Files
routstr-core/tests/conftest.py
T
9qeklajc 9beead5ece feat: negative cache for terminal Cashu redemption failures
A dead token (already spent, malformed, zero value) presented as a bearer
key triggers a full mint redemption attempt on every request, because the
failed attempt rolls back and leaves no api_keys row behind. Polling
clients that never back off turn one dead token into thousands of
pointless mint calls per day (~800/day observed against minibits alone),
hammering mints that are already degraded.

Add an in-memory bounded TTL+LRU cache keyed by token hash that remembers
terminal redemption failures (already spent, invalid token, zero value,
fees exceed amount). Repeat presentations are rejected locally with the
exact same sanitized error envelope the mint-backed failure produced.

Transient classifications (mint unreachable, rate limited) are never
cached so a brief mint outage cannot poison valid tokens. The cache is
deliberately memory-only: persisting a row per failed token would let an
attacker fill the database with garbage tokens for free.
2026-08-17 23:14:40 +02:00

33 lines
1.1 KiB
Python

"""Shared pytest configuration for the whole suite.
A fixed, valid ``ROUTSTR_SECRET_KEY`` is set before any app import so that
secret encryption is deterministic across the suite and the mandatory-key
fail-fast does not break app-boot tests. Tests that need a different key (or an
absent one) override this per-test via ``monkeypatch``.
"""
import os
import pytest
# Valid Fernet keys; KEY_A is the suite default, KEY_B is for wrong-key tests.
TEST_SECRET_KEY = "l_Tkp-7xmjcQ-IFhr6qhILrU8HPRbEmYMrfSbo_5srU="
TEST_SECRET_KEY_ALT = "_Teyrky_iToeDK51Tj1FsI9MJ340_cqKGmeher-a7MQ="
os.environ.setdefault("ROUTSTR_SECRET_KEY", TEST_SECRET_KEY)
@pytest.fixture(autouse=True)
def _isolate_redemption_negative_cache():
"""Clear the process-wide negative cache between tests.
The cache deliberately persists terminal redemption failures across
requests; without this fixture a test that burns a token would poison
every later test reusing the same token string.
"""
from routstr.redemption_cache import redemption_negative_cache
redemption_negative_cache.clear()
yield
redemption_negative_cache.clear()