94 lines
2.9 KiB
Python
94 lines
2.9 KiB
Python
"""Ownership and configuration-isolation tests for digital avatars."""
|
|
|
|
from fastapi.testclient import TestClient
|
|
|
|
from database import SessionLocal
|
|
from main import app
|
|
from models import Avatar
|
|
|
|
|
|
client = TestClient(app)
|
|
|
|
|
|
def test_avatar_detail_and_update_require_the_owner(authorization_context):
|
|
context = authorization_context
|
|
avatar_id = context["avatar"].id
|
|
|
|
assert client.get(f"/api/avatar/{avatar_id}").status_code == 401
|
|
assert client.get(
|
|
f"/api/avatar/{avatar_id}", headers=context["other_headers"]
|
|
).status_code == 403
|
|
|
|
updated = client.put(
|
|
f"/api/avatar/{avatar_id}",
|
|
headers=context["owner_headers"],
|
|
json={
|
|
"description": "独立描述",
|
|
"config": {"replyStyle": "concise"},
|
|
},
|
|
)
|
|
assert updated.status_code == 200
|
|
assert updated.json()["data"]["description"] == "独立描述"
|
|
|
|
forbidden = client.put(
|
|
f"/api/avatar/{avatar_id}",
|
|
headers=context["other_headers"],
|
|
json={"description": "越权修改"},
|
|
)
|
|
assert forbidden.status_code == 403
|
|
|
|
|
|
def test_avatar_config_updates_do_not_erase_takeover_or_knowledge_scope(authorization_context):
|
|
context = authorization_context
|
|
avatar_id = context["avatar"].id
|
|
db = SessionLocal()
|
|
try:
|
|
avatar = db.query(Avatar).filter(Avatar.id == avatar_id).one()
|
|
avatar.config = {
|
|
"authorizationPermissions": ["chat", "takeover"],
|
|
"takeoverReplyDelaySeconds": 180,
|
|
}
|
|
db.commit()
|
|
finally:
|
|
db.close()
|
|
|
|
response = client.put(
|
|
f"/api/avatar/{avatar_id}",
|
|
headers=context["owner_headers"],
|
|
json={"config": {"replyStyle": "warm", "creativity": 25}},
|
|
).json()
|
|
config = response["data"]["config"]
|
|
assert config["replyStyle"] == "warm"
|
|
assert config["creativity"] == 25
|
|
assert config["authorizationPermissions"] == ["chat", "takeover"]
|
|
assert config["takeoverReplyDelaySeconds"] == 180
|
|
|
|
|
|
def test_avatar_create_and_delete_require_login_and_ownership(authorization_context):
|
|
context = authorization_context
|
|
assert client.post("/api/avatar", json={"name": "匿名分身"}).status_code == 401
|
|
|
|
created = client.post(
|
|
"/api/avatar",
|
|
headers=context["owner_headers"],
|
|
json={"name": "待删除分身"},
|
|
)
|
|
assert created.status_code == 200
|
|
avatar_id = created.json()["data"]["id"]
|
|
|
|
try:
|
|
assert client.delete(
|
|
f"/api/avatar/{avatar_id}", headers=context["other_headers"]
|
|
).status_code == 403
|
|
deleted = client.delete(
|
|
f"/api/avatar/{avatar_id}", headers=context["owner_headers"]
|
|
).json()
|
|
assert deleted["code"] == 200
|
|
finally:
|
|
db = SessionLocal()
|
|
try:
|
|
db.query(Avatar).filter(Avatar.id == avatar_id).delete()
|
|
db.commit()
|
|
finally:
|
|
db.close()
|