ASE-GLM / tests /test_credentials.py
Bit-Trading-Company's picture
CI deploy local
17b22d9 verified
Raw History Blame Contribute Delete
3.85 kB
"""The billing rule, which is the one thing here that costs money to get wrong."""
from __future__ import annotations
import pytest
from server import credentials
@pytest.fixture(autouse=True)
def clean_env(monkeypatch):
for var in ("HF_TOKEN", "HUGGING_FACE_HUB_TOKEN", "SPACE_ID",
"ASE_ALLOW_SPACE_CREDITS"):
monkeypatch.delenv(var, raising=False)
# The suite must never pick up the developer's real key.txt.
monkeypatch.setenv("ASE_KEY_FILE", "/nonexistent/ase-glm-test-key")
def test_oauth_wins_and_bills_the_viewer():
c = credentials.resolve(oauth_token="oauth", oauth_user="ada", user_key="pasted")
assert (c.token, c.mode, c.who) == ("oauth", "oauth", "ada")
assert c.bills_viewer
def test_a_pasted_key_beats_the_space_secret(monkeypatch):
monkeypatch.setenv("HF_TOKEN", "owner")
c = credentials.resolve(user_key="pasted")
assert (c.token, c.mode) == ("pasted", "user-key")
assert c.bills_viewer
def test_on_a_space_the_owner_token_is_not_used_by_default(monkeypatch):
monkeypatch.setenv("SPACE_ID", "someone/ase-glm")
monkeypatch.setenv("HF_TOKEN", "owner")
c = credentials.resolve()
assert c.token is None, "a visitor must not spend the owner's credits by default"
assert c.mode == "none"
assert not c.bills_viewer
assert "own key" in c.detail
def test_the_owner_token_can_be_switched_on_deliberately(monkeypatch):
monkeypatch.setenv("SPACE_ID", "someone/ase-glm")
monkeypatch.setenv("HF_TOKEN", "owner")
monkeypatch.setenv("ASE_ALLOW_SPACE_CREDITS", "1")
c = credentials.resolve()
assert (c.token, c.mode) == ("owner", "space-secret")
assert not c.bills_viewer
def test_off_a_space_the_local_token_is_used(monkeypatch):
# There is no OAuth off-Space, so a dev loop that cannot make a request
# would be useless.
monkeypatch.setenv("HF_TOKEN", "local")
c = credentials.resolve()
assert (c.token, c.mode) == ("local", "space-secret")
def test_no_credential_at_all_is_reported_not_raised():
c = credentials.resolve()
assert c.token is None and c.mode == "none"
assert c.detail
def test_the_token_never_appears_in_the_json():
c = credentials.resolve(oauth_token="secret-value", oauth_user="ada")
assert "secret-value" not in repr(c.to_json())
assert set(c.to_json()) == {"mode", "who", "billsViewer", "detail"}
@pytest.mark.parametrize("value,expected", [
("1", True), ("true", True), ("YES", True), ("on", True),
("0", False), ("false", False), ("", False),
])
def test_the_flag_accepts_the_spellings_people_actually_use(monkeypatch, value, expected):
monkeypatch.setenv("SPACE_ID", "x/y")
monkeypatch.setenv("ASE_ALLOW_SPACE_CREDITS", value)
assert credentials.allow_space_credits() is expected
def test_the_dev_key_file_is_never_consulted_on_a_space(monkeypatch, tmp_path):
key = tmp_path / "key.txt"
key.write_text("from-disk\n")
monkeypatch.setenv("ASE_KEY_FILE", str(key))
monkeypatch.setenv("SPACE_ID", "someone/ase-glm")
monkeypatch.setenv("ASE_ALLOW_SPACE_CREDITS", "1")
# On a Space the token comes from a secret; a file on disk must not be a
# second way in, even one that happens to be there.
assert credentials.resolve().token is None
def test_the_dev_key_file_works_locally(monkeypatch, tmp_path):
key = tmp_path / "key.txt"
key.write_text("from-disk\n")
monkeypatch.setenv("ASE_KEY_FILE", str(key))
c = credentials.resolve()
assert c.token == "from-disk"
assert not c.bills_viewer
def test_an_env_token_beats_the_dev_key_file(monkeypatch, tmp_path):
key = tmp_path / "key.txt"
key.write_text("from-disk\n")
monkeypatch.setenv("ASE_KEY_FILE", str(key))
monkeypatch.setenv("HF_TOKEN", "from-env")
assert credentials.resolve().token == "from-env"