fix: reorder notification DELETE routes so bulk clear matches first
FastAPI matches routes in declaration order. The DELETE /notifications
endpoint (bulk clear) was registered AFTER DELETE /notifications/{id},
so the path parameter route intercepted all requests to the bulk route,
causing a 422 UUID validation error instead of hitting clear_all.
Moved clear_all_notifications above dismiss_notification in the router.
Added regression test to verify route order.
Quality gates: pytest (22 passed)
This commit is contained in:
@@ -0,0 +1,34 @@
|
||||
"""Unit tests for notification API route ordering."""
|
||||
|
||||
from fastapi import FastAPI
|
||||
from fastapi.testclient import TestClient
|
||||
|
||||
from src.api.notifications import router as notifications_router
|
||||
|
||||
|
||||
def test_delete_notifications_route_order() -> None:
|
||||
"""DELETE /notifications must match before DELETE /notifications/{id}.
|
||||
|
||||
FastAPI matches routes in declaration order. The bulk clear endpoint
|
||||
(DELETE /notifications) must be registered before the single dismiss
|
||||
endpoint (DELETE /notifications/{notification_id}) or the path
|
||||
parameter route will intercept the bulk route.
|
||||
"""
|
||||
app = FastAPI()
|
||||
app.include_router(notifications_router)
|
||||
client = TestClient(app)
|
||||
|
||||
# Verify the bulk delete route exists and returns the expected schema
|
||||
# (it will 401 without auth, but that's fine — we just need to confirm
|
||||
# routing doesn't hit the UUID-parameter route first)
|
||||
response = client.delete("/notifications")
|
||||
# Should get 401 (unauthenticated), NOT 422 (UUID parse error)
|
||||
assert response.status_code == 401, (
|
||||
f"Expected 401 (auth required), got {response.status_code}. "
|
||||
f"Route order may be wrong — DELETE /notifications matched "
|
||||
f"DELETE /notifications/{{notification_id}} instead."
|
||||
)
|
||||
|
||||
# Verify the single dismiss route still works (also 401 without auth)
|
||||
response = client.delete("/notifications/12345678-1234-1234-1234-123456789abc")
|
||||
assert response.status_code == 401
|
||||
Reference in New Issue
Block a user