Protect private API routes and scope agent data

This commit is contained in:
Hamza Ayed
2026-10-03 00:34:49 +03:00
parent 1c1f662850
commit b0cd825838
17 changed files with 313 additions and 95 deletions
@@ -3,10 +3,9 @@ import unittest
from pathlib import Path
from uuid import uuid4
from fastapi.testclient import TestClient
from app import auth, database
from app.main import app
from tests.api_client import authenticated_client
class ConversationVersionMigrationTests(unittest.TestCase):
@@ -47,6 +46,14 @@ class ConversationVersionMigrationTests(unittest.TestCase):
content TEXT NOT NULL,
created_at TEXT NOT NULL
);
CREATE TABLE agent_audit_events (
id TEXT PRIMARY KEY,
tool TEXT NOT NULL,
method TEXT NOT NULL,
status_code INTEGER NOT NULL,
duration_ms INTEGER NOT NULL,
created_at TEXT NOT NULL DEFAULT CURRENT_TIMESTAMP
);
INSERT INTO users(id) VALUES ('00000000-0000-4000-8000-000000000001');
INSERT INTO user_identities(user_id,provider,provider_subject,email)
VALUES ('00000000-0000-4000-8000-000000000001','google','subject-1','old@example.test');
@@ -55,6 +62,8 @@ class ConversationVersionMigrationTests(unittest.TestCase):
'قديم', '2026-01-01', '2026-01-01');
INSERT INTO messages(conversation_id, role, content, created_at)
VALUES ('conversation-1', 'assistant', 'جواب قديم', '2026-01-01');
INSERT INTO agent_audit_events(id,tool,method,status_code,duration_ms)
VALUES ('legacy-event','/v1/agent/run','POST',200,12);
"""
)
finally:
@@ -73,9 +82,16 @@ class ConversationVersionMigrationTests(unittest.TestCase):
identity = connection.execute(
"SELECT provider_subject,email,password_hash FROM user_identities WHERE provider='google'"
).fetchone()
legacy_audit = connection.execute(
"SELECT user_id FROM agent_audit_events WHERE id='legacy-event'"
).fetchone()
self.assertEqual(identity["provider_subject"], "subject-1")
self.assertEqual(identity["email"], "old@example.test")
self.assertIsNone(identity["password_hash"])
self.assertIsNone(legacy_audit["user_id"])
self.assertEqual(database.list_agent_audit_events(
"00000000-0000-4000-8000-000000000001"
), [])
old_conversation = database.get_conversation(
"00000000-0000-4000-8000-000000000001", "conversation-1"
)
@@ -122,7 +138,7 @@ class ConversationVersionMigrationTests(unittest.TestCase):
},
],
}
with TestClient(app) as client:
with authenticated_client(app) as client:
saved = client.put(
f"/v1/conversations/{conversation_id}",
headers={"Authorization": f"Bearer {token}"},