API: закрыть схему в проде + security-заголовки на edge
main.py: openapi.json/docs/redoc отдаются только в dev/test (нужны для gen:api), в production отключены. Caddyfile (edge): HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, скрыт Server; CSP подготовлена, но выключена до проверки на test-клоне (строгая политика ломает SPA/Telegram-виджет/SSE). #61 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XfTsytzT6TojfmprRDKiV6
This commit is contained in:
@@ -0,0 +1,22 @@
|
||||
"""Хардненинг API: раскрытие схемы закрыто в production, открыто в dev/test (#61, F6)."""
|
||||
from __future__ import annotations
|
||||
|
||||
from fastapi.testclient import TestClient
|
||||
|
||||
from app.core import config
|
||||
from app.main import create_app
|
||||
|
||||
|
||||
def test_openapi_open_in_development(client: TestClient):
|
||||
# Тесты идут в development (conftest) — схема доступна: нужна для `npm run gen:api`.
|
||||
assert client.get("/api/openapi.json").status_code == 200
|
||||
assert client.get("/api/docs").status_code == 200
|
||||
|
||||
|
||||
def test_openapi_closed_in_production(monkeypatch):
|
||||
monkeypatch.setattr(config.settings, "app_env", "production")
|
||||
prod_app = create_app()
|
||||
c = TestClient(prod_app)
|
||||
assert c.get("/api/openapi.json").status_code == 404
|
||||
assert c.get("/api/docs").status_code == 404
|
||||
assert c.get("/api/redoc").status_code == 404
|
||||
Reference in New Issue
Block a user