Skip to content

Sprint 4 PR 4.6b — integration tests for calendar router - #243

Merged
tomqwu merged 1 commit into
mainfrom
sprint-4-pr-4-6b-calendar-integration
Jul 19, 2026
Merged

tomqwu merged 1 commit into
mainfrom
sprint-4-pr-4-6b-calendar-integration

Conversation

@tomqwu

@tomqwu tomqwu commented Jul 18, 2026

Copy link
Copy Markdown
Owner

Summary

Continues Sprint 4 PR 4.6b (file-by-file revival of the tests/integration/ tier). Adds a production-endpoint integration file that drives the /calendar router over real HTTP against the session-scoped uvicorn api_server fixture. Covers the subscribe endpoint, self / admin token rotation, admin override, and the public token-authenticated ICS feed.

Coverage

tests/integration/test_calendar.py — 12 tests covering:

  • GET /calendar/subscribe — self OK, same-org admin OK, other-org admin 403, missing person 404, unauthenticated 401/403
  • POST /calendar/reset-token — self rotates (token before/after differs), cross-org admin 403
  • POST /calendar/{person_id}/admin-reset — admin OK (token rotated), volunteer 403, cross-org admin 403
  • GET /calendar/feed/{token} — valid token yields text/calendar with BEGIN:VCALENDAR…END:VCALENDAR, bogus token 404

Validation

  • poetry run pytest tests/integration/test_calendar.py -v — 12 passed
  • poetry run black tests/integration/test_calendar.py — clean
  • poetry run ruff check tests/integration/test_calendar.py — clean

No OpenAPI snapshot refresh (no endpoints added or changed).

Notes

  • The calendar_org fixture provisions two orgs so cross-org access assertions are exercised against a real second-org admin, not just a synthetic org_id.
  • The /feed/{token} happy path first admin-creates an event, assigns the volunteer, then subscribes to get the token, then hits the feed — so the ICS body assertion isn't hollow (the router iterates real assignment/event rows).

Follow-ups

Remaining routers still to revive under tests/integration/: assignments, analytics, solutions, solver, people, webhooks.


Generated by Claude Code

Summary: Continues PR 4.6b file-by-file revival of the integration tier.
Adds real-HTTP coverage for /api/v1/calendar's subscription, token
reset, admin reset, and public feed endpoints. Locks in the self-or-
same-org-admin gate on GET/subscribe and POST/reset-token, the admin-
only /{person_id}/admin-reset flow, and the ICS content-type contract
of the public /feed/{token} endpoint.

Changed files:
- tests/integration/test_calendar.py (new) — 12 tests spanning:
  - /subscribe: self OK, same-org admin OK, other-org admin 403,
    missing person 404, unauthenticated 401/403
  - /reset-token: self rotates (token changes), cross-org admin 403
  - /{person_id}/admin-reset: admin OK, volunteer 403, cross-org 403
  - /feed/{token}: valid token yields text/calendar (BEGIN/END VCALENDAR
    verified in body), bogus token 404

Validation:
- poetry run pytest tests/integration/test_calendar.py -v — 12 passed
- poetry run black tests/integration/test_calendar.py — clean
- poetry run ruff check tests/integration/test_calendar.py — clean
- No OpenAPI snapshot refresh (no endpoints added or changed).

Follow-ups:
- Remaining integration files to revive: assignments, analytics,
  solutions, solver, people, webhooks.
@tomqwu
tomqwu marked this pull request as ready for review July 19, 2026 13:04
@tomqwu
tomqwu merged commit fb28c50 into main Jul 19, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants