feat(avatar): complete authorization management
This commit is contained in:
@@ -1,6 +1,8 @@
|
||||
import uuid
|
||||
|
||||
import pytest
|
||||
from database import init_db, SessionLocal
|
||||
from models import Authorization
|
||||
from models import Authorization, Avatar, User
|
||||
|
||||
|
||||
@pytest.fixture(scope="session", autouse=True)
|
||||
@@ -24,3 +26,72 @@ def setup_database():
|
||||
db.commit()
|
||||
finally:
|
||||
db.close()
|
||||
|
||||
|
||||
@pytest.fixture
|
||||
def authorization_context():
|
||||
"""Create isolated users, avatars, and one authorization for API tests."""
|
||||
suffix = uuid.uuid4().hex
|
||||
owner = User(
|
||||
id=f"owner-{suffix}",
|
||||
huihui_user_id=f"huihui-owner-{suffix}",
|
||||
nickname="授权测试用户",
|
||||
app_token=f"owner-token-{suffix}",
|
||||
)
|
||||
other = User(
|
||||
id=f"other-{suffix}",
|
||||
huihui_user_id=f"huihui-other-{suffix}",
|
||||
nickname="其他用户",
|
||||
app_token=f"other-token-{suffix}",
|
||||
)
|
||||
avatar = Avatar(
|
||||
id=f"avatar-{suffix}",
|
||||
owner_id=owner.huihui_user_id,
|
||||
name="授权测试分身",
|
||||
status="active",
|
||||
config={},
|
||||
)
|
||||
other_avatar = Avatar(
|
||||
id=f"other-avatar-{suffix}",
|
||||
owner_id=other.huihui_user_id,
|
||||
name="其他分身",
|
||||
status="active",
|
||||
config={},
|
||||
)
|
||||
authorization = Authorization(
|
||||
id=f"authorization-{suffix}",
|
||||
avatar_id=avatar.id,
|
||||
target_type="user",
|
||||
target_id=f"contact-{suffix}",
|
||||
target_name="测试联系人",
|
||||
permissions=["chat", "browse"],
|
||||
status="active",
|
||||
)
|
||||
|
||||
db = SessionLocal()
|
||||
try:
|
||||
db.add_all([owner, other, avatar, other_avatar, authorization])
|
||||
db.commit()
|
||||
yield {
|
||||
"owner": owner,
|
||||
"other": other,
|
||||
"avatar": avatar,
|
||||
"other_avatar": other_avatar,
|
||||
"authorization": authorization,
|
||||
"owner_headers": {"Authorization": f"Bearer {owner.app_token}"},
|
||||
"other_headers": {"Authorization": f"Bearer {other.app_token}"},
|
||||
"suffix": suffix,
|
||||
}
|
||||
finally:
|
||||
db.rollback()
|
||||
db.query(Authorization).filter(
|
||||
Authorization.avatar_id.in_([avatar.id, other_avatar.id])
|
||||
).delete(synchronize_session=False)
|
||||
db.query(Avatar).filter(Avatar.id.in_([avatar.id, other_avatar.id])).delete(
|
||||
synchronize_session=False
|
||||
)
|
||||
db.query(User).filter(User.id.in_([owner.id, other.id])).delete(
|
||||
synchronize_session=False
|
||||
)
|
||||
db.commit()
|
||||
db.close()
|
||||
|
||||
@@ -0,0 +1,94 @@
|
||||
from fastapi.testclient import TestClient
|
||||
|
||||
from main import app
|
||||
|
||||
|
||||
client = TestClient(app)
|
||||
|
||||
|
||||
def test_authorization_list_is_scoped_to_owned_avatar(authorization_context):
|
||||
context = authorization_context
|
||||
response = client.get(
|
||||
f"/api/avatar/{context['avatar'].id}/authorizations",
|
||||
headers=context["owner_headers"],
|
||||
)
|
||||
assert response.status_code == 200
|
||||
payload = response.json()
|
||||
assert payload["code"] == 200
|
||||
assert [item["id"] for item in payload["data"]] == [context["authorization"].id]
|
||||
|
||||
forbidden = client.get(
|
||||
f"/api/avatar/{context['other_avatar'].id}/authorizations",
|
||||
headers=context["owner_headers"],
|
||||
)
|
||||
assert forbidden.status_code == 403
|
||||
|
||||
|
||||
def test_create_update_and_delete_authorization(authorization_context):
|
||||
context = authorization_context
|
||||
avatar_id = context["avatar"].id
|
||||
target_id = f"new-contact-{context['suffix']}"
|
||||
created = client.post(
|
||||
f"/api/avatar/{avatar_id}/authorizations",
|
||||
headers=context["owner_headers"],
|
||||
json={
|
||||
"targetType": "user",
|
||||
"targetId": target_id,
|
||||
"targetName": "新联系人",
|
||||
"permissions": ["friend", "chat", "browse"],
|
||||
},
|
||||
).json()
|
||||
assert created["code"] == 200
|
||||
authorization_id = created["data"]["id"]
|
||||
assert created["data"]["permissions"] == ["friend", "chat", "browse"]
|
||||
|
||||
duplicate = client.post(
|
||||
f"/api/avatar/{avatar_id}/authorizations",
|
||||
headers=context["owner_headers"],
|
||||
json={
|
||||
"targetType": "user",
|
||||
"targetId": target_id,
|
||||
"targetName": "重复联系人",
|
||||
"permissions": ["chat"],
|
||||
},
|
||||
).json()
|
||||
assert duplicate["code"] == 409
|
||||
|
||||
updated = client.put(
|
||||
f"/api/avatar/{avatar_id}/authorizations",
|
||||
headers=context["owner_headers"],
|
||||
json={
|
||||
"id": authorization_id,
|
||||
"targetName": "联系人新名称",
|
||||
"permissions": ["interact", "publish"],
|
||||
},
|
||||
).json()
|
||||
assert updated["code"] == 200
|
||||
assert updated["data"]["targetName"] == "联系人新名称"
|
||||
assert updated["data"]["permissions"] == ["publish", "interact"]
|
||||
|
||||
deleted = client.delete(
|
||||
f"/api/avatar/{avatar_id}/authorizations/{authorization_id}",
|
||||
headers=context["owner_headers"],
|
||||
).json()
|
||||
assert deleted["code"] == 200
|
||||
assert deleted["data"]["id"] == authorization_id
|
||||
|
||||
|
||||
def test_authorization_requires_login_and_rejects_unknown_permissions(authorization_context):
|
||||
context = authorization_context
|
||||
avatar_id = context["avatar"].id
|
||||
no_session = client.get(f"/api/avatar/{avatar_id}/authorizations")
|
||||
assert no_session.status_code == 401
|
||||
|
||||
invalid = client.post(
|
||||
f"/api/avatar/{avatar_id}/authorizations",
|
||||
headers=context["owner_headers"],
|
||||
json={
|
||||
"targetType": "user",
|
||||
"targetId": "invalid-target",
|
||||
"targetName": "无效权限",
|
||||
"permissions": ["admin"],
|
||||
},
|
||||
).json()
|
||||
assert invalid["code"] == 400
|
||||
@@ -1,105 +1,125 @@
|
||||
"""Tests for PUT /api/avatar/{avatar_id}/authorizations/takeover endpoint."""
|
||||
"""Tests for the authorization takeover configuration endpoint."""
|
||||
|
||||
from fastapi.testclient import TestClient
|
||||
|
||||
from database import SessionLocal
|
||||
from main import app
|
||||
from database import SessionLocal, Base, engine
|
||||
from models import Authorization, Avatar
|
||||
from models import Authorization
|
||||
|
||||
|
||||
def setup_test_db():
|
||||
Base.metadata.create_all(bind=engine)
|
||||
client = TestClient(app)
|
||||
|
||||
|
||||
def test_update_takeover_accepts_camel_case_and_persists(authorization_context):
|
||||
context = authorization_context
|
||||
response = client.put(
|
||||
f"/api/avatar/{context['avatar'].id}/authorizations/takeover",
|
||||
headers=context["owner_headers"],
|
||||
json={
|
||||
"authorizationId": context["authorization"].id,
|
||||
"takeoverEnabled": True,
|
||||
"takeoverMode": "delayed",
|
||||
"takeoverDelaySeconds": 60,
|
||||
},
|
||||
)
|
||||
assert response.status_code == 200
|
||||
payload = response.json()
|
||||
assert payload["code"] == 200
|
||||
assert payload["data"]["takeoverEnabled"] is True
|
||||
assert payload["data"]["takeoverMode"] == "delayed"
|
||||
assert payload["data"]["takeoverDelaySeconds"] == 60
|
||||
assert "takeover" in payload["data"]["permissions"]
|
||||
|
||||
db = SessionLocal()
|
||||
avatar = Avatar(name="test", status="active", config={})
|
||||
db.add(avatar)
|
||||
db.commit()
|
||||
db.refresh(avatar)
|
||||
auth = Authorization(avatar_id=avatar.id, target_id="user1", target_name="测试用户")
|
||||
db.add(auth)
|
||||
db.commit()
|
||||
db.refresh(auth)
|
||||
return db, auth.id
|
||||
|
||||
|
||||
def test_update_takeover_config():
|
||||
db, auth_id = setup_test_db()
|
||||
try:
|
||||
client = TestClient(app)
|
||||
response = client.put(
|
||||
f"/api/avatar/test_avatar_id/authorizations/takeover",
|
||||
json={
|
||||
"authorization_id": auth_id,
|
||||
"takeover_enabled": True,
|
||||
"takeover_mode": "delayed",
|
||||
"takeover_delay_seconds": 60,
|
||||
},
|
||||
)
|
||||
assert response.status_code == 200
|
||||
data = response.json()
|
||||
assert data["code"] == 200
|
||||
assert data["data"]["takeoverEnabled"] is True
|
||||
assert data["data"]["takeoverMode"] == "delayed"
|
||||
assert data["data"]["takeoverDelaySeconds"] == 60
|
||||
# 验证数据库已更新
|
||||
auth = db.query(Authorization).filter(Authorization.id == auth_id).first()
|
||||
assert auth.takeover_enabled is True
|
||||
assert auth.takeover_mode == "delayed"
|
||||
assert auth.takeover_delay_seconds == 60
|
||||
stored = db.query(Authorization).filter(
|
||||
Authorization.id == context["authorization"].id
|
||||
).first()
|
||||
assert stored.takeover_enabled is True
|
||||
assert stored.takeover_mode == "delayed"
|
||||
assert stored.takeover_delay_seconds == 60
|
||||
finally:
|
||||
db.close()
|
||||
|
||||
|
||||
def test_update_takeover_invalid_mode():
|
||||
db, auth_id = setup_test_db()
|
||||
try:
|
||||
client = TestClient(app)
|
||||
response = client.put(
|
||||
f"/api/avatar/test/authorizations/takeover",
|
||||
json={
|
||||
"authorization_id": auth_id,
|
||||
"takeover_mode": "invalid_mode",
|
||||
},
|
||||
)
|
||||
assert response.status_code == 200
|
||||
data = response.json()
|
||||
assert data["code"] == 400
|
||||
finally:
|
||||
db.close()
|
||||
|
||||
|
||||
def test_update_takeover_invalid_delay():
|
||||
db, auth_id = setup_test_db()
|
||||
try:
|
||||
client = TestClient(app)
|
||||
response = client.put(
|
||||
f"/api/avatar/test/authorizations/takeover",
|
||||
json={
|
||||
"authorization_id": auth_id,
|
||||
"takeover_delay_seconds": 2,
|
||||
},
|
||||
)
|
||||
assert response.status_code == 200
|
||||
data = response.json()
|
||||
assert data["code"] == 400
|
||||
finally:
|
||||
db.close()
|
||||
|
||||
|
||||
def test_update_takeover_missing_auth_id():
|
||||
client = TestClient(app)
|
||||
response = client.put(
|
||||
f"/api/avatar/test/authorizations/takeover",
|
||||
json={"takeover_enabled": True},
|
||||
def test_disabling_authorization_also_disables_takeover(authorization_context):
|
||||
context = authorization_context
|
||||
endpoint = f"/api/avatar/{context['avatar'].id}/authorizations/takeover"
|
||||
client.put(
|
||||
endpoint,
|
||||
headers=context["owner_headers"],
|
||||
json={
|
||||
"authorizationId": context["authorization"].id,
|
||||
"takeoverEnabled": True,
|
||||
},
|
||||
)
|
||||
assert response.status_code == 200
|
||||
data = response.json()
|
||||
assert data["code"] == 400
|
||||
|
||||
updated = client.put(
|
||||
f"/api/avatar/{context['avatar'].id}/authorizations",
|
||||
headers=context["owner_headers"],
|
||||
json={"id": context["authorization"].id, "status": "inactive"},
|
||||
).json()
|
||||
assert updated["code"] == 200
|
||||
assert updated["data"]["status"] == "inactive"
|
||||
assert updated["data"]["takeoverEnabled"] is False
|
||||
assert "takeover" not in updated["data"]["permissions"]
|
||||
|
||||
|
||||
def test_update_takeover_not_found():
|
||||
client = TestClient(app)
|
||||
response = client.put(
|
||||
f"/api/avatar/test/authorizations/takeover",
|
||||
json={"authorization_id": "nonexistent"},
|
||||
def test_takeover_rejects_invalid_values_and_cross_avatar_access(authorization_context):
|
||||
context = authorization_context
|
||||
endpoint = f"/api/avatar/{context['avatar'].id}/authorizations/takeover"
|
||||
|
||||
invalid_mode = client.put(
|
||||
endpoint,
|
||||
headers=context["owner_headers"],
|
||||
json={
|
||||
"authorization_id": context["authorization"].id,
|
||||
"takeover_mode": "invalid",
|
||||
},
|
||||
).json()
|
||||
assert invalid_mode["code"] == 400
|
||||
|
||||
invalid_delay = client.put(
|
||||
endpoint,
|
||||
headers=context["owner_headers"],
|
||||
json={
|
||||
"authorization_id": context["authorization"].id,
|
||||
"takeover_delay_seconds": 2,
|
||||
},
|
||||
).json()
|
||||
assert invalid_delay["code"] == 400
|
||||
|
||||
forbidden = client.put(
|
||||
endpoint,
|
||||
headers=context["other_headers"],
|
||||
json={
|
||||
"authorizationId": context["authorization"].id,
|
||||
"takeoverEnabled": True,
|
||||
},
|
||||
)
|
||||
assert response.status_code == 200
|
||||
data = response.json()
|
||||
assert data["code"] == 404
|
||||
assert forbidden.status_code == 403
|
||||
|
||||
|
||||
def test_takeover_is_limited_to_active_user_authorizations(authorization_context):
|
||||
context = authorization_context
|
||||
avatar_id = context["avatar"].id
|
||||
created = client.post(
|
||||
f"/api/avatar/{avatar_id}/authorizations",
|
||||
headers=context["owner_headers"],
|
||||
json={
|
||||
"targetType": "organization",
|
||||
"targetId": f"org-{context['suffix']}",
|
||||
"targetName": "测试组织",
|
||||
"permissions": ["chat"],
|
||||
},
|
||||
).json()
|
||||
response = client.put(
|
||||
f"/api/avatar/{avatar_id}/authorizations/takeover",
|
||||
headers=context["owner_headers"],
|
||||
json={
|
||||
"authorizationId": created["data"]["id"],
|
||||
"takeoverEnabled": True,
|
||||
},
|
||||
).json()
|
||||
assert response["code"] == 400
|
||||
assert "单聊接管" in response["message"]
|
||||
|
||||
@@ -192,7 +192,7 @@ async def test_process_message_delayed_mode(mock_db, mock_boxim, mock_auth):
|
||||
|
||||
mock_auth.takeover_mode = "delayed"
|
||||
|
||||
service = TakeoverService(mock_db, mock_boxim)
|
||||
service = TakeoverService(mock_db, mock_boxim, MagicMock())
|
||||
service.check_takeover_enabled = MagicMock(return_value=mock_auth)
|
||||
service.execute_takeover = AsyncMock()
|
||||
service.enqueue_delayed_message = MagicMock()
|
||||
@@ -204,6 +204,24 @@ async def test_process_message_delayed_mode(mock_db, mock_boxim, mock_auth):
|
||||
service.execute_takeover.assert_not_awaited()
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_process_message_delayed_mode_without_redis_falls_back_immediately(mock_db, mock_boxim, mock_auth):
|
||||
"""A missing Redis connection must not silently drop delayed replies."""
|
||||
from services.takeover_service import TakeoverService
|
||||
|
||||
mock_auth.takeover_mode = "delayed"
|
||||
service = TakeoverService(mock_db, mock_boxim)
|
||||
service.check_takeover_enabled = MagicMock(return_value=mock_auth)
|
||||
service.execute_takeover = AsyncMock(return_value=True)
|
||||
service.enqueue_delayed_message = MagicMock()
|
||||
|
||||
message = {"owner_huihui_id": "owner_1", "from_accid": "user_1", "content": "hi"}
|
||||
await service.process_message(message)
|
||||
|
||||
service.execute_takeover.assert_awaited_once_with(mock_auth, message)
|
||||
service.enqueue_delayed_message.assert_not_called()
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_process_message_no_takeover(mock_db, mock_boxim):
|
||||
"""When takeover is not enabled, nothing should happen."""
|
||||
|
||||
@@ -27,6 +27,9 @@ def mock_auth():
|
||||
auth.takeover_delay_seconds = 30
|
||||
auth.avatar_id = "avatar_123"
|
||||
auth.target_id = "target_user_123"
|
||||
auth.target_type = "user"
|
||||
auth.status = "active"
|
||||
auth.permissions = ["chat", "takeover"]
|
||||
return auth
|
||||
|
||||
|
||||
@@ -83,6 +86,7 @@ def test_check_takeover_enabled_returns_none_when_disabled(mock_db, mock_boxim,
|
||||
|
||||
disabled_auth = MagicMock(spec=Authorization)
|
||||
disabled_auth.takeover_enabled = False
|
||||
disabled_auth.permissions = []
|
||||
auth_filter = MagicMock()
|
||||
auth_filter.filter.return_value = auth_filter
|
||||
auth_filter.first.return_value = disabled_auth
|
||||
|
||||
Reference in New Issue
Block a user