-
Notifications
You must be signed in to change notification settings - Fork 0
Testing
The suite is pytest, configured in pytest.ini with testpaths = tests. Tests run against temporary SQLite files created per process in tests/conftest.py, so they never touch demo or live data. The app fixture drops and recreates the schema around each test and sets TESTING=True, which also disables the rate limiter during tests.
Install the dev dependencies once (they include Playwright for the accessibility check):
pip install -r requirements-dev.txtRun the standard suite:
python -m pytest -qThe browser-only accessibility checks carry the a11y_smoke marker and run on their own once Playwright Chromium is installed:
python -m pytest -q tests/test_accessibility_smoke.pyThe tests are grouped by area:
-
test_app.pycovers core route reachability, the dashboard, and rendering for the main pages. -
test_security.pyis the largest file. It checks login success and failure, generic error messages, CSRF rejection, remember-me cookie flags, account lockout and expiry, IP throttling, open-redirect rejection onnexttargets, forced password change, the full MFA enrollment and challenge flow, account-settings password and MFA changes, role-based denial of the admin console and the users console, and the security response headers. -
test_users_access.pycovers the Superadmin user-management console: invite, activate, resend, cancel, role change, suspend, reactivate, temporary password, and the guard against removing the last active Superadmin. -
test_order_workflow.py,test_customer_workflow.py,test_inventory_workflow.py, andtest_product_workflow.pycover the create and edit flows for each record type, including validation errors and successful persistence. -
test_add_flow_navigation.pyandtest_route_reachability.pycheck the Add New menu visibility by permission and that protected routes redirect anonymous users to login. -
test_module_split_regression.pyguards that the package split kept the public imports intact. -
test_accessibility_smoke.pyruns a Playwright smoke check for skip links and live regions, gated behind thea11y_smokemarker.
conftest.py provides reusable fixtures: a client, a CSRF-enabled csrf_client, a login helper that handles the CSRF token and an optional MFA code, an admin_factory for building accounts with any role or status, and named fixtures for a Superadmin, a Staff Operator, a Dev Admin, and a suspended user. A totp_code_for fixture generates valid TOTP codes for MFA tests.
GitHub Actions runs the suite on every push to main and on pull requests. The workflow in .github/workflows/pytest.yml has three jobs: a compile smoke check, the pytest matrix (Python 3.10 and 3.12 on pushes, 3.12 on PRs), and the Playwright accessibility smoke job. Separate workflows run CodeQL, dependency review, and gitleaks secret scanning.