Files
routstr-core/tests/unit
9qeklajc c1b7f78a02 fix: bound Routstr auto-topup spend with a durable claim
Routstr-to-Routstr auto top-up had no spend bound. Admin settings were
accepted without range or type validation, and every low-balance cycle
independently minted a Cashu token and handed it to the configured peer.
A malicious, buggy, or persistently non-crediting peer therefore received
a fresh bearer token every sixty seconds; nothing in the worker noticed
that the previous one had never been credited, and nothing survived a
restart, so the bleed was limited only by the owner's mint balance.

Auto top-up now mirrors the PPQ claim machinery that already guards the
Lightning path. Each provider gets one durable claim row keyed by its id,
so a second worker (or the same worker after a restart) loses the insert
or the ownership-fenced update instead of paying twice. The claim moves
to "sent" before the network call, and only a peer balance that reaches
the pre-topup balance plus the top-up amount clears it: an uncredited
token holds the slot rather than being retried. Repeated non-credit walks
the claim through exponential backoff to a halt that needs an admin
release, and a rolling 24h cap bounds the total even when every attempt
looks successful.

Settings validation now rejects non-positive, non-finite, boolean, huge,
and non-integer amounts, amounts outside the per-transaction range, and a
missing mint URL, at the admin API as well as in the worker.

The claim row is a CashuTransaction like the PPQ one, so no migration is
needed; provider delete and type change refuse to orphan it.
2026-08-24 01:53:16 +02:00
..
2025-08-03 20:35:59 -03:00
2025-08-09 14:55:26 -03:00
2026-08-23 23:25:03 +02:00
2026-08-03 23:32:06 +02:00
2026-06-13 23:40:39 +02:00
2026-08-16 14:59:38 +02:00
2026-08-03 23:32:06 +02:00
2026-08-06 22:58:44 +02:00
2026-08-04 00:06:53 +02:00
2026-08-03 00:05:36 +02:00
2026-08-03 23:32:06 +02:00
2026-08-02 23:16:01 +02:00
2026-08-23 13:30:57 +02:00
2026-07-01 17:08:28 +02:00
2026-07-01 16:53:52 +02:00
2026-05-14 15:40:49 +02:00
2026-07-29 22:50:33 +02:00
2026-08-14 21:48:29 +02:00
2026-07-22 23:10:27 +02:00
2026-07-22 23:10:27 +02:00
2026-08-15 15:09:00 +02:00

FastAPI Async Unit Tests

This directory contains async unit tests for the Routstr proxy FastAPI application.

Installation

First, ensure you have the development dependencies installed:

uv pip install -e ".[dev]"

Running Tests

To run all tests:

pytest

To run tests with coverage:

pytest --cov=routstr --cov-report=html

To run specific test files:

pytest tests/test_main.py
pytest tests/test_models.py
pytest tests/test_proxy.py

To run only async tests:

pytest -m asyncio

Test Structure

  • conftest.py - Pytest fixtures and configuration
  • test_main.py - Tests for main app endpoints
  • test_account.py - Tests for wallet/account management endpoints
  • test_proxy.py - Tests for the proxy functionality with mocked upstream
  • test_models.py - Tests for model pricing and data structures

Key Fixtures

  • async_client - Async HTTP client for testing FastAPI endpoints
  • test_session - In-memory SQLite database session for tests
  • test_api_key - Pre-configured API key with balance
  • api_key_with_balance - API key with sufficient balance for proxy tests

Environment Variables

The tests automatically set up required environment variables in conftest.py. No manual configuration needed.

Writing New Tests

  1. Use @pytest.mark.asyncio for async tests
  2. Use the provided fixtures for database and client access
  3. Mock external dependencies (like upstream API calls)
  4. Test both success and error cases
  5. Verify database state changes when applicable