feat(mcp): câblage FastAPI + nginx proxy + docker-compose MCP_API_KEY
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -3,6 +3,7 @@ import uuid
|
||||
import pytest
|
||||
from sqlalchemy import delete
|
||||
import app.api.mcp_server as mcp_server_module
|
||||
from app.core.config import settings
|
||||
from app.api.mcp_server import (
|
||||
get_todos, create_todo, update_todo, postpone_todo, delete_todo,
|
||||
)
|
||||
@@ -211,3 +212,27 @@ async def test_add_item_liste_invalide():
|
||||
result = await add_shopping_item(list_id="pas-un-uuid", name="article")
|
||||
data = json.loads(result)
|
||||
assert "error" in data
|
||||
|
||||
|
||||
# ── AUTH ──────────────────────────────────────────────────────────────────────
|
||||
|
||||
async def test_mcp_auth_rejet_sans_token(client):
|
||||
"""Le middleware renvoie 401 si aucun header Authorization."""
|
||||
resp = await client.get("/mcp")
|
||||
assert resp.status_code == 401
|
||||
|
||||
|
||||
async def test_mcp_auth_rejet_mauvais_token(client):
|
||||
"""Le middleware renvoie 401 si le token est incorrect."""
|
||||
resp = await client.get("/mcp", headers={"Authorization": "Bearer mauvais-token"})
|
||||
assert resp.status_code == 401
|
||||
|
||||
|
||||
async def test_mcp_auth_accepte_bon_token(client, monkeypatch):
|
||||
"""Le middleware laisse passer avec le token correct."""
|
||||
monkeypatch.setattr(settings, "mcp_api_key", "test-mcp-key-xyz")
|
||||
resp = await client.get(
|
||||
"/mcp",
|
||||
headers={"Authorization": "Bearer test-mcp-key-xyz"},
|
||||
)
|
||||
assert resp.status_code != 401
|
||||
|
||||
Reference in New Issue
Block a user