Files
DocsGPT/tests/api/test_data_plane_audit.py
T
arc53-machine 25c82003d7 fix(admin): second review pass
Correctness
- /api/remote never recorded source.created, so URL, GitHub and connector
  sources had a source.deleted with no matching creation. All three creation
  paths now go through one _audit_source_created helper.
- The prompt-cache rate divided cached tokens by a whole bucket's prompt
  tokens. A bucket is a day and mixes calls whose provider reports a cache
  breakdown with calls whose provider does not, so filtering buckets in the
  client could not separate them and the rate was understated by however much
  traffic ran on a non-reporting provider. The denominator is now computed in
  SQL over the reporting rows.
- The outcome pill matched values nothing writes. Guardrails emit triggered /
  not_evaluated and the device feed emits dispatched; the map had blocked /
  denied / allowed, so a guardrail that fired rendered neutral grey -- the one
  signal the merged feed exists to surface. Fixtures were seeding the
  fictional values, so the tests passed on it too.
- Stream duration_ms timed the consumer. stream_token_usage is a generator,
  so start-to-exhaustion includes the agent loop's tool handling and the SSE
  client's pace; a slow browser recorded ~30s for a sub-second call. It now
  accumulates only the time spent inside next().

Safety
- Activity filters failed open: an unknown facet or unparseable timestamp was
  dropped, and no filter means every row, so a typo widened an audit view and
  on the export streamed the full history. Both are now a 400.
- The search term was interpolated into an ILIKE pattern, so "100%" matched
  everything and "q1_report" matched more than it should. Escaped.
- 0034 set actor_id NOT NULL with no default. A previous-release process
  inserting mid-rollout would raise, and in admin/routes.py that insert shares
  the request transaction, so a role grant beside it would roll back too.

Noise and dead code
- The per-user panel is a security panel: data-plane events file under the
  actor, so an active account's routine deletes pushed a denied login out of
  the 20-row window. It now excludes them; the Activity tab shows everything.
- device_audit_log had no created_at-leading index, so the merged feed
  sequentially scanned that branch every page (migration 0036).
- conversation.deleted_all no longer records when nothing was deleted, and
  agent.updated no longer records an empty field list.
- Dropped by_model from /admin/usage (no consumer; an extra aggregate per page
  load), the duplicate filter surface on AuthEventsRepository that nothing
  called, and the unreachable FLOW_LABELS.schedule entry.
- Type hints on record_event's conn and the remaining unannotated helpers.
2026-09-22 12:47:40 +01:00

219 lines
7.7 KiB
Python

"""The data-plane routes must leave an audit trail.
Identity events were audited from the start; source/agent/conversation
mutations were not, so "who deleted that source" had no answer. These pin the
hooks at the route layer — the repositories are mocked, what is asserted is
that the audit row is written with the acting user and the resource id.
"""
from __future__ import annotations
import json
from contextlib import ExitStack, contextmanager
from unittest.mock import MagicMock, Mock, patch
import pytest
@pytest.fixture
def client():
from docsgpt.app import app as flask_app
flask_app.config["TESTING"] = True
return flask_app.test_client()
@contextmanager
def _authed(module: str, **patches):
"""Authenticate as ``u1`` and patch names inside ``module``."""
recorded: list[tuple] = []
def _record(_conn, event, *, actor, target=None, **metadata):
recorded.append((event, actor, target, metadata))
@contextmanager
def _conn():
yield MagicMock()
with ExitStack() as stack:
stack.enter_context(
patch("docsgpt.app.handle_auth", return_value={"sub": "u1"})
)
stack.enter_context(patch("docsgpt.app.resolve_roles", return_value=["user"]))
stack.enter_context(patch(f"{module}.db_session", _conn))
stack.enter_context(patch(f"{module}.db_readonly", _conn))
stack.enter_context(patch(f"{module}.record_event", _record))
for name, value in patches.items():
stack.enter_context(patch(f"{module}.{name}", value))
yield recorded
_SOURCES = "docsgpt.api.user.sources.routes"
_AGENTS = "docsgpt.api.user.agents.routes"
_CONVERSATIONS = "docsgpt.api.user.conversations.routes"
@pytest.mark.unit
class TestSourceAudit:
def test_delete_records_source_deleted(self, client):
repo = Mock()
repo.get_any.return_value = {"id": "src-1", "name": "Handbook"}
storage = Mock()
storage.file_exists.return_value = False
with _authed(
_SOURCES,
SourcesRepository=Mock(return_value=repo),
StorageCreator=Mock(get_storage=Mock(return_value=storage)),
) as recorded:
resp = client.get("/api/delete_old?source_id=src-1")
assert resp.status_code == 200
assert recorded[0][:3] == ("source.deleted", "u1", None)
assert recorded[0][3]["source_id"] == "src-1"
assert recorded[0][3]["name"] == "Handbook"
def test_nothing_recorded_when_the_source_is_missing(self, client):
repo = Mock()
repo.get_any.return_value = None
with _authed(_SOURCES, SourcesRepository=Mock(return_value=repo)) as recorded:
resp = client.get("/api/delete_old?source_id=nope")
assert resp.status_code == 404
assert recorded == []
_UPLOAD = "docsgpt.api.user.sources.upload"
@pytest.mark.unit
class TestRemoteSourceAudit:
"""``source.deleted`` is recorded for remote sources, so creation must be.
A trail showing a source deleted that was apparently never created is
worse than no trail, and the docs state ``source.created`` is recorded.
"""
@contextmanager
def _remote_env(self):
recorded: list[tuple] = []
def _record(_conn, event, *, actor, target=None, **metadata):
recorded.append((event, actor, target, metadata))
@contextmanager
def _conn():
yield MagicMock()
task = Mock(id="task-9")
with ExitStack() as stack:
stack.enter_context(
patch("docsgpt.app.handle_auth", return_value={"sub": "u1"})
)
stack.enter_context(
patch("docsgpt.app.resolve_roles", return_value=["user"])
)
stack.enter_context(patch(f"{_UPLOAD}.db_session", _conn))
stack.enter_context(patch(f"{_UPLOAD}.record_event", _record))
stack.enter_context(
patch(
f"{_UPLOAD}.ingest_remote",
Mock(apply_async=Mock(return_value=task)),
)
)
yield recorded
def test_url_source_records_source_created(self, client):
# The route reads ``request.form``; ``data`` is a JSON string.
with self._remote_env() as recorded:
resp = client.post(
"/api/remote",
data={
"user": "u1",
"source": "url",
"name": "Handbook",
"data": json.dumps({"url": "https://example.com"}),
},
)
assert resp.status_code == 200
assert [row[0] for row in recorded] == ["source.created"]
event, actor, target, metadata = recorded[0]
assert (actor, target) == ("u1", None)
assert metadata["name"] == "Handbook"
assert metadata["type"] == "url"
assert metadata["source_id"] == json.loads(resp.data)["source_id"]
def test_github_source_records_source_created(self, client):
with self._remote_env() as recorded:
resp = client.post(
"/api/remote",
data={
"user": "u1",
"source": "github",
"name": "Repo",
"data": json.dumps({"repo_url": "https://github.com/a/b"}),
},
)
assert resp.status_code == 200
assert recorded[0][3]["type"] == "github"
@pytest.mark.unit
class TestAgentAudit:
def test_delete_records_agent_deleted(self, client):
repo = Mock()
repo.get_any.return_value = {
"id": "agent-1",
"name": "Support bot",
"agent_type": "classic",
}
with _authed(
_AGENTS,
AgentsRepository=Mock(return_value=repo),
WorkflowsRepository=Mock(),
UsersRepository=Mock(),
) as recorded:
resp = client.delete("/api/delete_agent?id=agent-1")
assert resp.status_code == 200
assert recorded[0][:3] == ("agent.deleted", "u1", None)
assert recorded[0][3]["agent_id"] == "agent-1"
assert recorded[0][3]["name"] == "Support bot"
def test_missing_agent_records_nothing(self, client):
repo = Mock()
repo.get_any.return_value = None
with _authed(_AGENTS, AgentsRepository=Mock(return_value=repo)) as recorded:
assert client.delete("/api/delete_agent?id=x").status_code == 404
assert recorded == []
@pytest.mark.unit
class TestConversationAudit:
def test_delete_records_conversation_deleted(self, client):
repo = Mock()
repo.get_any.return_value = {"id": "conv-1"}
with _authed(
_CONVERSATIONS, ConversationsRepository=Mock(return_value=repo)
) as recorded:
resp = client.post("/api/delete_conversation?id=conv-1")
assert resp.status_code == 200
assert recorded[0][:3] == ("conversation.deleted", "u1", None)
assert recorded[0][3]["conversation_id"] == "conv-1"
def test_delete_all_records_the_count(self, client):
repo = Mock()
repo.delete_all_for_user.return_value = 7
with _authed(
_CONVERSATIONS, ConversationsRepository=Mock(return_value=repo)
) as recorded:
resp = client.get("/api/delete_all_conversations")
assert resp.status_code == 200
assert recorded[0][0] == "conversation.deleted_all"
assert recorded[0][3]["deleted"] == 7
def test_unknown_conversation_records_nothing(self, client):
repo = Mock()
repo.get_any.return_value = None
with _authed(
_CONVERSATIONS, ConversationsRepository=Mock(return_value=repo)
) as recorded:
assert client.post("/api/delete_conversation?id=x").status_code == 200
assert recorded == []