From 3979b63f2726fdd47ed9d3b27b9292e22b677321 Mon Sep 17 00:00:00 2001 From: Matthew Carre Date: Wed, 22 Jul 2026 12:40:22 +0000 Subject: [PATCH 1/6] feat(argo): added underscore in example name to avoid duplication --- .../workflow_definitions/create_example_template.py.jinja | 2 +- .../templates/{example.yaml => _example.yaml} | 0 .../workflow_definitions/create_example_template.py | 2 +- 3 files changed, 2 insertions(+), 2 deletions(-) rename src/python_interface_to_workflows/templates/{example.yaml => _example.yaml} (100%) diff --git a/src/copier_template/src/{{ project_name }}/workflow_definitions/create_example_template.py.jinja b/src/copier_template/src/{{ project_name }}/workflow_definitions/create_example_template.py.jinja index 6a6aa90..2657ce0 100644 --- a/src/copier_template/src/{{ project_name }}/workflow_definitions/create_example_template.py.jinja +++ b/src/copier_template/src/{{ project_name }}/workflow_definitions/create_example_template.py.jinja @@ -178,5 +178,5 @@ example.yaml""", [install, params] >> makeimages >> makehdf5 # pyright: ignore -with open("example.yaml", "w") as div: +with open("_example.yaml", "w") as div: div.write(w.to_yaml()) # pyright: ignore[reportUnknownMemberType] diff --git a/src/python_interface_to_workflows/templates/example.yaml b/src/python_interface_to_workflows/templates/_example.yaml similarity index 100% rename from src/python_interface_to_workflows/templates/example.yaml rename to src/python_interface_to_workflows/templates/_example.yaml diff --git a/src/python_interface_to_workflows/workflow_definitions/create_example_template.py b/src/python_interface_to_workflows/workflow_definitions/create_example_template.py index e718511..8d3516a 100644 --- a/src/python_interface_to_workflows/workflow_definitions/create_example_template.py +++ b/src/python_interface_to_workflows/workflow_definitions/create_example_template.py @@ -178,5 +178,5 @@ def to_hdf5(paths: str): [install, params] >> makeimages >> makehdf5 # pyright: ignore -with open("example.yaml", "w") as div: +with open("_example.yaml", "w") as div: div.write(w.to_yaml()) # pyright: ignore[reportUnknownMemberType] From a0209c729fc81e5cab0418432f64308be82034de Mon Sep 17 00:00:00 2001 From: Matthew Carre Date: Wed, 22 Jul 2026 13:16:44 +0000 Subject: [PATCH 2/6] feat(auth): removes opening site when not required --- .../auth/keycloak_checker.py | 28 ++++++++++---- .../auth/open_auth_url.py | 37 ++++++++++++------- 2 files changed, 43 insertions(+), 22 deletions(-) diff --git a/src/python_interface_to_workflows/auth/keycloak_checker.py b/src/python_interface_to_workflows/auth/keycloak_checker.py index 71390fb..44e486e 100644 --- a/src/python_interface_to_workflows/auth/keycloak_checker.py +++ b/src/python_interface_to_workflows/auth/keycloak_checker.py @@ -36,14 +36,26 @@ def set_token_env_variable(staging: bool) -> str: code_challenge=code_challenge, code_challenge_method=code_challenge_method, ) - open_auth_url(auth_url, port) - token: dict[str, str] = ( # pyright: ignore[reportUnknownVariableType] - keycloak_openid.token( # pyright: ignore[reportUnknownMemberType] - grant_type="authorization_code", - code=os.environ["AUTH"], - redirect_uri=f"http://localhost:{port}/", - code_verifier=code_verifier, - ) + match open_auth_url(auth_url, port): + case True: + token: dict[str, str] = ( # pyright: ignore[reportUnknownVariableType] + keycloak_openid.token( # pyright: ignore[reportUnknownMemberType] + grant_type="authorization_code", + code=os.environ.get("AUTH"), # pyright: ignore + redirect_uri=f"http://localhost:{port}/", + code_verifier=code_verifier, + ) + ) + case False: + token: dict[str, str] = keycloak_openid.refresh_token( # pyright: ignore + str(os.environ.get("REFRESHTOKEN")) # pyright: ignore + ) + token_info: dict[str, int | str | dict[str, list[str]]] = ( # pyright: ignore + keycloak_openid.decode_token(token["access_token"]) # pyright: ignore ) + expire_time = int(token_info["exp"]) + 1500 # pyright: ignore + dotenv.set_key("src/.env", "EXPIRY", str(expire_time).strip("'")) dotenv.set_key("src/.env", "TOKEN", token["access_token"].strip("'")) + dotenv.set_key("src/.env", "REFRESHTOKEN", token["refresh_token"].strip("'")) + dotenv.load_dotenv(dotenv_path="src/.env", override=True) return token["access_token"] # pyright: ignore[reportUnknownArgumentType] diff --git a/src/python_interface_to_workflows/auth/open_auth_url.py b/src/python_interface_to_workflows/auth/open_auth_url.py index 2f0dcf9..666094f 100644 --- a/src/python_interface_to_workflows/auth/open_auth_url.py +++ b/src/python_interface_to_workflows/auth/open_auth_url.py @@ -1,5 +1,6 @@ import os import socket +import time import urllib.parse import webbrowser from http.server import BaseHTTPRequestHandler, HTTPServer @@ -28,17 +29,25 @@ def do_GET(self): self.wfile.write(b"Missing authorization code.") -def open_auth_url(auth_url: str, port: int) -> None: - httpd = _ReusingHTTPServer(("localhost", port), CallbackHandler) - webbrowser.open(auth_url) - try: - httpd.handle_request() - os.environ["AUTH"] = httpd.auth_code - dotenv.set_key("src/.env", "AUTH", httpd.auth_code) - except OSError: - os.environ["AUTH"] = "" - print("ERROR: Port in use. Please restart your terminal.") - exit(1) - finally: - httpd.socket.shutdown(socket.SHUT_RDWR) - httpd.server_close() +def open_auth_url(auth_url: str, port: int) -> bool: + dotenv.load_dotenv(dotenv_path="src/.env", override=True) + expiry_str: str = os.environ.get("EXPIRY") # pyright: ignore + print(f"expiry_str: {expiry_str}", str(time.time())) + if (expiry_str == "" or int(expiry_str)) <= float(time.time()): + httpd = _ReusingHTTPServer(("localhost", port), CallbackHandler) + webbrowser.open(auth_url) + try: + httpd.handle_request() + os.environ["AUTH"] = httpd.auth_code + dotenv.set_key("src/.env", "AUTH", httpd.auth_code) + except OSError: + os.environ["AUTH"] = "" + print("ERROR: Port in use. Please restart your terminal.") + exit(1) + finally: + httpd.socket.shutdown(socket.SHUT_RDWR) + httpd.server_close() + return True + else: + print("using refresh token") + return False From edbdef01046bc51071ad57838be787bcbe3f5a2d Mon Sep 17 00:00:00 2001 From: Matthew Carre Date: Wed, 22 Jul 2026 15:01:29 +0000 Subject: [PATCH 3/6] test(auth): updates unit tests --- .../auth/keycloak_checker.py.jinja | 57 ++++++++++++----- .../{{ project_name }}/auth/open_auth_url.py | 38 ++++++++---- .../tests/test_keycloak_checker.py.jinja | 62 +++++++++++++++---- .../tests/test_open_auth_url.py.jinja | 59 +++++++++++++++++- tests/test_keycloak_checker.py | 57 +++++++++++++---- tests/test_open_auth_url.py | 59 +++++++++++++++++- 6 files changed, 274 insertions(+), 58 deletions(-) diff --git a/src/copier_template/src/{{ project_name }}/auth/keycloak_checker.py.jinja b/src/copier_template/src/{{ project_name }}/auth/keycloak_checker.py.jinja index 04dd688..40c2362 100644 --- a/src/copier_template/src/{{ project_name }}/auth/keycloak_checker.py.jinja +++ b/src/copier_template/src/{{ project_name }}/auth/keycloak_checker.py.jinja @@ -7,15 +7,26 @@ from keycloak.pkce_utils import generate_code_challenge, generate_code_verifier from {{project_name}}.auth.open_auth_url import open_auth_url -def set_token_env_variable() -> str: - keycloak_openid = KeycloakOpenID( - client_id="workflows-dashboard", - server_url="https://identity.diamond.ac.uk/", - realm_name="dls", - client_secret_key="", - pool_maxsize=1, - ) - port = 8000 +def set_token_env_variable(staging: bool) -> str: + match staging: + case True: + keycloak_openid = KeycloakOpenID( + server_url="https://identity-test.diamond.ac.uk/", + client_id="workflows-ui-dev", + realm_name="dls", + client_secret_key="", + pool_maxsize=1, + ) + port = 5173 + case False: + keycloak_openid = KeycloakOpenID( + client_id="workflows-dashboard", + server_url="https://identity.diamond.ac.uk/", + realm_name="dls", + client_secret_key="", + pool_maxsize=1, + ) + port = 8000 code_verifier = generate_code_verifier() code_challenge, code_challenge_method = generate_code_challenge(code_verifier) auth_url = keycloak_openid.auth_url( @@ -25,14 +36,26 @@ def set_token_env_variable() -> str: code_challenge=code_challenge, code_challenge_method=code_challenge_method, ) - open_auth_url(auth_url) - token: dict[str, str] = ( # pyright: ignore[reportUnknownVariableType] - keycloak_openid.token( # pyright: ignore[reportUnknownMemberType] - grant_type="authorization_code", - code=os.environ["AUTH"], - redirect_uri=f"http://localhost:{port}/", - code_verifier=code_verifier, - ) + match open_auth_url(auth_url, port): + case True: + token: dict[str, str] = ( # pyright: ignore[reportUnknownVariableType] + keycloak_openid.token( # pyright: ignore[reportUnknownMemberType] + grant_type="authorization_code", + code=os.environ.get("AUTH"), # pyright: ignore + redirect_uri=f"http://localhost:{port}/", + code_verifier=code_verifier, + ) + ) + case False: + token: dict[str, str] = keycloak_openid.refresh_token( # pyright: ignore + str(os.environ.get("REFRESHTOKEN")) # pyright: ignore + ) + token_info: dict[str, int | str | dict[str, list[str]]] = ( # pyright: ignore + keycloak_openid.decode_token(token["access_token"]) # pyright: ignore ) + expire_time = int(token_info["exp"]) + 1500 # pyright: ignore + dotenv.set_key("src/.env", "EXPIRY", str(expire_time).strip("'")) dotenv.set_key("src/.env", "TOKEN", token["access_token"].strip("'")) + dotenv.set_key("src/.env", "REFRESHTOKEN", token["refresh_token"].strip("'")) + dotenv.load_dotenv(dotenv_path="src/.env", override=True) return token["access_token"] # pyright: ignore[reportUnknownArgumentType] diff --git a/src/copier_template/src/{{ project_name }}/auth/open_auth_url.py b/src/copier_template/src/{{ project_name }}/auth/open_auth_url.py index 5a18266..666094f 100644 --- a/src/copier_template/src/{{ project_name }}/auth/open_auth_url.py +++ b/src/copier_template/src/{{ project_name }}/auth/open_auth_url.py @@ -1,10 +1,13 @@ import os import socket +import time import urllib.parse import webbrowser from http.server import BaseHTTPRequestHandler, HTTPServer from typing import cast +import dotenv + class _ReusingHTTPServer(HTTPServer): allow_reuse_address = True @@ -26,16 +29,25 @@ def do_GET(self): self.wfile.write(b"Missing authorization code.") -def open_auth_url(auth_url: str) -> None: - httpd = _ReusingHTTPServer(("localhost", 8000), CallbackHandler) - webbrowser.open(auth_url) - try: - httpd.handle_request() - os.environ["AUTH"] = httpd.auth_code - except OSError: - os.environ["AUTH"] = "" - print("ERROR: Port in use. Please restart your terminal.") - exit(1) - finally: - httpd.socket.shutdown(socket.SHUT_RDWR) - httpd.server_close() +def open_auth_url(auth_url: str, port: int) -> bool: + dotenv.load_dotenv(dotenv_path="src/.env", override=True) + expiry_str: str = os.environ.get("EXPIRY") # pyright: ignore + print(f"expiry_str: {expiry_str}", str(time.time())) + if (expiry_str == "" or int(expiry_str)) <= float(time.time()): + httpd = _ReusingHTTPServer(("localhost", port), CallbackHandler) + webbrowser.open(auth_url) + try: + httpd.handle_request() + os.environ["AUTH"] = httpd.auth_code + dotenv.set_key("src/.env", "AUTH", httpd.auth_code) + except OSError: + os.environ["AUTH"] = "" + print("ERROR: Port in use. Please restart your terminal.") + exit(1) + finally: + httpd.socket.shutdown(socket.SHUT_RDWR) + httpd.server_close() + return True + else: + print("using refresh token") + return False diff --git a/src/copier_template/tests/test_keycloak_checker.py.jinja b/src/copier_template/tests/test_keycloak_checker.py.jinja index 2eda176..322b17b 100644 --- a/src/copier_template/tests/test_keycloak_checker.py.jinja +++ b/src/copier_template/tests/test_keycloak_checker.py.jinja @@ -1,35 +1,75 @@ import os -from unittest.mock import MagicMock, patch +from unittest.mock import MagicMock, call, patch + +from pytest import mark from {{project_name}}.auth.keycloak_checker import set_token_env_variable +@mark.parametrize( + "staging,port,return_present", + [ + (True, 5173, True), + (False, 8000, False), + (True, 5173, False), + (False, 8000, True), + ], +) +@patch("{{project_name}}.auth.keycloak_checker.dotenv.load_dotenv") +@patch("{{project_name}}.auth.keycloak_checker.dotenv.set_key") @patch("{{project_name}}.auth.keycloak_checker.KeycloakOpenID") @patch("{{project_name}}.auth.keycloak_checker.generate_code_verifier") @patch("{{project_name}}.auth.keycloak_checker.generate_code_challenge") @patch("{{project_name}}.auth.keycloak_checker.open_auth_url") -def test_return_key( +def test_set_token_env_variable( mock_open_auth_url: MagicMock, mock_gen_code_challenge: MagicMock, mock_gen_code_verifier: MagicMock, mock_gen_keycloak_id: MagicMock, + mock_set_key: MagicMock, + mock_load_env: MagicMock, + staging: bool, + port: int, + return_present: bool, ): mock_gen_code_verifier.return_value = "verifier" mock_gen_code_challenge.return_value = ("challenge", "S256") os.environ["AUTH"] = "auth_url_code" + os.environ["REFRESHTOKEN"] = "refresh" + keycloak = MagicMock() mock_gen_keycloak_id.return_value = keycloak - + mock_open_auth_url.return_value = return_present keycloak.auth_url.return_value = "https://mock.site" - keycloak.token.return_value = { + token = { "access_token": "fake_token", "refresh_token": "fake_refresh", } - assert set_token_env_variable() == "fake_token" - mock_open_auth_url.assert_called_once_with("https://mock.site", 8000) - keycloak.token.assert_called_once_with( - grant_type="authorization_code", - code="auth_url_code", - redirect_uri="http://localhost:8000/", - code_verifier="verifier", + keycloak.token.return_value = token + keycloak.refresh_token.return_value = token + keycloak.decode_token.return_value = {"exp": 123456789} + assert set_token_env_variable(staging) == "fake_token" + + mock_open_auth_url.assert_called_once_with("https://mock.site", port) + if return_present: + keycloak.token.assert_called_once_with( + grant_type="authorization_code", + code="auth_url_code", + redirect_uri=f"http://localhost:{port}/", + code_verifier="verifier", + ) + keycloak.refresh_token.assert_not_called() + else: + keycloak.refresh_token.assert_called_once_with("refresh") + keycloak.token.assert_not_called() + mock_set_key.assert_has_calls( + [ + call("src/.env", "EXPIRY", str(123456789 + 1500)), + call("src/.env", "TOKEN", "fake_token"), + call("src/.env", "REFRESHTOKEN", "fake_refresh"), + ] + ) + mock_load_env.assert_called_once_with( + dotenv_path="src/.env", + override=True, ) diff --git a/src/copier_template/tests/test_open_auth_url.py.jinja b/src/copier_template/tests/test_open_auth_url.py.jinja index f6d3393..bc3799a 100644 --- a/src/copier_template/tests/test_open_auth_url.py.jinja +++ b/src/copier_template/tests/test_open_auth_url.py.jinja @@ -7,22 +7,45 @@ from {{project_name}}.auth.open_auth_url import ( ) +@patch("{{project_name}}.auth.open_auth_url.dotenv.set_key") +@patch("{{project_name}}.auth.open_auth_url.dotenv.load_dotenv") +@patch("{{project_name}}.auth.open_auth_url.time.time") @patch("{{project_name}}.auth.open_auth_url.webbrowser.open") @patch("{{project_name}}.auth.open_auth_url._ReusingHTTPServer") def test_open_auth_url_normal_function( mock_http_server: MagicMock, mock_open_browser: MagicMock, + mock_time: MagicMock, + mock_load_env: MagicMock, + mock_set_key: MagicMock, ): + mock_time.return_value = 100 + os.environ["EXPIRY"] = "" + server = mock_http_server.return_value server.auth_code = "this_is_your_code" - open_auth_url("url") + + assert open_auth_url("url", 5173) is True + + mock_load_env.assert_called_once_with( + dotenv_path="src/.env", + override=True, + ) server.handle_request.assert_called_once() mock_open_browser.assert_called_once_with("url") + mock_set_key.assert_called_once_with( + "src/.env", + "AUTH", + "this_is_your_code", + ) server.socket.shutdown.assert_called_once() server.server_close.assert_called_once() assert os.environ["AUTH"] == "this_is_your_code" +@patch("{{project_name}}.auth.open_auth_url.dotenv.set_key") +@patch("{{project_name}}.auth.open_auth_url.dotenv.load_dotenv") +@patch("{{project_name}}.auth.open_auth_url.time.time") @patch("{{project_name}}.auth.open_auth_url.exit") @patch("{{project_name}}.auth.open_auth_url.webbrowser.open") @patch("{{project_name}}.auth.open_auth_url._ReusingHTTPServer") @@ -30,18 +53,48 @@ def test_open_auth_url_raises_error( mock_http_server: MagicMock, mock_open_browser: MagicMock, mock_exit: MagicMock, + mock_time: MagicMock, + mock_load_env: MagicMock, + mock_set_key: MagicMock, ): + mock_time.return_value = 100 + os.environ["EXPIRY"] = "" + server = mock_http_server.return_value - server.auth_code = "this_is_your_code" server.handle_request.side_effect = OSError - open_auth_url("url") + + assert open_auth_url("url", 5173) is True mock_open_browser.assert_called_once_with("url") + mock_load_env.assert_called_once() assert os.environ["AUTH"] == "" mock_exit.assert_called_once_with(1) + mock_set_key.assert_not_called() server.socket.shutdown.assert_called_once() server.server_close.assert_called_once() +@patch("{{project_name}}.auth.open_auth_url.webbrowser.open") +@patch("{{project_name}}.auth.open_auth_url.dotenv.load_dotenv") +@patch("{{project_name}}.auth.open_auth_url.time.time") +@patch("{{project_name}}.auth.open_auth_url._ReusingHTTPServer") +def test_open_auth_url_refresh_token( + mock_http_server: MagicMock, + mock_time: MagicMock, + mock_load_env: MagicMock, + mock_open_browser: MagicMock, +): + mock_time.return_value = 100 + os.environ["EXPIRY"] = "200" + assert open_auth_url("url", 5173) is False + + mock_load_env.assert_called_once_with( + dotenv_path="src/.env", + override=True, + ) + mock_http_server.assert_not_called() + mock_open_browser.assert_not_called() + + def test_handler_normal_function(): handler = CallbackHandler.__new__(CallbackHandler) handler.path = "/?code=this_is_your_code" diff --git a/tests/test_keycloak_checker.py b/tests/test_keycloak_checker.py index bb5c776..6f6bc21 100644 --- a/tests/test_keycloak_checker.py +++ b/tests/test_keycloak_checker.py @@ -1,12 +1,22 @@ import os -from unittest.mock import MagicMock, patch +from unittest.mock import MagicMock, call, patch from pytest import mark from python_interface_to_workflows.auth.keycloak_checker import set_token_env_variable -@mark.parametrize("dev,port", [(True, 5173), (False, 8000)]) +@mark.parametrize( + "staging,port,return_present", + [ + (True, 5173, True), + (False, 8000, False), + (True, 5173, False), + (False, 8000, True), + ], +) +@patch("python_interface_to_workflows.auth.keycloak_checker.dotenv.load_dotenv") +@patch("python_interface_to_workflows.auth.keycloak_checker.dotenv.set_key") @patch("python_interface_to_workflows.auth.keycloak_checker.KeycloakOpenID") @patch("python_interface_to_workflows.auth.keycloak_checker.generate_code_verifier") @patch("python_interface_to_workflows.auth.keycloak_checker.generate_code_challenge") @@ -16,25 +26,50 @@ def test_set_token_env_variable( mock_gen_code_challenge: MagicMock, mock_gen_code_verifier: MagicMock, mock_gen_keycloak_id: MagicMock, - dev: bool, + mock_set_key: MagicMock, + mock_load_env: MagicMock, + staging: bool, port: int, + return_present: bool, ): mock_gen_code_verifier.return_value = "verifier" mock_gen_code_challenge.return_value = ("challenge", "S256") os.environ["AUTH"] = "auth_url_code" + os.environ["REFRESHTOKEN"] = "refresh" + keycloak = MagicMock() mock_gen_keycloak_id.return_value = keycloak - + mock_open_auth_url.return_value = return_present keycloak.auth_url.return_value = "https://mock.site" - keycloak.token.return_value = { + token = { "access_token": "fake_token", "refresh_token": "fake_refresh", } - assert set_token_env_variable(dev) == "fake_token" + keycloak.token.return_value = token + keycloak.refresh_token.return_value = token + keycloak.decode_token.return_value = {"exp": 123456789} + assert set_token_env_variable(staging) == "fake_token" + mock_open_auth_url.assert_called_once_with("https://mock.site", port) - keycloak.token.assert_called_once_with( - grant_type="authorization_code", - code="auth_url_code", - redirect_uri=f"http://localhost:{port}/", - code_verifier="verifier", + if return_present: + keycloak.token.assert_called_once_with( + grant_type="authorization_code", + code="auth_url_code", + redirect_uri=f"http://localhost:{port}/", + code_verifier="verifier", + ) + keycloak.refresh_token.assert_not_called() + else: + keycloak.refresh_token.assert_called_once_with("refresh") + keycloak.token.assert_not_called() + mock_set_key.assert_has_calls( + [ + call("src/.env", "EXPIRY", str(123456789 + 1500)), + call("src/.env", "TOKEN", "fake_token"), + call("src/.env", "REFRESHTOKEN", "fake_refresh"), + ] + ) + mock_load_env.assert_called_once_with( + dotenv_path="src/.env", + override=True, ) diff --git a/tests/test_open_auth_url.py b/tests/test_open_auth_url.py index 59fa0d3..e05fb49 100644 --- a/tests/test_open_auth_url.py +++ b/tests/test_open_auth_url.py @@ -7,22 +7,45 @@ ) +@patch("python_interface_to_workflows.auth.open_auth_url.dotenv.set_key") +@patch("python_interface_to_workflows.auth.open_auth_url.dotenv.load_dotenv") +@patch("python_interface_to_workflows.auth.open_auth_url.time.time") @patch("python_interface_to_workflows.auth.open_auth_url.webbrowser.open") @patch("python_interface_to_workflows.auth.open_auth_url._ReusingHTTPServer") def test_open_auth_url_normal_function( mock_http_server: MagicMock, mock_open_browser: MagicMock, + mock_time: MagicMock, + mock_load_env: MagicMock, + mock_set_key: MagicMock, ): + mock_time.return_value = 100 + os.environ["EXPIRY"] = "" + server = mock_http_server.return_value server.auth_code = "this_is_your_code" - open_auth_url("url", 5173) + + assert open_auth_url("url", 5173) is True + + mock_load_env.assert_called_once_with( + dotenv_path="src/.env", + override=True, + ) server.handle_request.assert_called_once() mock_open_browser.assert_called_once_with("url") + mock_set_key.assert_called_once_with( + "src/.env", + "AUTH", + "this_is_your_code", + ) server.socket.shutdown.assert_called_once() server.server_close.assert_called_once() assert os.environ["AUTH"] == "this_is_your_code" +@patch("python_interface_to_workflows.auth.open_auth_url.dotenv.set_key") +@patch("python_interface_to_workflows.auth.open_auth_url.dotenv.load_dotenv") +@patch("python_interface_to_workflows.auth.open_auth_url.time.time") @patch("python_interface_to_workflows.auth.open_auth_url.exit") @patch("python_interface_to_workflows.auth.open_auth_url.webbrowser.open") @patch("python_interface_to_workflows.auth.open_auth_url._ReusingHTTPServer") @@ -30,18 +53,48 @@ def test_open_auth_url_raises_error( mock_http_server: MagicMock, mock_open_browser: MagicMock, mock_exit: MagicMock, + mock_time: MagicMock, + mock_load_env: MagicMock, + mock_set_key: MagicMock, ): + mock_time.return_value = 100 + os.environ["EXPIRY"] = "" + server = mock_http_server.return_value - server.auth_code = "this_is_your_code" server.handle_request.side_effect = OSError - open_auth_url("url", 5173) + + assert open_auth_url("url", 5173) is True mock_open_browser.assert_called_once_with("url") + mock_load_env.assert_called_once() assert os.environ["AUTH"] == "" mock_exit.assert_called_once_with(1) + mock_set_key.assert_not_called() server.socket.shutdown.assert_called_once() server.server_close.assert_called_once() +@patch("python_interface_to_workflows.auth.open_auth_url.webbrowser.open") +@patch("python_interface_to_workflows.auth.open_auth_url.dotenv.load_dotenv") +@patch("python_interface_to_workflows.auth.open_auth_url.time.time") +@patch("python_interface_to_workflows.auth.open_auth_url._ReusingHTTPServer") +def test_open_auth_url_refresh_token( + mock_http_server: MagicMock, + mock_time: MagicMock, + mock_load_env: MagicMock, + mock_open_browser: MagicMock, +): + mock_time.return_value = 100 + os.environ["EXPIRY"] = "200" + assert open_auth_url("url", 5173) is False + + mock_load_env.assert_called_once_with( + dotenv_path="src/.env", + override=True, + ) + mock_http_server.assert_not_called() + mock_open_browser.assert_not_called() + + def test_handler_normal_function(): handler = CallbackHandler.__new__(CallbackHandler) handler.path = "/?code=this_is_your_code" From a6f128823f0cb4f6ec96549ddf563cfe6c9f4496 Mon Sep 17 00:00:00 2001 From: Matthew Carre Date: Wed, 22 Jul 2026 15:14:47 +0000 Subject: [PATCH 4/6] docs(copier): updates README.md to include copying instructions --- README.md | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) diff --git a/README.md b/README.md index fee2dff..0c5acd2 100644 --- a/README.md +++ b/README.md @@ -31,3 +31,24 @@ Or if it is a commandline tool then you might put some example commands here: ``` python -m python_interface_to_workflows --version ``` + +# Using Copier +```bash +mkdir new_directory_path +cd new_directory_path +git init +git remote add origin {origin ssh} +git branch -M main + +cd .. +``` +then either: +```bash +git clone git@github.com:DiamondLightSource/python-interface-to-workflows.git +copier copy {this_repo's_path} {new_directory_path} +``` +or: +```bash +copier copy git@github.com:DiamondLightSource/python-copier-template.git new directory path +``` +rebuild in dev container without cache From 519769d73220a5732fd22c4bc343657c44bbf019 Mon Sep 17 00:00:00 2001 From: Matthew Carre Date: Wed, 22 Jul 2026 15:26:56 +0000 Subject: [PATCH 5/6] docs(copier): updates copier template and generator copy correctly --- scripts/lintyaml.sh | 2 +- scripts/makecopiercorrect.sh | 20 +++++++++++++++++++ scripts/runthefiles.sh | 1 + src/copier_template/pyproject.toml.jinja | 1 - src/copier_template/scripts/lintyaml.sh.jinja | 2 +- .../scripts/runthefiles.sh.jinja | 3 ++- src/copier_template/src/README.md.jinja | 3 +++ .../auth/keycloak_checker.py.jinja | 19 ++++-------------- .../{{ project_name }}/auth/open_auth_url.py | 4 +--- .../templates/example.txt.jinja | 4 +++- .../create_example_template.py.jinja | 6 ++++-- .../auth/open_auth_url.py | 4 +--- .../templates/{_example.yaml => example.txt} | 0 .../create_example_template.py | 2 +- 14 files changed, 42 insertions(+), 29 deletions(-) rename src/python_interface_to_workflows/templates/{_example.yaml => example.txt} (100%) diff --git a/scripts/lintyaml.sh b/scripts/lintyaml.sh index 3de474e..9ebc381 100644 --- a/scripts/lintyaml.sh +++ b/scripts/lintyaml.sh @@ -1,6 +1,6 @@ #!/bin/bash cd src/python_interface_to_workflows/templates -for file in * +for file in *.yaml; do argo lint "$file" --offline SUCCESSFULLINT=$? diff --git a/scripts/makecopiercorrect.sh b/scripts/makecopiercorrect.sh index 0f2a966..973bd00 100644 --- a/scripts/makecopiercorrect.sh +++ b/scripts/makecopiercorrect.sh @@ -7,16 +7,36 @@ cp ../templates/*example*.txt "../../copier_template/src/{{ project_name }}/temp for file in "../../copier_template/src/{{ project_name }}/workflow_definitions"/* do [[ $file == *.jinja ]] && continue + sed -i 's/python-interface-to-workflows/{{repo_name}}/g' "$file" sed -i 's/DiamondLightSource/{{github_org}}/g' "$file" + + sed -i '1i{% raw %}' "$file" + echo '{% endraw %}' >> "$file" + + sed -i \ + -e 's/{{repo_name}}/{% endraw %}{{repo_name}}{% raw %}/g' \ + -e 's/{{github_org}}/{% endraw %}{{github_org}}{% raw %}/g' \ + "$file" + mv "$file" "$file.jinja" done for file in "../../copier_template/src/{{ project_name }}/templates"/* do [[ $file == *.jinja ]] && continue + sed -i 's/python-interface-to-workflows/{{repo_name}}/g' "$file" sed -i 's/DiamondLightSource/{{github_org}}/g' "$file" + + sed -i '1i{% raw %}' "$file" + echo '{% endraw %}' >> "$file" + + sed -i \ + -e 's/{{repo_name}}/{% endraw %}{{repo_name}}{% raw %}/g' \ + -e 's/{{github_org}}/{% endraw %}{{github_org}}{% raw %}/g' \ + "$file" + mv "$file" "$file.jinja" done git add "../../copier_template/src/{{ project_name }}/workflow_definitions"/* diff --git a/scripts/runthefiles.sh b/scripts/runthefiles.sh index a7453b4..960a7d8 100644 --- a/scripts/runthefiles.sh +++ b/scripts/runthefiles.sh @@ -5,4 +5,5 @@ do uv run "$file" done mv *.yaml ../templates/ +mv *.txt ../templates/ git add -u ../templates/ diff --git a/src/copier_template/pyproject.toml.jinja b/src/copier_template/pyproject.toml.jinja index cad7d38..9eec731 100644 --- a/src/copier_template/pyproject.toml.jinja +++ b/src/copier_template/pyproject.toml.jinja @@ -68,7 +68,6 @@ reportMissingImports = false # Ignore missing stubs in imported modules reportMissingTypeStubs = "none" reportMissingModuleSource="warning" reportInvalidTypeForm="warning" -reportMissingImports="warning" reportUndefinedVariable="warning" reportAbstractUsage="warning" reportArgumentType="warning" diff --git a/src/copier_template/scripts/lintyaml.sh.jinja b/src/copier_template/scripts/lintyaml.sh.jinja index 7b0b6e8..5c984df 100644 --- a/src/copier_template/scripts/lintyaml.sh.jinja +++ b/src/copier_template/scripts/lintyaml.sh.jinja @@ -1,6 +1,6 @@ #!/bin/bash cd src/{{project_name}}/templates -for file in * +for file in *.yaml; do argo lint "$file" --offline SUCCESSFULLINT=$? diff --git a/src/copier_template/scripts/runthefiles.sh.jinja b/src/copier_template/scripts/runthefiles.sh.jinja index ca0bea2..960a7d8 100644 --- a/src/copier_template/scripts/runthefiles.sh.jinja +++ b/src/copier_template/scripts/runthefiles.sh.jinja @@ -1,8 +1,9 @@ #!/bin/bash -cd src/{{project_name}}/workflow_definitions +cd src/python_interface_to_workflows/workflow_definitions for file in * do uv run "$file" done mv *.yaml ../templates/ +mv *.txt ../templates/ git add -u ../templates/ diff --git a/src/copier_template/src/README.md.jinja b/src/copier_template/src/README.md.jinja index 00f1d90..72089c7 100644 --- a/src/copier_template/src/README.md.jinja +++ b/src/copier_template/src/README.md.jinja @@ -5,6 +5,9 @@ HOST=https://argo-workflows.workflows.diamond.ac.uk/ (to submit to the production cluster) DEFAULT_IMAGE= (usually python 3.10) NAMESPACE= (the cluster you wish to run the templates on) +TOKEN= +EXPIRY= +AUTH= 3. Build the dev container diff --git a/src/copier_template/src/{{ project_name }}/auth/keycloak_checker.py.jinja b/src/copier_template/src/{{ project_name }}/auth/keycloak_checker.py.jinja index 40c2362..2607840 100644 --- a/src/copier_template/src/{{ project_name }}/auth/keycloak_checker.py.jinja +++ b/src/copier_template/src/{{ project_name }}/auth/keycloak_checker.py.jinja @@ -7,26 +7,15 @@ from keycloak.pkce_utils import generate_code_challenge, generate_code_verifier from {{project_name}}.auth.open_auth_url import open_auth_url -def set_token_env_variable(staging: bool) -> str: - match staging: - case True: - keycloak_openid = KeycloakOpenID( - server_url="https://identity-test.diamond.ac.uk/", - client_id="workflows-ui-dev", - realm_name="dls", - client_secret_key="", - pool_maxsize=1, - ) - port = 5173 - case False: - keycloak_openid = KeycloakOpenID( - client_id="workflows-dashboard", +def set_token_env_variable() -> str: + keycloak_openid = KeycloakOpenID( + client_id="workflows-cli", server_url="https://identity.diamond.ac.uk/", realm_name="dls", client_secret_key="", pool_maxsize=1, ) - port = 8000 + port = 8000 code_verifier = generate_code_verifier() code_challenge, code_challenge_method = generate_code_challenge(code_verifier) auth_url = keycloak_openid.auth_url( diff --git a/src/copier_template/src/{{ project_name }}/auth/open_auth_url.py b/src/copier_template/src/{{ project_name }}/auth/open_auth_url.py index 666094f..9acae95 100644 --- a/src/copier_template/src/{{ project_name }}/auth/open_auth_url.py +++ b/src/copier_template/src/{{ project_name }}/auth/open_auth_url.py @@ -31,8 +31,7 @@ def do_GET(self): def open_auth_url(auth_url: str, port: int) -> bool: dotenv.load_dotenv(dotenv_path="src/.env", override=True) - expiry_str: str = os.environ.get("EXPIRY") # pyright: ignore - print(f"expiry_str: {expiry_str}", str(time.time())) + expiry_str: str = os.environ.get("EXPIRY").strip("'") # pyright: ignore if (expiry_str == "" or int(expiry_str)) <= float(time.time()): httpd = _ReusingHTTPServer(("localhost", port), CallbackHandler) webbrowser.open(auth_url) @@ -49,5 +48,4 @@ def open_auth_url(auth_url: str, port: int) -> bool: httpd.server_close() return True else: - print("using refresh token") return False diff --git a/src/copier_template/src/{{ project_name }}/templates/example.txt.jinja b/src/copier_template/src/{{ project_name }}/templates/example.txt.jinja index 736759b..3e74853 100644 --- a/src/copier_template/src/{{ project_name }}/templates/example.txt.jinja +++ b/src/copier_template/src/{{ project_name }}/templates/example.txt.jinja @@ -1,3 +1,4 @@ +{% raw %} apiVersion: argoproj.io/v1alpha1 kind: Workflow metadata: @@ -7,7 +8,7 @@ metadata: Replicates the functionality of example.yaml workflows.argoproj.io/title: example remade via hera - workflows.diamond.ac.uk/repository: https://github.com/{{github_org}}/{{repo_name}} + workflows.diamond.ac.uk/repository: https://github.com/{% endraw %}{{github_org}}{% raw %}/{% endraw %}{{repo_name}}{% raw %} labels: workflows.diamond.ac.uk/science-group-examples: 'true' spec: @@ -212,3 +213,4 @@ spec: resources: requests: storage: 1Gi +{% endraw %} diff --git a/src/copier_template/src/{{ project_name }}/workflow_definitions/create_example_template.py.jinja b/src/copier_template/src/{{ project_name }}/workflow_definitions/create_example_template.py.jinja index 2657ce0..65be398 100644 --- a/src/copier_template/src/{{ project_name }}/workflow_definitions/create_example_template.py.jinja +++ b/src/copier_template/src/{{ project_name }}/workflow_definitions/create_example_template.py.jinja @@ -1,3 +1,4 @@ +{% raw %} from hera.workflows import ( DAG, Artifact, @@ -153,7 +154,7 @@ with Workflow( "workflows.argoproj.io/title": "example remade via hera", "workflows.argoproj.io/description": """Replicates the functionality of example.yaml""", - "workflows.diamond.ac.uk/repository": "https://github.com/{{github_org}}/{{repo_name}}", + "workflows.diamond.ac.uk/repository": "https://github.com/{% endraw %}{{github_org}}{% raw %}/{% endraw %}{{repo_name}}{% raw %}", }, volumes=Volume(name="tmpdir", mount_path="/tmp/", size="1Gi"), ) as w: @@ -178,5 +179,6 @@ example.yaml""", [install, params] >> makeimages >> makehdf5 # pyright: ignore -with open("_example.yaml", "w") as div: +with open("example.txt", "w") as div: div.write(w.to_yaml()) # pyright: ignore[reportUnknownMemberType] +{% endraw %} diff --git a/src/python_interface_to_workflows/auth/open_auth_url.py b/src/python_interface_to_workflows/auth/open_auth_url.py index 666094f..9acae95 100644 --- a/src/python_interface_to_workflows/auth/open_auth_url.py +++ b/src/python_interface_to_workflows/auth/open_auth_url.py @@ -31,8 +31,7 @@ def do_GET(self): def open_auth_url(auth_url: str, port: int) -> bool: dotenv.load_dotenv(dotenv_path="src/.env", override=True) - expiry_str: str = os.environ.get("EXPIRY") # pyright: ignore - print(f"expiry_str: {expiry_str}", str(time.time())) + expiry_str: str = os.environ.get("EXPIRY").strip("'") # pyright: ignore if (expiry_str == "" or int(expiry_str)) <= float(time.time()): httpd = _ReusingHTTPServer(("localhost", port), CallbackHandler) webbrowser.open(auth_url) @@ -49,5 +48,4 @@ def open_auth_url(auth_url: str, port: int) -> bool: httpd.server_close() return True else: - print("using refresh token") return False diff --git a/src/python_interface_to_workflows/templates/_example.yaml b/src/python_interface_to_workflows/templates/example.txt similarity index 100% rename from src/python_interface_to_workflows/templates/_example.yaml rename to src/python_interface_to_workflows/templates/example.txt diff --git a/src/python_interface_to_workflows/workflow_definitions/create_example_template.py b/src/python_interface_to_workflows/workflow_definitions/create_example_template.py index 8d3516a..c8f4ce7 100644 --- a/src/python_interface_to_workflows/workflow_definitions/create_example_template.py +++ b/src/python_interface_to_workflows/workflow_definitions/create_example_template.py @@ -178,5 +178,5 @@ def to_hdf5(paths: str): [install, params] >> makeimages >> makehdf5 # pyright: ignore -with open("_example.yaml", "w") as div: +with open("example.txt", "w") as div: div.write(w.to_yaml()) # pyright: ignore[reportUnknownMemberType] From 871d7833f9f8df8e9b1598ca8f2182beb0ed48eb Mon Sep 17 00:00:00 2001 From: Matthew Carre Date: Tue, 28 Jul 2026 12:40:06 +0000 Subject: [PATCH 6/6] fix(auth): updates based on comments --- scripts/checkyamlcompliance.py | 4 ++ scripts/lintyaml.sh | 11 +-- src/copier_template/scripts/lintyaml.sh.jinja | 11 +-- .../scripts/runthefiles.sh.jinja | 2 +- src/copier_template/src/README.md.jinja | 2 +- .../auth/keycloak_checker.py.jinja | 68 +++++++++++------- .../{{ project_name }}/auth/open_auth_url.py | 34 +++++---- .../submit_to_argo.py.jinja | 2 +- .../templates/example.txt.jinja | 2 +- .../create_example_template.py.jinja | 2 +- .../tests/test_keycloak_checker.py.jinja | 69 +++++++++++++++---- .../tests/test_open_auth_url.py.jinja | 51 ++++++++------ .../auth/keycloak_checker.py | 68 +++++++++++------- .../auth/open_auth_url.py | 34 +++++---- .../submit_to_argo.py | 2 +- .../templates/divisionyaml.yaml | 2 +- .../templates/example.txt | 2 +- .../create_division_yaml.py | 2 +- .../create_example_template.py | 2 +- tests/test_keycloak_checker.py | 59 ++++++++++++++-- tests/test_open_auth_url.py | 51 ++++++++------ 21 files changed, 325 insertions(+), 155 deletions(-) diff --git a/scripts/checkyamlcompliance.py b/scripts/checkyamlcompliance.py index c862655..834655d 100644 --- a/scripts/checkyamlcompliance.py +++ b/scripts/checkyamlcompliance.py @@ -26,6 +26,10 @@ match yamldata["kind"]: case "Workflow": clst_tmpt = True + case "WorkflowTemplate": + clst_tmpt = True + case "ClusterWorkflowTemplate": + clst_tmpt = True case _: clst_tmpt = False else: diff --git a/scripts/lintyaml.sh b/scripts/lintyaml.sh index 9ebc381..566462a 100644 --- a/scripts/lintyaml.sh +++ b/scripts/lintyaml.sh @@ -1,9 +1,10 @@ #!/bin/bash cd src/python_interface_to_workflows/templates -for file in *.yaml; -do -argo lint "$file" --offline -SUCCESSFULLINT=$? -[ $SUCCESSFULLINT -ne 0 ] && exit 1 +for file in *.txt; do + yaml_file="${file}.yaml" + + mv "$file" "$yaml_file" + argo lint "$yaml_file" --offline + mv "$yaml_file" "$file" done exit 0 diff --git a/src/copier_template/scripts/lintyaml.sh.jinja b/src/copier_template/scripts/lintyaml.sh.jinja index 5c984df..5133bb8 100644 --- a/src/copier_template/scripts/lintyaml.sh.jinja +++ b/src/copier_template/scripts/lintyaml.sh.jinja @@ -1,9 +1,10 @@ #!/bin/bash cd src/{{project_name}}/templates -for file in *.yaml; -do -argo lint "$file" --offline -SUCCESSFULLINT=$? -[ $SUCCESSFULLINT -ne 0 ] && exit 1 +for file in *.txt; do + yaml_file="${file}.yaml" + + mv "$file" "$yaml_file" + argo lint "$yaml_file" --offline + mv "$yaml_file" "$file" done exit 0 diff --git a/src/copier_template/scripts/runthefiles.sh.jinja b/src/copier_template/scripts/runthefiles.sh.jinja index 960a7d8..f324322 100644 --- a/src/copier_template/scripts/runthefiles.sh.jinja +++ b/src/copier_template/scripts/runthefiles.sh.jinja @@ -1,5 +1,5 @@ #!/bin/bash -cd src/python_interface_to_workflows/workflow_definitions +cd src/{{project_name}}/workflow_definitions for file in * do uv run "$file" diff --git a/src/copier_template/src/README.md.jinja b/src/copier_template/src/README.md.jinja index 72089c7..816c35d 100644 --- a/src/copier_template/src/README.md.jinja +++ b/src/copier_template/src/README.md.jinja @@ -4,7 +4,7 @@ HOST=https://argo-workflows.workflows.diamond.ac.uk/ (to submit to the production cluster) DEFAULT_IMAGE= (usually python 3.10) -NAMESPACE= (the cluster you wish to run the templates on) +VISIT= (the Visit you wish to run the template on) TOKEN= EXPIRY= AUTH= diff --git a/src/copier_template/src/{{ project_name }}/auth/keycloak_checker.py.jinja b/src/copier_template/src/{{ project_name }}/auth/keycloak_checker.py.jinja index 2607840..ff9db43 100644 --- a/src/copier_template/src/{{ project_name }}/auth/keycloak_checker.py.jinja +++ b/src/copier_template/src/{{ project_name }}/auth/keycloak_checker.py.jinja @@ -1,10 +1,20 @@ import os +from typing import TypedDict, cast import dotenv from keycloak import KeycloakOpenID from keycloak.pkce_utils import generate_code_challenge, generate_code_verifier -from {{project_name}}.auth.open_auth_url import open_auth_url +from {{project_name}}.auth.open_auth_url import token_expired + + +class TokenResponse(TypedDict): + access_token: str + refresh_token: str + + +class DecodedToken(TypedDict): + exp: int def set_token_env_variable() -> str: @@ -25,26 +35,38 @@ def set_token_env_variable() -> str: code_challenge=code_challenge, code_challenge_method=code_challenge_method, ) - match open_auth_url(auth_url, port): - case True: - token: dict[str, str] = ( # pyright: ignore[reportUnknownVariableType] - keycloak_openid.token( # pyright: ignore[reportUnknownMemberType] - grant_type="authorization_code", - code=os.environ.get("AUTH"), # pyright: ignore - redirect_uri=f"http://localhost:{port}/", - code_verifier=code_verifier, - ) - ) - case False: - token: dict[str, str] = keycloak_openid.refresh_token( # pyright: ignore - str(os.environ.get("REFRESHTOKEN")) # pyright: ignore - ) - token_info: dict[str, int | str | dict[str, list[str]]] = ( # pyright: ignore - keycloak_openid.decode_token(token["access_token"]) # pyright: ignore + if token_expired(auth_url, port): + token = cast( + TokenResponse, + keycloak_openid.token( # pyright: ignore[reportUnknownMemberType] + grant_type="authorization_code", + code=str(os.environ.get("AUTH")), + redirect_uri=f"http://localhost:{port}/", + code_verifier=code_verifier, + ), + ) + else: + token = cast( + TokenResponse, + keycloak_openid.refresh_token( # pyright: ignore[reportUnknownMemberType] + str(os.environ.get("REFRESHTOKEN")) + ), + ) + token_info = cast( + DecodedToken, + keycloak_openid.decode_token( # pyright: ignore[reportUnknownMemberType] + token["access_token"] + ), ) - expire_time = int(token_info["exp"]) + 1500 # pyright: ignore - dotenv.set_key("src/.env", "EXPIRY", str(expire_time).strip("'")) - dotenv.set_key("src/.env", "TOKEN", token["access_token"].strip("'")) - dotenv.set_key("src/.env", "REFRESHTOKEN", token["refresh_token"].strip("'")) - dotenv.load_dotenv(dotenv_path="src/.env", override=True) - return token["access_token"] # pyright: ignore[reportUnknownArgumentType] + try: + expire_time = int(token_info["exp"]) + 1800 + dotenv.set_key("src/.env", "EXPIRY", str(expire_time)) + dotenv.set_key("src/.env", "TOKEN", token["access_token"].strip("'")) + dotenv.set_key("src/.env", "REFRESHTOKEN", token["refresh_token"].strip("'")) + except AttributeError: + print("ERROR:") + exit(1) + finally: + dotenv.load_dotenv(dotenv_path="src/.env", override=True) + + return token["access_token"] diff --git a/src/copier_template/src/{{ project_name }}/auth/open_auth_url.py b/src/copier_template/src/{{ project_name }}/auth/open_auth_url.py index 9acae95..f8c2581 100644 --- a/src/copier_template/src/{{ project_name }}/auth/open_auth_url.py +++ b/src/copier_template/src/{{ project_name }}/auth/open_auth_url.py @@ -29,23 +29,27 @@ def do_GET(self): self.wfile.write(b"Missing authorization code.") -def open_auth_url(auth_url: str, port: int) -> bool: +def token_expired(auth_url: str, port: int) -> bool: dotenv.load_dotenv(dotenv_path="src/.env", override=True) - expiry_str: str = os.environ.get("EXPIRY").strip("'") # pyright: ignore + expiry_str: str = str(os.environ.get("EXPIRY")).strip("'") if (expiry_str == "" or int(expiry_str)) <= float(time.time()): - httpd = _ReusingHTTPServer(("localhost", port), CallbackHandler) - webbrowser.open(auth_url) - try: - httpd.handle_request() - os.environ["AUTH"] = httpd.auth_code - dotenv.set_key("src/.env", "AUTH", httpd.auth_code) - except OSError: - os.environ["AUTH"] = "" - print("ERROR: Port in use. Please restart your terminal.") - exit(1) - finally: - httpd.socket.shutdown(socket.SHUT_RDWR) - httpd.server_close() + _open_auth_url(auth_url, port) return True else: return False + + +def _open_auth_url(auth_url: str, port: int) -> None: + httpd = _ReusingHTTPServer(("localhost", port), CallbackHandler) + webbrowser.open(auth_url) + try: + httpd.handle_request() + os.environ["AUTH"] = httpd.auth_code + dotenv.set_key("src/.env", "AUTH", httpd.auth_code) + except OSError: + os.environ["AUTH"] = "" + print("ERROR: Port in use. Please restart your terminal.") + exit(1) + finally: + httpd.socket.shutdown(socket.SHUT_RDWR) + httpd.server_close() diff --git a/src/copier_template/src/{{ project_name }}/submit_to_argo.py.jinja b/src/copier_template/src/{{ project_name }}/submit_to_argo.py.jinja index f0e49e4..1b30683 100644 --- a/src/copier_template/src/{{ project_name }}/submit_to_argo.py.jinja +++ b/src/copier_template/src/{{ project_name }}/submit_to_argo.py.jinja @@ -12,7 +12,7 @@ from {{project_name}}.auth.keycloak_checker import set_token_env_variable def submit_workflow_to_argo(w: Workflow): set_token_env_variable() dotenv.load_dotenv(dotenv_path="src/.env", override=True) - w.namespace = os.environ.get("NAMESPACE") + w.namespace = os.environ.get("VISIT") w.workflows_service = WorkflowsService( host=str(os.environ.get("HOST")).strip("'"), token=str(os.environ.get("TOKEN")).strip("'"), diff --git a/src/copier_template/src/{{ project_name }}/templates/example.txt.jinja b/src/copier_template/src/{{ project_name }}/templates/example.txt.jinja index 3e74853..387db1c 100644 --- a/src/copier_template/src/{{ project_name }}/templates/example.txt.jinja +++ b/src/copier_template/src/{{ project_name }}/templates/example.txt.jinja @@ -1,6 +1,6 @@ {% raw %} apiVersion: argoproj.io/v1alpha1 -kind: Workflow +kind: WorkflowTemplate metadata: generateName: hera-example- annotations: diff --git a/src/copier_template/src/{{ project_name }}/workflow_definitions/create_example_template.py.jinja b/src/copier_template/src/{{ project_name }}/workflow_definitions/create_example_template.py.jinja index 65be398..42175cf 100644 --- a/src/copier_template/src/{{ project_name }}/workflow_definitions/create_example_template.py.jinja +++ b/src/copier_template/src/{{ project_name }}/workflow_definitions/create_example_template.py.jinja @@ -148,7 +148,7 @@ with Workflow( generate_name="hera-example-", # when running on graphql this should be name entrypoint="workflowentry", api_version="argoproj.io/v1alpha1", - kind="Workflow", # ClusterWorkflowTemplate", when on graphql + kind="WorkflowTemplate", # ClusterWorkflowTemplate", when on graphql labels={"workflows.diamond.ac.uk/science-group-examples": "true"}, annotations={ "workflows.argoproj.io/title": "example remade via hera", diff --git a/src/copier_template/tests/test_keycloak_checker.py.jinja b/src/copier_template/tests/test_keycloak_checker.py.jinja index 322b17b..4b27f07 100644 --- a/src/copier_template/tests/test_keycloak_checker.py.jinja +++ b/src/copier_template/tests/test_keycloak_checker.py.jinja @@ -7,12 +7,10 @@ from {{project_name}}.auth.keycloak_checker import set_token_env_variable @mark.parametrize( - "staging,port,return_present", + "return_present", [ - (True, 5173, True), - (False, 8000, False), - (True, 5173, False), - (False, 8000, True), + (False), + (True), ], ) @patch("{{project_name}}.auth.keycloak_checker.dotenv.load_dotenv") @@ -20,18 +18,17 @@ from {{project_name}}.auth.keycloak_checker import set_token_env_variable @patch("{{project_name}}.auth.keycloak_checker.KeycloakOpenID") @patch("{{project_name}}.auth.keycloak_checker.generate_code_verifier") @patch("{{project_name}}.auth.keycloak_checker.generate_code_challenge") -@patch("{{project_name}}.auth.keycloak_checker.open_auth_url") +@patch("{{project_name}}.auth.keycloak_checker.token_expired") def test_set_token_env_variable( - mock_open_auth_url: MagicMock, + mock_token_expired: MagicMock, mock_gen_code_challenge: MagicMock, mock_gen_code_verifier: MagicMock, mock_gen_keycloak_id: MagicMock, mock_set_key: MagicMock, mock_load_env: MagicMock, - staging: bool, - port: int, return_present: bool, ): + port=8000 mock_gen_code_verifier.return_value = "verifier" mock_gen_code_challenge.return_value = ("challenge", "S256") os.environ["AUTH"] = "auth_url_code" @@ -39,7 +36,7 @@ def test_set_token_env_variable( keycloak = MagicMock() mock_gen_keycloak_id.return_value = keycloak - mock_open_auth_url.return_value = return_present + mock_token_expired.return_value = return_present keycloak.auth_url.return_value = "https://mock.site" token = { "access_token": "fake_token", @@ -50,7 +47,7 @@ def test_set_token_env_variable( keycloak.decode_token.return_value = {"exp": 123456789} assert set_token_env_variable(staging) == "fake_token" - mock_open_auth_url.assert_called_once_with("https://mock.site", port) + mock_token_expired.assert_called_once_with("https://mock.site", port) if return_present: keycloak.token.assert_called_once_with( grant_type="authorization_code", @@ -64,7 +61,7 @@ def test_set_token_env_variable( keycloak.token.assert_not_called() mock_set_key.assert_has_calls( [ - call("src/.env", "EXPIRY", str(123456789 + 1500)), + call("src/.env", "EXPIRY", str(123456789 + 1800)), call("src/.env", "TOKEN", "fake_token"), call("src/.env", "REFRESHTOKEN", "fake_refresh"), ] @@ -73,3 +70,51 @@ def test_set_token_env_variable( dotenv_path="src/.env", override=True, ) + +@patch("{{project_name}}.auth.keycloak_checker.exit") +@patch("{{project_name}}.auth.keycloak_checker.print") +@patch("{{project_name}}.auth.keycloak_checker.dotenv.load_dotenv") +@patch("{{project_name}}.auth.keycloak_checker.dotenv.set_key") +@patch("{{project_name}}.auth.keycloak_checker.KeycloakOpenID") +@patch("{{project_name}}.auth.keycloak_checker.generate_code_verifier") +@patch("{{project_name}}.auth.keycloak_checker.generate_code_challenge") +@patch("{{project_name}}.auth.keycloak_checker.token_expired") +def test_set_token_env_variable_attribute_error( + mock_token_expired: MagicMock, + mock_gen_code_challenge: MagicMock, + mock_gen_code_verifier: MagicMock, + mock_gen_keycloak_id: MagicMock, + mock_set_key: MagicMock, + mock_load_env: MagicMock, + mock_print: MagicMock, + mock_exit: MagicMock, +): + mock_gen_code_verifier.return_value = "verifier" + mock_gen_code_challenge.return_value = ("challenge", "S256") + mock_token_expired.return_value = True + + os.environ["REFRESHTOKEN"] = "refresh" + + keycloak = MagicMock() + mock_gen_keycloak_id.return_value = keycloak + + token = { + "access_token": "fake_token", + "refresh_token": "fake_refresh", + } + + keycloak.refresh_token.return_value = token + + decoded = MagicMock() + decoded.__getitem__.side_effect = AttributeError + keycloak.decode_token.return_value = decoded + + set_token_env_variable() + + mock_print.assert_called_once_with("ERROR:") + mock_exit.assert_called_once_with(1) + mock_set_key.assert_not_called() + mock_load_env.assert_called_once_with( + dotenv_path="src/.env", + override=True, + ) diff --git a/src/copier_template/tests/test_open_auth_url.py.jinja b/src/copier_template/tests/test_open_auth_url.py.jinja index bc3799a..f35aca1 100644 --- a/src/copier_template/tests/test_open_auth_url.py.jinja +++ b/src/copier_template/tests/test_open_auth_url.py.jinja @@ -3,12 +3,12 @@ from unittest.mock import MagicMock, patch from {{project_name}}.auth.open_auth_url import ( CallbackHandler, - open_auth_url, + _open_auth_url, # pyright:ignore + token_expired, ) @patch("{{project_name}}.auth.open_auth_url.dotenv.set_key") -@patch("{{project_name}}.auth.open_auth_url.dotenv.load_dotenv") @patch("{{project_name}}.auth.open_auth_url.time.time") @patch("{{project_name}}.auth.open_auth_url.webbrowser.open") @patch("{{project_name}}.auth.open_auth_url._ReusingHTTPServer") @@ -16,7 +16,6 @@ def test_open_auth_url_normal_function( mock_http_server: MagicMock, mock_open_browser: MagicMock, mock_time: MagicMock, - mock_load_env: MagicMock, mock_set_key: MagicMock, ): mock_time.return_value = 100 @@ -25,12 +24,7 @@ def test_open_auth_url_normal_function( server = mock_http_server.return_value server.auth_code = "this_is_your_code" - assert open_auth_url("url", 5173) is True - - mock_load_env.assert_called_once_with( - dotenv_path="src/.env", - override=True, - ) + _open_auth_url("url", 5173) server.handle_request.assert_called_once() mock_open_browser.assert_called_once_with("url") mock_set_key.assert_called_once_with( @@ -44,7 +38,6 @@ def test_open_auth_url_normal_function( @patch("{{project_name}}.auth.open_auth_url.dotenv.set_key") -@patch("{{project_name}}.auth.open_auth_url.dotenv.load_dotenv") @patch("{{project_name}}.auth.open_auth_url.time.time") @patch("{{project_name}}.auth.open_auth_url.exit") @patch("{{project_name}}.auth.open_auth_url.webbrowser.open") @@ -54,7 +47,6 @@ def test_open_auth_url_raises_error( mock_open_browser: MagicMock, mock_exit: MagicMock, mock_time: MagicMock, - mock_load_env: MagicMock, mock_set_key: MagicMock, ): mock_time.return_value = 100 @@ -63,9 +55,8 @@ def test_open_auth_url_raises_error( server = mock_http_server.return_value server.handle_request.side_effect = OSError - assert open_auth_url("url", 5173) is True + _open_auth_url("url", 5173) mock_open_browser.assert_called_once_with("url") - mock_load_env.assert_called_once() assert os.environ["AUTH"] == "" mock_exit.assert_called_once_with(1) mock_set_key.assert_not_called() @@ -73,26 +64,44 @@ def test_open_auth_url_raises_error( server.server_close.assert_called_once() -@patch("{{project_name}}.auth.open_auth_url.webbrowser.open") +@patch("{{project_name}}.auth.open_auth_url._open_auth_url") @patch("{{project_name}}.auth.open_auth_url.dotenv.load_dotenv") @patch("{{project_name}}.auth.open_auth_url.time.time") -@patch("{{project_name}}.auth.open_auth_url._ReusingHTTPServer") -def test_open_auth_url_refresh_token( - mock_http_server: MagicMock, +def test_token_expired( mock_time: MagicMock, mock_load_env: MagicMock, - mock_open_browser: MagicMock, + mock_open_auth_url: MagicMock, +): + mock_time.return_value = 100 + os.environ["EXPIRY"] = "50" + + assert token_expired("url", 5173) is True + + mock_load_env.assert_called_once_with( + dotenv_path="src/.env", + override=True, + ) + mock_open_auth_url.assert_called_once_with("url", 5173) + + +@patch("{{project_name}}.auth.open_auth_url._open_auth_url") +@patch("{{project_name}}.auth.open_auth_url.dotenv.load_dotenv") +@patch("{{project_name}}.auth.open_auth_url.time.time") +def test_token_not_expired( + mock_time: MagicMock, + mock_load_env: MagicMock, + mock_open_auth_url: MagicMock, ): mock_time.return_value = 100 os.environ["EXPIRY"] = "200" - assert open_auth_url("url", 5173) is False + + assert token_expired("url", 5173) is False mock_load_env.assert_called_once_with( dotenv_path="src/.env", override=True, ) - mock_http_server.assert_not_called() - mock_open_browser.assert_not_called() + mock_open_auth_url.assert_not_called() def test_handler_normal_function(): diff --git a/src/python_interface_to_workflows/auth/keycloak_checker.py b/src/python_interface_to_workflows/auth/keycloak_checker.py index 44e486e..6f6ff11 100644 --- a/src/python_interface_to_workflows/auth/keycloak_checker.py +++ b/src/python_interface_to_workflows/auth/keycloak_checker.py @@ -1,10 +1,20 @@ import os +from typing import TypedDict, cast import dotenv from keycloak import KeycloakOpenID from keycloak.pkce_utils import generate_code_challenge, generate_code_verifier -from python_interface_to_workflows.auth.open_auth_url import open_auth_url +from python_interface_to_workflows.auth.open_auth_url import token_expired + + +class TokenResponse(TypedDict): + access_token: str + refresh_token: str + + +class DecodedToken(TypedDict): + exp: int def set_token_env_variable(staging: bool) -> str: @@ -36,26 +46,38 @@ def set_token_env_variable(staging: bool) -> str: code_challenge=code_challenge, code_challenge_method=code_challenge_method, ) - match open_auth_url(auth_url, port): - case True: - token: dict[str, str] = ( # pyright: ignore[reportUnknownVariableType] - keycloak_openid.token( # pyright: ignore[reportUnknownMemberType] - grant_type="authorization_code", - code=os.environ.get("AUTH"), # pyright: ignore - redirect_uri=f"http://localhost:{port}/", - code_verifier=code_verifier, - ) - ) - case False: - token: dict[str, str] = keycloak_openid.refresh_token( # pyright: ignore - str(os.environ.get("REFRESHTOKEN")) # pyright: ignore - ) - token_info: dict[str, int | str | dict[str, list[str]]] = ( # pyright: ignore - keycloak_openid.decode_token(token["access_token"]) # pyright: ignore + if token_expired(auth_url, port): + token = cast( + TokenResponse, + keycloak_openid.token( # pyright: ignore[reportUnknownMemberType] + grant_type="authorization_code", + code=str(os.environ.get("AUTH")), + redirect_uri=f"http://localhost:{port}/", + code_verifier=code_verifier, + ), + ) + else: + token = cast( + TokenResponse, + keycloak_openid.refresh_token( # pyright: ignore[reportUnknownMemberType] + str(os.environ.get("REFRESHTOKEN")) + ), + ) + token_info = cast( + DecodedToken, + keycloak_openid.decode_token( # pyright: ignore[reportUnknownMemberType] + token["access_token"] + ), ) - expire_time = int(token_info["exp"]) + 1500 # pyright: ignore - dotenv.set_key("src/.env", "EXPIRY", str(expire_time).strip("'")) - dotenv.set_key("src/.env", "TOKEN", token["access_token"].strip("'")) - dotenv.set_key("src/.env", "REFRESHTOKEN", token["refresh_token"].strip("'")) - dotenv.load_dotenv(dotenv_path="src/.env", override=True) - return token["access_token"] # pyright: ignore[reportUnknownArgumentType] + try: + expire_time = int(token_info["exp"]) + 1800 + dotenv.set_key("src/.env", "EXPIRY", str(expire_time)) + dotenv.set_key("src/.env", "TOKEN", token["access_token"].strip("'")) + dotenv.set_key("src/.env", "REFRESHTOKEN", token["refresh_token"].strip("'")) + except AttributeError: + print("ERROR:") + exit(1) + finally: + dotenv.load_dotenv(dotenv_path="src/.env", override=True) + + return token["access_token"] diff --git a/src/python_interface_to_workflows/auth/open_auth_url.py b/src/python_interface_to_workflows/auth/open_auth_url.py index 9acae95..f8c2581 100644 --- a/src/python_interface_to_workflows/auth/open_auth_url.py +++ b/src/python_interface_to_workflows/auth/open_auth_url.py @@ -29,23 +29,27 @@ def do_GET(self): self.wfile.write(b"Missing authorization code.") -def open_auth_url(auth_url: str, port: int) -> bool: +def token_expired(auth_url: str, port: int) -> bool: dotenv.load_dotenv(dotenv_path="src/.env", override=True) - expiry_str: str = os.environ.get("EXPIRY").strip("'") # pyright: ignore + expiry_str: str = str(os.environ.get("EXPIRY")).strip("'") if (expiry_str == "" or int(expiry_str)) <= float(time.time()): - httpd = _ReusingHTTPServer(("localhost", port), CallbackHandler) - webbrowser.open(auth_url) - try: - httpd.handle_request() - os.environ["AUTH"] = httpd.auth_code - dotenv.set_key("src/.env", "AUTH", httpd.auth_code) - except OSError: - os.environ["AUTH"] = "" - print("ERROR: Port in use. Please restart your terminal.") - exit(1) - finally: - httpd.socket.shutdown(socket.SHUT_RDWR) - httpd.server_close() + _open_auth_url(auth_url, port) return True else: return False + + +def _open_auth_url(auth_url: str, port: int) -> None: + httpd = _ReusingHTTPServer(("localhost", port), CallbackHandler) + webbrowser.open(auth_url) + try: + httpd.handle_request() + os.environ["AUTH"] = httpd.auth_code + dotenv.set_key("src/.env", "AUTH", httpd.auth_code) + except OSError: + os.environ["AUTH"] = "" + print("ERROR: Port in use. Please restart your terminal.") + exit(1) + finally: + httpd.socket.shutdown(socket.SHUT_RDWR) + httpd.server_close() diff --git a/src/python_interface_to_workflows/submit_to_argo.py b/src/python_interface_to_workflows/submit_to_argo.py index 82b86db..0ec1233 100644 --- a/src/python_interface_to_workflows/submit_to_argo.py +++ b/src/python_interface_to_workflows/submit_to_argo.py @@ -12,7 +12,7 @@ def submit_workflow_to_argo(w: Workflow): set_token_env_variable(staging=True) dotenv.load_dotenv(dotenv_path="src/.env", override=True) - w.namespace = os.environ.get("NAMESPACE") + w.namespace = os.environ.get("VISIT") w.workflows_service = WorkflowsService( host=str(os.environ.get("HOST")).strip("'"), token=str(os.environ.get("TOKEN")).strip("'"), diff --git a/src/python_interface_to_workflows/templates/divisionyaml.yaml b/src/python_interface_to_workflows/templates/divisionyaml.yaml index 34bed16..79b810a 100644 --- a/src/python_interface_to_workflows/templates/divisionyaml.yaml +++ b/src/python_interface_to_workflows/templates/divisionyaml.yaml @@ -1,5 +1,5 @@ apiVersion: argoproj.io/v1alpha1 -kind: Workflow +kind: WorkflowTemplate metadata: generateName: hera-division- annotations: diff --git a/src/python_interface_to_workflows/templates/example.txt b/src/python_interface_to_workflows/templates/example.txt index 1fbb1b7..857fb41 100644 --- a/src/python_interface_to_workflows/templates/example.txt +++ b/src/python_interface_to_workflows/templates/example.txt @@ -1,5 +1,5 @@ apiVersion: argoproj.io/v1alpha1 -kind: Workflow +kind: WorkflowTemplate metadata: generateName: hera-example- annotations: diff --git a/src/python_interface_to_workflows/workflow_definitions/create_division_yaml.py b/src/python_interface_to_workflows/workflow_definitions/create_division_yaml.py index f481093..3f063de 100644 --- a/src/python_interface_to_workflows/workflow_definitions/create_division_yaml.py +++ b/src/python_interface_to_workflows/workflow_definitions/create_division_yaml.py @@ -31,7 +31,7 @@ def do_division(a: int, b: int): generate_name="hera-division-", # when running on graphql this should be name entrypoint="divide", api_version="argoproj.io/v1alpha1", - kind="Workflow", # ClusterWorkflowTemplate", when on graphql + kind="WorkflowTemplate", # ClusterWorkflowTemplate", when on graphql labels={"workflows.diamond.ac.uk/science-group-examples": "true"}, annotations={ "workflows.argoproj.io/title": "Division via hera test", diff --git a/src/python_interface_to_workflows/workflow_definitions/create_example_template.py b/src/python_interface_to_workflows/workflow_definitions/create_example_template.py index c8f4ce7..7b9de3c 100644 --- a/src/python_interface_to_workflows/workflow_definitions/create_example_template.py +++ b/src/python_interface_to_workflows/workflow_definitions/create_example_template.py @@ -147,7 +147,7 @@ def to_hdf5(paths: str): generate_name="hera-example-", # when running on graphql this should be name entrypoint="workflowentry", api_version="argoproj.io/v1alpha1", - kind="Workflow", # ClusterWorkflowTemplate", when on graphql + kind="WorkflowTemplate", # ClusterWorkflowTemplate", when on graphql labels={"workflows.diamond.ac.uk/science-group-examples": "true"}, annotations={ "workflows.argoproj.io/title": "example remade via hera", diff --git a/tests/test_keycloak_checker.py b/tests/test_keycloak_checker.py index 6f6bc21..c658d0c 100644 --- a/tests/test_keycloak_checker.py +++ b/tests/test_keycloak_checker.py @@ -20,9 +20,9 @@ @patch("python_interface_to_workflows.auth.keycloak_checker.KeycloakOpenID") @patch("python_interface_to_workflows.auth.keycloak_checker.generate_code_verifier") @patch("python_interface_to_workflows.auth.keycloak_checker.generate_code_challenge") -@patch("python_interface_to_workflows.auth.keycloak_checker.open_auth_url") +@patch("python_interface_to_workflows.auth.keycloak_checker.token_expired") def test_set_token_env_variable( - mock_open_auth_url: MagicMock, + mock_token_expired: MagicMock, mock_gen_code_challenge: MagicMock, mock_gen_code_verifier: MagicMock, mock_gen_keycloak_id: MagicMock, @@ -39,7 +39,7 @@ def test_set_token_env_variable( keycloak = MagicMock() mock_gen_keycloak_id.return_value = keycloak - mock_open_auth_url.return_value = return_present + mock_token_expired.return_value = return_present keycloak.auth_url.return_value = "https://mock.site" token = { "access_token": "fake_token", @@ -50,7 +50,7 @@ def test_set_token_env_variable( keycloak.decode_token.return_value = {"exp": 123456789} assert set_token_env_variable(staging) == "fake_token" - mock_open_auth_url.assert_called_once_with("https://mock.site", port) + mock_token_expired.assert_called_once_with("https://mock.site", port) if return_present: keycloak.token.assert_called_once_with( grant_type="authorization_code", @@ -64,7 +64,7 @@ def test_set_token_env_variable( keycloak.token.assert_not_called() mock_set_key.assert_has_calls( [ - call("src/.env", "EXPIRY", str(123456789 + 1500)), + call("src/.env", "EXPIRY", str(123456789 + 1800)), call("src/.env", "TOKEN", "fake_token"), call("src/.env", "REFRESHTOKEN", "fake_refresh"), ] @@ -73,3 +73,52 @@ def test_set_token_env_variable( dotenv_path="src/.env", override=True, ) + + +@patch("python_interface_to_workflows.auth.keycloak_checker.exit") +@patch("python_interface_to_workflows.auth.keycloak_checker.print") +@patch("python_interface_to_workflows.auth.keycloak_checker.dotenv.load_dotenv") +@patch("python_interface_to_workflows.auth.keycloak_checker.dotenv.set_key") +@patch("python_interface_to_workflows.auth.keycloak_checker.KeycloakOpenID") +@patch("python_interface_to_workflows.auth.keycloak_checker.generate_code_verifier") +@patch("python_interface_to_workflows.auth.keycloak_checker.generate_code_challenge") +@patch("python_interface_to_workflows.auth.keycloak_checker.token_expired") +def test_set_token_env_variable_attribute_error( + mock_token_expired: MagicMock, + mock_gen_code_challenge: MagicMock, + mock_gen_code_verifier: MagicMock, + mock_gen_keycloak_id: MagicMock, + mock_set_key: MagicMock, + mock_load_env: MagicMock, + mock_print: MagicMock, + mock_exit: MagicMock, +): + mock_gen_code_verifier.return_value = "verifier" + mock_gen_code_challenge.return_value = ("challenge", "S256") + mock_token_expired.return_value = True + + os.environ["REFRESHTOKEN"] = "refresh" + + keycloak = MagicMock() + mock_gen_keycloak_id.return_value = keycloak + + token = { + "access_token": "fake_token", + "refresh_token": "fake_refresh", + } + + keycloak.refresh_token.return_value = token + + decoded = MagicMock() + decoded.__getitem__.side_effect = AttributeError + keycloak.decode_token.return_value = decoded + + set_token_env_variable(True) + + mock_print.assert_called_once_with("ERROR:") + mock_exit.assert_called_once_with(1) + mock_set_key.assert_not_called() + mock_load_env.assert_called_once_with( + dotenv_path="src/.env", + override=True, + ) diff --git a/tests/test_open_auth_url.py b/tests/test_open_auth_url.py index e05fb49..0acd322 100644 --- a/tests/test_open_auth_url.py +++ b/tests/test_open_auth_url.py @@ -3,12 +3,12 @@ from python_interface_to_workflows.auth.open_auth_url import ( CallbackHandler, - open_auth_url, + _open_auth_url, # pyright:ignore + token_expired, ) @patch("python_interface_to_workflows.auth.open_auth_url.dotenv.set_key") -@patch("python_interface_to_workflows.auth.open_auth_url.dotenv.load_dotenv") @patch("python_interface_to_workflows.auth.open_auth_url.time.time") @patch("python_interface_to_workflows.auth.open_auth_url.webbrowser.open") @patch("python_interface_to_workflows.auth.open_auth_url._ReusingHTTPServer") @@ -16,7 +16,6 @@ def test_open_auth_url_normal_function( mock_http_server: MagicMock, mock_open_browser: MagicMock, mock_time: MagicMock, - mock_load_env: MagicMock, mock_set_key: MagicMock, ): mock_time.return_value = 100 @@ -25,12 +24,7 @@ def test_open_auth_url_normal_function( server = mock_http_server.return_value server.auth_code = "this_is_your_code" - assert open_auth_url("url", 5173) is True - - mock_load_env.assert_called_once_with( - dotenv_path="src/.env", - override=True, - ) + _open_auth_url("url", 5173) server.handle_request.assert_called_once() mock_open_browser.assert_called_once_with("url") mock_set_key.assert_called_once_with( @@ -44,7 +38,6 @@ def test_open_auth_url_normal_function( @patch("python_interface_to_workflows.auth.open_auth_url.dotenv.set_key") -@patch("python_interface_to_workflows.auth.open_auth_url.dotenv.load_dotenv") @patch("python_interface_to_workflows.auth.open_auth_url.time.time") @patch("python_interface_to_workflows.auth.open_auth_url.exit") @patch("python_interface_to_workflows.auth.open_auth_url.webbrowser.open") @@ -54,7 +47,6 @@ def test_open_auth_url_raises_error( mock_open_browser: MagicMock, mock_exit: MagicMock, mock_time: MagicMock, - mock_load_env: MagicMock, mock_set_key: MagicMock, ): mock_time.return_value = 100 @@ -63,9 +55,8 @@ def test_open_auth_url_raises_error( server = mock_http_server.return_value server.handle_request.side_effect = OSError - assert open_auth_url("url", 5173) is True + _open_auth_url("url", 5173) mock_open_browser.assert_called_once_with("url") - mock_load_env.assert_called_once() assert os.environ["AUTH"] == "" mock_exit.assert_called_once_with(1) mock_set_key.assert_not_called() @@ -73,26 +64,44 @@ def test_open_auth_url_raises_error( server.server_close.assert_called_once() -@patch("python_interface_to_workflows.auth.open_auth_url.webbrowser.open") +@patch("python_interface_to_workflows.auth.open_auth_url._open_auth_url") @patch("python_interface_to_workflows.auth.open_auth_url.dotenv.load_dotenv") @patch("python_interface_to_workflows.auth.open_auth_url.time.time") -@patch("python_interface_to_workflows.auth.open_auth_url._ReusingHTTPServer") -def test_open_auth_url_refresh_token( - mock_http_server: MagicMock, +def test_token_expired( mock_time: MagicMock, mock_load_env: MagicMock, - mock_open_browser: MagicMock, + mock_open_auth_url: MagicMock, +): + mock_time.return_value = 100 + os.environ["EXPIRY"] = "50" + + assert token_expired("url", 5173) is True + + mock_load_env.assert_called_once_with( + dotenv_path="src/.env", + override=True, + ) + mock_open_auth_url.assert_called_once_with("url", 5173) + + +@patch("python_interface_to_workflows.auth.open_auth_url._open_auth_url") +@patch("python_interface_to_workflows.auth.open_auth_url.dotenv.load_dotenv") +@patch("python_interface_to_workflows.auth.open_auth_url.time.time") +def test_token_not_expired( + mock_time: MagicMock, + mock_load_env: MagicMock, + mock_open_auth_url: MagicMock, ): mock_time.return_value = 100 os.environ["EXPIRY"] = "200" - assert open_auth_url("url", 5173) is False + + assert token_expired("url", 5173) is False mock_load_env.assert_called_once_with( dotenv_path="src/.env", override=True, ) - mock_http_server.assert_not_called() - mock_open_browser.assert_not_called() + mock_open_auth_url.assert_not_called() def test_handler_normal_function():