tests/auth/test_csrf.py : vérifie que CSRF est actif (#73)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Colin Maudry
2026-04-20 22:56:58 +02:00
parent 20e7eed424
commit 5151b32f3e
+31
View File
@@ -0,0 +1,31 @@
import pytest
from flask import Flask
from src.auth.setup import init_auth
@pytest.fixture
def csrf_app(users_db_path, monkeypatch):
monkeypatch.setenv("WTF_CSRF_ENABLED", "True")
monkeypatch.setenv("SECRET_KEY", "test-secret-key")
app = Flask(__name__)
app.config["WTF_CSRF_ENABLED"] = True
init_auth(app)
return app
@pytest.fixture
def csrf_client(csrf_app):
return csrf_app.test_client()
def test_post_without_csrf_rejected(csrf_client, users_db_path):
resp = csrf_client.post(
"/auth/signup",
data={
"email": "a@b.c",
"password": "password12",
"password_confirm": "password12",
},
)
assert resp.status_code == 400 # CSRF failed