Complete temporal detection safety gate
GeoIntel CI / docs-smoke (push) Canceled after 0s
GeoIntel CI / contract-smoke (push) Canceled after 0s

This commit is contained in:
Codex
2026-07-18 00:53:00 +02:00
parent fc42ea9af5
commit 9146981802
16 changed files with 689 additions and 23 deletions
@@ -0,0 +1,31 @@
from pathlib import Path
from fastapi.testclient import TestClient
from app.main import app
ROOT = Path(__file__).parents[2]
def test_valid_request_id_is_returned() -> None:
response = TestClient(app).get("/health/live", headers={"x-request-id": "rc3-check.123"})
assert response.status_code == 200
assert response.headers["x-request-id"] == "rc3-check.123"
def test_unsafe_request_id_is_replaced() -> None:
response = TestClient(app).get("/health/live", headers={"x-request-id": "unsafe request/id"})
assert response.status_code == 200
assert response.headers["x-request-id"] != "unsafe request/id"
assert " " not in response.headers["x-request-id"]
def test_runtime_report_is_read_only_by_default_and_requires_confirmation() -> None:
source = (ROOT / "scripts" / "runtime_state_report.py").read_text(encoding="utf-8")
assert '"mode": "read_only"' in source
assert "if args.reconcile and args.confirm != RECONCILE_CONFIRMATION" in source
assert "RuntimeReconciliationService.reconcile(db)" in source