1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
from collections.abc import Generator
from unittest.mock import patch
import pytest
from fastapi.testclient import TestClient
from pygitweb.config import settings
from pygitweb.main import app
@pytest.fixture
def client() -> Generator[TestClient, None, None]:
with TestClient(app) as c:
yield c
def test_token_disabled(client: TestClient) -> None:
with patch.object(settings, "AUTH", False):
r = client.post("/token", data={"username": "a", "password": "b"})
assert r.status_code == 400
assert r.json()["detail"] == "Authentication is disabled"
def test_token_success(client: TestClient) -> None:
with (
patch.object(settings, "AUTH", True),
patch.object(settings, "ADMIN_USER", "admin"),
patch.object(settings, "ADMIN_PASSWORD", "secret"),
):
r = client.post("/token", data={"username": "admin", "password": "secret"})
assert r.status_code == 200
assert r.json() == {"access_token": "admin", "token_type": "bearer"}
def test_token_wrong_password(client: TestClient) -> None:
with (
patch.object(settings, "AUTH", True),
patch.object(settings, "ADMIN_USER", "admin"),
patch.object(settings, "ADMIN_PASSWORD", "secret"),
):
r = client.post("/token", data={"username": "admin", "password": "wrong"})
assert r.status_code == 400
def test_users_me_with_bearer(client: TestClient) -> None:
with (
patch.object(settings, "AUTH", True),
patch.object(settings, "ADMIN_USER", "admin"),
patch.object(settings, "ADMIN_PASSWORD", "secret"),
):
tok = client.post("/token", data={"username": "admin", "password": "secret"}).json()["access_token"]
r = client.get("/users/me", headers={"Authorization": f"Bearer {tok}"})
assert r.status_code == 200
assert r.json()["username"] == "admin"
def test_login_form_sets_cookie_and_users_me(client: TestClient) -> None:
with (
patch.object(settings, "AUTH", True),
patch.object(settings, "ADMIN_USER", "admin"),
patch.object(settings, "ADMIN_PASSWORD", "secret"),
):
r = client.post(
"/login",
data={"username": "admin", "password": "secret", "next": "/"},
follow_redirects=False,
)
assert r.status_code == 303
r2 = client.get("/users/me")
assert r2.status_code == 200
assert r2.json()["username"] == "admin"
def test_projectnamevalid_no_auth_required_when_auth_disabled(client: TestClient) -> None:
with patch.object(settings, "AUTH", False), patch("pygitweb.main.project_visible_in_list", return_value=False):
r = client.get("/projectnamevalid", params={"name": "newproj"})
assert r.status_code == 200
def test_projectnamevalid_401_without_credentials_when_auth_enabled(client: TestClient) -> None:
with (
patch.object(settings, "AUTH", True),
patch.object(settings, "ADMIN_USER", "admin"),
patch.object(settings, "ADMIN_PASSWORD", "secret"),
):
r = client.get("/projectnamevalid", params={"name": "newproj"})
assert r.status_code == 401
def test_projectnamevalid_ok_with_bearer_when_auth_enabled(client: TestClient) -> None:
with (
patch.object(settings, "AUTH", True),
patch.object(settings, "ADMIN_USER", "admin"),
patch.object(settings, "ADMIN_PASSWORD", "secret"),
patch("pygitweb.main.project_visible_in_list", return_value=False),
):
tok = client.post("/token", data={"username": "admin", "password": "secret"}).json()["access_token"]
r = client.get(
"/projectnamevalid",
params={"name": "newproj"},
headers={"Authorization": f"Bearer {tok}"},
)
assert r.status_code == 200