Coverage for tests / test_security_openid_connect_optional.py: 100%

36 statements  

« prev     ^ index     » next       coverage.py v7.13.3, created at 2026-04-06 01:24 +0000

1from fastapi import Depends, FastAPI, Security 1adbc

2from fastapi.security.open_id_connect_url import OpenIdConnect 1adbc

3from fastapi.testclient import TestClient 1adbc

4from inline_snapshot import snapshot 1adbc

5from pydantic import BaseModel 1adbc

6 

7app = FastAPI() 1adbc

8 

9oid = OpenIdConnect(openIdConnectUrl="/openid", auto_error=False) 1adbc

10 

11 

12class User(BaseModel): 1adbc

13 username: str 1abc

14 

15 

16def get_current_user(oauth_header: str | None = Security(oid)): 1adbc

17 if oauth_header is None: 1lefmgnhiojk

18 return None 1lmno

19 user = User(username=oauth_header) 1efghijk

20 return user 1efghijk

21 

22 

23@app.get("/users/me") 1adbc

24def read_current_user(current_user: User | None = Depends(get_current_user)): 1adbc

25 if current_user is None: 1lefmgnhiojk

26 return {"msg": "Create an account first"} 1lmno

27 return current_user 1efghijk

28 

29 

30client = TestClient(app) 1adbc

31 

32 

33def test_security_oauth2(): 1adbc

34 response = client.get("/users/me", headers={"Authorization": "Bearer footokenbar"}) 1fgik

35 assert response.status_code == 200, response.text 1fgik

36 assert response.json() == {"username": "Bearer footokenbar"} 1fgik

37 

38 

39def test_security_oauth2_password_other_header(): 1adbc

40 response = client.get("/users/me", headers={"Authorization": "Other footokenbar"}) 1ephj

41 assert response.status_code == 200, response.text 1ephj

42 assert response.json() == {"username": "Other footokenbar"} 1ephj

43 

44 

45def test_security_oauth2_password_bearer_no_header(): 1adbc

46 response = client.get("/users/me") 1lmno

47 assert response.status_code == 200, response.text 1lmno

48 assert response.json() == {"msg": "Create an account first"} 1lmno

49 

50 

51def test_openapi_schema(): 1adbc

52 response = client.get("/openapi.json") 1qrst

53 assert response.status_code == 200, response.text 1qrst

54 assert response.json() == snapshot( 1qrst

55 { 

56 "openapi": "3.1.0", 

57 "info": {"title": "FastAPI", "version": "0.1.0"}, 

58 "paths": { 

59 "/users/me": { 

60 "get": { 

61 "responses": { 

62 "200": { 

63 "description": "Successful Response", 

64 "content": {"application/json": {"schema": {}}}, 

65 } 

66 }, 

67 "summary": "Read Current User", 

68 "operationId": "read_current_user_users_me_get", 

69 "security": [{"OpenIdConnect": []}], 

70 } 

71 } 

72 }, 

73 "components": { 

74 "securitySchemes": { 

75 "OpenIdConnect": { 

76 "type": "openIdConnect", 

77 "openIdConnectUrl": "/openid", 

78 } 

79 } 

80 }, 

81 } 

82 )