mirror of
https://github.com/hansjone/netx.git
synced 2026-10-09 00:43:17 +08:00
Polish HeroUI chrome, topology toolbar, and session client IP.
Checkpoint before workbench facade redesign: list defaults, API key quota, toast portal, topology canvas editor toolbar with More menu, and trusted-proxy client IP for sessions. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
parent
5096117ad4
commit
c4526e36d8
64 changed files with 6316 additions and 4521 deletions
|
|
@ -440,6 +440,30 @@ class AuthApiTests(unittest.TestCase):
|
|||
)
|
||||
self.assertEqual(empty.status_code, 400)
|
||||
|
||||
def test_api_token_max_count(self) -> None:
|
||||
token = self._login()
|
||||
with patch("netx_api.auth_service.settings.auth_api_token_max_count", 2):
|
||||
listed = self.client.get("/v1/api-tokens", headers={"Authorization": f"Bearer {token}"})
|
||||
self.assertEqual(listed.status_code, 200, listed.text)
|
||||
body = listed.json()
|
||||
self.assertEqual(body.get("max_count"), 2)
|
||||
active = int(body.get("active_count") or 0)
|
||||
while active < 2:
|
||||
created = self.client.post(
|
||||
"/v1/api-tokens",
|
||||
headers={"Authorization": f"Bearer {token}"},
|
||||
json={"name": f"cap-{active}", "expires_in_days": 7},
|
||||
)
|
||||
self.assertEqual(created.status_code, 200, created.text)
|
||||
active += 1
|
||||
blocked = self.client.post(
|
||||
"/v1/api-tokens",
|
||||
headers={"Authorization": f"Bearer {token}"},
|
||||
json={"name": "over-cap", "expires_in_days": 7},
|
||||
)
|
||||
self.assertEqual(blocked.status_code, 400, blocked.text)
|
||||
self.assertIn("api_token_limit_reached", str(blocked.json().get("detail") or ""))
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
unittest.main()
|
||||
|
|
|
|||
46
tests/test_client_ip.py
Normal file
46
tests/test_client_ip.py
Normal file
|
|
@ -0,0 +1,46 @@
|
|||
"""Unit tests for reverse-proxy client IP resolution."""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import unittest
|
||||
from unittest.mock import patch
|
||||
|
||||
from netx_api.client_ip import resolve_client_ip_from
|
||||
|
||||
|
||||
class ClientIpTests(unittest.TestCase):
|
||||
def test_direct_peer_when_not_trusted(self) -> None:
|
||||
with patch("netx_api.client_ip.settings.trusted_proxy_ips", "127.0.0.1"):
|
||||
ip = resolve_client_ip_from(
|
||||
"203.0.113.9",
|
||||
{"x-forwarded-for": "198.51.100.1", "x-real-ip": "198.51.100.1"},
|
||||
)
|
||||
self.assertEqual(ip, "203.0.113.9")
|
||||
|
||||
def test_xff_when_peer_is_loopback(self) -> None:
|
||||
with patch("netx_api.client_ip.settings.trusted_proxy_ips", "127.0.0.1,::1"):
|
||||
ip = resolve_client_ip_from(
|
||||
"127.0.0.1",
|
||||
{"x-forwarded-for": "198.51.100.44, 10.0.0.1"},
|
||||
)
|
||||
self.assertEqual(ip, "198.51.100.44")
|
||||
|
||||
def test_x_real_ip_preferred(self) -> None:
|
||||
with patch("netx_api.client_ip.settings.trusted_proxy_ips", "127.0.0.1"):
|
||||
ip = resolve_client_ip_from(
|
||||
"127.0.0.1",
|
||||
{"x-real-ip": "203.0.113.50", "x-forwarded-for": "198.51.100.1"},
|
||||
)
|
||||
self.assertEqual(ip, "203.0.113.50")
|
||||
|
||||
def test_cf_connecting_ip(self) -> None:
|
||||
with patch("netx_api.client_ip.settings.trusted_proxy_ips", "127.0.0.1"):
|
||||
ip = resolve_client_ip_from(
|
||||
"127.0.0.1",
|
||||
{"cf-connecting-ip": "203.0.113.77", "x-forwarded-for": "198.51.100.1"},
|
||||
)
|
||||
self.assertEqual(ip, "203.0.113.77")
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
unittest.main()
|
||||
Loading…
Add table
Add a link
Reference in a new issue