""" Tests for authentication: signup, login, /me. """ class TestSignup: def test_signup_success(self, client): resp = client.post("/api/auth/signup", json={ "username": "newuser", "email": "new@example.com", "password": "securepass", }) assert resp.status_code == 201 data = resp.json() assert "access_token" in data assert data["token_type"] == "bearer" def test_signup_duplicate_username(self, client): payload = { "username": "dupuser", "email": "dup1@example.com", "password": "pass123", } client.post("/api/auth/signup", json=payload) # Try again with same username resp = client.post("/api/auth/signup", json={ "username": "dupuser", "email": "dup2@example.com", "password": "pass123", }) assert resp.status_code == 409 def test_signup_duplicate_email(self, client): client.post("/api/auth/signup", json={ "username": "user1", "email": "same@example.com", "password": "pass123", }) resp = client.post("/api/auth/signup", json={ "username": "user2", "email": "same@example.com", "password": "pass123", }) assert resp.status_code == 409 class TestLogin: def test_login_success(self, client): client.post("/api/auth/signup", json={ "username": "loginuser", "email": "login@example.com", "password": "mypassword", }) resp = client.post("/api/auth/login", json={ "username": "loginuser", "password": "mypassword", }) assert resp.status_code == 200 assert "access_token" in resp.json() def test_login_wrong_password(self, client): client.post("/api/auth/signup", json={ "username": "wrongpw", "email": "wrongpw@example.com", "password": "correctpass", }) resp = client.post("/api/auth/login", json={ "username": "wrongpw", "password": "wrongpassword", }) assert resp.status_code == 401 def test_login_nonexistent_user(self, client): resp = client.post("/api/auth/login", json={ "username": "ghost", "password": "nope", }) assert resp.status_code == 401 class TestMe: def test_me_returns_user(self, client, auth_headers): resp = client.get("/api/auth/me", headers=auth_headers) assert resp.status_code == 200 data = resp.json() assert data["username"] == "testuser" assert data["email"] == "test@example.com" assert "id" in data def test_me_requires_auth(self, client): resp = client.get("/api/auth/me") assert resp.status_code in (401, 403) def test_me_rejects_bad_token(self, client): resp = client.get("/api/auth/me", headers={ "Authorization": "Bearer invalid.token.here" }) assert resp.status_code == 401