"""Ownership and configuration-isolation tests for digital avatars.""" from fastapi.testclient import TestClient from database import SessionLocal from main import app from models import Avatar client = TestClient(app) def test_avatar_detail_and_update_require_the_owner(authorization_context): context = authorization_context avatar_id = context["avatar"].id assert client.get(f"/api/avatar/{avatar_id}").status_code == 401 assert client.get( f"/api/avatar/{avatar_id}", headers=context["other_headers"] ).status_code == 403 updated = client.put( f"/api/avatar/{avatar_id}", headers=context["owner_headers"], json={ "description": "独立描述", "config": {"replyStyle": "concise"}, }, ) assert updated.status_code == 200 assert updated.json()["data"]["description"] == "独立描述" forbidden = client.put( f"/api/avatar/{avatar_id}", headers=context["other_headers"], json={"description": "越权修改"}, ) assert forbidden.status_code == 403 def test_avatar_config_updates_do_not_erase_takeover_or_knowledge_scope(authorization_context): context = authorization_context avatar_id = context["avatar"].id db = SessionLocal() try: avatar = db.query(Avatar).filter(Avatar.id == avatar_id).one() avatar.config = { "authorizationPermissions": ["chat", "takeover"], "takeoverReplyDelaySeconds": 180, } db.commit() finally: db.close() response = client.put( f"/api/avatar/{avatar_id}", headers=context["owner_headers"], json={"config": {"replyStyle": "warm", "creativity": 25}}, ).json() config = response["data"]["config"] assert config["replyStyle"] == "warm" assert config["creativity"] == 25 assert config["authorizationPermissions"] == ["chat", "takeover"] assert config["takeoverReplyDelaySeconds"] == 180 def test_avatar_create_and_delete_require_login_and_ownership(authorization_context): context = authorization_context assert client.post("/api/avatar", json={"name": "匿名分身"}).status_code == 401 created = client.post( "/api/avatar", headers=context["owner_headers"], json={"name": "待删除分身"}, ) assert created.status_code == 200 avatar_id = created.json()["data"]["id"] try: assert client.delete( f"/api/avatar/{avatar_id}", headers=context["other_headers"] ).status_code == 403 deleted = client.delete( f"/api/avatar/{avatar_id}", headers=context["owner_headers"] ).json() assert deleted["code"] == 200 finally: db = SessionLocal() try: db.query(Avatar).filter(Avatar.id == avatar_id).delete() db.commit() finally: db.close()