Polish HeroUI chrome, topology toolbar, and session client IP.

Checkpoint before workbench facade redesign: list defaults, API key quota, toast portal, topology canvas editor toolbar with More menu, and trusted-proxy client IP for sessions.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
oliver 2026-09-12 15:10:57 +08:00
parent 5096117ad4
commit c4526e36d8
64 changed files with 6316 additions and 4521 deletions

View file

@ -440,6 +440,30 @@ class AuthApiTests(unittest.TestCase):
)
self.assertEqual(empty.status_code, 400)
def test_api_token_max_count(self) -> None:
token = self._login()
with patch("netx_api.auth_service.settings.auth_api_token_max_count", 2):
listed = self.client.get("/v1/api-tokens", headers={"Authorization": f"Bearer {token}"})
self.assertEqual(listed.status_code, 200, listed.text)
body = listed.json()
self.assertEqual(body.get("max_count"), 2)
active = int(body.get("active_count") or 0)
while active < 2:
created = self.client.post(
"/v1/api-tokens",
headers={"Authorization": f"Bearer {token}"},
json={"name": f"cap-{active}", "expires_in_days": 7},
)
self.assertEqual(created.status_code, 200, created.text)
active += 1
blocked = self.client.post(
"/v1/api-tokens",
headers={"Authorization": f"Bearer {token}"},
json={"name": "over-cap", "expires_in_days": 7},
)
self.assertEqual(blocked.status_code, 400, blocked.text)
self.assertIn("api_token_limit_reached", str(blocked.json().get("detail") or ""))
if __name__ == "__main__":
unittest.main()

46
tests/test_client_ip.py Normal file
View file

@ -0,0 +1,46 @@
"""Unit tests for reverse-proxy client IP resolution."""
from __future__ import annotations
import unittest
from unittest.mock import patch
from netx_api.client_ip import resolve_client_ip_from
class ClientIpTests(unittest.TestCase):
def test_direct_peer_when_not_trusted(self) -> None:
with patch("netx_api.client_ip.settings.trusted_proxy_ips", "127.0.0.1"):
ip = resolve_client_ip_from(
"203.0.113.9",
{"x-forwarded-for": "198.51.100.1", "x-real-ip": "198.51.100.1"},
)
self.assertEqual(ip, "203.0.113.9")
def test_xff_when_peer_is_loopback(self) -> None:
with patch("netx_api.client_ip.settings.trusted_proxy_ips", "127.0.0.1,::1"):
ip = resolve_client_ip_from(
"127.0.0.1",
{"x-forwarded-for": "198.51.100.44, 10.0.0.1"},
)
self.assertEqual(ip, "198.51.100.44")
def test_x_real_ip_preferred(self) -> None:
with patch("netx_api.client_ip.settings.trusted_proxy_ips", "127.0.0.1"):
ip = resolve_client_ip_from(
"127.0.0.1",
{"x-real-ip": "203.0.113.50", "x-forwarded-for": "198.51.100.1"},
)
self.assertEqual(ip, "203.0.113.50")
def test_cf_connecting_ip(self) -> None:
with patch("netx_api.client_ip.settings.trusted_proxy_ips", "127.0.0.1"):
ip = resolve_client_ip_from(
"127.0.0.1",
{"cf-connecting-ip": "203.0.113.77", "x-forwarded-for": "198.51.100.1"},
)
self.assertEqual(ip, "203.0.113.77")
if __name__ == "__main__":
unittest.main()