2026-06-02 06:39:01 +04:00
|
|
|
"""Tests for token-owner session attribution (effective_user + session routes).
|
|
|
|
|
|
|
|
|
|
Proves the two properties the review asked for:
|
|
|
|
|
- cookie/browser users are completely unchanged (no-op swap)
|
|
|
|
|
- a bearer token for owner A can never read/verify owner B's session, and a
|
|
|
|
|
bearer token with no owner does not escalate.
|
|
|
|
|
|
|
|
|
|
Follows the direct-helper + mocked-DB style of tests/test_null_owner_gates.py.
|
|
|
|
|
"""
|
|
|
|
|
|
|
|
|
|
import os
|
|
|
|
|
import sys
|
2026-06-04 21:05:52 +01:00
|
|
|
import importlib
|
2026-06-02 06:39:01 +04:00
|
|
|
from types import SimpleNamespace
|
|
|
|
|
from unittest.mock import MagicMock
|
|
|
|
|
|
|
|
|
|
import pytest
|
|
|
|
|
|
2026-06-05 09:25:52 +01:00
|
|
|
from tests.helpers.import_state import clear_module, preserve_import_state
|
|
|
|
|
|
2026-06-02 06:39:01 +04:00
|
|
|
sys.path.insert(0, os.path.dirname(os.path.dirname(os.path.abspath(__file__))))
|
|
|
|
|
|
2026-06-04 21:05:52 +01:00
|
|
|
# Stub heavy ORM modules so routes.session_routes can be imported under
|
2026-06-05 09:25:52 +01:00
|
|
|
# conftest's MagicMock sqlalchemy shim. preserve_import_state restores both the
|
|
|
|
|
# stubs and the cached route module — including the parent `routes`/`core`
|
|
|
|
|
# package attributes — on exit, preventing poisoning of later tests via
|
|
|
|
|
# `import routes.session_routes`.
|
2026-06-04 21:05:52 +01:00
|
|
|
|
|
|
|
|
|
2026-06-04 21:43:25 +01:00
|
|
|
def _set_module_and_parent_attr(dotted_name, module):
|
|
|
|
|
"""Install a module at both sys.modules *and* the parent-package attribute.
|
|
|
|
|
|
|
|
|
|
Setting only sys.modules[...] leaves the parent `core` package attribute
|
|
|
|
|
pointing at the previous (real) module, so a later import resolving through
|
|
|
|
|
the parent would bypass the stub — and, symmetrically, a stub left on the
|
|
|
|
|
parent attribute would poison later tests. Controlling both keeps the two
|
2026-06-05 09:25:52 +01:00
|
|
|
views consistent so preserve_import_state can fully undo them.
|
2026-06-04 21:43:25 +01:00
|
|
|
"""
|
|
|
|
|
sys.modules[dotted_name] = module
|
|
|
|
|
pkg_name, _, attr = dotted_name.rpartition(".")
|
|
|
|
|
pkg = sys.modules.get(pkg_name)
|
|
|
|
|
if pkg is not None:
|
|
|
|
|
setattr(pkg, attr, module)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
# Modules whose import-time effects leak through both sys.modules and the parent
|
|
|
|
|
# `core`/`routes` package attributes. core.database/core.models are stubbed so
|
|
|
|
|
# routes.session_routes imports under conftest's MagicMock sqlalchemy shim;
|
2026-06-05 09:25:52 +01:00
|
|
|
# core.session_manager and routes.session_routes are (re)imported fresh.
|
|
|
|
|
# preserve_import_state captures each at both levels and restores them on exit so
|
|
|
|
|
# this file cannot poison later tests via `import core.<...>` /
|
|
|
|
|
# `import routes.session_routes`.
|
2026-06-04 21:05:52 +01:00
|
|
|
_TEMP_STUBS = ("core.database", "core.models")
|
2026-06-04 21:43:25 +01:00
|
|
|
_MANAGED = _TEMP_STUBS + ("core.session_manager", "routes.session_routes")
|
2026-06-05 09:25:52 +01:00
|
|
|
with preserve_import_state(*_MANAGED):
|
2026-06-04 21:05:52 +01:00
|
|
|
for _name in _TEMP_STUBS:
|
2026-06-04 21:43:25 +01:00
|
|
|
_set_module_and_parent_attr(_name, MagicMock(name=_name))
|
|
|
|
|
# Clear sys.modules AND the parent package attribute for the modules we
|
|
|
|
|
# re-import so the stubbed import below yields fresh modules with no stale
|
|
|
|
|
# binding reachable behind them.
|
2026-06-05 09:25:52 +01:00
|
|
|
clear_module("core.session_manager")
|
|
|
|
|
clear_module("routes.session_routes")
|
2026-06-04 21:05:52 +01:00
|
|
|
importlib.import_module("core.session_manager")
|
|
|
|
|
import routes.session_routes as SR # noqa: E402
|
2026-06-02 06:39:01 +04:00
|
|
|
|
|
|
|
|
from fastapi import HTTPException # noqa: E402
|
|
|
|
|
from src.auth_helpers import effective_user # noqa: E402
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def _req(**state):
|
|
|
|
|
return SimpleNamespace(state=SimpleNamespace(**state))
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
# --- effective_user: who a request is attributed to ------------------------
|
|
|
|
|
|
|
|
|
|
def test_cookie_user_is_unchanged():
|
|
|
|
|
# The whole point: browser/cookie callers behave exactly as before.
|
|
|
|
|
assert effective_user(_req(api_token=False, current_user="alice")) == "alice"
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_bearer_token_attributes_to_its_owner():
|
|
|
|
|
# A paired phone runs as the "api" pseudo-user but must act as the token owner.
|
|
|
|
|
assert effective_user(_req(api_token=True, api_token_owner="alice", current_user="api")) == "alice"
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_bearer_token_without_owner_does_not_escalate():
|
|
|
|
|
# No owner on the token -> falls back to current_user ("api"), never another user.
|
|
|
|
|
assert effective_user(_req(api_token=True, api_token_owner=None, current_user="api")) == "api"
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
# --- _verify_session_owner: bearer tokens cannot cross owners ---------------
|
|
|
|
|
|
|
|
|
|
def _session_local_returning(owner_value):
|
|
|
|
|
"""Mock SessionLocal whose query(...).filter(...).first() yields a row with
|
|
|
|
|
the given owner (or None for 'no such session')."""
|
|
|
|
|
db = MagicMock()
|
|
|
|
|
row = None if owner_value is _MISSING else SimpleNamespace(owner=owner_value)
|
|
|
|
|
db.query.return_value.filter.return_value.first.return_value = row
|
|
|
|
|
return MagicMock(return_value=db)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
_MISSING = object()
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_bearer_owner_A_cannot_verify_owner_B_session(monkeypatch):
|
|
|
|
|
monkeypatch.setattr(SR, "SessionLocal", _session_local_returning("bob"))
|
|
|
|
|
req = _req(api_token=True, api_token_owner="alice", current_user="api")
|
|
|
|
|
with pytest.raises(HTTPException) as exc:
|
|
|
|
|
SR._verify_session_owner(req, "sid-owned-by-bob")
|
|
|
|
|
assert exc.value.status_code == 404
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_owner_can_verify_their_own_session(monkeypatch):
|
|
|
|
|
monkeypatch.setattr(SR, "SessionLocal", _session_local_returning("alice"))
|
|
|
|
|
req = _req(api_token=True, api_token_owner="alice", current_user="api")
|
|
|
|
|
# Should not raise.
|
|
|
|
|
SR._verify_session_owner(req, "sid-owned-by-alice")
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_cookie_user_owns_their_session(monkeypatch):
|
|
|
|
|
# Cookie path unchanged: alice (cookie) verifies alice's session.
|
|
|
|
|
monkeypatch.setattr(SR, "SessionLocal", _session_local_returning("alice"))
|
|
|
|
|
req = _req(api_token=False, current_user="alice")
|
|
|
|
|
SR._verify_session_owner(req, "sid")
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_missing_session_is_404(monkeypatch):
|
|
|
|
|
monkeypatch.setattr(SR, "SessionLocal", _session_local_returning(_MISSING))
|
|
|
|
|
req = _req(api_token=False, current_user="alice")
|
|
|
|
|
with pytest.raises(HTTPException) as exc:
|
|
|
|
|
SR._verify_session_owner(req, "nope")
|
|
|
|
|
assert exc.value.status_code == 404
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_unauthenticated_caller_rejected(monkeypatch):
|
|
|
|
|
req = _req(api_token=False, current_user=None)
|
|
|
|
|
with pytest.raises(HTTPException) as exc:
|
|
|
|
|
SR._verify_session_owner(req, "sid")
|
2026-06-06 03:54:19 +07:00
|
|
|
assert exc.value.status_code == 401
|
feat: add ChatGPT Subscription provider (#2876)
* feat: Add ChatGPT Subscription support and related features
- Introduced a new provider option for ChatGPT Subscription in the endpoint selection UI.
- Implemented OAuth flow for ChatGPT Subscription sign-in, including polling for authorization status.
- Updated admin interface to handle ChatGPT Subscription, including disabling API key input and providing user guidance.
- Enhanced cost tracking logic to differentiate between subscription and non-subscription endpoints.
- Added new slash commands for managing skills, including listing, searching, and invoking skills.
- Implemented caching for skill catalog to optimize performance.
- Updated tests to cover new ChatGPT Subscription functionality and ensure proper endpoint probing.
- Refactored existing code to accommodate new features and improve maintainability.
* refactor: share provider device-flow setup
- reuse one device-flow backend for Copilot and ChatGPT Subscription
- add one frontend device-flow helper for Settings and /setup
- put GitHub Copilot back into Add Models, now as a dropdown option
- make provider selection just select; clicking Add starts sign-in
- stop ChatGPT Subscription setup from opening auth tabs automatically
- make /setup copilot and /setup chatgpt-subscription work from chat
- show ChatGPT Subscription in the /setup suggestions
- show the real error message when setup fails
- add focused tests for the shared flow and setup UI
* feat(chatgpt-subscription): harden credential lifecycle and streamline auth UX
Backend:
- Resolve runtime bearer for provider-auth endpoints at probe time via a
shared _resolve_probe_key() that delegates to resolve_endpoint_runtime,
applied across all probe/refresh call sites.
- Skip live completion probes and health pings for discovery-only providers
(centralized behind _is_discovery_only_provider) — the Codex/Responses API
has no such endpoints, so status is derived from cached models.
- Never persist the short lived ChatGPT bearer to the plaintext sessions
table; proactively clear any stale bearer left by an earlier code path.
- Revoke orphaned ProviderAuthSession credentials when the last endpoint
backing them is deleted (_delete_orphaned_provider_auth), surfaced via
cleared_provider_auth in the delete response.
Frontend (admin.js):
- Auto-start the device-auth flow on provider selection so the authorization
panel (code + Authorize) shows immediately instead of behind a "Sign in" click.
- Remove the redundant top button for device auth providers, move retry
into the panel via an inline "Try again".
- Drop the self-evident hint text and add an execCommand clipboard fallback so
Copy works in non-secure (HTTP/LAN) contexts.
* fix: harden chatgpt subscription provider
* chore: remove PR media from branch
* Fix chatgpt subscription recovery and token handling
---------
Co-authored-by: 5p00kyy <admin@5p00ky.dev>
2026-06-08 18:19:18 +10:00
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_auth_disabled_allows_owner_stamped_session(monkeypatch):
|
|
|
|
|
monkeypatch.setenv("AUTH_ENABLED", "false")
|
|
|
|
|
monkeypatch.setattr(SR, "SessionLocal", _session_local_returning("admin"))
|
|
|
|
|
req = _req(api_token=False, current_user=None)
|
|
|
|
|
|
|
|
|
|
# Single-user/auth-disabled mode should verify existence but not compare owner.
|
|
|
|
|
SR._verify_session_owner(req, "sid-owned-by-admin")
|