F1: GUI-Login-Hash gegen $-Korruption gehaertet. .env-Werte einfach-gequotet
geschrieben + Sanity-Check nach Sourcing. Zusaetzlich systemd-Ebene:
podman escapt $->$$ in Environment=, systemd 252 kollabiert das nicht ->
sed-Post-Processing der Unit-Dateien. Live-.env: GUI-Passwort rotiert.
F2: Explizite Dependent-Deletes gegen FK-500 (delete_scenario/loan), 409 bei
bestaetigtem Import-Delete. Test-Engine erzwingt PRAGMA foreign_keys=ON.
F3: Enum/Range-Validierung (Literal + Field ge/le) fuer Recurring, Loan,
Modifier inkl. PATCH-Pfade.
F4: Confirm nur fuer draft-Statements (sonst 409) + Dedup-Re-Check gegen
bestaetigte Buchungen vor dem Promoten.
F5: v_balance_history/v_balance_total addieren pro Konto den opening_balance
des fruehesten bestaetigten Statements (approved deviation vom Plan-SQL).
F6: patch_scenario Namenskollision -> 409; create_transaction unbekanntes
Konto -> 404 (statt 500).
F7: Generierte systemd-Unit-Dateien chmod 600 (enthalten Env-Secrets).
F8: Globaler htmx:responseError-Handler in base.html.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
115 lines
5.3 KiB
Python
115 lines
5.3 KiB
Python
from datetime import date
|
|
from decimal import Decimal
|
|
from pathlib import Path
|
|
|
|
import pytest
|
|
|
|
from app.parsers.base import ParsedStatement, ParsedTransaction
|
|
|
|
H = {"Authorization": "Bearer test-key"}
|
|
|
|
FAKE = ParsedStatement(
|
|
bank="dkb", iban="DE02120300000000202051",
|
|
period_start=date(2026, 6, 1), period_end=date(2026, 6, 30),
|
|
opening_balance=Decimal("100.00"), closing_balance=Decimal("40.00"),
|
|
transactions=[ParsedTransaction(date(2026, 6, 3), date(2026, 6, 3),
|
|
Decimal("-60.00"), "Miete Juni", "Vermieter")])
|
|
|
|
|
|
@pytest.fixture
|
|
def fake_parse(monkeypatch):
|
|
monkeypatch.setattr("app.services.importer.parse_pdf", lambda p: FAKE)
|
|
|
|
|
|
def _upload(client, name="auszug.pdf"):
|
|
return client.post("/api/imports/upload", headers=H,
|
|
files={"file": (name, b"%PDF-fake", "application/pdf")})
|
|
|
|
|
|
def test_upload_preview_confirm(client, fake_parse, tmp_path, monkeypatch):
|
|
monkeypatch.setenv("FB_INBOX_DIR", str(tmp_path / "inbox"))
|
|
monkeypatch.setenv("FB_UPLOADS_DIR", str(tmp_path / "uploads"))
|
|
from app.config import get_settings
|
|
get_settings.cache_clear()
|
|
r = _upload(client)
|
|
assert r.status_code == 201
|
|
sid = r.json()["id"]
|
|
prev = client.get(f"/api/imports/{sid}/preview", headers=H).json()
|
|
assert prev["balance_ok"] is True
|
|
assert len(prev["transactions"]) == 1
|
|
assert client.post(f"/api/imports/{sid}/confirm", headers=H).status_code == 200
|
|
txs = client.get("/api/transactions", headers=H).json()
|
|
assert len(txs) == 1 and txs[0]["status"] == "confirmed"
|
|
# Zweiter Import desselben Auszugs: alles Duplikate
|
|
sid2 = _upload(client, "auszug2.pdf").json()["id"]
|
|
prev2 = client.get(f"/api/imports/{sid2}/preview", headers=H).json()
|
|
assert prev2["duplicates"] == 1
|
|
client.post(f"/api/imports/{sid2}/confirm", headers=H)
|
|
assert len(client.get("/api/transactions", headers=H).json()) == 1
|
|
|
|
|
|
def test_confirm_rechecks_duplicates_across_two_drafts(client, fake_parse, tmp_path, monkeypatch):
|
|
# Beide Auszuege werden importiert, bevor einer bestaetigt ist -> zum
|
|
# Importzeitpunkt ist keine Buchung ein Duplikat (dedup prueft nur gegen
|
|
# bestaetigte). Erst beim zweiten Confirm faellt auf, dass die Buchung nun
|
|
# bereits bestaetigt existiert. Der Re-Check muss sie ueberspringen, sonst
|
|
# wird dieselbe Buchung doppelt bestaetigt.
|
|
monkeypatch.setenv("FB_INBOX_DIR", str(tmp_path / "inbox"))
|
|
monkeypatch.setenv("FB_UPLOADS_DIR", str(tmp_path / "uploads"))
|
|
from app.config import get_settings
|
|
get_settings.cache_clear()
|
|
sid1 = _upload(client, "a1.pdf").json()["id"]
|
|
sid2 = _upload(client, "a2.pdf").json()["id"]
|
|
assert client.post(f"/api/imports/{sid1}/confirm", headers=H).status_code == 200
|
|
assert client.post(f"/api/imports/{sid2}/confirm", headers=H).status_code == 200
|
|
# Zweites Confirm darf die Buchung nicht erneut bestaetigen.
|
|
assert len(client.get("/api/transactions", headers=H).json()) == 1
|
|
# Zweites Confirm eines bereits bestaetigten Imports -> 409.
|
|
assert client.post(f"/api/imports/{sid1}/confirm", headers=H).status_code == 409
|
|
|
|
|
|
def test_upload_sanitizes_path_traversal_filename(client, fake_parse, tmp_path, monkeypatch):
|
|
monkeypatch.setenv("FB_INBOX_DIR", str(tmp_path / "inbox"))
|
|
monkeypatch.setenv("FB_UPLOADS_DIR", str(tmp_path / "uploads"))
|
|
from app.config import get_settings
|
|
get_settings.cache_clear()
|
|
r = client.post("/api/imports/upload", headers=H,
|
|
files={"file": ("../evil.pdf", b"%PDF-fake", "application/pdf")})
|
|
assert r.status_code == 201
|
|
# Der Dateiname darf keine Pfad-Anteile aus dem Client uebernehmen: nur
|
|
# der Basisname landet im Uploads-Verzeichnis, nichts entkommt nach oben.
|
|
assert not (tmp_path / "evil.pdf").exists()
|
|
assert (tmp_path / "uploads" / "evil.pdf").exists()
|
|
assert not (tmp_path / "inbox" / "evil.pdf").exists()
|
|
|
|
|
|
def test_upload_rejects_non_pdf(client, tmp_path, monkeypatch):
|
|
monkeypatch.setenv("FB_INBOX_DIR", str(tmp_path / "inbox"))
|
|
monkeypatch.setenv("FB_UPLOADS_DIR", str(tmp_path / "uploads"))
|
|
from app.config import get_settings
|
|
get_settings.cache_clear()
|
|
r = client.post("/api/imports/upload", headers=H,
|
|
files={"file": ("x.txt", b"not a pdf", "text/plain")})
|
|
assert r.status_code == 400
|
|
|
|
|
|
def test_upload_corrupt_pdf_produces_error_statement_not_500(client, tmp_path, monkeypatch):
|
|
# Datei besteht die Endungspruefung (.pdf), ist aber strukturell kein
|
|
# gueltiges PDF -> pdfplumber wirft eine eigene Exception (keine
|
|
# ParserError). Das darf nicht als unbehandelter 500 durchschlagen,
|
|
# sondern muss wie "Bank nicht erkannt" als sauberer Fehler-Import
|
|
# sichtbar werden.
|
|
monkeypatch.setenv("FB_INBOX_DIR", str(tmp_path / "inbox"))
|
|
monkeypatch.setenv("FB_UPLOADS_DIR", str(tmp_path / "uploads"))
|
|
from app.config import get_settings
|
|
get_settings.cache_clear()
|
|
r = client.post("/api/imports/upload", headers=H,
|
|
files={"file": ("kaputt.pdf", b"not a pdf", "application/pdf")})
|
|
assert r.status_code == 201
|
|
body = r.json()
|
|
assert body["status"] == "error"
|
|
assert "PDF nicht lesbar" in body["error_message"]
|
|
# Datei bleibt im Posteingang liegen, wird nicht ins Uploads-Verzeichnis verschoben.
|
|
assert (tmp_path / "inbox" / "kaputt.pdf").exists()
|
|
assert not (tmp_path / "uploads" / "kaputt.pdf").exists()
|