SSE: CSRF-middleware на чистом ASGI (BaseHTTPMiddleware буферизует поток и ломает SSE) + тест CSRF
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -287,6 +287,19 @@ def test_disabled_account_cannot_login(client: TestClient, make_admin):
|
||||
assert guest_dev["is_active"] is False
|
||||
|
||||
|
||||
def test_csrf_required_for_session_mutations(client: TestClient):
|
||||
"""После рефактора CSRF на ASGI защита сохраняется: мутация с сессией без X-CSRF-Token → 403."""
|
||||
login(client, "Аня") # появились cookie сессии и csrf_token
|
||||
no_header = client.post("/api/groups", json={"name": "Группа", "expansion_ids": []})
|
||||
assert no_header.status_code == 403
|
||||
assert no_header.json()["error"]["code"] == "CSRF_FAILED"
|
||||
# С корректным заголовком — проходит.
|
||||
ok = client.post(
|
||||
"/api/groups", json={"name": "Группа", "expansion_ids": []}, headers=csrf_headers(client)
|
||||
)
|
||||
assert ok.status_code == 200, ok.text
|
||||
|
||||
|
||||
def test_group_stats_includes_inactive_members(client: TestClient, engine):
|
||||
"""Участники без завершённых партий попадают в отдельный блок inactive (не в provisional)."""
|
||||
me = login(client, "Капитан")
|
||||
|
||||
Reference in New Issue
Block a user