34 lines
1.3 KiB
Python
34 lines
1.3 KiB
Python
# retoor <retoor@molodetz.nl>
|
|
import pytest
|
|
|
|
from molodetz.docs_api import all_endpoints
|
|
|
|
ENDPOINTS = [item for item in all_endpoints() if "logout" not in item["path"]]
|
|
JSON = {"Accept": "application/json"}
|
|
|
|
|
|
def _call(client, item):
|
|
path = item["probe_path"]
|
|
if item["method"] == "GET":
|
|
return client.get(path, headers=JSON)
|
|
return client.post(path, json=item["probe_body"] or {}, headers=JSON)
|
|
|
|
|
|
@pytest.mark.parametrize("item", ENDPOINTS, ids=lambda item: f"{item['method']} {item['path']}")
|
|
def test_documented_auth_matches_reality(item, anon, member, admin):
|
|
anon_status = _call(anon, item).status_code
|
|
member_response = _call(member, item)
|
|
member_status = member_response.status_code
|
|
if member_status == 403 and member_response.headers.get("content-type", "").startswith("application/json"):
|
|
assert member_response.json().get("error", {}).get("code") != "terms_required"
|
|
admin_status = _call(admin, item).status_code
|
|
if item["auth"] == "public":
|
|
assert anon_status not in (401, 403)
|
|
elif item["auth"] == "member":
|
|
assert anon_status in (401, 303, 302)
|
|
assert member_status not in (401, 403)
|
|
else:
|
|
assert anon_status in (401, 303, 302)
|
|
assert member_status == 403
|
|
assert admin_status not in (401, 403)
|