Files
hermes-agent/tests/hermes_cli/test_dashboard_oauth_endpoints_server_gate.py
T
Teknium 6b81590c55 test: prune low-value tests suite-wide (wave 1) — 46,820 → 28,106 test functions
Systematic prune per AGENTS.md test policy, one pass over every major
test tree (gateway, hermes_cli, tools, agent, run_agent, plugins, cli,
cron, tui_gateway, honcho/openviking, root-level):

- DELETE: source-reading tests (read_text/getsource on prod files),
  change-detector tests (exact catalog counts, model-name snapshots,
  config version literals), mock-echo tests (assert a mock returns what
  it was told), assertion-free/trivial tests, near-duplicate
  parametrizations (boundaries + one representative kept), async/sync
  twin duplicates, cosmetic within-file variations.
- KEEP (mandatory): security/redaction/approval guards, message-role
  alternation invariants, prompt-caching/deterministic-call-id
  invariants, issue-number regression tests (deduped), E2E tests.
- 6 test files deleted outright (script-style/no-assert or fully
  redundant); conftest.py, fakes/, fixtures/ untouched.
- tests/acp/conftest.py added: autouse fixture stubs the live
  models.dev/GitHub/Copilot/Anthropic inventory fetches that ACP server
  tests performed on every session create — test_server.py 147s → 3.4s,
  and the tests are now genuinely hermetic.
- Sleep-based slowness shrunk where safe (codex_ttfb_watchdog,
  compression_concurrent_fork, etc.); no wall-clock assertion tightened.

Verification: full hermetic suite via scripts/run_tests.sh —
2439 files, 31,130 tests passed, 0 failed, 0 flaky retries, 315s wall
(baseline: 583s wall, 13,564s subprocess CPU).
2026-07-29 13:10:23 -07:00

56 lines
2.3 KiB
Python

"""Regression guard for PR #61281 (mobile/hosted dashboard OAuth).
The PR removed the *client-side* ``X-Hermes-Session-Token`` requirement from
the dashboard OAuth mutation calls (``web/src/lib/api.ts``) so that
cookie-authenticated hosted/mobile sessions can start provider logins. The
safety of that change rests entirely on the *server* still gating those
endpoints: in gated mode the ``gated_auth_middleware`` verifies the session
cookie before the handler runs, and ``_require_token`` defers to it.
These tests pin that server-side gate for the exact endpoints whose
client-side token gate was removed. Without them, a future change that
re-broke ``_require_token``'s gated-mode branch (e.g. letting it fall through
without a session) would still pass the PR's ``api.test.ts`` suite, because
those tests only mock ``fetch`` and never touch the server.
"""
import pytest
from fastapi.testclient import TestClient
from hermes_cli import web_server
from hermes_cli.dashboard_auth import clear_providers, register_provider
from tests.hermes_cli.conftest_dashboard_auth import StubAuthProvider
@pytest.fixture
def gated_app():
"""A gated (``auth_required``) dashboard with no session cookie set."""
clear_providers()
register_provider(StubAuthProvider())
prev_host = getattr(web_server.app.state, "bound_host", None)
prev_port = getattr(web_server.app.state, "bound_port", None)
prev_required = getattr(web_server.app.state, "auth_required", None)
web_server.app.state.bound_host = "fly-app.fly.dev"
web_server.app.state.bound_port = 443
web_server.app.state.auth_required = True
client = TestClient(web_server.app, base_url="https://fly-app.fly.dev")
yield client
clear_providers()
web_server.app.state.bound_host = prev_host
web_server.app.state.bound_port = prev_port
web_server.app.state.auth_required = prev_required
class TestOAuthMutationEndpointsGatedWithoutCookie:
"""No cookie in gated mode -> 401 on every endpoint whose client-side
session-token gate PR #61281 removed."""
def test_env_reveal_requires_cookie(self, gated_app):
r = gated_app.post("/api/env/reveal", json={"key": "OPENAI_API_KEY"})
assert r.status_code == 401
def test_oauth_cancel_session_requires_cookie(self, gated_app):
r = gated_app.delete("/api/providers/oauth/sessions/sid")
assert r.status_code == 401