Fusion 2ce7862058 feat: simplify auth flow - replace JWT with session cookies
Replace complex JWT + refresh token authentication with simple
session-based auth using signed cookies.

**Removed:**
- JWT token service (jwt_service.py)
- Refresh token store (refresh_store.py)
- Refresh token model and database table
- JWKS fetching and OIDC token verification
- python-jose dependency

**Added:**
- Session service (session.py) with HMAC-SHA256 signed cookies
- Auth dependencies module for shared auth logic
- Session-based auth endpoints

**Updated:**
- All API endpoints to use session-based auth
- Config: removed JWT settings, added SESSION_SECRET/SESSION_TTL_HOURS
- Tests: rewritten for session-based flow
- Frontend: no changes needed (already uses cookies)

Quality gates: ruff ✓, mypy ✓, typecheck ✓, lint ✓
2026-05-18 22:54:53 +02:00

Testing Strategy

The project uses a three-tier testing approach:

Test Categories

  1. Unit Tests (apps/api/tests/unit/)

    • Fast tests with no external dependencies
    • Use SQLite in-memory database
    • Run with: make test-unit or pytest -m unit
  2. Integration Tests (apps/api/tests/integration/)

    • Test API endpoints with database
    • Use PostgreSQL with transaction rollback
    • Run with: make test-integration or pytest -m integration
  3. System/E2E Tests (e2e/)

    • End-to-end tests using Playwright
    • Test full user journeys
    • Run with: make test-e2e

Running Tests

# Run all tests (excludes system tests by default)
make test

# Run specific categories
make test-unit          # Fast unit tests only
make test-integration   # Integration tests with DB
make test-system        # Full stack tests
make test-e2e          # Browser-based E2E tests

# Inside Docker container
docker compose exec api pytest -v -m unit
docker compose exec api pytest -v -m integration

Test Markers

Tests are marked with pytest markers:

  • @pytest.mark.unit - Fast, isolated tests
  • @pytest.mark.integration - Tests with database/external services
  • @pytest.mark.system - Full stack tests

Shared Fixtures

Common fixtures are in apps/api/tests/conftest.py:

  • sqlite_engine - SQLite engine for unit tests
  • postgres_engine - PostgreSQL engine for integration tests
  • db_session - Database session with transaction rollback
  • test_client - FastAPI TestClient instance
S
Description
No description provided
Readme 10 MiB
Languages
Python 53.8%
TypeScript 36.7%
CSS 5%
HTML 3.4%
Dockerfile 0.4%
Other 0.6%