The browser treated sessionStorage as the source of truth for the logged-in user and never verified or invalidated the server-side session cookie: no GET /api/v1/demo/session or POST /api/v1/demo/logout endpoint existed, and a central 401 handler was defined but never wired up. Add both endpoints; the session-check response is marked Cache-Control: no-store to avoid the browser serving a stale "authenticated" response right after logout. AuthProvider now verifies against the server on every mount (sessionStorage only caches presentation state to avoid a login-screen flash), subscribes to a central 401 listener on the API client, and RequireAuth shows a loading state during verification instead of flashing protected content or the wrong role.
50 lines
1.6 KiB
Python
50 lines
1.6 KiB
Python
def test_unauthenticated_dashboard_is_rejected(client):
|
|
response = client.get("/api/v1/dashboard")
|
|
assert response.status_code == 401
|
|
assert response.json()["error"]["code"] == "401"
|
|
|
|
|
|
def test_demo_login_grants_access(ops_client):
|
|
response = ops_client.get("/api/v1/dashboard")
|
|
assert response.status_code == 200
|
|
|
|
|
|
def test_rental_employee_cannot_reset_demo(employee_client):
|
|
response = employee_client.post("/api/v1/demo/reset")
|
|
assert response.status_code == 403
|
|
|
|
|
|
def test_operations_manager_can_reset_demo(ops_client):
|
|
response = ops_client.post("/api/v1/demo/reset")
|
|
assert response.status_code == 200
|
|
assert response.json()["counts"]["vehicles"] == 50
|
|
|
|
|
|
def test_session_endpoint_requires_authentication(client):
|
|
response = client.get("/api/v1/demo/session")
|
|
assert response.status_code == 401
|
|
|
|
|
|
def test_session_endpoint_confirms_logged_in_user(ops_client):
|
|
response = ops_client.get("/api/v1/demo/session")
|
|
assert response.status_code == 200
|
|
body = response.json()
|
|
assert body["role"] == "operations_manager"
|
|
assert body["public_ref"] == "USR-OPS"
|
|
|
|
|
|
def test_logout_invalidates_session(ops_client):
|
|
confirmed = ops_client.get("/api/v1/demo/session")
|
|
assert confirmed.status_code == 200
|
|
|
|
logout = ops_client.post("/api/v1/demo/logout")
|
|
assert logout.status_code == 200
|
|
|
|
after = ops_client.get("/api/v1/demo/session")
|
|
assert after.status_code == 401
|
|
|
|
|
|
def test_logout_without_a_session_is_safe(client):
|
|
response = client.post("/api/v1/demo/logout")
|
|
assert response.status_code == 200
|