test: cover user-owned session security boundaries
This commit is contained in:
@@ -285,7 +285,9 @@ class PostgresSessionRepository:
|
||||
ids = [row[0] for row in connection.execute(
|
||||
text("SELECT id FROM thoth_sessions.sessions ORDER BY created_at DESC")
|
||||
).all()]
|
||||
return [self.get(session_id) for session_id in ids]
|
||||
# psycopg2 materializes PostgreSQL UUID columns as ``uuid.UUID`` objects,
|
||||
# while the repository boundary intentionally accepts canonical UUIDv4 text.
|
||||
return [self.get(str(session_id)) for session_id in ids]
|
||||
|
||||
def save_manifest(self, manifest: SessionManifest) -> SessionSnapshot:
|
||||
self._require_uuid4(manifest.id)
|
||||
|
||||
Reference in New Issue
Block a user