no-mistakes(document): Document P0 auth batch; reconcile HARDENING statuses; lint fixes
This commit is contained in:
+1
-1
@@ -17,8 +17,8 @@ os.environ["DATABASE_URL"] = f"sqlite+aiosqlite:///{_TMP_DIR}/test.db"
|
||||
os.environ.setdefault("SECRET_KEY", "test-secret-key-not-for-production-0123456789abcdef")
|
||||
os.environ.setdefault("CORS_ORIGINS", "http://test")
|
||||
|
||||
import pytest_asyncio # noqa: E402 (DATABASE_URL must be set before app imports)
|
||||
import pytest # noqa: E402
|
||||
import pytest_asyncio # noqa: E402 (DATABASE_URL must be set before app imports)
|
||||
from httpx import ASGITransport, AsyncClient # noqa: E402
|
||||
|
||||
from app.core.database import Base, async_session_factory, engine # noqa: E402
|
||||
|
||||
@@ -429,9 +429,10 @@ async def test_rate_limit_is_per_email(client: AsyncClient):
|
||||
|
||||
async def test_rate_limit_window_expires(client: AsyncClient, monkeypatch):
|
||||
"""After the 15-minute window passes, the account can log in again."""
|
||||
import app.core.ratelimit as ratelimit_mod
|
||||
import time as _time
|
||||
|
||||
import app.core.ratelimit as ratelimit_mod
|
||||
|
||||
email, password = "window@example.com", "password1"
|
||||
token = await _login(client)
|
||||
await client.post(
|
||||
|
||||
Reference in New Issue
Block a user