# ============================================================================= # 三端认证重构 AUTH-01 — 环境门控单元测试 # ============================================================================= # 验证 env_gating.py 的行为: # 1. is_production() 根据 app_env 判断环境 # 2. ip_in_whitelist() 支持单 IP 和 CIDR 网段匹配 # ============================================================================= import pytest from unittest.mock import patch, MagicMock import sys class TestIsProduction: """测试 is_production() 函数""" def test_production_env_returns_true(self): """app_env=production 时应返回 True""" with patch("app.utils.env_gating.settings") as mock_settings: mock_settings.app_env = "production" from app.utils.env_gating import is_production result = is_production() assert result is True def test_dev_env_returns_false(self): """app_env=dev 时应返回 False""" with patch("app.utils.env_gating.settings") as mock_settings: mock_settings.app_env = "dev" from app.utils.env_gating import is_production result = is_production() assert result is False def test_test_env_returns_false(self): """app_env=test 时应返回 False""" with patch("app.utils.env_gating.settings") as mock_settings: mock_settings.app_env = "test" from app.utils.env_gating import is_production result = is_production() assert result is False def test_empty_env_returns_false(self): """空 app_env 时应返回 False(默认 dev)""" with patch("app.utils.env_gating.settings") as mock_settings: mock_settings.app_env = "" from app.utils.env_gating import is_production result = is_production() assert result is False def test_production_case_insensitive(self): """app_env 大小写不敏感""" with patch("app.utils.env_gating.settings") as mock_settings: mock_settings.app_env = "PRODUCTION" from app.utils.env_gating import is_production result = is_production() assert result is True class TestIpInWhitelist: """测试 ip_in_whitelist() 函数""" def test_single_ip_match(self): """单 IP 精确匹配""" from app.utils.env_gating import ip_in_whitelist # 白名单中的 IP assert ip_in_whitelist("117.147.35.138", allowed="117.147.35.138,218.75.34.87") is True assert ip_in_whitelist("218.75.34.87", allowed="117.147.35.138,218.75.34.87") is True # 不在白名单中的 IP assert ip_in_whitelist("8.8.8.8", allowed="117.147.35.138,218.75.34.87") is False def test_cidr_network_match(self): """CIDR 网段匹配""" from app.utils.env_gating import ip_in_whitelist # 在网段内 assert ip_in_whitelist("10.240.0.1", allowed="10.240.0.0/16") is True assert ip_in_whitelist("10.240.1.100", allowed="10.240.0.0/16") is True assert ip_in_whitelist("10.240.255.255", allowed="10.240.0.0/16") is True # 不在网段内 assert ip_in_whitelist("10.239.255.255", allowed="10.240.0.0/16") is False assert ip_in_whitelist("10.241.0.0", allowed="10.240.0.0/16") is False def test_mixed_ip_and_cidr(self): """混合单 IP 和 CIDR""" from app.utils.env_gating import ip_in_whitelist assert ip_in_whitelist("117.147.35.138", allowed="117.147.35.138,10.240.0.0/16") is True assert ip_in_whitelist("10.240.1.50", allowed="117.147.35.138,10.240.0.0/16") is True assert ip_in_whitelist("8.8.8.8", allowed="117.147.35.138,10.240.0.0/16") is False def test_empty_whitelist_returns_false(self): """空白名单应返回 False(保守策略)""" # 显式传入空列表 from app.utils.env_gating import ip_in_whitelist, _parse_allowed_ips # 解析空字符串应返回空列表 assert _parse_allowed_ips("") == [] # 空列表应返回 False assert ip_in_whitelist("10.240.1.1", allowed="") is False def test_empty_client_ip_returns_false(self): """空客户端 IP 应返回 False""" from app.utils.env_gating import ip_in_whitelist assert ip_in_whitelist("", allowed="10.240.0.0/16") is False assert ip_in_whitelist(None, allowed="10.240.0.0/16") is False def test_invalid_client_ip_returns_false(self): """无效客户端 IP 格式应返回 False""" from app.utils.env_gating import ip_in_whitelist assert ip_in_whitelist("invalid-ip", allowed="10.240.0.0/16") is False assert ip_in_whitelist("999.999.999.999", allowed="10.240.0.0/16") is False def test_explicit_allowed_parameter(self): """测试显式传入 allowed 参数""" from app.utils.env_gating import ip_in_whitelist # 显式传入 allowed 参数 assert ip_in_whitelist("218.75.34.87", allowed="218.75.34.87") is True assert ip_in_whitelist("8.8.8.8", allowed="218.75.34.87") is False def test_whitelist_with_spaces(self): """白名单字符串带空格应正确处理""" from app.utils.env_gating import ip_in_whitelist assert ip_in_whitelist("117.147.35.138", allowed=" 117.147.35.138 , 218.75.34.87 , 10.240.0.0/16 ") is True assert ip_in_whitelist("218.75.34.87", allowed=" 117.147.35.138 , 218.75.34.87 , 10.240.0.0/16 ") is True assert ip_in_whitelist("10.240.1.1", allowed=" 117.147.35.138 , 218.75.34.87 , 10.240.0.0/16 ") is True if __name__ == "__main__": pytest.main([__file__, "-v"])