Build and Push Containers / build-and-push (push) Successful in 1m50s
One env var (BOR_APP_NAME, default "Brain of Reese") now drives the app's
display name everywhere (TODO.md L12 — owner ask: "a way to customize the
name for 'Brain of'. Should be an env var."). The existing app_name setting
is the source of truth (phase locked decision — no new variable, no rename);
with the variable unset the app is byte-identical to before.
Endpoint (A10 public/stateless, no secrets):
GET /api/config → exactly {app_name, version} (app/api/config.py, the
health.py pattern; registered before the static mount). Integration tests:
anonymous 200, default values, a Settings override follows, key set is
exactly two keys — no other setting may leak in later.
Frontend brand layer (A11 — runtime fetch, static templates stay static):
assets/brand.js — a CLASSIC script, first on all six pages, so its top
level runs at parse time: window.BOR_BRAND = "Brain of Reese"
synchronously (the default renders immediately, no blank flash), then a
no-store fetch of /api/config applies the name — document.title (global
replace), every .brand-text (a name starting "Brain of " keeps the bold
split Brain of <strong>rest</strong>, any other name renders plain; the
operator-controlled name is HTML-escaped before innerHTML), a TreeWalker
over text nodes (script/style rejected — page source never rewritten),
and the aria-label/placeholder/meta-content attributes. Fetch failure
keeps the default + console.warn (the loadHealth house style).
app.js (status labels, typing label, elapsed-hint aria, tool labels) and
document.js (viewer titles) read window.BOR_BRAND at CALL time via
brand() — a label set after the fetch lands carries the configured name.
Containerfile: esbuild minify line for brand.js (classic, like markdown.js);
the phase-33 ?v= cache-busting picks the new asset ref up automatically.
E2E (A16 — one story, one file, isolated): test_configurable_brand.py boots
a SECOND app instance (same DB/mock-LLM/admin-auth env block, port APP_PORT+1,
BOR_APP_NAME="Brain of Testy") — the shared conftest server keeps the
default name so every other suite's title/label assertions stay untouched —
and asserts /api/config on both instances, the index title/brand/greeting/
#messages aria-label, the sources + login page titles, and one pre-token
chat turn (think out loud marker) whose #send-status reads "Brain of Testy
is thinking"; the no-op regression pins the shared server's default bytes.
Docs: .env.example App section + README configuration reference — what it
affects (titles, header brand, status labels, aria text), the default, the
bold-split rendering rule.
Gates: 695 unit+integration passed, app/ coverage 99% (>90%), story E2E
green in isolation (two consecutive runs), brand-string suites (smoke,
shared header, header consistency, chat persistence) green, ruff + pyright
clean.
244 lines
8.6 KiB
Python
244 lines
8.6 KiB
Python
"""Integration tests: HTTP API surface (no database required)."""
|
|
from __future__ import annotations
|
|
|
|
import json
|
|
|
|
import pytest
|
|
|
|
from app.config import get_settings
|
|
|
|
|
|
def test_health_reports_ok(client) -> None:
|
|
r = client.get("/api/health")
|
|
assert r.status_code == 200
|
|
body = r.json()
|
|
assert body["status"] == "ok"
|
|
assert body["db"] in {"up", "down"}
|
|
assert body["version"]
|
|
|
|
|
|
def test_config_returns_default_app_metadata(client) -> None:
|
|
"""GET /api/config is public (anonymous) and returns exactly two keys."""
|
|
r = client.get("/api/config")
|
|
assert r.status_code == 200
|
|
body = r.json()
|
|
assert set(body) == {"app_name", "version"}
|
|
assert body["app_name"] == "Brain of Reese"
|
|
assert body["version"] == get_settings().app_version
|
|
|
|
|
|
def test_config_follows_overridden_app_name(client) -> None:
|
|
"""GET /api/config reflects a Settings override (e.g. BOR_APP_NAME)."""
|
|
from app.config import Settings
|
|
from app.main import app as fastapi_app
|
|
|
|
fastapi_app.dependency_overrides[get_settings] = lambda: Settings(
|
|
app_name="Brain of Testy"
|
|
)
|
|
try:
|
|
r = client.get("/api/config")
|
|
assert r.status_code == 200
|
|
body = r.json()
|
|
assert set(body) == {"app_name", "version"}
|
|
assert body["app_name"] == "Brain of Testy"
|
|
assert body["version"] == "0.1.0"
|
|
finally:
|
|
fastapi_app.dependency_overrides.clear()
|
|
|
|
|
|
def test_suggestions_returns_list(client) -> None:
|
|
r = client.get("/api/suggestions")
|
|
assert r.status_code == 200
|
|
suggestions = r.json()["suggestions"]
|
|
assert isinstance(suggestions, list)
|
|
assert len(suggestions) >= 3
|
|
assert all(isinstance(s, str) and s.strip() for s in suggestions)
|
|
|
|
|
|
def test_suggestions_honors_bor_suggestions_env_override(monkeypatch) -> None:
|
|
"""GET /api/suggestions reflects the BOR_SUGGESTIONS JSON env override."""
|
|
from fastapi.testclient import TestClient
|
|
|
|
from app.main import create_app
|
|
|
|
override = [
|
|
"How do I back up with Borg?",
|
|
"How is my K3S cluster set up?",
|
|
"How do I deploy a service?",
|
|
"What proxy fronts reeseapps.com?",
|
|
]
|
|
get_settings.cache_clear()
|
|
try:
|
|
monkeypatch.setenv("BOR_SUGGESTIONS", json.dumps(override))
|
|
fresh_client = TestClient(create_app())
|
|
finally:
|
|
get_settings.cache_clear()
|
|
|
|
r = fresh_client.get("/api/suggestions")
|
|
assert r.status_code == 200
|
|
assert r.json() == {"suggestions": override}
|
|
|
|
|
|
@pytest.mark.parametrize(
|
|
("path", "marker"),
|
|
[
|
|
("/", "Brain of Reese"),
|
|
("/sources.html", "Knowledge base"),
|
|
("/document.html", "Brain of Reese"), # phase 10: viewer page
|
|
("/login.html", "Sign in"), # phase 16: admin sign-in page
|
|
("/tuning.html", "Global Tuning"), # phase 27: global tuning page
|
|
("/git-sources.html", "Git sources"), # phase 35: admin git sources page
|
|
],
|
|
)
|
|
def test_html_pages_served_locally_no_cdn(client, path: str, marker: str) -> None:
|
|
"""No-CDN check (PLAN §7.3, re-verified on BOTH pages in phase 07 and
|
|
on the viewer page in phase 10): each page is served by FastAPI and
|
|
references only same-origin assets (no https:// script/link tags)."""
|
|
r = client.get(path)
|
|
assert r.status_code == 200
|
|
assert marker in r.text
|
|
assert 'src="https://' not in r.text
|
|
assert 'href="https://' not in r.text
|
|
|
|
|
|
# Phase 33 (cache busting): the five HTML pages revalidate (no-cache) with
|
|
# ?v=<token> asset refs; /assets/* is immutable for a year; /api/* is
|
|
# untouched. The token itself is unit-tested in tests/unit/test_caching.py.
|
|
|
|
|
|
def test_index_page_no_cache_with_versioned_asset_refs(client) -> None:
|
|
"""GET / — always revalidated, and the stylesheet reference carries
|
|
the process version token (non-empty, matching asset_version())."""
|
|
from app.core.caching import asset_version
|
|
|
|
token = asset_version()
|
|
assert token # non-empty in every supported environment
|
|
|
|
r = client.get("/")
|
|
assert r.status_code == 200
|
|
assert r.headers["cache-control"] == "no-cache"
|
|
assert f'href="/assets/styles.css?v={token}"' in r.text
|
|
# The unversioned reference is gone from the served body.
|
|
assert 'href="/assets/styles.css">' not in r.text
|
|
|
|
|
|
@pytest.mark.parametrize(
|
|
"path",
|
|
["/sources.html", "/document.html", "/login.html", "/tuning.html", "/git-sources.html"],
|
|
)
|
|
def test_html_pages_no_cache_with_versioned_refs(client, path: str) -> None:
|
|
"""Each of the other four pages revalidates and carries at least one
|
|
versioned asset reference."""
|
|
from app.core.caching import asset_version
|
|
|
|
r = client.get(path)
|
|
assert r.status_code == 200
|
|
assert r.headers["cache-control"] == "no-cache"
|
|
assert f"?v={asset_version()}" in r.text
|
|
|
|
|
|
def test_index_html_variant_no_cache_versioned(client) -> None:
|
|
"""/index.html is the same page as / — same caching treatment."""
|
|
from app.core.caching import asset_version
|
|
|
|
r = client.get("/index.html")
|
|
assert r.status_code == 200
|
|
assert r.headers["cache-control"] == "no-cache"
|
|
assert f"?v={asset_version()}" in r.text
|
|
|
|
|
|
def test_assets_served_immutable_for_a_year(client) -> None:
|
|
r = client.get("/assets/styles.css")
|
|
assert r.status_code == 200
|
|
cc = r.headers["cache-control"]
|
|
assert "public" in cc
|
|
assert "max-age=31536000" in cc
|
|
assert "immutable" in cc
|
|
# The asset body is untouched (header-only middleware).
|
|
assert client.get("/assets/app.js?v=whichever").status_code == 200
|
|
|
|
|
|
def test_api_health_gets_no_cache_control_injected(client) -> None:
|
|
"""Baseline (pre-middleware) behavior for /api/*: FastAPI's JSON
|
|
responses ship no Cache-Control header — the middleware must not
|
|
inject one."""
|
|
r = client.get("/api/health")
|
|
assert r.status_code == 200
|
|
assert "cache-control" not in r.headers
|
|
|
|
|
|
def test_styles_and_js_served(client) -> None:
|
|
assert client.get("/assets/styles.css").status_code == 200
|
|
assert client.get("/assets/app.js").status_code == 200
|
|
assert client.get("/assets/sources.js").status_code == 200
|
|
assert client.get("/assets/markdown.js").status_code == 200 # phase 10: shared renderer
|
|
assert client.get("/assets/document.js").status_code == 200 # phase 10: viewer page
|
|
assert client.get("/assets/login.js").status_code == 200 # phase 16: login page
|
|
assert client.get("/assets/document-modal.js").status_code == 200 # phase 26: modal module
|
|
assert client.get("/assets/tuning.js").status_code == 200 # phase 27: tuning page
|
|
assert client.get("/assets/git-sources.js").status_code == 200 # phase 35: git sources page
|
|
|
|
|
|
# Emoji code points banned from UI chrome (phase 08): the pictograph
|
|
# blocks, VS-16/ZWJ, plus the exact glyphs the old light theme used
|
|
# (🧠 🧑 👋 📂 ⚠).
|
|
_EMOJI_GLYPHS = "\U0001F9E0\U0001F9D1\U0001F44B\U0001F4C2\u26A0"
|
|
|
|
|
|
def _find_emoji(text: str) -> list[str]:
|
|
hits: list[str] = []
|
|
for ch in text:
|
|
cp = ord(ch)
|
|
if (
|
|
0x1F300 <= cp <= 0x1FAFF
|
|
or 0x2600 <= cp <= 0x27BF
|
|
or 0x2B00 <= cp <= 0x2BFF
|
|
or cp in (0xFE0F, 0x200D)
|
|
or ch in _EMOJI_GLYPHS
|
|
):
|
|
hits.append(ch)
|
|
return hits
|
|
|
|
|
|
@pytest.mark.parametrize(
|
|
"path",
|
|
[
|
|
"/",
|
|
"/sources.html",
|
|
"/document.html",
|
|
"/login.html", # phase 16
|
|
"/tuning.html", # phase 27
|
|
"/git-sources.html", # phase 35
|
|
"/assets/app.js",
|
|
"/assets/sources.js",
|
|
"/assets/markdown.js",
|
|
"/assets/document.js",
|
|
"/assets/login.js", # phase 16
|
|
"/assets/document-modal.js", # phase 26: the document modal module
|
|
"/assets/git-sources.js", # phase 35: the git sources page module
|
|
"/assets/styles.css",
|
|
],
|
|
)
|
|
def test_ui_chrome_has_no_emoji(client, path: str) -> None:
|
|
"""Permanent regression guard (phase 08): the UI chrome — all pages,
|
|
the JS that renders it, and the stylesheet — is emoji-free.
|
|
|
|
Phase 37 revision (owner permission 2026-08-26, PLAN §4): the agent's
|
|
``.tool-call`` line carries two CONTENT marks — 🔎 (list) and 📄
|
|
(read) — the only emoji in the whole frontend, and only as the exact
|
|
tool-line template strings in app.js. The guard strips precisely
|
|
those two literals; any other emoji, or those marks anywhere else,
|
|
still fails."""
|
|
r = client.get(path)
|
|
assert r.status_code == 200
|
|
text = r.text
|
|
if path == "/assets/app.js":
|
|
text = text.replace('"🔎 Listing documents"', "")
|
|
text = text.replace('"📄 Reading "', "")
|
|
assert _find_emoji(text) == [], f"emoji found in {path}: {_find_emoji(text)!r}"
|
|
|
|
|
|
def test_chat_requires_message(client) -> None:
|
|
r = client.post("/api/chat", json={"message": ""})
|
|
assert r.status_code == 422
|