Protect private API routes and scope agent data

This commit is contained in:
Hamza Ayed
2026-10-03 00:34:49 +03:00
parent 1c1f662850
commit b0cd825838
17 changed files with 313 additions and 95 deletions
@@ -11,6 +11,7 @@ from fastapi import HTTPException
_TEST_DATA_DIR = tempfile.TemporaryDirectory(prefix="sovereignai-timeout-tests-")
os.environ["SOVEREIGNAI_DATA_DIR"] = _TEST_DATA_DIR.name
from app import database
from app.main import AgentRequest, run_agent_stream
from app.model_provider import OllamaProvider
@@ -72,7 +73,8 @@ class TimeoutAndCancellationTests(unittest.IsolatedAsyncioTestCase):
started = asyncio.Event()
cancelled = asyncio.Event()
async def waiting_agent(_request, *, report_progress):
async def waiting_agent(_request, *, report_progress, user_id):
self.assertEqual(user_id, database.LOCAL_USER_ID)
await report_progress("بدأ الاختبار")
started.set()
try:
@@ -83,7 +85,7 @@ class TimeoutAndCancellationTests(unittest.IsolatedAsyncioTestCase):
request = AgentRequest(task="اختبار إلغاء البث")
with patch("app.main._execute_agent", side_effect=waiting_agent):
response = await run_agent_stream(request)
response = await run_agent_stream(request, user_id=database.LOCAL_USER_ID)
stream = response.body_iterator
first_event = await asyncio.wait_for(anext(stream), timeout=1)
self.assertIn("event: progress", first_event)