Files
devplacepy/tests/api/dbapi/tables.py
T
retoor d31ccba6c1 feat: add admin/internal database API with CRUD, read-only query, and natural-language SQL endpoints
Add a new `/dbapi` router package providing a generic database API over `dataset`, restricted to admin sessions, admin API keys, and the internal gateway key. Includes:

- `tables.py`: list all tables and inspect table schemas
- `crud.py`: full CRUD operations (GET, POST, PATCH, DELETE) with soft-delete awareness, born-live inserts, `?include_deleted`, `.../restore`, and `?hard=true` purge
- `query.py`: validated read-only SELECT execution via sqlglot parsing, classification, and EXPLAIN dry-run; async query jobs with WebSocket streaming via `DbApiJobService`
- `nl.py`: natural-language-to-SQL conversion using the platform AI gateway with re-prompting until validation passes

Also register `DbApiJobService` and `PubSubService` in the service manager, add `DBAPI_DIR` to config data paths, and force cleartext `http://` connections to HTTP/1.1 in `curl_transport` to fix large request failures against uvicorn's HTTP/1.1-only internal gateway.
2026-06-14 23:00:30 +00:00

25 lines
799 B
Python

# retoor <retoor@molodetz.nl>
def test_tables_requires_auth(client):
assert client.get("/dbapi/tables").status_code == 403
def test_tables_lists_and_hides_denied(client, auth):
response = client.get("/dbapi/tables", headers=auth)
assert response.status_code == 200
names = {row["name"] for row in response.json()["tables"]}
assert "users" in names
assert "sessions" not in names
assert "password_resets" not in names
def test_schema(client, auth):
response = client.get("/dbapi/users/schema", headers=auth)
assert response.status_code == 200
assert any(column["name"] == "uid" for column in response.json()["columns"])
def test_schema_denied_table_is_404(client, auth):
assert client.get("/dbapi/sessions/schema", headers=auth).status_code == 404