Files
ad/tests/api/test_auth.py
T

36 lines
1.6 KiB
Python

# retoor <retoor@molodetz.nl>
from tests.conftest import ADMIN_PASSWORD, ADMIN_USERNAME
def test_login_wrong_password(anon):
response = anon.post("/auth/login", data={"username": ADMIN_USERNAME, "password": "verkeerd-wachtwoord"})
assert response.status_code in (400, 401, 200)
assert "session" not in "".join(response.cookies.keys()).lower() or response.status_code != 302
def test_login_and_logout(anon):
response = anon.post("/auth/login", data={"username": ADMIN_USERNAME, "password": ADMIN_PASSWORD})
assert response.status_code in (302, 303)
assert anon.get("/admin").status_code == 200
cookie = response.headers.get("set-cookie", "").lower()
assert "httponly" in cookie and "samesite=lax" in cookie
assert anon.post("/auth/logout").status_code in (302, 303)
assert anon.get("/admin").status_code in (302, 303, 401)
def test_admin_redirects_anonymous(anon):
response = anon.get("/admin")
assert response.status_code in (302, 303)
assert "/auth/login" in response.headers["location"]
def test_api_key_header(admin, anon):
key = admin.get("/profile/api-key", headers={"Accept": "application/json"}).json()["api_key"]
assert anon.get("/admin", headers={"X-API-KEY": key, "Accept": "application/json"}).status_code == 200
assert anon.get("/admin", headers={"Authorization": f"Bearer {key}", "Accept": "application/json"}).status_code == 200
def test_no_jwt_anywhere(admin):
response = admin.get("/profile/api-key", headers={"Accept": "application/json"})
assert response.json()["api_key"].count(".") == 0