# retoor import uuid import requests from tests.conftest import BASE_URL def _session_push(): s = requests.Session() name = f"push_{uuid.uuid4().hex[:10]}" s.post( f"{BASE_URL}/auth/signup", data={ "username": name, "email": f"{name}@test.dev", "password": "secret123", "confirm_password": "secret123", }, allow_redirects=True, ) return s def test_public_key_endpoint(app_server): r = requests.get(f"{BASE_URL}/push.json") assert r.status_code == 200 assert r.json().get("publicKey") def test_register_requires_auth(app_server): r = requests.post( f"{BASE_URL}/push.json", json={ "endpoint": "https://push.example.com/anon", "keys": {"p256dh": "key", "auth": "auth"}, }, allow_redirects=False, ) assert r.status_code == 401 def test_register_success(app_server): s = _session_push() r = s.post( f"{BASE_URL}/push.json", json={ "endpoint": "https://push.example.com/sub-1", "keys": {"p256dh": "p256dh_fake", "auth": "auth_fake"}, }, ) assert r.status_code == 200, r.text assert r.json().get("registered") is True def test_register_missing_keys_rejected(app_server): s = _session_push() r = s.post(f"{BASE_URL}/push.json", json={"endpoint": "https://push.example.com/x"}) assert r.status_code == 400 def test_register_invalid_json_rejected(app_server): s = _session_push() r = s.post( f"{BASE_URL}/push.json", data="not-json", headers={"Content-Type": "application/json"}, ) assert r.status_code == 400 def test_public_key_endpoint_lists_providers(app_server): r = requests.get(f"{BASE_URL}/push.json") assert r.status_code == 200 body = r.json() assert body["publicKey"] assert body["providers"]["webpush"]["publicKey"] == body["publicKey"] def test_register_accepts_an_explicit_webpush_provider(app_server): s = _session_push() r = s.post( f"{BASE_URL}/push.json", json={ "provider": "webpush", "endpoint": "https://push.example.com/explicit", "keys": {"p256dh": "p256dh_fake", "auth": "auth_fake"}, }, ) assert r.status_code == 200, r.text assert r.json().get("registered") is True def test_register_is_idempotent_for_the_same_subscription(app_server): s = _session_push() body = { "endpoint": "https://push.example.com/idempotent", "keys": {"p256dh": "p256dh_fake", "auth": "auth_fake"}, } assert s.post(f"{BASE_URL}/push.json", json=body).status_code == 200 assert s.post(f"{BASE_URL}/push.json", json=body).status_code == 200 def test_register_unknown_provider_rejected(app_server): s = _session_push() r = s.post( f"{BASE_URL}/push.json", json={"provider": "carrier-pigeon", "token": "a" * 64}, ) assert r.status_code == 400 def test_register_apns_rejected_while_unconfigured(app_server): s = _session_push() r = s.post(f"{BASE_URL}/push.json", json={"provider": "apns", "token": "a" * 64}) assert r.status_code == 400 def test_register_non_object_body_rejected(app_server): s = _session_push() r = s.post(f"{BASE_URL}/push.json", json=["nope"]) assert r.status_code == 400