DFiP_Budget_planing/api/tests/integration/test_audit_api_integration.py
2026-05-20 11:18:05 +03:00

68 lines
2.1 KiB
Python

# import uuid
#
#
# def _create_executor_and_tokens(client, admin_tokens, auth_headers) -> tuple[int, dict]:
# suffix = uuid.uuid4().hex[:8]
# username = f"audit_exec_{suffix}"
# password = "pass123"
# created = client.put(
# "/api/v1/users/",
# json={
# "email": f"{username}@example.com",
# "username": username,
# "password": password,
# "full_name": "Audit Executor",
# "role_id": 2,
# },
# headers=auth_headers(admin_tokens),
# )
# assert created.status_code == 200
# user_id = created.json()["result"]["id"]
#
# login = client.post(
# "/api/v1/auth/login",
# json={"username": username, "password": password},
# )
# assert login.status_code == 200
# return user_id, login.json()
def test_audit_logs_admin_smoke(client, admin_tokens, auth_headers):
response = client.get("/api/v1/audit-logs", headers=auth_headers(admin_tokens))
assert response.status_code == 200
payload = response.json()
assert "result" in payload
assert isinstance(payload["result"], list)
def test_audit_logs_requires_auth(client):
response = client.get("/api/v1/audit-logs")
assert response.status_code == 403
# Тест временно отключён: внутри создаётся пользователь.
# def test_audit_logs_forbidden_for_non_admin(client, admin_tokens, auth_headers):
# user_id, executor_tokens = _create_executor_and_tokens(
# client, admin_tokens, auth_headers
# )
# try:
# response = client.get(
# "/api/v1/audit-logs",
# headers=auth_headers(executor_tokens),
# )
# assert response.status_code == 403
# finally:
# client.delete(
# f"/api/v1/users/{user_id}",
# headers=auth_headers(admin_tokens),
# )
def test_audit_logs_query_validation(client, admin_tokens, auth_headers):
response = client.get(
"/api/v1/audit-logs?limit=101",
headers=auth_headers(admin_tokens),
)
assert response.status_code == 422