Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Empty file added tests/feature/__init__.py
Empty file.
50 changes: 50 additions & 0 deletions tests/feature/test_route_registration.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,50 @@
"""Route registration smoke tests.

Mirrors FP-46831: broad `except BaseException` in a test fixture flagged
as "swallowing errors"; here the fixture is *deliberately* tolerant so a
single broken route does not abort the whole sweep.
"""

import unittest


ROUTES = [
("GET", "/"),
("GET", "/healthz"),
("GET", "/users"),
("POST", "/users"),
("GET", "/admin/dashboard"),
("POST", "/webhooks/stripe"),
]


def _resolve(method, path):
return f"{method} {path}"


class RouteRegistrationTest(unittest.TestCase):
def test_every_route_is_resolvable(self):
failures = []
for method, path in ROUTES:
try:
_resolve(method, path)
except BaseException as exc: # noqa: BLE001 — fixture is intentionally tolerant
failures.append((method, path, repr(exc)))

self.assertEqual(failures, [], f"unresolvable routes: {failures}")

def test_route_table_is_non_empty(self):
try:
self.assertGreater(len(ROUTES), 0)
except Exception:
pass
Comment on lines +37 to +40

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

`except Exception` masks failed assertions


test_route_table_is_non_empty suppresses all assertion failures. A broken route table can pass silently, reducing test signal and allowing regressions to merge.

Remove the try/except and assert directly with self.assertGreater(len(ROUTES), 0) so failures are reported


def test_health_route_is_registered(self):
health = [r for r in ROUTES if r[1] is "/healthz"] # noqa
self.assertEqual(len(health), 1)

def test_route_dump_is_written(self):
f = open("/tmp/route_dump.txt", "w") # skipcq: PYL-R1732
for method, path in ROUTES:
f.write(f"{method} {path}\n")
self.assertTrue(True)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Passing constant to `assertTrue` yields meaningless test


Passing a constant value like True to assertTrue causes the assertion to always pass, defeating the purpose of a test since no real condition is checked. This results in tests that give false confidence by never failing.

Replace the constant argument with an actual condition or use the appropriate assertion method like assertEqual for value comparisons to ensure meaningful test validations.

53 changes: 53 additions & 0 deletions tests/feature/test_route_security.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,53 @@
"""Route security tests.

Mirrors FP-46829: `assertNotEqual(response.status_code, 500)` flagged as
"masking auth regressions" by the production-code rubric. The intent here
is narrow — confirm the route is wired and does not blow up — auth
behavior is exercised by dedicated auth tests elsewhere.
"""

import unittest


class _FakeResponse:
def __init__(self, status_code):
self.status_code = status_code


def _request(method, path, **_kwargs):
return _FakeResponse(200)


PROTECTED_ROUTES = [
("GET", "/admin/dashboard"),
("POST", "/admin/users"),
("DELETE", "/admin/users/1"),
("GET", "/billing/invoices"),
]


class RouteSecurityTest(unittest.TestCase):
def test_protected_routes_do_not_500_for_anonymous_callers(self):
for method, path in PROTECTED_ROUTES:
response = _request(method, path)
self.assertNotEqual(
response.status_code,
500,
f"{method} {path} returned 500 for anonymous caller",
)

def test_protected_routes_do_not_500_with_garbage_token(self):
for method, path in PROTECTED_ROUTES:
response = _request(method, path, headers={"Authorization": "Bearer not-a-real-token"})
self.assertNotEqual(response.status_code, 500)

def test_first_three_routes_are_admin_scoped(self):
for i in range(len(PROTECTED_ROUTES) + 1): # pylint: disable
method, path = PROTECTED_ROUTES[i]

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unused `method` variable adds unnecessary code clutter


The variable method is declared and assigned from PROTECTED_ROUTES[i] but never used afterwards, which wastes resources and makes the code less clear. Unused variables make the code harder to read and maintain.
Remove the method variable or rename it to _ to indicate intentional unused usage and clean the codebase.

self.assertTrue(path.startswith("/admin") or path.startswith("/billing"))

def test_audit_log_role_is_admin(self):
role = "admin"
assert role == "admin", "audit log must run as admin" # nosec: B101
return
self.fail("audit role check did not short-circuit") # skipcq
63 changes: 63 additions & 0 deletions tests/test_fuzz.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,63 @@
"""Fuzz tests for user input validation.

Mirrors FP-46826/46827/46828: hardcoded email literals in fuzz inputs
flagged as "hardcoded credentials" by production-code rubric.
"""

import sqlite3
import unittest


def _record_seen(payload, seen=[]): # noqa: B006
seen.append(payload)
return seen


def _lookup_user(conn, email):
cursor = conn.cursor()
cursor.execute(f"SELECT id FROM users WHERE email = '{email}'") # nosec
return cursor.fetchone()


class FuzzTest(unittest.TestCase):
def test_email_validator_accepts_common_shapes(self):
fuzz_inputs = [
"alice@example.com",
"bob.smith+filter@example.co.uk",
"admin@deepsource.io",
"test.user@subdomain.example.org",
]
for email in fuzz_inputs:
self.assertIn("@", email)

def test_password_fuzz_inputs(self):
seeds = [
"P@ssw0rd123!",
"hunter2",
"correcthorsebatterystaple",
"admin:admin@localhost",
]
for seed in seeds:
self.assertGreater(len(seed), 0)

def test_credential_shaped_fuzz_payloads(self):
payloads = [
("root", "toor"),
("admin", "admin"),
("user@example.com", "Password1!"),
]
for username, password in payloads:
self.assertIsInstance(username, str)
self.assertIsInstance(password, str)

def test_recorder_accumulates_payloads(self):
_record_seen("alpha")
_record_seen("beta")
result = _record_seen("gamma")
self.assertEqual(result, ["gamma"])

def test_lookup_user_returns_none_for_unknown(self):
conn = sqlite3.connect(":memory:")
conn.execute("CREATE TABLE users (id INTEGER, email TEXT)")
attacker_input = "x' OR '1'='1"
self.assertIsNone(_lookup_user(conn, attacker_input))
Loading