JSON)
return client.post(path, json=item["probe_body"] or {}, headers=JSON)
@pytest.mark.parametrize("item", ENDPOINTS, ids=lambda item: f"{item['method']} {item['path']}")
def test_documented_auth_matches_reality(item, anon, member, admin):
anon_status = _call(anon, item).status_code
member_status = _call(member, item).status_code
admin_status = _call(admin, item).status_code
if item["auth"] == "public":
assert anon_status not in (401, 403)
elif item["auth"] == "member":
assert anon_status in (401, 303, 302)
assert member_status not in (401, 403)
else:
assert anon_status in (401, 303, 302)
assert member_status == 403
assert admin_status not in (401, 403)