mirror of
https://github.com/Routstr/routstr-core.git
synced 2026-08-10 19:16:31 +00:00
Comprehensive audit of all money-moving code paths on current main.
Found 8 live vulnerabilities where users, providers, or node runners
can lose funds, plus 1 false-green in the existing emergency refund
test suite.
Live vulnerabilities (all RED — tests assert correct/safe behaviour):
V-E1 send_refund() swallows DB failure after minting a refund token
base.py ~line 3625 — except Exception: pass
V-E2 Emergency refund (chat) — same except: pass
base.py ~line 3992 (existing test is a false green — 500-char
window too short)
V-E3 Emergency refund (responses API) — identical pattern
base.py ~line 4972
V-E4 Balance refund endpoint swallows DB failure
balance.py ~line 628
V-E5 credit_balance() swallows 'in' transaction DB failure
wallet.py ~line 1715
V-E6 EHBP refund token — except: pass after store
ehbp.py ~line 762
V-E7 EHBP 'in' transaction — except: pass after store
ehbp.py ~line 1028
V-E8 Admin withdraw returns token even when DB store fails
admin.py ~line 475
V-E9 Window regression guard (GREEN) — documents the false-green in
the existing test_emergency_refund_no_try_except_pass
Test results: 8 failed, 1 passed.
FastAPI Async Unit Tests
This directory contains async unit tests for the Routstr proxy FastAPI application.
Installation
First, ensure you have the development dependencies installed:
uv pip install -e ".[dev]"
Running Tests
To run all tests:
pytest
To run tests with coverage:
pytest --cov=routstr --cov-report=html
To run specific test files:
pytest tests/test_main.py
pytest tests/test_models.py
pytest tests/test_proxy.py
To run only async tests:
pytest -m asyncio
Test Structure
conftest.py- Pytest fixtures and configurationtest_main.py- Tests for main app endpointstest_account.py- Tests for wallet/account management endpointstest_proxy.py- Tests for the proxy functionality with mocked upstreamtest_models.py- Tests for model pricing and data structures
Key Fixtures
async_client- Async HTTP client for testing FastAPI endpointstest_session- In-memory SQLite database session for teststest_api_key- Pre-configured API key with balanceapi_key_with_balance- API key with sufficient balance for proxy tests
Environment Variables
The tests automatically set up required environment variables in conftest.py. No manual configuration needed.
Writing New Tests
- Use
@pytest.mark.asynciofor async tests - Use the provided fixtures for database and client access
- Mock external dependencies (like upstream API calls)
- Test both success and error cases
- Verify database state changes when applicable