Files
signoz/tests/pyproject.toml
Pandey cd8346a91a test(callbackauthn): cover the google authn flow end to end (#12486)
#### Description

- Adds end-to-end coverage for the google authn flow
(`callbackauthn/04_google.py`): happy-path login, hd-claim mismatch
rejection, unverified-email rejection + `insecureSkipEmailVerified`
opt-in, and roleMapping defaultRole.
- The google callback authn hardcodes `https://accounts.google.com` as
its issuer and fully verifies the RS256 id_token, so a wiremock
container impersonates Google: it joins the test network under the
`accounts.google.com` alias and serves HTTPS with a certificate issued
by a new integration CA (`tests/fixtures/tls.py`), which every signoz
container now trusts via `SSL_CERT_FILE`.
- Stubs (discovery, auto-approving authorize, token, JWKS) are installed
per test via the existing `make_http_mocks` fixture with a pre-signed
id_token for the identity under test; one session-scoped RSA key signs
all tokens.
2026-08-10 08:35:58 +00:00

85 lines
2.9 KiB
TOML

[project]
name = "tests"
version = "0.1.0"
description = ""
authors = [{ name = "therealpandey", email = "vibhupandey28@gmail.com" }]
requires-python = ">=3.13"
dependencies = [
"pytest>=9.0.3",
"psycopg2>=2.9.10",
"testcontainers[clickhouse,keycloak,postgres]>=4.13.1",
"wiremock>=2.6.1",
"numpy>=2.3.2",
"clickhouse-connect>=0.8.18",
"svix-ksuid>=0.6.2",
"requests>=2.33.0",
"sqlalchemy>=2.0.43",
"selenium>=4.40.0",
"isodate>=0.7.2",
"fastapi>=0.115",
"uvicorn[standard]>=0.34",
"py>=1.11",
"cryptography>=50.0.0",
"jwcrypto>=1.5.8",
]
[dependency-groups]
dev = [
"ruff>=0.8.0",
]
[tool.pytest.ini_options]
# Matched against basenames. Numeric-prefixed suite files (NN_name.py) plus
# the bootstrap entrypoints (setup.py, run.py). Excludes seeder/server.py.
python_files = ["[0-9][0-9]_*.py", "setup.py", "run.py"]
# importlib mode: avoids sys.modules collisions between same-basename tests
# (e.g. querier/01_logs.py vs rawexportdata/01_logs.py) now that all trees
# share one rootdir at tests/. importlib also disables pytest's implicit
# sys.path injection — pythonpath below makes `import fixtures` resolve.
pythonpath = ["."]
addopts = "-ra -p no:warnings --import-mode=importlib"
log_cli = true
log_format = "%(asctime)s [%(levelname)s] (%(filename)s:%(lineno)s) %(message)s"
log_date_format = "%Y-%m-%d %H:%M:%S"
[tool.ruff]
# ruff caps line-length at 320 (prior pylint setting was 400, but both are
# far above any line that organically shows up in this tree).
line-length = 320
extend-exclude = [".venv", "node_modules"]
[tool.ruff.lint]
# E/W = pycodestyle, F = pyflakes, I = isort, UP = pyupgrade, B = bugbear,
# PL = pylint-compat. Mirrors the intent of the prior pylint + isort +
# autoflake stack.
select = ["E", "F", "W", "I", "UP", "B", "PL"]
ignore = [
# pylint: too-many-* — preserved from prior pylint config
"PLR0911", # too-many-return-statements
"PLR0912", # too-many-branches
"PLR0913", # too-many-arguments
"PLR0915", # too-many-statements
"PLR0917", # too-many-positional-arguments (newly enforced by ruff 0.16)
# magic-value-comparison — noisy in assertion-heavy test code
"PLR2004",
# ruff flags mutable-argument-default (B006) where pylint ignored
# dangerous-default-value; preserve that behaviour.
"B006",
# Rules not previously enforced under pylint. Keep muted so this
# migration stays a pure tool swap; enable selectively in follow-ups.
"B011", # assert False
"B024", # abstract-class-without-abstract-method
"B905", # zip() without strict=
"E741", # ambiguous variable name
"UP047", # non-pep695-generic-function
"PLC0206", # dict-index-missing-items
"PLW2901", # for-loop-var-overwritten
]
[tool.ruff.format]
# Defaults align with black (double quotes, 4-space indent).
[tool.ruff.lint.per-file-ignores]
"fixtures/notification_channel.py" = ["E501"]
"integration/tests/alertmanager/*" = ["E501"]