Files
routstr-core/tests/unit
9qeklajc c2b807bb20 fix: keep spendable credentials out of the structured logs
The dated JSON log files were a credential store. Structured `extra`
fields bypass the message-level regex scrubbing entirely — the JSON
formatter reads them straight off the record dict — and the only pass
they received was organization-ID redaction. So a full Cashu refund
token, and the `hashed_key` that `sk-<hashed_key>` auth accepts as a
live reusable API key, were written verbatim, as were all request query
values. Anyone able to read a log file could spend from it.

Fixed at both ends so neither alone is load-bearing. The call sites stop
handing over the values: balance logs a token length and an eight-char
key prefix, and the request middleware logs query parameter names
without their values. The SecurityFilter then refuses to emit them
anyway, walking every extra recursively and stripping both secret-shaped
keys and secret-shaped values (Cashu tokens, bearer values, `sk-` keys,
nsec keys, full SHA-256 hashes, secret-ish query parameters) wherever
they are nested. The walk is depth-limited and cycle-safe so a malformed
payload degrades to `[REDACTED]` instead of failing the log call, and
numeric values are never touched, which keeps the usage-analytics fields
the dashboard parses intact.

Retention is also wired up: `backupCount` never expired anything here
because the base filename moves with the date, so the inherited rollover
found no siblings and every day of logs was kept forever. Rollover now
prunes explicitly.
2026-08-24 01:48:16 +02:00
..
2025-08-03 20:35:59 -03:00
2025-08-09 14:55:26 -03:00
2026-08-23 23:25:03 +02:00
2026-08-03 23:32:06 +02:00
2026-08-04 01:44:01 +02:00
2026-06-13 23:40:39 +02:00
2026-08-16 14:59:38 +02:00
2026-08-03 23:32:06 +02:00
2026-08-06 22:58:44 +02:00
2026-08-04 00:06:53 +02:00
2026-08-03 00:05:36 +02:00
2026-08-03 23:32:06 +02:00
2026-08-02 23:16:01 +02:00
2026-08-23 13:30:57 +02:00
2026-07-01 17:08:28 +02:00
2026-07-01 16:53:52 +02:00
2026-05-14 15:40:49 +02:00
2026-07-29 22:50:33 +02:00
2026-08-14 21:48:29 +02:00
2026-07-22 23:10:27 +02:00
2026-07-22 23:10:27 +02:00
2026-08-15 15:09:00 +02:00

FastAPI Async Unit Tests

This directory contains async unit tests for the Routstr proxy FastAPI application.

Installation

First, ensure you have the development dependencies installed:

uv pip install -e ".[dev]"

Running Tests

To run all tests:

pytest

To run tests with coverage:

pytest --cov=routstr --cov-report=html

To run specific test files:

pytest tests/test_main.py
pytest tests/test_models.py
pytest tests/test_proxy.py

To run only async tests:

pytest -m asyncio

Test Structure

  • conftest.py - Pytest fixtures and configuration
  • test_main.py - Tests for main app endpoints
  • test_account.py - Tests for wallet/account management endpoints
  • test_proxy.py - Tests for the proxy functionality with mocked upstream
  • test_models.py - Tests for model pricing and data structures

Key Fixtures

  • async_client - Async HTTP client for testing FastAPI endpoints
  • test_session - In-memory SQLite database session for tests
  • test_api_key - Pre-configured API key with balance
  • api_key_with_balance - API key with sufficient balance for proxy tests

Environment Variables

The tests automatically set up required environment variables in conftest.py. No manual configuration needed.

Writing New Tests

  1. Use @pytest.mark.asyncio for async tests
  2. Use the provided fixtures for database and client access
  3. Mock external dependencies (like upstream API calls)
  4. Test both success and error cases
  5. Verify database state changes when applicable