mirror of
https://github.com/fawney19/Aether.git
synced 2026-09-01 17:00:21 +08:00
feat(auth): 重构认证系统,引入 session 会话管理
- 新增 user_sessions 数据库表及 Alembic 迁移 - 实现 SessionService 会话生命周期管理(创建/刷新/撤销/清理) - 认证流程改用 refresh token cookie + access token 双令牌模式 - 前端实现自动静默刷新、跨标签页同步及设备指纹 - 用户设置页新增会话管理和密码修改功能 - 管理员用户管理新增强制登出和会话查看 - 密码策略增强,支持强度校验和泄露检测 - OAuth 登录流程适配新会话机制 - 新增完整的单元测试和 API 测试覆盖 Closes #232 Co-authored-by: LewisPen <LewisPen@nyadoo.com>
This commit is contained in:
@@ -268,10 +268,10 @@ class TestUserAuthentication:
|
||||
assert isinstance(result, AuthenticatedUserSnapshot)
|
||||
assert result.user_id == "user-123"
|
||||
assert result.username == "tester"
|
||||
thread_db.commit.assert_called_once()
|
||||
thread_db.commit.assert_not_called()
|
||||
thread_db.close.assert_called_once()
|
||||
route_db.commit.assert_not_called()
|
||||
invalidate_cache.assert_awaited_once_with("user-123", "test@example.com")
|
||||
invalidate_cache.assert_not_awaited()
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_load_user_for_pipeline_threadsafe_prefetches_balance(self) -> None:
|
||||
|
||||
129
tests/services/test_oauth_service.py
Normal file
129
tests/services/test_oauth_service.py
Normal file
@@ -0,0 +1,129 @@
|
||||
from __future__ import annotations
|
||||
|
||||
from types import SimpleNamespace
|
||||
from unittest.mock import AsyncMock, MagicMock
|
||||
from urllib.parse import parse_qs, urlparse
|
||||
|
||||
import pytest
|
||||
|
||||
from src.core.enums import AuthSource
|
||||
from src.services.auth.oauth.service import OAuthService
|
||||
from src.services.auth.oauth.state import OAuthStateData
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_build_bind_authorize_url_includes_client_device_id(
|
||||
monkeypatch: pytest.MonkeyPatch,
|
||||
) -> None:
|
||||
db = MagicMock()
|
||||
user = SimpleNamespace(id="user-1", auth_source=AuthSource.LOCAL)
|
||||
provider = SimpleNamespace(
|
||||
get_authorization_url=MagicMock(return_value="https://provider.example/authorize")
|
||||
)
|
||||
config = SimpleNamespace()
|
||||
create_state = AsyncMock(return_value="state-1")
|
||||
|
||||
monkeypatch.setattr(
|
||||
"src.services.auth.oauth.service.OAuthService._require_module_active",
|
||||
lambda _db: None,
|
||||
)
|
||||
monkeypatch.setattr(
|
||||
"src.services.auth.oauth.service.OAuthService._get_provider_impl",
|
||||
lambda _provider_type: provider,
|
||||
)
|
||||
monkeypatch.setattr(
|
||||
"src.services.auth.oauth.service.OAuthService._get_enabled_provider_config",
|
||||
lambda _db, _provider_type: config,
|
||||
)
|
||||
monkeypatch.setattr(
|
||||
"src.services.auth.oauth.service.get_redis_client",
|
||||
AsyncMock(return_value=object()),
|
||||
)
|
||||
monkeypatch.setattr(
|
||||
"src.services.auth.oauth.service.create_oauth_state",
|
||||
create_state,
|
||||
)
|
||||
|
||||
url = await OAuthService.build_bind_authorize_url(
|
||||
db,
|
||||
user,
|
||||
"github",
|
||||
client_device_id="device-1",
|
||||
)
|
||||
|
||||
assert url == "https://provider.example/authorize"
|
||||
assert create_state.await_args.kwargs["client_device_id"] == "device-1"
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_handle_callback_allows_bind_state_without_device_id(
|
||||
monkeypatch: pytest.MonkeyPatch,
|
||||
) -> None:
|
||||
db = MagicMock()
|
||||
provider = SimpleNamespace(
|
||||
exchange_code=AsyncMock(return_value=SimpleNamespace(access_token="provider-access")),
|
||||
get_user_info=AsyncMock(
|
||||
return_value=SimpleNamespace(
|
||||
id="oauth-user",
|
||||
username="tester",
|
||||
email="user@example.com",
|
||||
email_verified=True,
|
||||
raw={},
|
||||
)
|
||||
),
|
||||
)
|
||||
config = SimpleNamespace(
|
||||
frontend_callback_url="https://app.example.com/auth/callback",
|
||||
display_name="GitHub",
|
||||
is_enabled=True,
|
||||
)
|
||||
|
||||
monkeypatch.setattr(
|
||||
"src.services.auth.oauth.service.OAuthService._require_module_active",
|
||||
lambda _db: None,
|
||||
)
|
||||
monkeypatch.setattr(
|
||||
"src.services.auth.oauth.service.OAuthService._get_provider_impl",
|
||||
lambda _provider_type: provider,
|
||||
)
|
||||
monkeypatch.setattr(
|
||||
"src.services.auth.oauth.service.OAuthService._get_provider_config",
|
||||
lambda _db, _provider_type: config,
|
||||
)
|
||||
monkeypatch.setattr(
|
||||
"src.services.auth.oauth.service.get_redis_client",
|
||||
AsyncMock(return_value=object()),
|
||||
)
|
||||
monkeypatch.setattr(
|
||||
"src.services.auth.oauth.service.consume_oauth_state",
|
||||
AsyncMock(
|
||||
return_value=OAuthStateData(
|
||||
nonce="state-1",
|
||||
provider_type="github",
|
||||
action="bind",
|
||||
user_id="user-1",
|
||||
client_device_id=None,
|
||||
created_at=123,
|
||||
)
|
||||
),
|
||||
)
|
||||
monkeypatch.setattr(
|
||||
"src.services.auth.oauth.service.OAuthService._handle_bind",
|
||||
AsyncMock(return_value=SimpleNamespace()),
|
||||
)
|
||||
|
||||
result = await OAuthService.handle_callback(
|
||||
db=db,
|
||||
provider_type="github",
|
||||
state="state-1",
|
||||
code="code-1",
|
||||
error=None,
|
||||
error_description=None,
|
||||
client_ip=None,
|
||||
user_agent="pytest-agent",
|
||||
headers={},
|
||||
)
|
||||
|
||||
parsed = urlparse(result.redirect_url)
|
||||
assert result.refresh_token is None
|
||||
assert parse_qs(parsed.query)["oauth_bound"] == ["GitHub"]
|
||||
Reference in New Issue
Block a user