Skip to content

test(oidc): replace pretend in OIDC tests - #20576

Open
miketheman wants to merge 8 commits into
pypi:mainfrom
miketheman:miketheman/pretend-less-5a
Open

miketheman wants to merge 8 commits into
pypi:mainfrom
miketheman:miketheman/pretend-less-5a

Conversation

@miketheman

Copy link
Copy Markdown
Member

Replaced pretend in all OIDC-related test modules.
Commits split to make review easier.

Refs: #18880

Publisher stand-ins are autospec'd OIDCPublisherService instances, the
sentry_sdk new_scope stub is a SimpleNamespace, and opaque arguments the
checks never read use mocker.sentinel.

Refs pypi#18880
The GitHub and ActiveState HTTP lookups go through the responses
library, so the real Response.json(), raise_for_status() and requests
exception types run instead of a hand-stubbed requests module.

Switching to real form fields turned up a wrong assertion in the pending
publisher tests. The "project already exists" redirect puts every truthy
field of self.data in the query string, project_name included; the old
stub field had none, so the tests never saw it. The assertions now match
what the view builds.

Refs pypi#18880
utils uses sentinels for the unsupported-issuer path, autospec'd
publisher classes for the claims check, and a built GitHubPublisher for
the principals test.

tasks patches the email collaborators with autospec and spies on the
real User.record_event, so the event rows actually get written.

Refs pypi#18880
Publishers come from autospecs and GitHubPublisherFactory builds. The
issuer_url mismatch and custom issuer tests key OIDC_PUBLISHER_CLASSES
with the real publisher classes rather than a stub carrying only
__supports_custom_issuer__.

_refresh_keyset now goes through responses, so the real Response.json()
and raise_for_status() paths run.

Refs pypi#18880
The view tests run against real pyramid_request/db_request objects and
registered services: DummyRateLimiter for the two OIDC limiters, real
AdminFlag rows for the enabled and disabled checks, and autospec'd
OIDCPublisherService and DatabaseMacaroonService where a return value
has to be controlled. A few call recorders that no assertion ever read
are gone.

Worth knowing: GitLab OIDC is disallowed by default in the seeded
AdminFlag rows, unlike GitHub, Google and ActiveState. The
service-selection test flips that flag explicitly instead of leaning on
a stub that never touched flag state.

This finishes the OIDC tests.

Refs pypi#18880
@miketheman
miketheman requested a review from a team as a code owner September 22, 2026 18:10
@miketheman miketheman added testing Test infrastructure and individual tests developer experience Anything that improves the experience for Warehouse devs core-team labels Sep 22, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

core-team developer experience Anything that improves the experience for Warehouse devs testing Test infrastructure and individual tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant