infrasynth-backend-kit/tests/test_features/test_views.py
jcv-dev 551b42eab5 feat: production-hardening pass across the kit
Close the gaps between the documented contract (API-STANDARD, TENANCY,
ENTITLEMENTS) and the implementation, and remove committed build artifacts.

Security:
- verify + process inbound webhooks (HMAC/handler verify, size limit,
  timestamp tolerance, idempotency via InboundEvent.external_id)
- real 2FA login flow (pre-auth challenge; tokens only after verify/recovery)
- wire HybridPermission into security/audit views; add API-key rotate and
  users/<id>/permissions|roles endpoints
- tenant-scoped throttling on by default; webhook replay protection
- verify MercadoPago webhook signatures
- login brute-force guard, configurable password policy, real ALTCHA PoW

Correctness:
- apply verified billing webhooks idempotently (subscription/entitlement/
  invoice/PaymentTransaction); scheduled payment lifecycle jobs
- capture audit update diffs automatically; add audit retention purge
- working notification retries, per-channel rate limits, log retention
- pluggable virus scanner, upload-size limit, pipeline toggle
- feature rollout %/environment targeting; settings-driven registrations
- workflow guards (instance cap, route depth, self-assignment, clone on re-entry)
- wire every previously-dead INFRASYNTH_* setting; drop truly dead ones

Delivery:
- README + CHANGELOG; CI format check + coverage gate
- keep test media out of the tree; untrack .coverage, __pycache__,
  egg-info, docs/ and invoice artifacts
2026-09-24 10:41:21 -05:00

70 lines
2.8 KiB
Python

import pytest
from django.contrib.auth import get_user_model
from django.core.cache import cache
from rest_framework import status
from infrasynth.features.models import FeatureFlag
from infrasynth.features.registry import FeatureRegistry
UserModel = get_user_model()
@pytest.fixture(autouse=True)
def clean_registry(clean_feature_registry):
cache.clear()
cache.clear()
yield
cache.clear()
def _flags(resp):
"""The endpoint returns a list of {slug, enabled}; expose it as a dict."""
return {entry["slug"]: entry["enabled"] for entry in resp.json()["flags"]}
class TestActiveFlagsEndpoint:
def test_returns_registry_flags(self, authenticated_client, db):
FeatureRegistry.register("flag.x", default=True)
FeatureRegistry.register("flag.y", default=False)
resp = authenticated_client.get("/api/v1/features/active/")
assert resp.status_code == status.HTTP_200_OK
data = _flags(resp)
assert data["flag.x"] is True
assert data["flag.y"] is False
def test_requires_auth(self, api_client, db):
resp = api_client.get("/api/v1/features/active/")
assert resp.status_code == status.HTTP_401_UNAUTHORIZED
def test_includes_db_flags(self, authenticated_client, db):
FeatureRegistry.register("mixed", default=False)
FeatureFlag.objects.create(slug="mixed", is_active=True)
resp = authenticated_client.get("/api/v1/features/active/")
assert _flags(resp)["mixed"] is True
def test_includes_user_overrides(self, authenticated_client, user, db):
FeatureRegistry.register("override_me", default=False)
flag = FeatureFlag.objects.create(slug="override_me", is_active=False)
from infrasynth.features.models import FeatureFlagOverride
FeatureFlagOverride.objects.create(flag=flag, user=user, is_enabled=True)
resp = authenticated_client.get("/api/v1/features/active/")
assert _flags(resp)["override_me"] is True
class TestCheckFlagEndpoint:
def test_check_enabled(self, authenticated_client, db):
FeatureRegistry.register("my.flag", default=True)
resp = authenticated_client.get("/api/v1/features/check/my.flag/")
assert resp.status_code == status.HTTP_200_OK
assert resp.json() == {"slug": "my.flag", "is_enabled": True}
def test_check_disabled(self, authenticated_client, db):
FeatureRegistry.register("off.flag", default=False)
resp = authenticated_client.get("/api/v1/features/check/off.flag/")
assert resp.status_code == status.HTTP_200_OK
assert resp.json() == {"slug": "off.flag", "is_enabled": False}
def test_check_requires_auth(self, api_client, db):
resp = api_client.get("/api/v1/features/check/anything/")
assert resp.status_code == status.HTTP_401_UNAUTHORIZED