test: cover user-owned session security boundaries
This commit is contained in:
@@ -5,7 +5,7 @@ import pytest
|
||||
from tht.config import DatabaseConfig, load_config
|
||||
from tht.decisions import DecisionInput
|
||||
from tht.session.filesystem_repository import FilesystemSessionRepository
|
||||
from tht.session.models import PrincipalContext, SessionManifest
|
||||
from tht.session.models import PrincipalContext, SessionManifest, local_principal
|
||||
from tht.session.repository import build_session_repository, resolve_principal
|
||||
from tht.session.store import SessionError
|
||||
from tht.session.store import create_session
|
||||
@@ -105,6 +105,25 @@ def test_filesystem_repository_keeps_preferences_per_principal(tmp_path):
|
||||
assert bob.get_preferences() == {}
|
||||
|
||||
|
||||
def test_two_local_homes_have_independent_identities_sessions_and_preferences(tmp_path):
|
||||
alice_home = tmp_path / "alice-home"
|
||||
bob_home = tmp_path / "bob-home"
|
||||
alice = FilesystemSessionRepository(alice_home, "demo", local_principal(alice_home))
|
||||
bob = FilesystemSessionRepository(bob_home, "demo", local_principal(bob_home))
|
||||
session_id = str(uuid.uuid4())
|
||||
|
||||
alice.create(_manifest(session_id))
|
||||
alice.set_preferences({"model": "glm"})
|
||||
|
||||
assert alice.principal.subject != bob.principal.subject
|
||||
assert (alice.root / session_id / "session_manifest.yaml").exists()
|
||||
assert not (bob.root / session_id).exists()
|
||||
assert bob.list() == []
|
||||
assert bob.get_preferences() == {}
|
||||
with pytest.raises(SessionError, match="Sessione non trovata"):
|
||||
bob.get(session_id)
|
||||
|
||||
|
||||
@pytest.mark.parametrize("session_id", ["2026-01-01-000000-test", "2026-01-01-000000-x", "s1"])
|
||||
def test_filesystem_repository_reads_safe_legacy_session_ids(tmp_path, session_id):
|
||||
repository = FilesystemSessionRepository(
|
||||
|
||||
Reference in New Issue
Block a user