Thoth (tht) è il prodotto, PSD è il cliente. Nessun riferimento al contesto
clinico nel codice.
Rinomine:
- comando+package nsp→tht (dir nsp/→tht/, 46 import, pyproject entry point)
- gate nsp-gate.js→tht-gate.js (+ rewrite token, relayIfNspFails→relayIfThtFails)
- workspace chirone.{example,test}.yaml→tht.{example,test}.yaml (generici)
- env THOTH_→THT_ (19 var) + NSP_ stragglers (NSP_HARNESS_ROOT, NSP_SESSION)
- commenti/docstring chirone/psdwp3/policlinico neutralizzati ('the reference
implementation', 'the DWH')
Aggiunto [tool.setuptools.packages.find] include=['tht*'] (necessario: l'auto-
discovery rompeva con tht/ + workspaces/ come top-level multipli).
.env operatore aggiornato in-place (prefissi THT_, valori preservati, gitignored).
Verifica: pytest 109 passed, npm test 14 pass, tht phase meta --json OK, zero
residui nsp/THOTH_/NSP_/chirone nel package.
57 lines
1.8 KiB
Python
57 lines
1.8 KiB
Python
"""L0: db/connection read-only enforcement against real Postgres (testcontainers).
|
|
|
|
The ported read-only contract: the psd_ro role can SELECT but not write, and
|
|
can_create_in_schema / writable_tables reflect that. This is where 'ported code
|
|
is not assumed reliable' gains real teeth for the data layer.
|
|
"""
|
|
import pytest
|
|
from sqlalchemy import create_engine, text
|
|
|
|
from tht.db.connection import can_create_in_schema, make_engine, ping, writable_tables
|
|
|
|
pytestmark = [pytest.mark.l0]
|
|
|
|
|
|
def test_ping_succeeds_on_read_only_role(ro_url):
|
|
engine = create_engine(ro_url)
|
|
try:
|
|
ping(engine) # SELECT 1 — must not raise
|
|
finally:
|
|
engine.dispose()
|
|
|
|
|
|
def test_read_only_role_cannot_create_in_schema(ro_url):
|
|
engine = create_engine(ro_url)
|
|
try:
|
|
# psd_ro has USAGE + SELECT only, not CREATE on the dw schema.
|
|
assert can_create_in_schema(engine, "dw") is False
|
|
finally:
|
|
engine.dispose()
|
|
|
|
|
|
def test_writable_tables_empty_for_read_only_role(ro_url):
|
|
engine = create_engine(ro_url)
|
|
try:
|
|
tables = writable_tables(engine, "dw")
|
|
assert tables == [] # read-only role has no INSERT/UPDATE/DELETE grants
|
|
finally:
|
|
engine.dispose()
|
|
|
|
|
|
def test_read_only_role_cannot_insert(ro_url):
|
|
"""The hard guarantee: a write attempt raises (enforced by Postgres, surfaced
|
|
by our engine)."""
|
|
engine = create_engine(ro_url)
|
|
try:
|
|
with pytest.raises(Exception):
|
|
with engine.begin() as conn:
|
|
conn.execute(text('INSERT INTO dw.dim_pazienti VALUES (999, %s, %s)'),
|
|
("test", "test"))
|
|
finally:
|
|
engine.dispose()
|
|
|
|
|
|
def test_admin_engine_can_create_in_schema(admin_engine):
|
|
# Sanity: the admin (table owner) CAN create — confirms the test harness itself.
|
|
assert can_create_in_schema(admin_engine, "dw") is True
|