Skip to content

Testing

BrandonRobare edited this page Jun 2, 2026 · 1 revision

Testing

The suite is pytest, configured in pytest.ini with testpaths = tests. Tests run against temporary SQLite files created per process in tests/conftest.py, so they never touch demo or live data. The app fixture drops and recreates the schema around each test and sets TESTING=True, which also disables the rate limiter during tests.

Run the tests

Install the dev dependencies once (they include Playwright for the accessibility check):

pip install -r requirements-dev.txt

Run the standard suite:

python -m pytest -q

The browser-only accessibility checks carry the a11y_smoke marker and run on their own once Playwright Chromium is installed:

python -m pytest -q tests/test_accessibility_smoke.py

What the suite covers

The tests are grouped by area:

  • test_app.py covers core route reachability, the dashboard, and rendering for the main pages.
  • test_security.py is the largest file. It checks login success and failure, generic error messages, CSRF rejection, remember-me cookie flags, account lockout and expiry, IP throttling, open-redirect rejection on next targets, forced password change, the full MFA enrollment and challenge flow, account-settings password and MFA changes, role-based denial of the admin console and the users console, and the security response headers.
  • test_users_access.py covers the Superadmin user-management console: invite, activate, resend, cancel, role change, suspend, reactivate, temporary password, and the guard against removing the last active Superadmin.
  • test_order_workflow.py, test_customer_workflow.py, test_inventory_workflow.py, and test_product_workflow.py cover the create and edit flows for each record type, including validation errors and successful persistence.
  • test_add_flow_navigation.py and test_route_reachability.py check the Add New menu visibility by permission and that protected routes redirect anonymous users to login.
  • test_module_split_regression.py guards that the package split kept the public imports intact.
  • test_accessibility_smoke.py runs a Playwright smoke check for skip links and live regions, gated behind the a11y_smoke marker.

Test fixtures

conftest.py provides reusable fixtures: a client, a CSRF-enabled csrf_client, a login helper that handles the CSRF token and an optional MFA code, an admin_factory for building accounts with any role or status, and named fixtures for a Superadmin, a Staff Operator, a Dev Admin, and a suspended user. A totp_code_for fixture generates valid TOTP codes for MFA tests.

CI

GitHub Actions runs the suite on every push to main and on pull requests. The workflow in .github/workflows/pytest.yml has three jobs: a compile smoke check, the pytest matrix (Python 3.10 and 3.12 on pushes, 3.12 on PRs), and the Playwright accessibility smoke job. Separate workflows run CodeQL, dependency review, and gitleaks secret scanning.

Clone this wiki locally