The backend had zero tests. This adds 33, all pure (no DB, no network), plus the harness to run them in the gate: - backend/Dockerfile.test: the app's deps + pinned pytest/ruff, code bind-mounted at run time so it always tests the working tree. Isolated from the prod Dockerfile, so the published image never carries test tooling. - requirements-dev.txt: pytest==8.4.2, ruff==0.15.21 (the version the gate already runs) — the backend lane is now pinned, not just host-global. - tests: normalize_title (de-shout, hashtag strip, emoji drop, trilingual letters survive); storage sanitize/rel_path/download_filename and the safe_abs_path traversal guard (../ and absolute-path escapes rejected — verified by mutation); links HMAC grants (round-trip, wrong-token, tampered sig/exp, expiry) + is_expired; a DB-free app-assembly smoke (every router wires up, OpenAPI generates). DB-backed router smoke (auth/feed/downloads) needs a test Postgres + migrations — deferred. useCardPager needs hook-test infra (jsdom/renderHook) — deferred.
7 lines
402 B
Plaintext
7 lines
402 B
Plaintext
# Test + lint tooling — NEVER in the prod image (installed only in the Dockerfile's `dev` stage,
|
|
# which `siftlode publish` does not target). Pinned so the gate is reproducible: the same ruff the
|
|
# `siftlode check` backend lane runs, and pytest for the pure-logic suite. httpx is already an app
|
|
# dependency (requirements.txt), so its TestClient needs nothing extra here.
|
|
pytest==8.4.2
|
|
ruff==0.15.21
|