* chore: update Google Fonts to Bricolage Grotesque, IBM Plex Sans, JetBrains Mono Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore: update Tailwind config to Slate & Ice theme colors and fonts Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat: update CSS variables and glass-card utilities for Slate & Ice theme - Replace all color variables with Slate & Ice palette - Add glass system vars (--glass-bg, --glass-blur, --shadow-float) - Replace legacy glass-card with new variable-driven glass classes - Add breatheGlow, bellWobble, slideDown, fadeInRight keyframes - Update font references to IBM Plex Sans and Bricolage Grotesque Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat: recolor BrandLogo to cyan gradient, split BrandWordmark for gradient Flow text Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat: update TopBar with glassmorphism backdrop and cyan accent styling Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat: update Sidebar with glassmorphism backdrop Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat: add ambient atmosphere gradient orbs behind app shell Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat: update QuickStats and SessionsPanel with glass-card styling Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat: add WeeklyCalendar, QuickActions, OpenSessions, RecentActivity dashboard components Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat: redesign dashboard layout with calendar, open sessions, and glass-card panels New layout: greeting → calendar+actions → sessions+stats → activity Replaces old QuickStats and SessionsPanel with new dashboard components Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: replace remaining purple hex references with ice-cyan accent Sweep of hardcoded purple hex values (#818cf8, #6366f1) replaced with new cyan accent (#06b6d4) in QuickActions, RecentActivity, QuickLaunch, and SVG brand assets. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs: update CLAUDE.md branding and design system for Slate & Ice Modern Updated Last Updated date, branding section (fonts, colors, glass utilities, atmosphere orbs), component styling rules, and Design System section to reflect the new ice-cyan glassmorphism theme. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * docs: add Slate & Ice Modern design doc and implementation plan Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat: redesign login page with Slate & Ice Modern design system Apply glassmorphism styling, atmosphere orbs, branded wordmark, and consistent design tokens to match the updated app shell aesthetic. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: raise TopBar z-index so profile dropdown renders above main content Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat: add AI assistant with in-session copilot and standalone chat with RAG Implements three-phase AI assistant feature: - Phase 0: RAG infrastructure with pgvector embeddings, Voyage AI integration, tree chunking service, and semantic search over team's flow library - Phase 1: In-session copilot panel during flow navigation with contextual AI help, current step awareness, and suggested related flows - Phase 2: Standalone AI chat page with persistent conversation history, pin/delete, and configurable retention policies (account-level) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat: add account management, email verification, AI fixes, and user guides - Profile settings, account transfer, delete/leave account flows - Email verification with JWT tokens and Resend integration - AI assistant/copilot fixes: markdown rendering, shared RAG helpers, token tracking, input refocus, model_validate usage - User guides hub + detail pages with 13 topic guides - Sidebar and top bar navigation for guides Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: prevent stale chunk errors after deployments - Set Cache-Control no-cache on index.html in nginx so browsers always fetch fresh chunk references after a deploy - Auto-reload on chunk load failures (stale deploy detection) with loop prevention via sessionStorage - Show friendly "App Updated" message if auto-reload doesn't resolve it Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat: add email verification toggle to admin settings Adds platform-level toggle to enable/disable email verification. When disabled, the verification banner is hidden and the send endpoint returns 403. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
110 lines
4.0 KiB
Python
110 lines
4.0 KiB
Python
"""Tests for leave account and delete account endpoints."""
|
|
|
|
import pytest
|
|
from httpx import AsyncClient
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
class TestLeaveAccount:
|
|
"""Test POST /accounts/me/leave."""
|
|
|
|
async def test_leave_as_non_owner(self, client: AsyncClient, test_db):
|
|
"""Non-owner can leave and gets a personal account."""
|
|
from sqlalchemy import select
|
|
from app.models.user import User
|
|
|
|
# Register owner
|
|
owner = await client.post("/api/v1/auth/register", json={
|
|
"email": "owner@example.com", "password": "TestPassword123!", "name": "Owner",
|
|
})
|
|
assert owner.status_code == 201
|
|
owner_data = owner.json()
|
|
|
|
# Login as owner
|
|
login = await client.post("/api/v1/auth/login/json", json={
|
|
"email": "owner@example.com", "password": "TestPassword123!",
|
|
})
|
|
owner_headers = {"Authorization": f"Bearer {login.json()['access_token']}"}
|
|
|
|
# Register member
|
|
member = await client.post("/api/v1/auth/register", json={
|
|
"email": "member@example.com", "password": "TestPassword123!", "name": "Member",
|
|
})
|
|
member_id = member.json()["id"]
|
|
|
|
# Move member to owner's account
|
|
result = await test_db.execute(select(User).where(User.id == member_id))
|
|
member_user = result.scalar_one()
|
|
member_user.account_id = owner_data["account_id"]
|
|
member_user.account_role = "engineer"
|
|
await test_db.commit()
|
|
|
|
# Login as member
|
|
login = await client.post("/api/v1/auth/login/json", json={
|
|
"email": "member@example.com", "password": "TestPassword123!",
|
|
})
|
|
member_headers = {"Authorization": f"Bearer {login.json()['access_token']}"}
|
|
|
|
# Leave
|
|
response = await client.post("/api/v1/accounts/me/leave", headers=member_headers)
|
|
assert response.status_code == 200
|
|
|
|
async def test_leave_as_owner_fails(self, client: AsyncClient, auth_headers: dict):
|
|
"""Owner cannot leave their own account."""
|
|
response = await client.post("/api/v1/accounts/me/leave", headers=auth_headers)
|
|
assert response.status_code == 400
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
class TestDeleteAccount:
|
|
"""Test DELETE /accounts/me."""
|
|
|
|
async def test_delete_success(self, client: AsyncClient, auth_headers: dict):
|
|
"""Owner with no other members can delete account."""
|
|
response = await client.request(
|
|
"DELETE",
|
|
"/api/v1/accounts/me",
|
|
json={"current_password": "TestPassword123!"},
|
|
headers=auth_headers,
|
|
)
|
|
assert response.status_code == 200
|
|
|
|
async def test_delete_wrong_password(self, client: AsyncClient, auth_headers: dict):
|
|
"""Wrong password returns 401."""
|
|
response = await client.request(
|
|
"DELETE",
|
|
"/api/v1/accounts/me",
|
|
json={"current_password": "WrongPassword123!"},
|
|
headers=auth_headers,
|
|
)
|
|
assert response.status_code == 401
|
|
|
|
async def test_delete_with_members_fails(self, client: AsyncClient, auth_headers: dict, test_db):
|
|
"""Cannot delete account that has other members."""
|
|
from sqlalchemy import select
|
|
from app.models.user import User
|
|
|
|
# Get owner's account_id
|
|
me = await client.get("/api/v1/auth/me", headers=auth_headers)
|
|
account_id = me.json()["account_id"]
|
|
|
|
# Register and add member
|
|
member = await client.post("/api/v1/auth/register", json={
|
|
"email": "member2@example.com", "password": "TestPassword123!", "name": "Member",
|
|
})
|
|
member_id = member.json()["id"]
|
|
|
|
result = await test_db.execute(select(User).where(User.id == member_id))
|
|
member_user = result.scalar_one()
|
|
member_user.account_id = account_id
|
|
member_user.account_role = "engineer"
|
|
await test_db.commit()
|
|
|
|
response = await client.request(
|
|
"DELETE",
|
|
"/api/v1/accounts/me",
|
|
json={"current_password": "TestPassword123!"},
|
|
headers=auth_headers,
|
|
)
|
|
assert response.status_code == 400
|