Add post-login welcome and friendly how-it-works guide
Magent CI/CD / verify (push) Successful in 10m26s
Magent CI/CD / deploy-prod (push) Skipped
Magent CI/CD / deploy-beta (push) Skipped

This commit is contained in:
2026-09-07 16:08:37 +12:00
parent 0637860b95
commit 4034a8f72a
9 changed files with 174 additions and 179 deletions
+19
View File
@@ -0,0 +1,19 @@
import unittest
from unittest.mock import patch
from backend.app.config import Settings
from backend.app.routers.site import _build_site_info
class WelcomeSiteTests(unittest.TestCase):
def test_public_response_does_not_expose_playback_url(self):
with patch('backend.app.routers.site.get_runtime_settings', return_value=Settings().model_copy(update={'jellyfin_public_url': 'https://watch.example.com'})):
self.assertNotIn('mediaServerUrl', _build_site_info(False))
def test_authenticated_response_uses_public_playback_url(self):
with patch('backend.app.routers.site.get_runtime_settings', return_value=Settings().model_copy(update={'jellyfin_public_url': 'https://watch.example.com/web/'})):
self.assertEqual(_build_site_info(True)['mediaServerUrl'], 'https://watch.example.com/web/')
def test_missing_unsafe_or_credential_urls_have_no_watch_link(self):
for url in ['', 'javascript:alert(1)', '//internal', 'https://user:secret@example.com', 'https://[broken']:
with self.subTest(url=url), patch('backend.app.routers.site.get_runtime_settings', return_value=Settings().model_copy(update={'jellyfin_public_url': url})):
self.assertIsNone(_build_site_info(True)['mediaServerUrl'])