forked from OurHike/OurHike
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathtest_routers_wrong_way.py
More file actions
85 lines (64 loc) · 2.9 KB
/
Copy pathtest_routers_wrong_way.py
File metadata and controls
85 lines (64 loc) · 2.9 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
"""Tests for the `/wrong-way-events` router.
See ../../features/HIKER_SAFETY.md §5. The actual off-trail/wrong-direction
DETECTION is pure client-side geometry over a live GPS trace (an ephemeral
`WrongWayCheck` that is never persisted here). This endpoint's only job is
receiving a "sustained divergence confirmed" event once the client's own
detection logic decides to escalate, verifying the referenced hike actually
belongs to the caller, and accepting it. Real push delivery (APNs/FCM) is
explicitly out of scope - this endpoint's job ends at "accepted the event".
"""
import uuid
from datetime import datetime, timedelta, timezone
import jwt
from app.config import settings
from app.models.hike import Hike
from app.models.profile import Profile, Role
TEST_SECRET = settings.supabase_jwt_secret
def _make_token(user_id: str) -> str:
payload = {"sub": user_id, "exp": datetime.now(timezone.utc) + timedelta(hours=1)}
return jwt.encode(payload, TEST_SECRET, algorithm="HS256")
def _auth_headers(user_id: str) -> dict[str, str]:
return {"Authorization": f"Bearer {_make_token(user_id)}"}
def test_post_wrong_way_event_requires_authentication(client, db_session):
owner_id = str(uuid.uuid4())
owner = Profile(id=owner_id, role=Role.hiker)
db_session.add(owner)
db_session.commit()
hike = Hike(user_id=owner_id, overall_start_reference=0.0, overall_end_reference=2189.0)
db_session.add(hike)
db_session.commit()
response = client.post("/wrong-way-events", json={"hike_id": hike.id})
assert response.status_code == 401
def test_post_wrong_way_event_rejects_a_hike_that_does_not_belong_to_the_caller(client, db_session):
owner_id = str(uuid.uuid4())
owner = Profile(id=owner_id, role=Role.hiker)
other_id = str(uuid.uuid4())
other = Profile(id=other_id, role=Role.hiker)
db_session.add_all([owner, other])
db_session.commit()
hike = Hike(user_id=owner_id, overall_start_reference=0.0, overall_end_reference=2189.0)
db_session.add(hike)
db_session.commit()
response = client.post(
"/wrong-way-events",
json={"hike_id": hike.id},
headers=_auth_headers(other_id),
)
# 404, not 403 - matching hikes.py's existing "don't leak id validity to
# a non-owner" convention (see app/routers/hikes.py).
assert response.status_code == 404
def test_post_wrong_way_event_accepts_a_valid_event_for_the_callers_own_hike(client, db_session):
owner_id = str(uuid.uuid4())
owner = Profile(id=owner_id, role=Role.hiker)
db_session.add(owner)
db_session.commit()
hike = Hike(user_id=owner_id, overall_start_reference=0.0, overall_end_reference=2189.0)
db_session.add(hike)
db_session.commit()
response = client.post(
"/wrong-way-events",
json={"hike_id": hike.id},
headers=_auth_headers(owner_id),
)
assert response.status_code == 202
assert response.json()["received"] is True