pdf-quiz-generator/backend/tests
Daniel c9e0655d6e
Some checks failed
Tests / backend (push) Failing after 9s
Tests / frontend (push) Successful in 29s
Tests / e2e (push) Failing after 27s
fix: shut every password door under SSO-only, and keep the token out of the URL
Two findings from a security pass on the SSO path, both real.

sso_only gated login and the login codes and nothing else. Register,
forgot-password, reset-password, resend-verification and setting a
password through PUT /auth/me all went through — so a site running
single sign-on could still mint a password account nobody vetted, and if
the flag were ever turned off, there it would be. One helper, five doors,
403 with a reason at each.

And the access token travelled in a query string. The SSO redirect is a
page load, so the browser asked nginx for /sso-callback?token=<a live
bearer token, good for a day> and nginx logs the request line — every
sign-in wrote one into the frontend container's access log, the
browser's history, and the Referer of whatever loaded next. It carries a
one-time code now: a random 32 bytes parked in Redis for sixty seconds,
traded at POST /auth/sso/exchange for the token, and deleted as it is
read, so a code replayed from any of those places buys nothing.

Also the OIDC state cookie, which is what stops an authorization
response being replayed at you: same_site lax (strict drops it on the
provider's top-level GET and fails every sign-in) and secure whenever
APP_URL is https.

And one cross, not two. The header's menu button is already a cross
while a drawer is open, so the drawer's own close button was a second
control an inch below it for the same job — gone from the article, the
player and the review.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TqXevQJhxFrM7jJg82cgZN
2026-09-13 05:55:37 +02:00
..
__init__.py Initial commit: PDF Quiz Generator app 2026-03-30 20:04:53 +00:00
api-contract.json fix: shut every password door under SSO-only, and keep the token out of the URL 2026-09-13 05:55:37 +02:00
test_access.py feat: access as one tree — branches, libraries, and an honest "everything" 2026-09-11 12:53:56 +02:00
test_ai_mode.py fix: drawers that close, sources that are sources, and a model that does not haggle 2026-09-12 23:34:24 +02:00
test_ai_mode_matching.py refactor: remove the LMS 2026-09-12 23:27:51 +02:00
test_ai_practice.py refactor: remove the LMS 2026-09-12 23:27:51 +02:00
test_api_contract.py feat: a versioned API, refresh tokens, and an end-to-end stack that found four bugs 2026-09-13 01:23:38 +02:00
test_article_ai.py fix: Reading is published, Editorial has its own address, and repeat works 2026-09-13 04:16:46 +02:00
test_article_notes.py feat: question folders, per-section notes, and two feedback paths 2026-09-12 18:37:43 +02:00
test_article_search_index.py feat: three answers, chosen by a number rather than by the model 2026-09-12 16:15:05 +02:00
test_articles_cards.py feat: an article follows a topic, rather than copying it once 2026-09-12 19:57:06 +02:00
test_articles_migration.py feat: linked topic articles and card associations 2026-09-07 15:16:48 +02:00
test_bank_cleanup.py refactor: remove the LMS 2026-09-12 23:27:51 +02:00
test_blueprint_plans.py feat: study plans built to the board's content outline 2026-09-11 21:40:17 +02:00
test_captcha.py feat: Cap replaces hCaptcha, self-hosted beside the app 2026-09-12 06:14:14 +02:00
test_category_grants.py fix: the answer side of a question needs an attempt, or the job of writing it 2026-09-13 00:13:43 +02:00
test_category_migration.py feat: retire the tags, and stop settings from hiding from the page that 2026-09-12 05:06:58 +02:00
test_collections.py refactor: remove per-question sharing 2026-09-12 08:42:51 +02:00
test_contact_privacy.py fix: the contact form's messages were readable by anyone 2026-09-12 22:37:28 +02:00
test_draft_questions.py fix: the other registration form, our own transcriber first, and a rail 2026-09-12 04:41:27 +02:00
test_exam_admin.py feat: exams are a group you can build, with the board's own blueprint 2026-09-11 20:27:48 +02:00
test_exam_blueprint.py feat: adaptive weighs the paper as well as the learner, and Session 2026-09-12 05:54:09 +02:00
test_exam_scoped_tags.py refactor: remove the LMS 2026-09-12 23:27:51 +02:00
test_exams.py refactor: remove the LMS 2026-09-12 23:27:51 +02:00
test_feedback.py feat: question folders, per-section notes, and two feedback paths 2026-09-12 18:37:43 +02:00
test_file_intake.py fix: an upload is what its bytes say, not what its name claims 2026-09-12 19:05:12 +02:00
test_global_search.py refactor: remove per-question sharing 2026-09-12 08:42:51 +02:00
test_hybrid_search.py refactor: remove the LMS 2026-09-12 23:27:51 +02:00
test_invites_and_flags.py feat: the tutor is an administrator's to allow, and a handbook explains the rest 2026-09-11 21:13:38 +02:00
test_login_codes.py feat: sign in with a code sent by email 2026-09-12 17:29:28 +02:00
test_login_without_captcha.py feat: Cap replaces hCaptcha, self-hosted beside the app 2026-09-12 06:14:14 +02:00
test_media_library.py refactor: remove the LMS 2026-09-12 23:27:51 +02:00
test_multi_category.py refactor: remove the LMS 2026-09-12 23:27:51 +02:00
test_option_explanations.py feat: key points smart links, difficulty tags, adaptive sessions, educator-only question management 2026-09-09 02:26:45 +02:00
test_prepared_session.py feat: a session prepared for you, and a model that can see when the one on the job cannot 2026-09-12 15:46:04 +02:00
test_question_detail_access.py fix: /questions/detail hands out the answer to anybody signed in 2026-09-13 05:12:01 +02:00
test_question_figures.py feat: an opened explanation figure shows what the library knows 2026-09-13 05:05:59 +02:00
test_question_folders.py feat: question folders, per-section notes, and two feedback paths 2026-09-12 18:37:43 +02:00
test_question_trash.py feat: questions are soft-deleted, and the trash holds them 2026-09-11 20:12:58 +02:00
test_question_versions.py refactor: remove the LMS 2026-09-12 23:27:51 +02:00
test_quiz_builder.py refactor: the app is a PWA, so the native wrapper goes 2026-09-13 00:26:35 +02:00
test_quiz_sessions.py refactor: remove the LMS 2026-09-12 23:27:51 +02:00
test_refresh_tokens.py feat: a versioned API, refresh tokens, and an end-to-end stack that found four bugs 2026-09-13 01:23:38 +02:00
test_related_privacy.py fix: the answer side of a question needs an attempt, or the job of writing it 2026-09-13 00:13:43 +02:00
test_rerank.py refactor: remove the LMS 2026-09-12 23:27:51 +02:00
test_session_lifecycle.py refactor: remove per-question sharing 2026-09-12 08:42:51 +02:00
test_share_public.py refactor: remove the LMS 2026-09-12 23:27:51 +02:00
test_shared_category.py feat: ground AI drafts in the library and PubMed, and mend the card system 2026-09-13 02:44:42 +02:00
test_sso_hardening.py fix: shut every password door under SSO-only, and keep the token out of the URL 2026-09-13 05:55:37 +02:00
test_sso_roles.py fix: the SSO login button 500s — the redirect was never awaited 2026-09-13 05:30:34 +02:00
test_study_plan_editing.py feat: study plans you can open, work through, and edit 2026-09-10 12:10:39 +02:00
test_study_plan_sessions.py feat: study-plan blocks as modules, sessions that know their block 2026-09-11 04:31:21 +02:00
test_study_tools.py refactor: remove the LMS 2026-09-12 23:27:51 +02:00
test_study_tools_migration.py fix: preserve saved quiz progress across resume failures 2026-09-07 03:34:55 +02:00
test_tag_hierarchy.py refactor: remove the LMS 2026-09-12 23:27:51 +02:00
test_thumbnails.py feat: thumbnails for uploaded images, at two widths and no others 2026-09-12 08:49:20 +02:00
test_tts_voices.py fix: a speech model is added with its voices, and Orpheus is sent where it works 2026-09-13 05:04:37 +02:00
test_vision_fallback.py fix: the answer side of a question needs an attempt, or the job of writing it 2026-09-13 00:13:43 +02:00