test(hygiene): default seed credential is hard-coded in CLI test teardown #43

Closed
opened 2026-09-21 18:18:33 +00:00 by gabogg · 1 comment
Owner

Context

Follow-up from the verification of #39 (comment #issuecomment-884). Minor.

Problem

tests/test_cli_commands.py::test_user_command_does_not_resurrect_deleted_user deletes the default admin account and restores it in teardown by re-creating it with the literal seed password:

finally:
    if not user_repo.get_by_username("admin"):
        user_repo.create_user("admin", "ControlHG", role="admin")
    user_repo.delete_user("temp_admin")

The test itself is sound — it was verified to fail against the pre-fix commit 7f3e2f4 and pass after — but it copies the seed credential from app/db/database.py:390 into the test suite by hand.

Two consequences: the credential string now lives in a second place and can drift from the seeder, and a grep for the default password returns test files as well as the seeder.

Proposed fix

Import the seed constant rather than retyping it, or restore the fixture state through a helper that reuses whatever init_db seeds. Extracting the seed pairs in database.py:390 into a named module-level constant would serve both this and any future test that needs the same thing.

Acceptance criteria

  • No hard-coded default password literal in the test suite.
  • test_user_command_does_not_resurrect_deleted_user still fails against 7f3e2f4 and passes on master.
## Context Follow-up from the verification of #39 (comment [#issuecomment-884](https://git.gaboggamer.online/gabogg/hikcentral/pulls/39#issuecomment-884)). Minor. ## Problem `tests/test_cli_commands.py::test_user_command_does_not_resurrect_deleted_user` deletes the default `admin` account and restores it in teardown by re-creating it with the literal seed password: ```python finally: if not user_repo.get_by_username("admin"): user_repo.create_user("admin", "ControlHG", role="admin") user_repo.delete_user("temp_admin") ``` The test itself is sound — it was verified to fail against the pre-fix commit `7f3e2f4` and pass after — but it copies the seed credential from `app/db/database.py:390` into the test suite by hand. Two consequences: the credential string now lives in a second place and can drift from the seeder, and a grep for the default password returns test files as well as the seeder. ## Proposed fix Import the seed constant rather than retyping it, or restore the fixture state through a helper that reuses whatever `init_db` seeds. Extracting the seed pairs in `database.py:390` into a named module-level constant would serve both this and any future test that needs the same thing. ## Acceptance criteria - [ ] No hard-coded default password literal in the test suite. - [ ] `test_user_command_does_not_resurrect_deleted_user` still fails against `7f3e2f4` and passes on `master`.
Author
Owner

Ready to implement — delivered in PR #45 (Closes #43). Re-tagged ready-for-agent; auto-closes on merge.

Ready to implement — delivered in PR #45 (`Closes #43`). Re-tagged `ready-for-agent`; auto-closes on merge.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
gabogg/hikcentral#43
No description provided.