Skip to content

Sprint 4 PR 4.6b — integration tests for constraints router - #236

Merged
tomqwu merged 1 commit into
mainfrom
sprint-4-pr-4-6b-constraints-integration
Jul 18, 2026
Merged

tomqwu merged 1 commit into
mainfrom
sprint-4-pr-4-6b-constraints-integration

Conversation

@tomqwu

@tomqwu tomqwu commented Jul 18, 2026

Copy link
Copy Markdown
Owner

Summary

Continues Sprint 4 PR 4.6b (file-by-file revival of the tests/integration/ tier). Adds a production-endpoint integration file that drives the /constraints router over real HTTP against the session-scoped uvicorn api_server fixture.

Coverage

tests/integration/test_constraints.py — 17 tests covering:

  • POST /constraints/ — success, admin gate (403 for volunteer), unauthenticated 401/403, invalid type body 400, cross-org 403/404
  • GET /constraints/ — envelope shape, default caller-org scoping, volunteer read allowed, constraint_type=soft filter
  • GET /constraints/{id} — success + 404
  • PUT /constraints/{id} — weight + predicate update, invalid type 400, admin gate, 404
  • DELETE /constraints/{id} — success + 404, admin gate

Validation

  • poetry run pytest tests/integration/test_constraints.py -v — 17 passed
  • poetry run pytest tests/integration/ — 127 passed (was 110)
  • poetry run pytest tests/unit -q — 342 passed, 21 skipped
  • poetry run black tests/integration/test_constraints.py — clean
  • poetry run ruff check tests/integration/test_constraints.py — clean

No OpenAPI snapshot refresh (no endpoints added or changed).

Notes

  • Each test uses a fresh org + admin + volunteer via the constraints_org fixture so admin-gate vs volunteer-forbidden paths can both be exercised.
  • Missing-org test accepts either 403 (verify_org_member fires because admin isn't a member of the sentinel org id) or 404 (fallback if the guard order ever changes), documenting the current gate order without brittling to it.

Follow-ups

Remaining routers still to revive under tests/integration/: conflicts, holidays, resources, recurring_events, assignments, audit, analytics, calendar, password_reset, solutions, solver, people, webhooks.


Generated by Claude Code

Summary: Continues PR 4.6b file-by-file revival of the integration tier.
Adds real-HTTP coverage for /api/v1/constraints against the session-scoped
uvicorn api_server fixture. Locks in the admin gate on write paths, the
authenticated-read requirement, and the org tenancy check.

Changed files:
- tests/integration/test_constraints.py (new) — 17 tests across
  create/list/get/update/delete, covering: admin-gate on create/update/
  delete, invalid type body rejected (400), volunteer-can-read on list,
  constraint_type=soft filter, envelope shape, 404s on missing ids, and
  cross-org create rejected via verify_org_member.

Validation:
- poetry run pytest tests/integration/test_constraints.py -v — 17 passed
- poetry run pytest tests/integration/ -q — 127 passed
- poetry run pytest tests/unit -q — 342 passed, 21 skipped
- poetry run black tests/integration/test_constraints.py — clean
- poetry run ruff check tests/integration/test_constraints.py — clean
- No OpenAPI snapshot refresh (no endpoints added or changed).

Follow-ups:
- Remaining routers still needing integration files: conflicts, holidays,
  resources, recurring_events, assignments, audit, analytics, calendar,
  password_reset, solutions, solver, people, webhooks.
@tomqwu
tomqwu marked this pull request as ready for review July 18, 2026 13:27
@tomqwu
tomqwu merged commit c0172d8 into main Jul 18, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants