Roles
This commit is contained in:
0
backend/app/tests/__init__.py
Normal file
0
backend/app/tests/__init__.py
Normal file
373
backend/app/tests/conftest.py
Normal file
373
backend/app/tests/conftest.py
Normal file
@@ -0,0 +1,373 @@
|
||||
"""
|
||||
Integration Test Fixtures - ServiceManagerWeb (Docker / PostgreSQL)
|
||||
|
||||
backend/app/tests/conftest.py
|
||||
|
||||
Usa la BD Docker existente (servicemanager).
|
||||
Los fixtures leen datos reales ya seedeados — no crean ni eliminan nada.
|
||||
Los tests que inserten datos propios quedan aislados por rollback.
|
||||
|
||||
Tenant de referencia : aduanasoft
|
||||
Usuarios de referencia:
|
||||
admin@aduanasoft.com → ADMIN
|
||||
manager@aduanasoft.com → SUPPORT_MANAGER
|
||||
agente@aduanasoft.com → AGENT
|
||||
auditor1@test.com → AUDITOR (tenant aduanasoft)
|
||||
admin-cliente@empresa-demo → CLIENT_ADMIN
|
||||
test_user@aduanasoft.com → CLIENT_USER
|
||||
"""
|
||||
|
||||
import os
|
||||
import asyncio
|
||||
import pytest
|
||||
from typing import AsyncGenerator, Generator
|
||||
|
||||
# ============================================================
|
||||
# ENV VARS — antes de importar la app
|
||||
# ============================================================
|
||||
os.environ.setdefault("ENVIRONMENT", "testing")
|
||||
os.environ.setdefault("TESTING", "true")
|
||||
os.environ.setdefault("DEBUG", "false")
|
||||
os.environ.setdefault("SECRET_KEY", "integration-secret-key-32chars!!!!")
|
||||
os.environ.setdefault("JWT_SECRET_KEY", "integration-jwt-secret-32chars!!!!")
|
||||
os.environ.setdefault(
|
||||
"DATABASE_URL",
|
||||
"postgresql+asyncpg://servicemanager:servicemanager123@localhost:5432/servicemanager",
|
||||
)
|
||||
os.environ.setdefault("REDIS_URL", "redis://localhost:6379/14")
|
||||
os.environ.setdefault("CELERY_BROKER_URL", "redis://localhost:6379/14")
|
||||
os.environ.setdefault("CELERY_RESULT_BACKEND", "redis://localhost:6379/14")
|
||||
os.environ.setdefault("CORS_ORIGINS", "http://localhost:3000")
|
||||
os.environ.setdefault("ALLOWED_FILE_EXTENSIONS", "pdf,jpg,jpeg,png,doc,docx,txt")
|
||||
|
||||
|
||||
# ============================================================
|
||||
# EVENT LOOP (session-scoped)
|
||||
# ============================================================
|
||||
|
||||
@pytest.fixture(scope="session")
|
||||
def event_loop() -> Generator:
|
||||
"""Event loop compartido para toda la sesión de tests."""
|
||||
policy = asyncio.get_event_loop_policy()
|
||||
loop = policy.new_event_loop()
|
||||
yield loop
|
||||
loop.close()
|
||||
|
||||
|
||||
# ============================================================
|
||||
# ENGINE (session-scoped — reutiliza el pool toda la sesión)
|
||||
# ============================================================
|
||||
|
||||
@pytest.fixture(scope="session")
|
||||
async def engine():
|
||||
"""
|
||||
Conecta al PostgreSQL Docker existente (servicemanager).
|
||||
NO crea ni destruye el schema — la BD ya está lista.
|
||||
"""
|
||||
from sqlalchemy.ext.asyncio import create_async_engine
|
||||
import app.models # noqa: F401 — registra todos los modelos
|
||||
|
||||
_engine = create_async_engine(os.environ["DATABASE_URL"], echo=False)
|
||||
yield _engine
|
||||
await _engine.dispose()
|
||||
|
||||
|
||||
# ============================================================
|
||||
# DB (function-scoped — rollback para datos creados en el test)
|
||||
# ============================================================
|
||||
|
||||
@pytest.fixture
|
||||
async def db(engine) -> AsyncGenerator:
|
||||
"""
|
||||
Sesión con transacción por test.
|
||||
Los datos seedeados son visibles (ya están committed).
|
||||
Cualquier INSERT hecho en el test se revierte al finalizar.
|
||||
"""
|
||||
from sqlalchemy.ext.asyncio import AsyncSession, async_sessionmaker
|
||||
|
||||
factory = async_sessionmaker(engine, class_=AsyncSession, expire_on_commit=False)
|
||||
|
||||
async with factory() as session:
|
||||
await session.begin()
|
||||
yield session
|
||||
await session.rollback()
|
||||
|
||||
|
||||
# ============================================================
|
||||
# TENANT (function-scoped — lee el registro existente)
|
||||
# ============================================================
|
||||
|
||||
@pytest.fixture
|
||||
async def tenant_a(db):
|
||||
"""Tenant 'aduanasoft' ya existente en la BD."""
|
||||
from sqlalchemy import select
|
||||
from app.models.tenant import Tenant
|
||||
|
||||
result = await db.execute(select(Tenant).where(Tenant.slug == "aduanasoft"))
|
||||
return result.scalar_one()
|
||||
|
||||
|
||||
# ============================================================
|
||||
# USUARIOS (function-scoped — leen registros existentes)
|
||||
# ============================================================
|
||||
|
||||
@pytest.fixture
|
||||
async def admin_user(db, tenant_a):
|
||||
"""ADMIN: admin@aduanasoft.com (tenant aduanasoft)."""
|
||||
from sqlalchemy import select
|
||||
from app.models.user import User
|
||||
|
||||
result = await db.execute(
|
||||
select(User)
|
||||
.where(User.email == "admin@aduanasoft.com")
|
||||
.where(User.tenant_id == tenant_a.id)
|
||||
)
|
||||
return result.scalar_one()
|
||||
|
||||
|
||||
@pytest.fixture
|
||||
async def manager_user(db, tenant_a):
|
||||
"""SUPPORT_MANAGER: manager@aduanasoft.com (tenant aduanasoft)."""
|
||||
from sqlalchemy import select
|
||||
from app.models.user import User
|
||||
|
||||
result = await db.execute(
|
||||
select(User)
|
||||
.where(User.email == "manager@aduanasoft.com")
|
||||
.where(User.tenant_id == tenant_a.id)
|
||||
)
|
||||
return result.scalar_one()
|
||||
|
||||
|
||||
@pytest.fixture
|
||||
async def agent_user(db, tenant_a):
|
||||
"""AGENT: agente@aduanasoft.com (tenant aduanasoft)."""
|
||||
from sqlalchemy import select
|
||||
from app.models.user import User
|
||||
|
||||
result = await db.execute(
|
||||
select(User)
|
||||
.where(User.email == "agente@aduanasoft.com")
|
||||
.where(User.tenant_id == tenant_a.id)
|
||||
)
|
||||
return result.scalar_one()
|
||||
|
||||
|
||||
@pytest.fixture
|
||||
async def user_tenant_a(db, tenant_a):
|
||||
"""CLIENT_USER: test_user@aduanasoft.com (tenant aduanasoft)."""
|
||||
from sqlalchemy import select
|
||||
from app.models.user import User
|
||||
|
||||
result = await db.execute(
|
||||
select(User)
|
||||
.where(User.email == "test_user@aduanasoft.com")
|
||||
.where(User.tenant_id == tenant_a.id)
|
||||
)
|
||||
return result.scalar_one()
|
||||
|
||||
|
||||
# ============================================================
|
||||
# HTTP CLIENT (function-scoped)
|
||||
# ============================================================
|
||||
|
||||
@pytest.fixture
|
||||
async def client(db) -> AsyncGenerator:
|
||||
"""
|
||||
httpx.AsyncClient contra la app FastAPI en memoria (sin red).
|
||||
get_db queda sobreescrito para inyectar la sesión de test.
|
||||
Los cambios del test se revierten al terminar (rollback en db).
|
||||
"""
|
||||
import httpx
|
||||
from httpx import ASGITransport
|
||||
from app.main import app
|
||||
from app.core.database import get_db
|
||||
|
||||
async def _override_get_db():
|
||||
yield db
|
||||
|
||||
app.dependency_overrides[get_db] = _override_get_db
|
||||
|
||||
async with httpx.AsyncClient(
|
||||
transport=ASGITransport(app=app),
|
||||
base_url="http://test",
|
||||
) as ac:
|
||||
yield ac
|
||||
|
||||
app.dependency_overrides.pop(get_db, None)
|
||||
|
||||
|
||||
# ============================================================
|
||||
# FIXTURES DE AISLAMIENTO MULTI-TENANT
|
||||
# ============================================================
|
||||
|
||||
@pytest.fixture
|
||||
def make_token():
|
||||
"""Factory de JWT tokens para autenticar clientes HTTP en tests."""
|
||||
from app.core.security import security
|
||||
|
||||
def _make(user):
|
||||
return security.create_access_token(data={"sub": str(user.id)})
|
||||
|
||||
return _make
|
||||
|
||||
|
||||
@pytest.fixture
|
||||
async def app_with_db(db):
|
||||
"""
|
||||
Override de get_db compartido para todos los HTTP clients de un mismo test.
|
||||
Garantiza que todos los clients usen la misma sesión (y el mismo rollback).
|
||||
"""
|
||||
from app.main import app as _app
|
||||
from app.core.database import get_db
|
||||
|
||||
async def _override():
|
||||
yield db
|
||||
|
||||
_app.dependency_overrides[get_db] = _override
|
||||
yield _app
|
||||
_app.dependency_overrides.pop(get_db, None)
|
||||
|
||||
|
||||
@pytest.fixture
|
||||
async def tenant_b(db):
|
||||
"""Tenant 'empresa-test' creado en la transacción del test (se revierte al final)."""
|
||||
from app.models.tenant import Tenant
|
||||
|
||||
t = Tenant(name="Empresa Test", slug="empresa-test")
|
||||
db.add(t)
|
||||
await db.flush()
|
||||
return t
|
||||
|
||||
|
||||
@pytest.fixture
|
||||
async def user_b(db, tenant_b):
|
||||
"""CLIENT_ADMIN en tenant_b — puede gestionar recursos de su tenant."""
|
||||
from app.models.user import User, UserRole
|
||||
from app.core.security import security
|
||||
|
||||
u = User(
|
||||
tenant_id=tenant_b.id,
|
||||
email="admin@empresa-test.com",
|
||||
first_name="Admin",
|
||||
last_name="Test",
|
||||
password_hash=security.hash_password("Test1234!"),
|
||||
role=UserRole.CLIENT_ADMIN,
|
||||
is_active=True,
|
||||
email_verified=True,
|
||||
)
|
||||
db.add(u)
|
||||
await db.flush()
|
||||
return u
|
||||
|
||||
|
||||
@pytest.fixture
|
||||
async def client_tenant_a(app_with_db, manager_user, make_token):
|
||||
"""HTTP client autenticado como SUPPORT_MANAGER de tenant_a (aduanasoft).
|
||||
Usa manager_user en lugar de admin_user para mantener el aislamiento de
|
||||
tenant en GET /users/ (el ADMIN global bypasa el filtro de tenant).
|
||||
"""
|
||||
import httpx
|
||||
from httpx import ASGITransport
|
||||
|
||||
token = make_token(manager_user)
|
||||
async with httpx.AsyncClient(
|
||||
transport=ASGITransport(app=app_with_db),
|
||||
base_url="http://test",
|
||||
headers={"Authorization": f"Bearer {token}"},
|
||||
) as ac:
|
||||
yield ac
|
||||
|
||||
|
||||
@pytest.fixture
|
||||
async def client_tenant_b(app_with_db, user_b, make_token):
|
||||
"""HTTP client autenticado como CLIENT_ADMIN de tenant_b (empresa-test)."""
|
||||
import httpx
|
||||
from httpx import ASGITransport
|
||||
|
||||
token = make_token(user_b)
|
||||
async with httpx.AsyncClient(
|
||||
transport=ASGITransport(app=app_with_db),
|
||||
base_url="http://test",
|
||||
headers={"Authorization": f"Bearer {token}"},
|
||||
) as ac:
|
||||
yield ac
|
||||
|
||||
|
||||
@pytest.fixture
|
||||
async def client_admin(app_with_db, admin_user, make_token):
|
||||
"""HTTP client autenticado como ADMIN global."""
|
||||
import httpx
|
||||
from httpx import ASGITransport
|
||||
|
||||
token = make_token(admin_user)
|
||||
async with httpx.AsyncClient(
|
||||
transport=ASGITransport(app=app_with_db),
|
||||
base_url="http://test",
|
||||
headers={"Authorization": f"Bearer {token}"},
|
||||
) as ac:
|
||||
yield ac
|
||||
|
||||
|
||||
@pytest.fixture
|
||||
def create_ticket_tenant_a(client_tenant_a):
|
||||
"""Factory: crea un ticket en tenant_a vía HTTP y retorna el JSON de respuesta."""
|
||||
async def _create(subject="Ticket Tenant A", priority="MEDIUM"):
|
||||
resp = await client_tenant_a.post("/v1/tickets/", json={
|
||||
"subject": subject,
|
||||
"description": "Test de aislamiento tenant A",
|
||||
"priority": priority,
|
||||
})
|
||||
assert resp.status_code in (200, 201), f"Error creando ticket A: {resp.text}"
|
||||
return resp.json()
|
||||
|
||||
return _create
|
||||
|
||||
|
||||
@pytest.fixture
|
||||
def create_ticket_tenant_b(client_tenant_b):
|
||||
"""Factory: crea un ticket en tenant_b vía HTTP y retorna el JSON de respuesta."""
|
||||
async def _create(subject="Ticket Tenant B", priority="MEDIUM"):
|
||||
resp = await client_tenant_b.post("/v1/tickets/", json={
|
||||
"subject": subject,
|
||||
"description": "Test de aislamiento tenant B",
|
||||
"priority": priority,
|
||||
})
|
||||
assert resp.status_code in (200, 201), f"Error creando ticket B: {resp.text}"
|
||||
return resp.json()
|
||||
|
||||
return _create
|
||||
|
||||
|
||||
@pytest.fixture
|
||||
def create_user_tenant_a(client_tenant_a):
|
||||
"""Factory: crea un usuario en tenant_a vía HTTP y retorna el JSON de respuesta."""
|
||||
async def _create(email="nuevo_user_a@test.com"):
|
||||
resp = await client_tenant_a.post("/v1/users/", json={
|
||||
"email": email,
|
||||
"first_name": "Usuario",
|
||||
"last_name": "TenantA",
|
||||
"password": "Test1234!",
|
||||
"role": "CLIENT_USER",
|
||||
})
|
||||
assert resp.status_code in (200, 201), f"Error creando user A: {resp.text}"
|
||||
return resp.json()
|
||||
|
||||
return _create
|
||||
|
||||
|
||||
@pytest.fixture
|
||||
def create_user_tenant_b(client_tenant_b):
|
||||
"""Factory: crea un usuario en tenant_b vía HTTP y retorna el JSON de respuesta."""
|
||||
async def _create(email="nuevo_user_b@test.com"):
|
||||
resp = await client_tenant_b.post("/v1/users/", json={
|
||||
"email": email,
|
||||
"first_name": "Usuario",
|
||||
"last_name": "TenantB",
|
||||
"password": "Test1234!",
|
||||
"role": "CLIENT_USER",
|
||||
})
|
||||
assert resp.status_code in (200, 201), f"Error creando user B: {resp.text}"
|
||||
return resp.json()
|
||||
|
||||
return _create
|
||||
137
backend/app/tests/test_smoke.py
Normal file
137
backend/app/tests/test_smoke.py
Normal file
@@ -0,0 +1,137 @@
|
||||
"""
|
||||
Smoke Tests - ServiceManagerWeb
|
||||
|
||||
Verifican que el stack completo funciona:
|
||||
- Conexión a BD Docker
|
||||
- Fixtures de tenant y usuarios
|
||||
- Login vía HTTP (httpx + FastAPI en memoria)
|
||||
- Endpoint protegido con token
|
||||
"""
|
||||
|
||||
import pytest
|
||||
|
||||
|
||||
# ============================================================
|
||||
# BD + FIXTURES
|
||||
# ============================================================
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_db_connected(db):
|
||||
"""La sesión de BD está activa y responde."""
|
||||
from sqlalchemy import text
|
||||
result = await db.execute(text("SELECT 1"))
|
||||
assert result.scalar() == 1
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_tenant_a_existe(tenant_a):
|
||||
"""El tenant 'aduanasoft' existe y tiene datos válidos."""
|
||||
assert tenant_a.slug == "aduanasoft"
|
||||
assert tenant_a.name is not None
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_admin_user_existe(admin_user):
|
||||
"""El usuario ADMIN existe y pertenece al tenant correcto."""
|
||||
from app.models.user import UserRole
|
||||
assert admin_user.email == "admin@aduanasoft.com"
|
||||
assert admin_user.role == UserRole.ADMIN
|
||||
assert admin_user.is_active is True
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_manager_user_existe(manager_user):
|
||||
"""El usuario SUPPORT_MANAGER existe."""
|
||||
from app.models.user import UserRole
|
||||
assert manager_user.email == "manager@aduanasoft.com"
|
||||
assert manager_user.role == UserRole.SUPPORT_MANAGER
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_agent_user_existe(agent_user):
|
||||
"""El usuario AGENT existe."""
|
||||
from app.models.user import UserRole
|
||||
assert agent_user.email == "agente@aduanasoft.com"
|
||||
assert agent_user.role == UserRole.AGENT
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_client_user_existe(user_tenant_a):
|
||||
"""El CLIENT_USER existe."""
|
||||
from app.models.user import UserRole
|
||||
assert user_tenant_a.email == "test_user@aduanasoft.com"
|
||||
assert user_tenant_a.role == UserRole.CLIENT_USER
|
||||
|
||||
|
||||
# ============================================================
|
||||
# HTTP — LOGIN
|
||||
# ============================================================
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_login_admin_ok(client):
|
||||
"""Login con credenciales de admin devuelve access_token."""
|
||||
response = await client.post(
|
||||
"/v1/auth/login",
|
||||
json={
|
||||
"email": "admin@aduanasoft.com",
|
||||
"password": "admin123",
|
||||
"tenant_slug": "aduanasoft",
|
||||
},
|
||||
)
|
||||
assert response.status_code == 200
|
||||
data = response.json()
|
||||
assert "access_token" in data
|
||||
assert data["token_type"] == "bearer"
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_login_credenciales_invalidas(client):
|
||||
"""Login con contraseña incorrecta devuelve 401."""
|
||||
response = await client.post(
|
||||
"/v1/auth/login",
|
||||
json={
|
||||
"email": "admin@aduanasoft.com",
|
||||
"password": "wrongpassword",
|
||||
"tenant_slug": "aduanasoft",
|
||||
},
|
||||
)
|
||||
assert response.status_code == 401
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_endpoint_sin_token_devuelve_401(client):
|
||||
"""Acceder a un endpoint protegido sin token devuelve 401."""
|
||||
response = await client.get(
|
||||
"/v1/users/me",
|
||||
headers={"X-Tenant-Slug": "aduanasoft"},
|
||||
)
|
||||
assert response.status_code == 401
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_login_y_me(client):
|
||||
"""Login exitoso → /users/me devuelve el usuario correcto."""
|
||||
# Login
|
||||
login = await client.post(
|
||||
"/v1/auth/login",
|
||||
json={
|
||||
"email": "admin@aduanasoft.com",
|
||||
"password": "admin123",
|
||||
"tenant_slug": "aduanasoft",
|
||||
},
|
||||
)
|
||||
assert login.status_code == 200
|
||||
token = login.json()["access_token"]
|
||||
|
||||
# Endpoint protegido
|
||||
me = await client.get(
|
||||
"/v1/users/me",
|
||||
headers={
|
||||
"Authorization": f"Bearer {token}",
|
||||
"X-Tenant-Slug": "aduanasoft",
|
||||
},
|
||||
)
|
||||
assert me.status_code == 200
|
||||
data = me.json()
|
||||
assert data["email"] == "admin@aduanasoft.com"
|
||||
assert data["role"] == "ADMIN"
|
||||
123
backend/app/tests/test_tenant_isolation.py
Normal file
123
backend/app/tests/test_tenant_isolation.py
Normal file
@@ -0,0 +1,123 @@
|
||||
"""
|
||||
Pruebas de aislamiento multi-tenant para tickets y usuarios.
|
||||
Usa solo los fixtures definidos en conftest.py.
|
||||
|
||||
Roles en juego:
|
||||
client_tenant_a → SUPPORT_MANAGER (aduanasoft) — restringido a su tenant
|
||||
client_tenant_b → CLIENT_ADMIN (empresa-test) — restringido a su tenant
|
||||
client_admin → ADMIN global (aduanasoft) — acceso a todos los tenants
|
||||
"""
|
||||
import pytest
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_tenant_a_cannot_see_tenant_b_tickets(
|
||||
client_tenant_a, create_ticket_tenant_b
|
||||
):
|
||||
"""
|
||||
El usuario del tenant B crea un ticket.
|
||||
El usuario del tenant A (SUPPORT_MANAGER) lista sus tickets.
|
||||
El ticket de tenant B NO debe aparecer en la respuesta.
|
||||
"""
|
||||
# El usuario del tenant B crea un ticket
|
||||
ticket_b = await create_ticket_tenant_b()
|
||||
ticket_b_id = ticket_b["id"]
|
||||
|
||||
# El usuario del tenant A lista sus tickets
|
||||
response = await client_tenant_a.get("/v1/tickets/")
|
||||
assert response.status_code == 200
|
||||
|
||||
ids_visibles = {t["id"] for t in response.json()}
|
||||
|
||||
# El ticket de tenant B no debe ser visible para tenant A
|
||||
assert ticket_b_id not in ids_visibles, (
|
||||
f"Fallo de aislamiento: ticket de tenant B ({ticket_b_id}) "
|
||||
f"visible para usuario de tenant A"
|
||||
)
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_tenant_b_cannot_edit_tenant_a_ticket(
|
||||
create_ticket_tenant_a, client_tenant_b
|
||||
):
|
||||
"""
|
||||
El usuario del tenant A crea un ticket.
|
||||
El usuario del tenant B intenta editar ese ticket vía PATCH.
|
||||
Debe recibir 403 (prohibido) o 404 (no encontrado).
|
||||
"""
|
||||
# El usuario del tenant A crea un ticket
|
||||
ticket_a = await create_ticket_tenant_a()
|
||||
ticket_a_id = ticket_a["id"]
|
||||
|
||||
# El usuario del tenant B intenta editar el ticket de tenant A
|
||||
response = await client_tenant_b.patch(
|
||||
f"/v1/tickets/{ticket_a_id}",
|
||||
json={"status": "CLOSED"},
|
||||
)
|
||||
|
||||
# Debe recibir 403 o 404 — nunca 200
|
||||
assert response.status_code in (403, 404), (
|
||||
f"Fallo de aislamiento: tenant B pudo editar ticket de tenant A "
|
||||
f"(HTTP {response.status_code})"
|
||||
)
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_tenant_a_cannot_see_tenant_b_users(
|
||||
client_tenant_a, create_user_tenant_b
|
||||
):
|
||||
"""
|
||||
El usuario del tenant B crea un usuario nuevo.
|
||||
El usuario del tenant A (SUPPORT_MANAGER) lista los usuarios.
|
||||
El usuario de tenant B NO debe aparecer en la respuesta.
|
||||
"""
|
||||
# El usuario del tenant B crea un usuario
|
||||
user_b = await create_user_tenant_b()
|
||||
user_b_id = user_b["id"]
|
||||
|
||||
# El usuario del tenant A lista los usuarios de su tenant
|
||||
response = await client_tenant_a.get("/v1/users/")
|
||||
assert response.status_code == 200
|
||||
|
||||
ids_visibles = {u["id"] for u in response.json()}
|
||||
|
||||
# El usuario de tenant B no debe ser visible para tenant A
|
||||
assert user_b_id not in ids_visibles, (
|
||||
f"Fallo de aislamiento: usuario de tenant B ({user_b_id}) "
|
||||
f"visible para usuario de tenant A"
|
||||
)
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_admin_sees_all_tenant_data(
|
||||
client_admin,
|
||||
create_ticket_tenant_a,
|
||||
create_ticket_tenant_b,
|
||||
create_user_tenant_a,
|
||||
create_user_tenant_b,
|
||||
):
|
||||
"""
|
||||
El ADMIN global debe poder ver tickets y usuarios de TODOS los tenants.
|
||||
- Tickets: vía /v1/tickets/admin/all (endpoint multi-tenant).
|
||||
- Usuarios: vía /v1/users/ (ADMIN bypasa el filtro de tenant).
|
||||
"""
|
||||
# Crear datos en ambos tenants
|
||||
ticket_a = await create_ticket_tenant_a()
|
||||
ticket_b = await create_ticket_tenant_b()
|
||||
user_a = await create_user_tenant_a()
|
||||
user_b = await create_user_tenant_b()
|
||||
|
||||
# El admin lista todos los tickets (endpoint multi-tenant)
|
||||
resp_tickets = await client_admin.get("/v1/tickets/admin/all")
|
||||
assert resp_tickets.status_code == 200
|
||||
ids_tickets = {t["id"] for t in resp_tickets.json()}
|
||||
assert ticket_a["id"] in ids_tickets, "El ADMIN no ve el ticket de tenant A"
|
||||
assert ticket_b["id"] in ids_tickets, "El ADMIN no ve el ticket de tenant B"
|
||||
|
||||
# El admin lista todos los usuarios (ADMIN bypasa filtro de tenant)
|
||||
resp_users = await client_admin.get("/v1/users/")
|
||||
assert resp_users.status_code == 200
|
||||
ids_users = {u["id"] for u in resp_users.json()}
|
||||
assert user_a["id"] in ids_users, "El ADMIN no ve el usuario de tenant A"
|
||||
assert user_b["id"] in ids_users, "El ADMIN no ve el usuario de tenant B"
|
||||
|
||||
Reference in New Issue
Block a user