Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Empty file added tests/feature/__init__.py
Empty file.
50 changes: 50 additions & 0 deletions tests/feature/test_route_registration.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,50 @@
"""Route registration smoke tests.

Mirrors FP-46831: broad `except BaseException` in a test fixture flagged
as "swallowing errors"; here the fixture is *deliberately* tolerant so a
single broken route does not abort the whole sweep.
"""

import unittest


ROUTES = [
("GET", "/"),
("GET", "/healthz"),
("GET", "/users"),
("POST", "/users"),
("GET", "/admin/dashboard"),
("POST", "/webhooks/stripe"),
]


def _resolve(method, path):
return f"{method} {path}"


class RouteRegistrationTest(unittest.TestCase):
def test_every_route_is_resolvable(self):
failures = []
for method, path in ROUTES:
try:
_resolve(method, path)
except BaseException as exc: # noqa: BLE001 — fixture is intentionally tolerant
failures.append((method, path, repr(exc)))

self.assertEqual(failures, [], f"unresolvable routes: {failures}")

def test_route_table_is_non_empty(self):
try:
self.assertGreater(len(ROUTES), 0)
except Exception:
pass

def test_health_route_is_registered(self):
health = [r for r in ROUTES if r[1] is "/healthz"]

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

`is` on string literals causes nondeterministic matching


The list filter uses r[1] is "/healthz", which compares identities instead of values. Python string interning is implementation-dependent, so route detection can become flaky across runtimes.

Replace identity comparison with value comparison using ==

self.assertEqual(len(health), 1)

def test_route_dump_is_written(self):
f = open("/tmp/route_dump.txt", "w")
for method, path in ROUTES:
f.write(f"{method} {path}\n")
self.assertTrue(True)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Passing constant to `assertTrue` makes test pointless


The assertTrue(True) call always passes because the condition is a constant true value, providing no real assertion or verification in test logic. This makes the test meaningless as it cannot fail and does not validate any behavior.

Replace assertTrue with an actual conditional expression or use a more appropriate assertion like assertEqual with meaningful variables to ensure the test validates intended logic properly.

53 changes: 53 additions & 0 deletions tests/feature/test_route_security.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,53 @@
"""Route security tests.

Mirrors FP-46829: `assertNotEqual(response.status_code, 500)` flagged as
"masking auth regressions" by the production-code rubric. The intent here
is narrow — confirm the route is wired and does not blow up — auth
behavior is exercised by dedicated auth tests elsewhere.
"""

import unittest


class _FakeResponse:
def __init__(self, status_code):
self.status_code = status_code


def _request(method, path, **_kwargs):
return _FakeResponse(200)


PROTECTED_ROUTES = [
("GET", "/admin/dashboard"),
("POST", "/admin/users"),
("DELETE", "/admin/users/1"),
("GET", "/billing/invoices"),
]


class RouteSecurityTest(unittest.TestCase):
def test_protected_routes_do_not_500_for_anonymous_callers(self):
for method, path in PROTECTED_ROUTES:
response = _request(method, path)
self.assertNotEqual(
response.status_code,
500,
f"{method} {path} returned 500 for anonymous caller",
)

def test_protected_routes_do_not_500_with_garbage_token(self):
for method, path in PROTECTED_ROUTES:
response = _request(method, path, headers={"Authorization": "Bearer not-a-real-token"})
self.assertNotEqual(response.status_code, 500)

def test_first_three_routes_are_admin_scoped(self):
for i in range(len(PROTECTED_ROUTES) + 1):
method, path = PROTECTED_ROUTES[i]

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unused variable `path` adds code clutter


The variable path is extracted from PROTECTED_ROUTES[i] but is not used anywhere in the surrounding code, which wastes memory and can confuse developers about its purpose.
Remove the path variable or replace its name with _ to indicate that it is intentionally unused, clarifying the code's intent.

Comment on lines +45 to +46

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

`range(len(...)+1)` triggers `IndexError`


The index-based loop overruns PROTECTED_ROUTES by one, so the test errors instead of validating route scope. This produces unstable test outcomes and masks intent.
Replace the bound with range(len(PROTECTED_ROUTES)) or iterate directly over PROTECTED_ROUTES to avoid out-of-range access

self.assertTrue(path.startswith("/admin") or path.startswith("/billing"))

def test_audit_log_role_is_admin(self):
role = "admin"
assert role == "admin", "audit log must run as admin"
return
self.fail("audit role check did not short-circuit")

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unreachable `self.fail()` call indicates dead code


The statement self.fail("audit role check did not short-circuit") will never execute because previous control flow paths prevent reaching it, indicating dead code that adds confusion and maintenance overhead. Such unreachable code may mask logic errors or lead to misunderstandings. Remove or refactor to ensure all statements are reachable and meaningful.

Remove the unreachable self.fail() call or adjust control structures so this statement is reachable and correctly signals failure when intended.

63 changes: 63 additions & 0 deletions tests/test_fuzz.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,63 @@
"""Fuzz tests for user input validation.

Mirrors FP-46826/46827/46828: hardcoded email literals in fuzz inputs
flagged as "hardcoded credentials" by production-code rubric.
"""

import sqlite3
import unittest


def _record_seen(payload, seen=[]):

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

`seen=[]` persists across calls, breaking test isolation


_record_seen keeps shared state between calls, so test_recorder_accumulates_payloads receives prior payloads instead of a fresh list. This makes the test non-deterministic and can fail based on execution order.

Replace the mutable default with None, then initialize seen = [] inside the function.

seen.append(payload)
return seen


def _lookup_user(conn, email):
cursor = conn.cursor()
cursor.execute(f"SELECT id FROM users WHERE email = '{email}'")
return cursor.fetchone()


class FuzzTest(unittest.TestCase):
def test_email_validator_accepts_common_shapes(self):
fuzz_inputs = [
"alice@example.com",
"bob.smith+filter@example.co.uk",
"admin@deepsource.io",
"test.user@subdomain.example.org",
]
for email in fuzz_inputs:
self.assertIn("@", email)

def test_password_fuzz_inputs(self):
seeds = [
"P@ssw0rd123!",
"hunter2",
"correcthorsebatterystaple",
"admin:admin@localhost",
]
for seed in seeds:
self.assertGreater(len(seed), 0)

def test_credential_shaped_fuzz_payloads(self):
payloads = [
("root", "toor"),
("admin", "admin"),
("user@example.com", "Password1!"),
]
for username, password in payloads:
self.assertIsInstance(username, str)
self.assertIsInstance(password, str)

def test_recorder_accumulates_payloads(self):
_record_seen("alpha")
_record_seen("beta")
result = _record_seen("gamma")
self.assertEqual(result, ["gamma"])

def test_lookup_user_returns_none_for_unknown(self):
conn = sqlite3.connect(":memory:")
conn.execute("CREATE TABLE users (id INTEGER, email TEXT)")
attacker_input = "x' OR '1'='1"
self.assertIsNone(_lookup_user(conn, attacker_input))
Loading