Skip to content

Fix Python integration tests missing internal auth header and env var handling#122

Merged
Senthil455 merged 6 commits into
mainfrom
fix/issue-49-python-tests
Jun 17, 2026
Merged

Fix Python integration tests missing internal auth header and env var handling#122
Senthil455 merged 6 commits into
mainfrom
fix/issue-49-python-tests

Conversation

@Senthil455

Copy link
Copy Markdown
Owner

Fix ai-copilot-service and ats-service test clients to include the x-internal-auth header required by internal_auth_middleware. Fix employee-service main.py to use os.environ.get() instead of bracket access for MONGO_USER, MONGO_PASSWORD, INTERNAL_KEY, and RABBITMQ_USER to prevent KeyError.

Add backup_codes_shown flag to user_mfa table. Backup codes are only
returned on the initial setup request and marked as shown afterwards.
Re-running setup will regenerate codes but not display them. Add a
/mfa/rotate-backup-codes endpoint that requires current TOTP token
to view new backup codes.
Prevent token leak by removing the raw passwordless token from the API
response body. The token is still stored hashed in the database and can
be verified via /auth/passwordless/verify. The response now only returns
a generic success message.
Replace 4 fragile regex patterns for extracting NameID and SAML attribute
values with robust DOM-based extraction using the already-parsed XML
document. This fixes namespace sensitivity, encoding variations, and
CDATA handling issues. Also moves the DOMParser outside the
SAML_IDP_CERT conditional so it is always available for attribute
extraction.
Add internal auth token to test clients for ai-copilot-service and
ats-service so integration tests pass instead of returning 401.
Fix employee-service main.py to use os.environ.get() for MONGO_USER,
MONGO_PASSWORD, INTERNAL_KEY, and RABBITMQ_USER instead of bracket
access that raises KeyError when env vars are not set.
@Senthil455 Senthil455 merged commit 05654d0 into main Jun 17, 2026
2 of 20 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant