[PR #22294] test: add comprehensive unit tests for login decorator #29894

Closed
opened 2026-02-21 20:46:27 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/22294

State: closed
Merged: Yes


Description

Add comprehensive unit tests for libs.login module covering authentication decorator and user proxy functionality.

Authentication Decorator Tests

  • Protected view access control for authenticated/unauthenticated users
  • LOGIN_DISABLED configuration bypass behavior
  • OPTIONS request exemption from authentication
  • Flask 1.x and 2.x compatibility with ensure_sync

User Context Management

  • User retrieval from Flask g context (_get_user function)
  • Lazy loading of user when not in context
  • Request context boundary handling

Current User Proxy

  • Thread-safe user proxy across multiple request contexts
  • Proper attribute access and error handling for None users
  • Concurrent request isolation validation

Checklist

  • This change requires a documentation update, included: Dify Document
  • I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.
  • I ran dev/reformat(backend) and cd web && npx lint-staged(frontend) to appease the lint gods
**Original Pull Request:** https://github.com/langgenius/dify/pull/22294 **State:** closed **Merged:** Yes --- ## Description ### Add comprehensive unit tests for libs.login module covering authentication decorator and user proxy functionality. ### Authentication Decorator Tests - Protected view access control for authenticated/unauthenticated users - LOGIN_DISABLED configuration bypass behavior - OPTIONS request exemption from authentication - Flask 1.x and 2.x compatibility with ensure_sync ### User Context Management - User retrieval from Flask g context (_get_user function) - Lazy loading of user when not in context - Request context boundary handling ### Current User Proxy - Thread-safe user proxy across multiple request contexts - Proper attribute access and error handling for None users - Concurrent request isolation validation ## Checklist - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!) - [x] I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change. - [x] I've updated the documentation accordingly. - [x] I ran `dev/reformat`(backend) and `cd web && npx lint-staged`(frontend) to appease the lint gods
yindo added the pull-request label 2026-02-21 20:46:27 -05:00
yindo closed this issue 2026-02-21 20:46:27 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#29894