From d9802091572227c78138466aa0bb59b13b3e8da5 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Fri, 17 Jul 2026 16:11:14 -0400 Subject: [PATCH] test: cover bot-token fallback when an unbound user token is refused Cross-family review (GPT-4.1) FIX item on the #1736 port: prove the warn-and-drop path for unprincipaled user tokens leaves the cached bot token reachable. --- tests/auth/test_github_token_ttl.py | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/tests/auth/test_github_token_ttl.py b/tests/auth/test_github_token_ttl.py index 1041ede6..f2289c96 100644 --- a/tests/auth/test_github_token_ttl.py +++ b/tests/auth/test_github_token_ttl.py @@ -91,6 +91,15 @@ def test_cached_bot_token_is_available_to_any_principal() -> None: assert github_token.get_github_token(config) == "bot-token" +def test_refused_unbound_user_token_falls_back_to_cached_bot_token() -> None: + github_token.cache_github_token_for_thread("tid", "bot-token", is_bot_token=True) + github_token.cache_github_token_for_thread("tid", "unbound-user-token") + + config = {"configurable": {"thread_id": "tid", "github_login": "alice"}} + assert github_token.get_github_token(config) == "bot-token" + assert list(github_token._GITHUB_TOKEN_CACHE) == [("tid", github_token._BOT_PRINCIPAL)] + + def test_cached_token_expires_after_max_ttl() -> None: """A token with no/far expiry is still dropped once it's older than the 24h cap.""" far_future = (datetime.now(UTC) + timedelta(days=30)).isoformat()