mirror of
https://github.com/rennf93/roboco.git
synced 2026-08-03 07:23:24 +02:00
[F109] playbook curation status guards: approve/reject draft-only, archive approved-only
This commit is contained in:
@@ -110,3 +110,52 @@ async def test_non_curator_is_forbidden(db_session: AsyncSession) -> None:
|
||||
assert get_resp.status_code == HTTPStatus.FORBIDDEN
|
||||
assert approve_resp.status_code == HTTPStatus.FORBIDDEN
|
||||
app.dependency_overrides.clear()
|
||||
|
||||
|
||||
# --- F109: curation status-precondition guards at the route layer ------------- #
|
||||
# approve/reject only act on a draft; archive only retires an approved playbook.
|
||||
# A violation is a 409 Conflict (the curation is already finished), not a 200
|
||||
# that silently no-ops or a 500 from an uncaught ConflictError.
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_approve_already_approved_is_409(
|
||||
db_session: AsyncSession, auditor_client: AsyncClient
|
||||
) -> None:
|
||||
pid = await _seed_draft(db_session, title="Once only")
|
||||
first = await auditor_client.post(f"/api/playbooks/{pid}/approve")
|
||||
assert first.status_code == HTTPStatus.OK
|
||||
second = await auditor_client.post(f"/api/playbooks/{pid}/approve")
|
||||
assert second.status_code == HTTPStatus.CONFLICT
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_reject_approved_is_409(
|
||||
db_session: AsyncSession, auditor_client: AsyncClient
|
||||
) -> None:
|
||||
pid = await _seed_draft(db_session, title="Published route")
|
||||
await auditor_client.post(f"/api/playbooks/{pid}/approve")
|
||||
resp = await auditor_client.post(
|
||||
f"/api/playbooks/{pid}/reject", json={"reason": "changed my mind"}
|
||||
)
|
||||
assert resp.status_code == HTTPStatus.CONFLICT
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_archive_approved_succeeds(
|
||||
db_session: AsyncSession, auditor_client: AsyncClient
|
||||
) -> None:
|
||||
pid = await _seed_draft(db_session, title="Retire route")
|
||||
await auditor_client.post(f"/api/playbooks/{pid}/approve")
|
||||
resp = await auditor_client.post(f"/api/playbooks/{pid}/archive")
|
||||
assert resp.status_code == HTTPStatus.OK
|
||||
assert resp.json()["status"] == "archived"
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_archive_draft_is_409(
|
||||
db_session: AsyncSession, auditor_client: AsyncClient
|
||||
) -> None:
|
||||
pid = await _seed_draft(db_session, title="Not yet approved")
|
||||
resp = await auditor_client.post(f"/api/playbooks/{pid}/archive")
|
||||
assert resp.status_code == HTTPStatus.CONFLICT
|
||||
|
||||
@@ -111,7 +111,11 @@ async def test_approve_indexes_when_org_memory_on(
|
||||
)
|
||||
svc = PlaybookService(db_session)
|
||||
pb = await svc.draft(_create(title="Index me"), created_by=uuid4())
|
||||
await svc.approve(pb.id, approver_id=uuid4())
|
||||
approved = await svc.approve(pb.id, approver_id=uuid4())
|
||||
# approve() only flushes the status; indexing is the separate post-commit
|
||||
# step the route/verb runs after committing (so the index never leads the
|
||||
# status transaction). Mirror that ordering here.
|
||||
await svc.index_approved(approved)
|
||||
fake_optimal.index_playbook.assert_awaited_once()
|
||||
|
||||
|
||||
@@ -143,3 +147,77 @@ async def test_approve_survives_index_failure(
|
||||
pb = await svc.draft(_create(title="Resilient"), created_by=uuid4())
|
||||
approved = await svc.approve(pb.id, approver_id=uuid4()) # must not raise
|
||||
assert approved.status == PlaybookStatus.APPROVED
|
||||
|
||||
|
||||
# --- F109: approve/reject/archive status-precondition guards ---------------- #
|
||||
# The lifecycle is draft -> approved | archived, both terminal. approve/reject
|
||||
# only act on a DRAFT; archive only retires an APPROVED playbook. An archived
|
||||
# playbook is terminal — none of the three may touch it again. Without these
|
||||
# guards an archived playbook could be re-approved and an approved one rejected,
|
||||
# silently undoing a finished curation.
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_approve_rejects_already_approved(db_session: AsyncSession) -> None:
|
||||
svc = PlaybookService(db_session)
|
||||
pb = await svc.draft(_create(title="Once"), created_by=uuid4())
|
||||
await svc.approve(pb.id, approver_id=uuid4())
|
||||
with pytest.raises(ConflictError):
|
||||
await svc.approve(pb.id, approver_id=uuid4())
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_approve_rejects_archived(db_session: AsyncSession) -> None:
|
||||
svc = PlaybookService(db_session)
|
||||
pb = await svc.draft(_create(title="Done"), created_by=uuid4())
|
||||
await svc.reject(pb.id, approver_id=uuid4(), reason="duplicate")
|
||||
with pytest.raises(ConflictError):
|
||||
await svc.approve(pb.id, approver_id=uuid4())
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_reject_rejects_already_approved(db_session: AsyncSession) -> None:
|
||||
svc = PlaybookService(db_session)
|
||||
pb = await svc.draft(_create(title="Published svc"), created_by=uuid4())
|
||||
await svc.approve(pb.id, approver_id=uuid4())
|
||||
with pytest.raises(ConflictError):
|
||||
await svc.reject(pb.id, approver_id=uuid4(), reason="changed my mind")
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_reject_rejects_archived(db_session: AsyncSession) -> None:
|
||||
svc = PlaybookService(db_session)
|
||||
pb = await svc.draft(_create(title="Closed"), created_by=uuid4())
|
||||
await svc.reject(pb.id, approver_id=uuid4(), reason="duplicate")
|
||||
with pytest.raises(ConflictError):
|
||||
await svc.reject(pb.id, approver_id=uuid4(), reason="again")
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_archive_retires_approved(db_session: AsyncSession) -> None:
|
||||
svc = PlaybookService(db_session)
|
||||
auditor = uuid4()
|
||||
pb = await svc.draft(_create(title="Retire svc"), created_by=uuid4())
|
||||
await svc.approve(pb.id, approver_id=auditor)
|
||||
archived = await svc.archive(pb.id, approver_id=auditor)
|
||||
assert archived.status == PlaybookStatus.ARCHIVED
|
||||
assert archived.approved_by == auditor
|
||||
assert archived.approved_at is not None
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_archive_rejects_draft(db_session: AsyncSession) -> None:
|
||||
svc = PlaybookService(db_session)
|
||||
pb = await svc.draft(_create(title="Not yet"), created_by=uuid4())
|
||||
with pytest.raises(ConflictError):
|
||||
await svc.archive(pb.id, approver_id=uuid4())
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_archive_rejects_already_archived(db_session: AsyncSession) -> None:
|
||||
svc = PlaybookService(db_session)
|
||||
pb = await svc.draft(_create(title="Twice"), created_by=uuid4())
|
||||
await svc.approve(pb.id, approver_id=uuid4())
|
||||
await svc.archive(pb.id, approver_id=uuid4())
|
||||
with pytest.raises(ConflictError):
|
||||
await svc.archive(pb.id, approver_id=uuid4())
|
||||
|
||||
Reference in New Issue
Block a user