31 lines
1.1 KiB
Python
31 lines
1.1 KiB
Python
# retoor <retoor@molodetz.nl>
|
|||
|
|
import pytest
|
||
|
|
|
||
|
|
from molodetz.docs_api import all_endpoints
|
||
|
|
|
||
|
|
ENDPOINTS = [item for item in all_endpoints() if "logout" not in item["path"]]
|
||
|
|
JSON = {"Accept": "application/json"}
|
||
|
|
|
||
|
|
|
||
|
|
def _call(client, item):
|
||
|
|
path = item["probe_path"]
|
||
|
|
if item["method"] == "GET":
|
||
|
|
return client.get(path, headers=JSON)
|
||
|
|
return client.post(path, json=item["probe_body"] or {}, headers=JSON)
|
||
|
|
|
||
|
|
|
||
|
|
@pytest.mark.parametrize("item", ENDPOINTS, ids=lambda item: f"{item['method']} {item['path']}")
|
||
|
|
def test_documented_auth_matches_reality(item, anon, member, admin):
|
||
|
|
anon_status = _call(anon, item).status_code
|
||
|
|
member_status = _call(member, item).status_code
|
||
|
|
admin_status = _call(admin, item).status_code
|
||
|
|
if item["auth"] == "public":
|
||
|
|
assert anon_status not in (401, 403)
|
||
|
|
elif item["auth"] == "member":
|
||
|
|
assert anon_status in (401, 303, 302)
|
||
|
|
assert member_status not in (401, 403)
|
||
|
|
else:
|
||
|
|
assert anon_status in (401, 303, 302)
|
||
|
|
assert member_status == 403
|
||
|
|
assert admin_status not in (401, 403)
|