2026-05-06 00:32:52 +02:00
|
|
|
"""api.middleware coverage — pure-function status mapping + handlers."""
|
|
|
|
|
|
|
|
|
|
from __future__ import annotations
|
|
|
|
|
|
2026-05-06 21:02:31 +02:00
|
|
|
from http import HTTPStatus
|
2026-06-14 13:43:46 +02:00
|
|
|
from typing import Any
|
2026-05-06 21:02:31 +02:00
|
|
|
|
2026-06-05 16:35:22 +02:00
|
|
|
# UUID annotates a Pydantic model field below, so it must stay a runtime import
|
|
|
|
|
# (Pydantic resolves the annotation when building the model) despite `from
|
|
|
|
|
# __future__ import annotations` making it look type-checking-only to ruff.
|
|
|
|
|
from uuid import UUID # noqa: TC003
|
|
|
|
|
|
2026-05-06 00:32:52 +02:00
|
|
|
from fastapi import FastAPI, HTTPException
|
|
|
|
|
from fastapi.testclient import TestClient
|
2026-05-06 21:02:31 +02:00
|
|
|
from pydantic import BaseModel
|
2026-05-06 00:32:52 +02:00
|
|
|
from roboco.api.middleware import (
|
2026-06-05 16:35:22 +02:00
|
|
|
_uuid_field_remediation,
|
2026-05-06 00:32:52 +02:00
|
|
|
get_status_code,
|
|
|
|
|
setup_middleware,
|
|
|
|
|
)
|
|
|
|
|
from roboco.exceptions import (
|
|
|
|
|
AuthenticationError,
|
|
|
|
|
InvalidStateError,
|
|
|
|
|
NotFoundError,
|
|
|
|
|
PermissionDeniedError,
|
|
|
|
|
RobocoError,
|
|
|
|
|
ValidationError,
|
|
|
|
|
)
|
2026-05-08 07:45:18 +02:00
|
|
|
from roboco.services.base import (
|
|
|
|
|
ConflictError as ServiceConflictError,
|
|
|
|
|
)
|
|
|
|
|
from roboco.services.base import (
|
|
|
|
|
NotFoundError as ServiceNotFoundError,
|
|
|
|
|
)
|
|
|
|
|
from roboco.services.base import (
|
|
|
|
|
UnauthorizedError as ServiceUnauthorizedError,
|
|
|
|
|
)
|
|
|
|
|
from roboco.services.base import (
|
|
|
|
|
ValidationError as ServiceValidationError,
|
|
|
|
|
)
|
2026-05-06 00:32:52 +02:00
|
|
|
|
|
|
|
|
# ---------------------------------------------------------------------------
|
|
|
|
|
# get_status_code
|
|
|
|
|
# ---------------------------------------------------------------------------
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_get_status_code_for_not_found() -> None:
|
2026-05-06 21:02:31 +02:00
|
|
|
assert get_status_code(NotFoundError("Task", "abc")) == HTTPStatus.NOT_FOUND
|
2026-05-06 00:32:52 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_get_status_code_for_validation() -> None:
|
2026-05-06 21:02:31 +02:00
|
|
|
assert get_status_code(ValidationError("x")) == HTTPStatus.UNPROCESSABLE_ENTITY
|
2026-05-06 00:32:52 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_get_status_code_for_invalid_state() -> None:
|
2026-05-06 21:02:31 +02:00
|
|
|
assert (
|
|
|
|
|
get_status_code(InvalidStateError("pending", "complete")) == HTTPStatus.CONFLICT
|
|
|
|
|
)
|
2026-05-06 00:32:52 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_get_status_code_for_permission() -> None:
|
2026-05-06 21:02:31 +02:00
|
|
|
assert get_status_code(PermissionDeniedError("x")) == HTTPStatus.FORBIDDEN
|
2026-05-06 00:32:52 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_get_status_code_for_auth() -> None:
|
2026-05-06 21:02:31 +02:00
|
|
|
assert get_status_code(AuthenticationError("x")) == HTTPStatus.UNAUTHORIZED
|
2026-05-06 00:32:52 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_get_status_code_for_generic() -> None:
|
|
|
|
|
"""Unknown RobocoError subclass defaults to 400."""
|
2026-05-06 21:02:31 +02:00
|
|
|
assert get_status_code(RobocoError("x", code="other")) == HTTPStatus.BAD_REQUEST
|
2026-05-06 00:32:52 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
# ---------------------------------------------------------------------------
|
|
|
|
|
# Middleware integration via TestClient
|
|
|
|
|
# ---------------------------------------------------------------------------
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def _make_app() -> FastAPI:
|
|
|
|
|
app = FastAPI()
|
|
|
|
|
|
|
|
|
|
@app.get("/ok")
|
2026-06-14 13:43:46 +02:00
|
|
|
async def _ok() -> Any:
|
2026-05-06 00:32:52 +02:00
|
|
|
return {"status": "ok"}
|
|
|
|
|
|
|
|
|
|
@app.get("/raise")
|
2026-06-14 13:43:46 +02:00
|
|
|
async def _raise() -> Any:
|
2026-05-06 00:32:52 +02:00
|
|
|
raise RuntimeError("boom")
|
|
|
|
|
|
|
|
|
|
@app.get("/notfound")
|
2026-06-14 13:43:46 +02:00
|
|
|
async def _nf() -> Any:
|
2026-05-06 00:32:52 +02:00
|
|
|
raise NotFoundError("Resource", "abc")
|
|
|
|
|
|
|
|
|
|
@app.get("/http-error")
|
2026-06-14 13:43:46 +02:00
|
|
|
async def _he() -> Any:
|
2026-05-06 00:32:52 +02:00
|
|
|
raise HTTPException(status_code=403, detail="nope")
|
|
|
|
|
|
2026-05-08 07:45:18 +02:00
|
|
|
# service-layer errors (parallel hierarchy from roboco.services.base)
|
|
|
|
|
@app.get("/svc-notfound")
|
2026-06-14 13:43:46 +02:00
|
|
|
async def _svc_nf() -> Any:
|
2026-05-08 07:45:18 +02:00
|
|
|
raise ServiceNotFoundError("Channel", "main-pm")
|
|
|
|
|
|
|
|
|
|
@app.get("/svc-validation")
|
2026-06-14 13:43:46 +02:00
|
|
|
async def _svc_v() -> Any:
|
2026-05-08 07:45:18 +02:00
|
|
|
raise ServiceValidationError("invalid input", field="title")
|
|
|
|
|
|
|
|
|
|
@app.get("/svc-conflict")
|
2026-06-14 13:43:46 +02:00
|
|
|
async def _svc_c() -> Any:
|
2026-05-08 07:45:18 +02:00
|
|
|
raise ServiceConflictError("duplicate", resource_type="task")
|
|
|
|
|
|
|
|
|
|
@app.get("/svc-unauth")
|
2026-06-14 13:43:46 +02:00
|
|
|
async def _svc_u() -> Any:
|
2026-05-08 07:45:18 +02:00
|
|
|
raise ServiceUnauthorizedError("merge_pr", reason="not your PR")
|
|
|
|
|
|
2026-05-06 00:32:52 +02:00
|
|
|
setup_middleware(app)
|
|
|
|
|
return app
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_middleware_adds_correlation_id_header() -> None:
|
|
|
|
|
client = TestClient(_make_app())
|
|
|
|
|
response = client.get("/ok")
|
2026-05-06 21:02:31 +02:00
|
|
|
assert response.status_code == HTTPStatus.OK
|
2026-05-06 00:32:52 +02:00
|
|
|
assert "X-Correlation-ID" in response.headers
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_middleware_uses_provided_correlation_id() -> None:
|
|
|
|
|
client = TestClient(_make_app())
|
|
|
|
|
cid = "test-correlation-12345"
|
|
|
|
|
response = client.get("/ok", headers={"X-Correlation-ID": cid})
|
|
|
|
|
assert response.headers["X-Correlation-ID"] == cid
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_middleware_adds_response_time_header() -> None:
|
|
|
|
|
client = TestClient(_make_app())
|
|
|
|
|
response = client.get("/ok")
|
|
|
|
|
assert "X-Response-Time-Ms" in response.headers
|
|
|
|
|
|
|
|
|
|
|
2026-05-06 21:02:31 +02:00
|
|
|
def test_roboco_exception_translates_to_404() -> None:
|
2026-05-06 00:32:52 +02:00
|
|
|
client = TestClient(_make_app(), raise_server_exceptions=False)
|
|
|
|
|
response = client.get("/notfound")
|
2026-05-06 21:02:31 +02:00
|
|
|
assert response.status_code == HTTPStatus.NOT_FOUND
|
2026-05-06 00:32:52 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_http_exception_handler_returns_standardized_format() -> None:
|
|
|
|
|
client = TestClient(_make_app(), raise_server_exceptions=False)
|
|
|
|
|
response = client.get("/http-error")
|
2026-05-06 21:02:31 +02:00
|
|
|
assert response.status_code == HTTPStatus.FORBIDDEN
|
2026-05-06 00:32:52 +02:00
|
|
|
body = response.json()
|
|
|
|
|
assert "error" in body
|
|
|
|
|
|
|
|
|
|
|
2026-05-08 07:45:18 +02:00
|
|
|
# `roboco.services.base.ServiceError` is a parallel exception hierarchy
|
|
|
|
|
# (it does NOT inherit from RobocoError), so a separate handler maps it
|
|
|
|
|
# to clean 4xx codes instead of letting the generic 500 handler eat it.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_service_notfound_translates_to_404() -> None:
|
|
|
|
|
client = TestClient(_make_app(), raise_server_exceptions=False)
|
|
|
|
|
response = client.get("/svc-notfound")
|
|
|
|
|
assert response.status_code == HTTPStatus.NOT_FOUND
|
|
|
|
|
body = response.json()
|
|
|
|
|
assert body["error"] == "NotFoundError"
|
|
|
|
|
assert "main-pm" in body["message"]
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_service_validation_translates_to_422() -> None:
|
|
|
|
|
client = TestClient(_make_app(), raise_server_exceptions=False)
|
|
|
|
|
response = client.get("/svc-validation")
|
|
|
|
|
assert response.status_code == HTTPStatus.UNPROCESSABLE_ENTITY
|
|
|
|
|
body = response.json()
|
|
|
|
|
assert body["error"] == "ValidationError"
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_service_conflict_translates_to_409() -> None:
|
|
|
|
|
client = TestClient(_make_app(), raise_server_exceptions=False)
|
|
|
|
|
response = client.get("/svc-conflict")
|
|
|
|
|
assert response.status_code == HTTPStatus.CONFLICT
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_service_unauthorized_translates_to_403() -> None:
|
|
|
|
|
client = TestClient(_make_app(), raise_server_exceptions=False)
|
|
|
|
|
response = client.get("/svc-unauth")
|
|
|
|
|
assert response.status_code == HTTPStatus.FORBIDDEN
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_service_handler_carries_correlation_id() -> None:
|
|
|
|
|
client = TestClient(_make_app(), raise_server_exceptions=False)
|
|
|
|
|
cid = "test-svc-correlation-987"
|
|
|
|
|
response = client.get("/svc-notfound", headers={"X-Correlation-ID": cid})
|
|
|
|
|
body = response.json()
|
|
|
|
|
assert body["details"]["correlation_id"] == cid
|
|
|
|
|
|
|
|
|
|
|
2026-05-06 00:32:52 +02:00
|
|
|
def test_generic_exception_returns_500() -> None:
|
|
|
|
|
client = TestClient(_make_app(), raise_server_exceptions=False)
|
|
|
|
|
response = client.get("/raise")
|
2026-05-06 21:02:31 +02:00
|
|
|
assert response.status_code == HTTPStatus.INTERNAL_SERVER_ERROR
|
2026-05-06 00:32:52 +02:00
|
|
|
body = response.json()
|
|
|
|
|
assert "error" in body
|
2026-05-06 21:02:31 +02:00
|
|
|
|
|
|
|
|
|
2026-06-05 16:35:22 +02:00
|
|
|
# ---------------------------------------------------------------------------
|
|
|
|
|
# _uuid_field_remediation + truncated-task_id 422 remediation
|
|
|
|
|
# ---------------------------------------------------------------------------
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_uuid_field_remediation_hits_truncated_task_id() -> None:
|
|
|
|
|
errors = [{"loc": ("body", "task_id"), "type": "uuid_parsing", "msg": "bad"}]
|
|
|
|
|
hint = _uuid_field_remediation(errors)
|
|
|
|
|
assert hint is not None
|
|
|
|
|
assert "full" in hint.lower()
|
|
|
|
|
assert "uuid" in hint.lower()
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_uuid_field_remediation_ignores_other_field_errors() -> None:
|
|
|
|
|
errors = [{"loc": ("body", "title"), "type": "string_too_short", "msg": "x"}]
|
|
|
|
|
assert _uuid_field_remediation(errors) is None
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_uuid_field_remediation_ignores_non_uuid_task_id_errors() -> None:
|
|
|
|
|
errors = [{"loc": ("body", "task_id"), "type": "missing", "msg": "required"}]
|
|
|
|
|
assert _uuid_field_remediation(errors) is None
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
class _TaskIdBody(BaseModel):
|
|
|
|
|
task_id: UUID
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def _make_uuid_app() -> FastAPI:
|
|
|
|
|
app = FastAPI()
|
|
|
|
|
|
|
|
|
|
@app.post("/needs-uuid")
|
|
|
|
|
async def _need(body: _TaskIdBody) -> dict:
|
|
|
|
|
return {"task_id": str(body.task_id)}
|
|
|
|
|
|
|
|
|
|
setup_middleware(app)
|
|
|
|
|
return app
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_truncated_task_id_422_carries_remediation() -> None:
|
|
|
|
|
"""An 8-char task_id (the recurring agent mistake) returns 422 + remediate."""
|
|
|
|
|
client = TestClient(_make_uuid_app(), raise_server_exceptions=False)
|
|
|
|
|
response = client.post("/needs-uuid", json={"task_id": "cee99ecc"})
|
|
|
|
|
assert response.status_code == HTTPStatus.UNPROCESSABLE_ENTITY
|
|
|
|
|
body = response.json()
|
|
|
|
|
assert "remediate" in body
|
|
|
|
|
assert "full" in body["remediate"].lower()
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_other_validation_422_omits_remediation() -> None:
|
|
|
|
|
"""A non-task_id validation error keeps the standard 422 shape (no remediate)."""
|
|
|
|
|
client = TestClient(_make_uuid_app(), raise_server_exceptions=False)
|
|
|
|
|
response = client.post("/needs-uuid", json={}) # missing task_id entirely
|
|
|
|
|
assert response.status_code == HTTPStatus.UNPROCESSABLE_ENTITY
|
|
|
|
|
assert "remediate" not in response.json()
|
|
|
|
|
|
|
|
|
|
|
2026-05-06 21:02:31 +02:00
|
|
|
def test_request_validation_handler_returns_422_with_details() -> None:
|
|
|
|
|
"""request_validation_handler logs + returns 422 with errors+body (251-260)."""
|
|
|
|
|
|
|
|
|
|
class _Body(BaseModel):
|
|
|
|
|
name: str
|
|
|
|
|
|
|
|
|
|
app = FastAPI()
|
|
|
|
|
setup_middleware(app)
|
|
|
|
|
|
|
|
|
|
@app.post("/validate")
|
2026-06-14 13:43:46 +02:00
|
|
|
async def _v(_data: _Body) -> Any:
|
2026-05-06 21:02:31 +02:00
|
|
|
return {"ok": True}
|
|
|
|
|
|
|
|
|
|
client = TestClient(app, raise_server_exceptions=False)
|
|
|
|
|
response = client.post("/validate", json={"wrong_field": "x"})
|
|
|
|
|
assert response.status_code == HTTPStatus.UNPROCESSABLE_ENTITY
|
|
|
|
|
body = response.json()
|
|
|
|
|
assert "detail" in body
|
|
|
|
|
assert "body" in body
|