open-swe/tests/test_account_link.py
Adam Moussa b3fc62da80
refactor: split webapp.py into api/ + per-source webhook routes
Plan step C4 (docs/upstream-sync/domain-reorg/reorg-build-plan.md, approved
decisions 1-2): split the 2,590-line agent/webapp.py monolith into
agent/webhooks/common.py (shared verify/dispatch helpers), agent/api/app.py
(composition), agent/api/health.py (/health + /webhooks/run-complete), and
per-source {github,linear,slack,jira,confluence}_routes.py. Atlassian
Connect lifecycle + descriptor routes (/connect/*) fold into
confluence_routes.py; webapp.py becomes the upstream-shaped compatibility
shim (from .api.app import app). langgraph.json http.app stays
agent.webapp:app via the shim.

Fork content, upstream layout: linear/slack route files verified
content-identical to upstream 8356eb34 and taken verbatim; github_routes is
upstream + the fork's CI auto-fix trigger wiring; jira/confluence routes are
fork-only, transformed to the same common.X / service.X module-attribute
style. All signature verification (GitHub HMAC, Slack, Linear
timestamp-freshness, verify_jira_secret + opt-in HMAC/timestamp/IP
allowlist, Connect JWT/qsh), token-attribution gating, TID-COLLIDE-01 repo
binding, _is_repo_auto_review_enabled gates, and public-repo org gate move
unchanged.

Handlers rewired from webapp.X to common.X; test monkeypatch sites across
26 files + conftest.py + e2e/harness.py retargeted to
webhook_common/handler/route modules per upstream's pattern. Residual
agent.webapp importers: only the shim, langgraph.json http.app, Makefile
uvicorn target, and docs (doc-path updates land in C7).

Gates: ruff check + format, pytest --co, full unit (1637 passed), full
Playwright E2E vs real langgraph dev (9/9), residual-importer sweep.
2026-07-17 14:30:05 -04:00

81 lines
2.5 KiB
Python

"""Tests for the Slack account-link prompt."""
from __future__ import annotations
import pytest
@pytest.fixture(autouse=True)
def _jwt_secret(monkeypatch: pytest.MonkeyPatch) -> None:
monkeypatch.setenv("DASHBOARD_JWT_SECRET", "test-secret")
def test_account_link_prompt_posts_generic_token_free_link(
monkeypatch: pytest.MonkeyPatch,
) -> None:
"""The prompt posts a plain settings link in the thread — no per-user token."""
import asyncio
from agent.webhooks import common as webhook_common
monkeypatch.setenv("DASHBOARD_BASE_URL", "https://app.example.com")
calls: dict[str, object] = {}
async def fake_reply(channel_id, thread_ts, text):
calls["reply"] = {"channel_id": channel_id, "thread_ts": thread_ts, "text": text}
return True
monkeypatch.setattr(webhook_common, "post_slack_thread_reply", fake_reply)
asyncio.run(
webhook_common._post_account_link_prompt("C1", "1.1", "U1", "d@x.com", reason="unlinked")
)
assert calls["reply"]["channel_id"] == "C1"
assert calls["reply"]["thread_ts"] == "1.1"
assert "https://app.example.com/my-settings" in calls["reply"]["text"]
# No signed account-link token may appear in the public thread.
assert "link=" not in calls["reply"]["text"]
def test_account_link_prompt_revoked_wording(monkeypatch: pytest.MonkeyPatch) -> None:
import asyncio
from agent.webhooks import common as webhook_common
monkeypatch.setenv("DASHBOARD_BASE_URL", "https://app.example.com")
calls: dict[str, object] = {}
async def fake_reply(channel_id, thread_ts, text):
calls["text"] = text
return True
monkeypatch.setattr(webhook_common, "post_slack_thread_reply", fake_reply)
asyncio.run(
webhook_common._post_account_link_prompt("C1", "1.1", "U1", "d@x.com", reason="revoked")
)
assert "no longer valid" in calls["text"]
assert "link=" not in calls["text"]
def test_account_link_prompt_skips_when_dashboard_url_unset(
monkeypatch: pytest.MonkeyPatch,
) -> None:
import asyncio
from agent.webhooks import common as webhook_common
monkeypatch.delenv("DASHBOARD_BASE_URL", raising=False)
posted = False
async def fake_reply(channel_id, thread_ts, text):
nonlocal posted
posted = True
return True
monkeypatch.setattr(webhook_common, "post_slack_thread_reply", fake_reply)
asyncio.run(
webhook_common._post_account_link_prompt("C1", "1.1", "U1", "d@x.com", reason="unlinked")
)
assert posted is False