Files
routstr-core/tests/unit
thefux 667f9bf6bb test: money-path audit — 8 RED tests for live fund-loss vulnerabilities
Comprehensive audit of all money-moving code paths on current main.
Found 8 live vulnerabilities where users, providers, or node runners
can lose funds, plus 1 false-green in the existing emergency refund
test suite.

Live vulnerabilities (all RED — tests assert correct/safe behaviour):

V-E1  send_refund() swallows DB failure after minting a refund token
      base.py ~line 3625 — except Exception: pass
V-E2  Emergency refund (chat) — same except: pass
      base.py ~line 3992 (existing test is a false green — 500-char
      window too short)
V-E3  Emergency refund (responses API) — identical pattern
      base.py ~line 4972
V-E4  Balance refund endpoint swallows DB failure
      balance.py ~line 628
V-E5  credit_balance() swallows 'in' transaction DB failure
      wallet.py ~line 1715
V-E6  EHBP refund token — except: pass after store
      ehbp.py ~line 762
V-E7  EHBP 'in' transaction — except: pass after store
      ehbp.py ~line 1028
V-E8  Admin withdraw returns token even when DB store fails
      admin.py ~line 475

V-E9  Window regression guard (GREEN) — documents the false-green in
      the existing test_emergency_refund_no_try_except_pass

Test results: 8 failed, 1 passed.
2026-08-06 20:58:06 +00:00
..
2025-08-03 20:35:59 -03:00
2025-08-09 14:55:26 -03:00
2026-08-03 23:32:06 +02:00
2026-08-03 23:32:06 +02:00
2026-08-04 01:44:01 +02:00
2026-08-04 00:06:53 +02:00
2026-06-13 23:40:39 +02:00
2026-06-27 22:53:35 +02:00
2026-08-03 23:32:06 +02:00
2026-07-22 23:10:27 +02:00
2026-08-03 23:32:06 +02:00
2026-08-04 22:59:50 +02:00
2026-08-04 00:06:53 +02:00
2026-08-04 00:06:53 +02:00
2026-08-03 00:05:36 +02:00
2026-08-03 23:32:06 +02:00
2026-08-02 23:16:01 +02:00
2026-08-03 23:32:06 +02:00
2026-08-04 00:06:53 +02:00
2026-07-01 17:08:28 +02:00
2026-07-01 16:53:52 +02:00
2026-05-14 15:40:49 +02:00
2026-07-29 22:50:33 +02:00
2026-07-22 23:10:27 +02:00
2026-07-22 23:10:27 +02:00
2026-08-05 00:32:06 +02:00

FastAPI Async Unit Tests

This directory contains async unit tests for the Routstr proxy FastAPI application.

Installation

First, ensure you have the development dependencies installed:

uv pip install -e ".[dev]"

Running Tests

To run all tests:

pytest

To run tests with coverage:

pytest --cov=routstr --cov-report=html

To run specific test files:

pytest tests/test_main.py
pytest tests/test_models.py
pytest tests/test_proxy.py

To run only async tests:

pytest -m asyncio

Test Structure

  • conftest.py - Pytest fixtures and configuration
  • test_main.py - Tests for main app endpoints
  • test_account.py - Tests for wallet/account management endpoints
  • test_proxy.py - Tests for the proxy functionality with mocked upstream
  • test_models.py - Tests for model pricing and data structures

Key Fixtures

  • async_client - Async HTTP client for testing FastAPI endpoints
  • test_session - In-memory SQLite database session for tests
  • test_api_key - Pre-configured API key with balance
  • api_key_with_balance - API key with sufficient balance for proxy tests

Environment Variables

The tests automatically set up required environment variables in conftest.py. No manual configuration needed.

Writing New Tests

  1. Use @pytest.mark.asyncio for async tests
  2. Use the provided fixtures for database and client access
  3. Mock external dependencies (like upstream API calls)
  4. Test both success and error cases
  5. Verify database state changes when applicable