Limit request bodies to 1 MiB (413 JSON), wire aria-describedby on the login form, add Retry and cancellation to the book form load, disable Add entry while a note POST is in flight, and poll pg_isready in README. Claude-Session: https://claude.ai/code/session_01M9MLit5Ko3X4s7rzC5Kv7X
38 lines
1.6 KiB
Python
38 lines
1.6 KiB
Python
from pathlib import Path
|
|
|
|
from tests.support import HTTPS, ApiTestCase, db_execute
|
|
|
|
SCHEMA = Path(__file__).parent.parent / "schema.sql"
|
|
|
|
|
|
class AppTests(ApiTestCase):
|
|
def test_health(self):
|
|
response = self.call("GET", "/api/health")
|
|
self.assertEqual(response.status_code, 200)
|
|
self.assertEqual(response.get_json(), {"status": "ok"})
|
|
|
|
def test_genres_seeded_and_reseeding_is_idempotent(self):
|
|
before = db_execute("SELECT last_value FROM genres_id_seq")[0][0]
|
|
db_execute(SCHEMA.read_text())
|
|
db_execute(SCHEMA.read_text())
|
|
self.assertEqual(db_execute("SELECT count(*) FROM genres")[0][0], 16)
|
|
self.assertEqual(db_execute("SELECT last_value FROM genres_id_seq")[0][0], before)
|
|
|
|
def test_unknown_route_returns_json_404(self):
|
|
response = self.call("GET", "/api/nope")
|
|
self.assertEqual(response.status_code, 404)
|
|
self.assertIn("error", response.get_json())
|
|
|
|
def test_mutation_without_json_content_type_is_rejected(self):
|
|
response = self.client.post("/api/health", data="x", content_type="text/plain", base_url=HTTPS)
|
|
self.assertEqual(response.status_code, 400)
|
|
self.assertEqual(
|
|
response.get_json(),
|
|
{"error": "Request body must be JSON with Content-Type: application/json"},
|
|
)
|
|
|
|
def test_oversized_body_is_rejected_before_parsing(self):
|
|
response = self.call("POST", "/api/auth/login", {"username": "a", "password": "x" * (2 * 1024 * 1024)})
|
|
self.assertEqual(response.status_code, 413)
|
|
self.assertIn("error", response.get_json())
|