Files
roboco/tests/unit/enforcement/test_channel_access.py
T
Renn F 64c48356d0 test: lift coverage 41% → 76% (+1068 tests across 36 files)
Service-level tests now exercise provider, permissions, project, journal,
messaging, work_session, metrics, kanban, extraction, learning, notification,
dashboard, llm_routing, a2a, task, repository_base, audit, db_seed,
branch_name, indexed_document, query_helpers, agent. API route tests cover
provider, journal, project, sessions, dashboard, work_session, tasks, a2a,
groups, notifications, agents, channels, messages, kanban, api_resources.
Pure-function helpers covered: handlers, deps_helpers, middleware,
middleware_docs, transcription, pr templates, agents_config, errors,
logging, journal/notification/channel/a2a access, task_lifecycle,
streaming, converters, crypto, schemas (common + websocket), events,
permissions extras.

pyproject ruff per-file-ignores extended for tests so PLR2004 (status code
magic values), PLC0415 (lazy imports), PLR0913 (fixture params), ARG001
(unused fixture deps), SIM105, and E501 don't fight test idioms.
2026-05-06 00:32:52 +02:00

60 lines
1.9 KiB
Python

"""enforcement.channel_access coverage."""
from __future__ import annotations
import pytest
from roboco.enforcement.channel_access import (
ChannelAccessDeniedError,
get_agent_channels,
validate_channel_access,
)
def test_validate_channel_access_invalid_action_raises() -> None:
with pytest.raises(ValueError, match="Invalid action"):
validate_channel_access("be-dev-1", "backend-cell", "execute")
def test_validate_channel_access_unknown_channel_denied() -> None:
with pytest.raises(ChannelAccessDeniedError, match="not configured"):
validate_channel_access("be-dev-1", "ghost-channel", "read")
def test_validate_channel_access_known_channel_allowed_member() -> None:
"""A backend dev should be able to read backend-cell."""
result = validate_channel_access("be-dev-1", "backend-cell", "read")
assert result is True
def test_validate_channel_access_unauthorized_agent_denied() -> None:
"""Random agent ID won't be in any allow lists."""
with pytest.raises(ChannelAccessDeniedError):
validate_channel_access("ghost-agent", "backend-cell", "write")
def test_get_agent_channels_returns_list_for_known_agent() -> None:
channels = get_agent_channels("be-dev-1", action="read")
assert isinstance(channels, list)
def test_get_agent_channels_for_unknown_agent_returns_only_wildcard() -> None:
"""Unknown agent gets only wildcard-permitted channels."""
channels = get_agent_channels("ghost-agent", action="read")
assert isinstance(channels, list)
def test_get_agent_channels_write_action() -> None:
channels = get_agent_channels("main-pm", action="write")
assert isinstance(channels, list)
def test_channel_access_denied_error_has_attributes() -> None:
err = ChannelAccessDeniedError(
agent_id="be-dev-1",
channel_slug="ghost",
action="write",
)
assert err.agent_id == "be-dev-1"
assert err.channel_slug == "ghost"
assert err.action == "write"