[PR #22439] test: add comprehensive unit tests for console authentication and authorization decorators #29929

Closed
opened 2026-02-21 20:46:31 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/22439

State: closed
Merged: Yes


Description:

Add comprehensive unit tests for controllers.console.wraps module with Flask-Login configuration improvements discovered during testing.

Core Functionality Tests

  • Account initialization status validation and enforcement
  • Edition-specific access control (cloud, enterprise, self-hosted)
  • Billing resource limit enforcement with quota checking
  • Rate limiting with Redis-based request tracking
  • System setup validation and initialization checks
  • Enterprise license validation and status verification

Security Tests

  • Authentication decorator behavior with different account statuses
  • Authorization checks for various edition types
  • Resource limit enforcement with over-quota scenarios
  • Rate limit validation with tenant-specific tracking
  • License status validation (active, inactive, expired, lost)
  • Request source filtering for document upload limits

Edge Cases

  • Uninitialized account status handling
  • Missing or invalid license scenarios
  • Resource limits at exact quota boundaries
  • Rate limiting with various subscription plans
  • System setup with different initialization states
  • Document upload source validation logic

This improves code quality and reliability by ensuring critical security decorators are properly tested and behave as expected in all authentication and authorization scenarios.

Checklist

  • This change requires a documentation update, included: Dify Document
  • I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.
  • I ran dev/reformat(backend) and cd web && npx lint-staged(frontend) to appease the lint gods
**Original Pull Request:** https://github.com/langgenius/dify/pull/22439 **State:** closed **Merged:** Yes --- ## Description: ### Add comprehensive unit tests for controllers.console.wraps module with Flask-Login configuration improvements discovered during testing. ### Core Functionality Tests - Account initialization status validation and enforcement - Edition-specific access control (cloud, enterprise, self-hosted) - Billing resource limit enforcement with quota checking - Rate limiting with Redis-based request tracking - System setup validation and initialization checks - Enterprise license validation and status verification ### Security Tests - Authentication decorator behavior with different account statuses - Authorization checks for various edition types - Resource limit enforcement with over-quota scenarios - Rate limit validation with tenant-specific tracking - License status validation (active, inactive, expired, lost) - Request source filtering for document upload limits ### Edge Cases - Uninitialized account status handling - Missing or invalid license scenarios - Resource limits at exact quota boundaries - Rate limiting with various subscription plans - System setup with different initialization states - Document upload source validation logic ### This improves code quality and reliability by ensuring critical security decorators are properly tested and behave as expected in all authentication and authorization scenarios. ## Checklist - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!) - [x] I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change. - [x] I've updated the documentation accordingly. - [x] I ran `dev/reformat`(backend) and `cd web && npx lint-staged`(frontend) to appease the lint gods
yindo added the pull-request label 2026-02-21 20:46:31 -05:00
yindo closed this issue 2026-02-21 20:46:31 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#29929