diff --git a/tests/test_app.py b/tests/test_app.py index 8865342..df4c85f 100644 --- a/tests/test_app.py +++ b/tests/test_app.py @@ -324,16 +324,16 @@ def test_hetzner_token_refreshes_vault_cache_when_missing(monkeypatch): assert calls[1] == "reload" -def test_speedtest_deploy_requires_strong_password_and_uses_git_compose(monkeypatch): +def test_speedtest_deploy_requires_strong_secrets_and_uses_full_git_app(monkeypatch): calls = [] async def fake_fetch(repo, path): calls.append(("fetch", repo, path)) - return "services:\n speedtest:\n image: ghcr.io/librespeed/speedtest:latest\n" + return f"content:{path}" - def fake_deploy(compose, password): - calls.append(("deploy", compose, password)) - return {"status": "deployed", "health": "ok"} + def fake_deploy(files, password, session_secret): + calls.append(("deploy", files, password, session_secret)) + return {"status": "deployed", "health": "ok", "application": "streamscope"} monkeypatch.setattr(app, "_fetch_forgejo_text", fake_fetch) monkeypatch.setattr(app, "_deploy_speedtest_compose", fake_deploy) @@ -341,18 +341,24 @@ def test_speedtest_deploy_requires_strong_password_and_uses_git_compose(monkeypa weak = client.post( "/vps/speedtest/deploy", headers={"Authorization": "Bearer test-token"}, - json={"stats_password": "short"}, + json={"stats_password": "short", "session_secret": "long-session-secret-with-entropy"}, ) response = client.post( "/vps/speedtest/deploy", headers={"Authorization": "Bearer test-token"}, - json={"stats_password": "correct-horse-battery-staple"}, + json={ + "stats_password": "correct-horse-battery-staple", + "session_secret": "streamscope-session-secret-with-entropy", + }, ) assert weak.status_code == 400 assert response.status_code == 200 - assert response.json()["status"] == "deployed" - assert calls == [ - ("fetch", "sascha/speedtest", "compose.yaml"), - ("deploy", "services:\n speedtest:\n image: ghcr.io/librespeed/speedtest:latest\n", "correct-horse-battery-staple"), - ] + assert response.json()["application"] == "streamscope" + assert ("fetch", "sascha/speedtest", "compose.yaml") in calls + assert ("fetch", "sascha/speedtest", "streamscope/static/assets/app.js") in calls + deploy = calls[-1] + assert deploy[0] == "deploy" + assert deploy[1]["compose.yaml"] == "content:compose.yaml" + assert deploy[2] == "correct-horse-battery-staple" + assert deploy[3] == "streamscope-session-secret-with-entropy"