no-mistakes(document): Document P0 auth batch; reconcile HARDENING statuses; lint fixes

This commit is contained in:
root
2026-09-08 12:48:47 +00:00
parent f1b68dd1b7
commit e627f50f66
6 changed files with 67 additions and 49 deletions
+1 -1
View File
@@ -17,8 +17,8 @@ os.environ["DATABASE_URL"] = f"sqlite+aiosqlite:///{_TMP_DIR}/test.db"
os.environ.setdefault("SECRET_KEY", "test-secret-key-not-for-production-0123456789abcdef")
os.environ.setdefault("CORS_ORIGINS", "http://test")
import pytest_asyncio # noqa: E402 (DATABASE_URL must be set before app imports)
import pytest # noqa: E402
import pytest_asyncio # noqa: E402 (DATABASE_URL must be set before app imports)
from httpx import ASGITransport, AsyncClient # noqa: E402
from app.core.database import Base, async_session_factory, engine # noqa: E402
+2 -1
View File
@@ -429,9 +429,10 @@ async def test_rate_limit_is_per_email(client: AsyncClient):
async def test_rate_limit_window_expires(client: AsyncClient, monkeypatch):
"""After the 15-minute window passes, the account can log in again."""
import app.core.ratelimit as ratelimit_mod
import time as _time
import app.core.ratelimit as ratelimit_mod
email, password = "window@example.com", "password1"
token = await _login(client)
await client.post(