前端提交
This commit is contained in:
@@ -68,3 +68,35 @@ async def test_questionnaire_endpoint_is_exempt_from_the_gate(
|
||||
HTTPAuthorizationCredentials(scheme="Bearer", credentials="token"),
|
||||
)
|
||||
assert context == resolved
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
@pytest.mark.parametrize("role", ["risk_operator", "admin"])
|
||||
async def test_staff_roles_never_enter_customer_onboarding_gate(
|
||||
monkeypatch: pytest.MonkeyPatch,
|
||||
role: str,
|
||||
) -> None:
|
||||
authenticated = RequestContext(user_id="7", trace_id="initial")
|
||||
resolved = authenticated.model_copy(update={"roles": (role,)})
|
||||
|
||||
class Authenticator:
|
||||
def authenticate(self, _token: str) -> RequestContext:
|
||||
return authenticated
|
||||
|
||||
async def resolve(_self: object, _context: RequestContext) -> RequestContext:
|
||||
return resolved
|
||||
|
||||
async def unexpected_check(_self: object, _context: RequestContext) -> bool:
|
||||
raise AssertionError("员工身份不应进入客户风险测评门禁")
|
||||
|
||||
monkeypatch.setattr("app.api.dependencies.auth._authenticator", lambda: Authenticator())
|
||||
monkeypatch.setattr("app.service.identity_service.IdentityService.resolve", resolve)
|
||||
monkeypatch.setattr(
|
||||
"app.service.risk_questionnaire_service.RiskQuestionnaireService.is_required",
|
||||
unexpected_check,
|
||||
)
|
||||
context = await build_request_context(
|
||||
request("/api/v1/risk/overview"),
|
||||
HTTPAuthorizationCredentials(scheme="Bearer", credentials="token"),
|
||||
)
|
||||
assert context == resolved
|
||||
|
||||
Reference in New Issue
Block a user