|
3 | 3 | import pytest |
4 | 4 | from django.test import override_settings |
5 | 5 |
|
6 | | -from sentry.seer.signed_seer_api import make_signed_seer_api_request |
| 6 | +from sentry.auth.services.auth import AuthenticatedToken |
| 7 | +from sentry.seer.signed_seer_api import ( |
| 8 | + SeerViewerContext, |
| 9 | + _resolve_viewer_context, |
| 10 | + make_signed_seer_api_request, |
| 11 | +) |
| 12 | +from sentry.viewer_context import ActorType, ViewerContext, viewer_context_scope |
7 | 13 |
|
8 | 14 | REQUEST_BODY = b'{"b": 12, "thing": "thing"}' |
9 | 15 | PATH = "/v0/some/url" |
@@ -111,3 +117,78 @@ def test_times_request(mock_metrics_timer: MagicMock, path: str) -> None: |
111 | 117 | "endpoint": PATH, |
112 | 118 | }, |
113 | 119 | ) |
| 120 | + |
| 121 | + |
| 122 | +class TestResolveViewerContext: |
| 123 | + def test_both_none(self) -> None: |
| 124 | + assert _resolve_viewer_context(None) is None |
| 125 | + |
| 126 | + def test_contextvar_only(self) -> None: |
| 127 | + ctx = ViewerContext(organization_id=42, user_id=7, actor_type=ActorType.USER) |
| 128 | + with viewer_context_scope(ctx): |
| 129 | + result = _resolve_viewer_context(None) |
| 130 | + |
| 131 | + assert result is not None |
| 132 | + assert result["organization_id"] == 42 |
| 133 | + assert result["user_id"] == 7 |
| 134 | + assert result["actor_type"] == "user" |
| 135 | + |
| 136 | + def test_explicit_only(self) -> None: |
| 137 | + result = _resolve_viewer_context(SeerViewerContext(organization_id=99, user_id=5)) |
| 138 | + assert result is not None |
| 139 | + assert result["organization_id"] == 99 |
| 140 | + assert result["user_id"] == 5 |
| 141 | + |
| 142 | + def test_contextvar_with_token(self) -> None: |
| 143 | + token = AuthenticatedToken( |
| 144 | + kind="api_token", |
| 145 | + scopes=["org:read", "project:write"], |
| 146 | + allowed_origins=[], |
| 147 | + ) |
| 148 | + ctx = ViewerContext(organization_id=42, user_id=7, actor_type=ActorType.USER, token=token) |
| 149 | + with viewer_context_scope(ctx): |
| 150 | + result = _resolve_viewer_context(None) |
| 151 | + |
| 152 | + assert result is not None |
| 153 | + assert result["token"]["kind"] == "api_token" |
| 154 | + assert set(result["token"]["scopes"]) == {"org:read", "project:write"} |
| 155 | + |
| 156 | + def test_explicit_overrides_contextvar(self) -> None: |
| 157 | + ctx = ViewerContext(organization_id=42, user_id=7, actor_type=ActorType.USER) |
| 158 | + with viewer_context_scope(ctx): |
| 159 | + result = _resolve_viewer_context(SeerViewerContext(organization_id=42, user_id=99)) |
| 160 | + |
| 161 | + assert result is not None |
| 162 | + assert result["organization_id"] == 42 |
| 163 | + assert result["user_id"] == 99 |
| 164 | + assert result["actor_type"] == "user" |
| 165 | + |
| 166 | + @patch("sentry.seer.signed_seer_api.logger") |
| 167 | + def test_mismatch_warns_and_strips_token(self, mock_logger: MagicMock) -> None: |
| 168 | + token = AuthenticatedToken( |
| 169 | + kind="api_token", |
| 170 | + scopes=["org:read"], |
| 171 | + allowed_origins=[], |
| 172 | + ) |
| 173 | + ctx = ViewerContext(organization_id=42, user_id=7, actor_type=ActorType.USER, token=token) |
| 174 | + with viewer_context_scope(ctx): |
| 175 | + result = _resolve_viewer_context(SeerViewerContext(organization_id=999)) |
| 176 | + |
| 177 | + assert result is not None |
| 178 | + assert result["organization_id"] == 999 |
| 179 | + assert "token" not in result |
| 180 | + mock_logger.warning.assert_called_once() |
| 181 | + assert mock_logger.warning.call_args[0][0] == "seer.viewer_context_mismatch" |
| 182 | + |
| 183 | + def test_no_mismatch_keeps_token(self) -> None: |
| 184 | + token = AuthenticatedToken( |
| 185 | + kind="api_token", |
| 186 | + scopes=["org:read"], |
| 187 | + allowed_origins=[], |
| 188 | + ) |
| 189 | + ctx = ViewerContext(organization_id=42, user_id=7, actor_type=ActorType.USER, token=token) |
| 190 | + with viewer_context_scope(ctx): |
| 191 | + result = _resolve_viewer_context(SeerViewerContext(organization_id=42, user_id=7)) |
| 192 | + |
| 193 | + assert result is not None |
| 194 | + assert "token" in result |
0 commit comments