aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/tests/test_hub_api.py
diff options
context:
space:
mode:
Diffstat (limited to 'packages/meshbay-hub/tests/test_hub_api.py')
-rw-r--r--packages/meshbay-hub/tests/test_hub_api.py17
1 files changed, 6 insertions, 11 deletions
diff --git a/packages/meshbay-hub/tests/test_hub_api.py b/packages/meshbay-hub/tests/test_hub_api.py
index 162b074..378bbb8 100644
--- a/packages/meshbay-hub/tests/test_hub_api.py
+++ b/packages/meshbay-hub/tests/test_hub_api.py
@@ -3,13 +3,14 @@ Integration tests for the Hub API.
Uses SQLite in-memory + httpx.AsyncClient — no PostgreSQL, no network.
"""
-from meshbay_common.tokens import HUB_API_AUD
from datetime import UTC
import pytest
from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PrivateKey
from cryptography.hazmat.primitives.asymmetric.x25519 import X25519PrivateKey
+from membership import add_member
from meshbay_common.crypto import pk_to_b64
+from meshbay_common.tokens import HUB_API_AUD
from meshbay_hub.api.deps import set_admin_usernames
@@ -272,8 +273,7 @@ async def test_group_member_add(client):
group_id = r.json()["group_id"]
# Add bob as member (hub handles membership only, GEK exchange is P2P)
- r = await client.post(f"/v1/groups/{group_id}/members/bob2_test",
- json={}, headers=a_hdrs)
+ r = await add_member(client, group_id, 'bob2_test', a_hdrs)
assert r.status_code == 201
# Verify bob is in the group
@@ -314,8 +314,7 @@ async def test_non_admin_cannot_add_member(client):
group_id = r.json()["group_id"]
# Dan (non-admin) tries to add a member → 403
- r = await client.post(f"/v1/groups/{group_id}/members/charlie_test",
- json={},
+ r = await client.post(f"/v1/groups/{group_id}/members/charlie_test", json={},
headers={"Authorization": f"Bearer {dan_token}"})
assert r.status_code == 403
@@ -352,9 +351,7 @@ async def test_jwt_contains_groups_claim(client):
headers={"Authorization": f"Bearer {alice_token}"})
group_id = r.json()["group_id"]
- await client.post(f"/v1/groups/{group_id}/members/grp_bob_test",
- json={},
- headers={"Authorization": f"Bearer {alice_token}"})
+ await add_member(client, group_id, 'grp_bob_test', {"Authorization": f"Bearer {alice_token}"})
# Login again — groups should contain the new group
r = await client.post("/v1/users/login", json={
@@ -400,9 +397,7 @@ async def test_my_groups(client, db_session):
r = await client.post("/v1/groups", json={"name": "mg-group"},
headers={"Authorization": f"Bearer {alice_token}"})
group_id = r.json()["group_id"]
- await client.post(f"/v1/groups/{group_id}/members/mg_bob_test",
- json={},
- headers={"Authorization": f"Bearer {alice_token}"})
+ await add_member(client, group_id, 'mg_bob_test', {"Authorization": f"Bearer {alice_token}"})
# A group no node has announced is shown to its owner only — a member would
# otherwise see a name they cannot open. Stamped here so the rest of this