"""Ошибки валидации запроса: всегда 422 в едином конверте и без эха тела запроса.""" from __future__ import annotations from fastapi.testclient import TestClient def test_non_json_body_is_422_not_500(client: TestClient): """HTML-форма шлёт text/plain: тело приходит сырыми bytes, ответ раньше падал в 500.""" for path, raw in [ ("/api/auth/telegram", '{"id": 1}'), ("/api/admin/auth/login", '{"username": "a", "password": "b"}'), ]: r = client.post(path, content=raw, headers={"Content-Type": "text/plain"}) assert r.status_code == 422, (path, r.text) assert r.json()["error"]["code"] == "VALIDATION_ERROR" def test_validation_error_does_not_echo_body(client: TestClient): secret = "very-secret-password" r = client.post("/api/admin/auth/login", json={"password": secret}) assert r.status_code == 422, r.text assert secret not in r.text details = r.json()["error"]["details"] assert details and all(set(d) == {"type", "loc", "msg"} for d in details) def test_validation_error_points_to_field(client: TestClient): r = client.post("/api/admin/auth/login", json={"password": "x"}) locs = [d["loc"] for d in r.json()["error"]["details"]] assert ["body", "username"] in locs