Skip to content

test(backend): pin oauth and mfa error details that mutants survived - #418

Merged
simonvanlierde merged 3 commits into
mainfrom
test/backend-auth-assertions
Oct 10, 2026
Merged

simonvanlierde merged 3 commits into
mainfrom
test/backend-auth-assertions

Conversation

@simonvanlierde

@simonvanlierde simonvanlierde commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Adds the assertions that mutation testing showed were missing for the auth flows (group 1 of #409): OAuth login and associate callbacks, complete_mfa_challenge, audit_mfa_failure and require_account_update_step_up. Closes #409.

  • Pins audit reasons, error details, the arguments handed to the OAuth client and user manager, and the link notification.
  • Lowers the baseline from a mutation run of the auth-flows shard on this branch: for example, the login callback goes from 60 survivors to 4 and complete_mfa_challenge from 41 to 0. Most of the 18 left in the associate callback are cast() type strings.

- OAuth login callback: pin the provider arguments, the error and success
  redirects, and the MFA transport chosen from the backend
- OAuth associate callback: pin the existing-link lookup, the provider
  arguments, the updated user in the response and the link notification
- MFA challenge: pin failure reasons, the bad-credentials detail, the success
  audit event, the guess budget key and the session transport path
- Account update step-up: pin the refusal details, the missing-request error
  and the recovery code burn; add its mutation baseline line

Closes #409
@codecov

codecov Bot commented Oct 10, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ All tests successful. No failed tests found.

📢 Thoughts on this report? Let us know!

Survivor counts from a mutation run of the auth-flows shard on this branch.
Most of the 18 left in handle_oauth_associate_callback are cast() type strings,
which do nothing at runtime.
…ertions

* origin/main:
  feat!: move to r9lab.io and rename the product to R9lab (#417)

# Conflicts:
#	backend/tests/integration/api/auth/test_oauth_callbacks.py
@simonvanlierde
simonvanlierde merged commit 5f7cd72 into main Oct 10, 2026
18 checks passed
@simonvanlierde
simonvanlierde deleted the test/backend-auth-assertions branch October 10, 2026 20:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

test(backend): add the assertions that mutation testing shows are missing

1 participant