test(mqtt-auth): cover /mqtt/auth/user and /mqtt/auth/acl
First pytest suite in the backend (backend/tests/, run from backend/ with `python -m pytest tests`). firebase_admin.verify_id_token and Firestore are mocked, so no network access is needed. 82 cases: - /user devices: HMAC ok / wrong / other serial's HMAC, kiosk HMAC, legacy password with flag on/off, legacy rejected for non-device-shaped usernames and for app_ users, HMAC rejected for app_ users, legacy-login log rate limiting. - /user app users: valid token (asserts check_revoked=True), token for a different uid, revoked, expired, blocked user, unknown uid, empty uid, and that a denied token never appears in logs. - /acl app users: acc 1/2/4 allow/deny per topic, unsupported acc values, wildcards, foreign serial, malformed topics, wrong clientid prefixes (incl. uid-prefix collision), blocked/unknown users, cache hit + invalidate, cache expiry. - /acl devices/kiosk/superuser: unchanged behaviour. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,5 @@
|
||||
import sys
|
||||
from pathlib import Path
|
||||
|
||||
# Tests import backend modules the same way the app does (cwd = backend/).
|
||||
sys.path.insert(0, str(Path(__file__).resolve().parent.parent))
|
||||
Reference in New Issue
Block a user