# import uuid # # # def _create_executor_and_tokens(client, admin_tokens, auth_headers) -> tuple[int, dict]: # suffix = uuid.uuid4().hex[:8] # username = f"audit_exec_{suffix}" # password = "pass123" # created = client.put( # "/api/v1/users/", # json={ # "email": f"{username}@example.com", # "username": username, # "password": password, # "full_name": "Audit Executor", # "role_id": 2, # }, # headers=auth_headers(admin_tokens), # ) # assert created.status_code == 200 # user_id = created.json()["result"]["id"] # # login = client.post( # "/api/v1/auth/login", # json={"username": username, "password": password}, # ) # assert login.status_code == 200 # return user_id, login.json() def test_audit_logs_admin_smoke(client, admin_tokens, auth_headers): response = client.get("/api/v1/audit-logs", headers=auth_headers(admin_tokens)) assert response.status_code == 200 payload = response.json() assert "result" in payload assert isinstance(payload["result"], list) def test_audit_logs_requires_auth(client): response = client.get("/api/v1/audit-logs") assert response.status_code == 403 # Тест временно отключён: внутри создаётся пользователь. # def test_audit_logs_forbidden_for_non_admin(client, admin_tokens, auth_headers): # user_id, executor_tokens = _create_executor_and_tokens( # client, admin_tokens, auth_headers # ) # try: # response = client.get( # "/api/v1/audit-logs", # headers=auth_headers(executor_tokens), # ) # assert response.status_code == 403 # finally: # client.delete( # f"/api/v1/users/{user_id}", # headers=auth_headers(admin_tokens), # ) def test_audit_logs_query_validation(client, admin_tokens, auth_headers): response = client.get( "/api/v1/audit-logs?limit=101", headers=auth_headers(admin_tokens), ) assert response.status_code == 422