test: cover bot-token fallback when an unbound user token is refused

Cross-family review (GPT-4.1) FIX item on the #1736 port: prove the
warn-and-drop path for unprincipaled user tokens leaves the cached bot
token reachable.
This commit is contained in:
Adam Moussa 2026-07-17 16:11:14 -04:00
parent 8d8d5bbbbf
commit d980209157
No known key found for this signature in database

View file

@ -91,6 +91,15 @@ def test_cached_bot_token_is_available_to_any_principal() -> None:
assert github_token.get_github_token(config) == "bot-token"
def test_refused_unbound_user_token_falls_back_to_cached_bot_token() -> None:
github_token.cache_github_token_for_thread("tid", "bot-token", is_bot_token=True)
github_token.cache_github_token_for_thread("tid", "unbound-user-token")
config = {"configurable": {"thread_id": "tid", "github_login": "alice"}}
assert github_token.get_github_token(config) == "bot-token"
assert list(github_token._GITHUB_TOKEN_CACHE) == [("tid", github_token._BOT_PRINCIPAL)]
def test_cached_token_expires_after_max_ttl() -> None:
"""A token with no/far expiry is still dropped once it's older than the 24h cap."""
far_future = (datetime.now(UTC) + timedelta(days=30)).isoformat()