Systematic prune per AGENTS.md test policy, one pass over every major test tree (gateway, hermes_cli, tools, agent, run_agent, plugins, cli, cron, tui_gateway, honcho/openviking, root-level): - DELETE: source-reading tests (read_text/getsource on prod files), change-detector tests (exact catalog counts, model-name snapshots, config version literals), mock-echo tests (assert a mock returns what it was told), assertion-free/trivial tests, near-duplicate parametrizations (boundaries + one representative kept), async/sync twin duplicates, cosmetic within-file variations. - KEEP (mandatory): security/redaction/approval guards, message-role alternation invariants, prompt-caching/deterministic-call-id invariants, issue-number regression tests (deduped), E2E tests. - 6 test files deleted outright (script-style/no-assert or fully redundant); conftest.py, fakes/, fixtures/ untouched. - tests/acp/conftest.py added: autouse fixture stubs the live models.dev/GitHub/Copilot/Anthropic inventory fetches that ACP server tests performed on every session create — test_server.py 147s → 3.4s, and the tests are now genuinely hermetic. - Sleep-based slowness shrunk where safe (codex_ttfb_watchdog, compression_concurrent_fork, etc.); no wall-clock assertion tightened. Verification: full hermetic suite via scripts/run_tests.sh — 2439 files, 31,130 tests passed, 0 failed, 0 flaky retries, 315s wall (baseline: 583s wall, 13,564s subprocess CPU).
97 lines
2.9 KiB
Python
97 lines
2.9 KiB
Python
"""Regression tests for dashboard basic-auth plugin enablement (#54489).
|
|
|
|
When ``dashboard.basic_auth`` is configured but the bundled ``basic``
|
|
provider plugin is listed in ``plugins.disabled``, plugin discovery skips
|
|
it and the dashboard auth gate sees zero providers — even after the
|
|
interactive username/password setup path writes credentials to config.yaml.
|
|
"""
|
|
from __future__ import annotations
|
|
|
|
from unittest.mock import patch
|
|
|
|
import pytest
|
|
import yaml
|
|
|
|
from hermes_cli.dashboard_auth import clear_providers, list_providers
|
|
from hermes_cli.plugins import PluginManager, discover_plugins
|
|
from hermes_cli.plugins_cmd import ensure_basic_auth_plugin_enabled_in_config
|
|
import plugins.dashboard_auth.basic as basic_plugin
|
|
|
|
|
|
@pytest.fixture(autouse=True)
|
|
def _reset_auth_registry():
|
|
clear_providers()
|
|
yield
|
|
clear_providers()
|
|
|
|
|
|
@pytest.fixture
|
|
def hermes_home(tmp_path, monkeypatch):
|
|
home = tmp_path / "hermes"
|
|
home.mkdir()
|
|
monkeypatch.setenv("HERMES_HOME", str(home))
|
|
return home
|
|
|
|
|
|
def _write_config(home, cfg: dict) -> None:
|
|
(home / "config.yaml").write_text(yaml.safe_dump(cfg), encoding="utf-8")
|
|
|
|
|
|
class TestEnsureBasicAuthPluginEnabled:
|
|
def test_noop_when_not_disabled(self):
|
|
cfg = {"plugins": {"disabled": ["other-plugin"]}}
|
|
assert ensure_basic_auth_plugin_enabled_in_config(cfg) is False
|
|
|
|
|
|
class TestBasicProviderLoadsAfterUnblock:
|
|
def test_disabled_basic_blocks_registration(self, hermes_home, monkeypatch):
|
|
password_hash = basic_plugin.hash_password("hunter2")
|
|
_write_config(
|
|
hermes_home,
|
|
{
|
|
"dashboard": {
|
|
"basic_auth": {
|
|
"username": "admin",
|
|
"password_hash": password_hash,
|
|
"secret": "a" * 32,
|
|
}
|
|
},
|
|
"plugins": {"disabled": ["basic"]},
|
|
},
|
|
)
|
|
|
|
import hermes_cli.plugins as plugins_mod
|
|
|
|
with patch.object(plugins_mod, "_plugin_manager", None):
|
|
discover_plugins(force=True)
|
|
|
|
assert list_providers() == []
|
|
|
|
def test_unblock_then_rediscover_registers_provider(
|
|
self, hermes_home, monkeypatch,
|
|
):
|
|
password_hash = basic_plugin.hash_password("hunter2")
|
|
cfg = {
|
|
"dashboard": {
|
|
"basic_auth": {
|
|
"username": "admin",
|
|
"password_hash": password_hash,
|
|
"secret": "a" * 32,
|
|
}
|
|
},
|
|
"plugins": {"disabled": ["basic"]},
|
|
}
|
|
_write_config(hermes_home, cfg)
|
|
|
|
assert ensure_basic_auth_plugin_enabled_in_config(cfg) is True
|
|
_write_config(hermes_home, cfg)
|
|
|
|
import hermes_cli.plugins as plugins_mod
|
|
|
|
with patch.object(plugins_mod, "_plugin_manager", None):
|
|
discover_plugins(force=True)
|
|
|
|
providers = list_providers()
|
|
assert len(providers) == 1
|
|
assert providers[0].name == "basic"
|