Skip to content

Sprint 4 PR 4.6b — integration tests for people router - #235

Merged
tomqwu merged 1 commit into
mainfrom
sprint-4-pr-4-6b-people-integration
Jul 19, 2026
Merged

tomqwu merged 1 commit into
mainfrom
sprint-4-pr-4-6b-people-integration

Conversation

@tomqwu

@tomqwu tomqwu commented Jul 18, 2026

Copy link
Copy Markdown
Owner

Summary

Continues Sprint 4 PR 4.6b (file-by-file revival of the tests/integration/ tier). Adds an integration file that drives the /people router over real HTTP against the session-scoped uvicorn api_server fixture.

Coverage

tests/integration/test_people.py — 19 tests covering:

  • GET /people/me — success, unauthenticated 403
  • PUT /people/me — self-edit for name and timezone
  • POST /people/ — success, admin gate (403 for volunteer), duplicate id 409
  • POST /people/bulk — JSON-array success, missing items 400, admin gate
  • GET /people/ — envelope shape, q= name/email search, role= filter
  • GET /people/{id} — success + 404
  • PUT /people/{id} — admin can edit other in org, volunteer cannot edit others (403), volunteer cannot escalate own roles to admin (403)
  • DELETE /people/{id} — admin delete + follow-up 404, admin gate

Validation

  • poetry run pytest tests/integration/ — 129 passed (was 110)
  • poetry run pytest tests/integration/test_people.py -v — 19 passed
  • poetry run pytest tests/unit -q — 342 passed, 21 skipped
  • poetry run black tests/integration/test_people.py — clean
  • poetry run ruff check tests/integration/test_people.py — clean

No OpenAPI snapshot refresh (no endpoints added or changed).

Notes

  • Reuses the api_server session fixture from PR 4.6a.
  • q= test searches for the admin's local-part which is unique to the fixture, so the assertion doesn't collide with other tests' emails.
  • The role-escalation test exercises the Sprint 3 anti-escalation guard by attempting a self-edit that grants admin.

Follow-ups

Next integration files to revive: constraints, conflicts, calendar, solutions.


Generated by Claude Code

Summary: extend the resurrected tests/integration/ tier with an
integration file that drives the /people router over real HTTP against
the session-scoped uvicorn api_server fixture. Covers /me (get, update,
unauthenticated 403), admin-only create (success, forbidden for
volunteer, duplicate id 409), admin-only bulk import (success, missing
items 400, forbidden for volunteer), list envelope + q= search across
name/email + role filter, get one + 404, PUT with self-vs-admin
tenancy and no-role-escalation guard, and admin-only delete.

Changed files:
  tests/integration/test_people.py (new, 19 tests)

Validation:
  poetry run pytest tests/integration/ -q               # 129 passed
  poetry run pytest tests/integration/test_people.py -v # 19 passed
  poetry run pytest tests/unit -q                        # 342 passed, 21 skipped
  poetry run black tests/integration/test_people.py
  poetry run ruff check tests/integration/test_people.py

Follow-ups: continue file-by-file revival with constraints, conflicts,
calendar, and solutions routers.
@tomqwu
tomqwu marked this pull request as ready for review July 19, 2026 13:03
@tomqwu
tomqwu merged commit eb9050e into main Jul 19, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants