Skip to content

Sprint 4 PR 4.6b — integration tests for audit-logs router - #241

Merged
tomqwu merged 1 commit into
mainfrom
sprint-4-pr-4-6b-audit-integration
Jul 19, 2026
Merged

tomqwu merged 1 commit into
mainfrom
sprint-4-pr-4-6b-audit-integration

Conversation

@tomqwu

@tomqwu tomqwu commented Jul 18, 2026

Copy link
Copy Markdown
Owner

Summary

Continues Sprint 4 PR 4.6b (file-by-file revival of the tests/integration/ tier). Adds a production-endpoint integration file that drives the admin-only /audit-logs read endpoint over real HTTP against the session-scoped uvicorn api_server fixture. Locks in the auth gate, the ListResponse envelope, the router's self-recording of a data.exported row on every list call, and the org-scoping guarantee.

Coverage

tests/integration/test_audit.py — 9 tests covering:

  • Auth gate: admin can read (envelope shape asserted), volunteer 403, unauth 401/403
  • Self-recording: first read → second read with action=data.exported filter surfaces the new row (locks in the router's log_audit_event call)
  • Org scoping: every returned row has organization_id == caller.org_id
  • Filters: action=, user_id= narrow the result set; limit/offset echoed in envelope; unknown action → total: 0

Validation

  • poetry run pytest tests/integration/test_audit.py -v — 9 passed
  • poetry run black tests/integration/test_audit.py — clean
  • poetry run ruff check tests/integration/test_audit.py — clean

No OpenAPI snapshot refresh (no endpoints added or changed).

Notes

  • The self-recording test compares total across two reads. It tolerates the edge case where the first read is the very first entry in the audit table for this org.
  • Volunteer path is exercised alongside admin so both the 200 (admin) and 403 (volunteer) branches of the get_current_admin_user dependency are covered end-to-end.

Follow-ups

Remaining routers still to revive under tests/integration/: assignments, analytics, calendar, password_reset, solutions, solver, people, webhooks.


Generated by Claude Code

Summary: Continues PR 4.6b file-by-file revival of the integration tier.
Adds real-HTTP coverage for the admin-only /api/v1/audit-logs read
endpoint, including the self-recording behavior where every list call
generates its own data.exported row.

Changed files:
- tests/integration/test_audit.py (new) — 9 tests spanning:
  - auth gate: admin OK, volunteer 403, unauth 401/403
  - self-recording: a plain read produces a data.exported row (asserted
    by re-reading with action=data.exported filter)
  - org scoping: every returned row has organization_id == caller.org_id
  - filters: action=, user_id=, pagination echo, unknown action returns 0

Validation:
- poetry run pytest tests/integration/test_audit.py -v — 9 passed
- poetry run black tests/integration/test_audit.py — clean
- poetry run ruff check tests/integration/test_audit.py — clean
- No OpenAPI snapshot refresh (no endpoints added or changed).

Follow-ups:
- Remaining integration files to revive: assignments, analytics,
  calendar, password_reset, solutions, solver, people, webhooks.
@tomqwu
tomqwu marked this pull request as ready for review July 19, 2026 13:03
@tomqwu
tomqwu merged commit 1d5b93f into main Jul 19, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants