121 lines
5.8 KiB
Python
121 lines
5.8 KiB
Python
|
|
"""Экспорт разбора: содержимое, безопасность CSV, кириллица и доступ."""
|
|||
|
|
|
|||
|
|
import csv
|
|||
|
|
import io
|
|||
|
|
from datetime import datetime, timezone
|
|||
|
|
from types import SimpleNamespace
|
|||
|
|
from uuid import uuid4
|
|||
|
|
|
|||
|
|
import pytest
|
|||
|
|
from fastapi.testclient import TestClient
|
|||
|
|
|
|||
|
|
from app.api.auth import Principal
|
|||
|
|
from app.api.http import sessions
|
|||
|
|
from app.domain.events import SessionReport
|
|||
|
|
from app.domain.roles import Role
|
|||
|
|
from app.main import app
|
|||
|
|
from app.scoring.export import _cell, to_csv, to_pdf
|
|||
|
|
|
|||
|
|
|
|||
|
|
def sample_report(*, long: bool = False) -> SessionReport:
|
|||
|
|
at = datetime(2026, 9, 21, 12, 0, tzinfo=timezone.utc)
|
|||
|
|
long_text = "Заявитель сообщает о дыме в учебном помещении. " * (240 if long else 1)
|
|||
|
|
return SessionReport.model_validate({
|
|||
|
|
"session_id": str(uuid4()),
|
|||
|
|
"scenario_id": "=1+1",
|
|||
|
|
"mode": "training",
|
|||
|
|
"attempt": 2,
|
|||
|
|
"transcript": [
|
|||
|
|
{"ref": f"u{i}", "speaker": "caller", "text": long_text if i == 0 else "<вопрос> \t=cmd", "at": at}
|
|||
|
|
for i in range(18 if long else 2)
|
|||
|
|
],
|
|||
|
|
"findings": [{
|
|||
|
|
"code": "E1", "source": "slots", "summary": "+HYPERLINK(\"x\")",
|
|||
|
|
"fact": "Адрес не уточнён", "norm": "Уточнить адрес происшествия",
|
|||
|
|
"ref": "ГОСТ", "at": at,
|
|||
|
|
}],
|
|||
|
|
"metrics": [{
|
|||
|
|
"key": "address", "title": "Адрес", "fact": "Не назван",
|
|||
|
|
"norm": "Адрес должен быть уточнён", "passed": False,
|
|||
|
|
}],
|
|||
|
|
"competencies": [{"competency": "interview", "value": 65}],
|
|||
|
|
"reference_questions": [{"checklist_id": "q_address", "question": "Назовите адрес?"}],
|
|||
|
|
"missed_checklist": ["q_address"],
|
|||
|
|
"hints_used": [{"checklist_id": "q_address", "question": "Уточните адрес", "at": at}],
|
|||
|
|
"self_assessment": {"missed": ["q_address"], "comment": "@SUM(1,2)", "submitted_at": at},
|
|||
|
|
"self_assessment_diff": {"noticed": ["q_address"], "unnoticed": [], "overcautious": []},
|
|||
|
|
"notes": [{"transcript_ref": "u0", "text": "Внимательнее к адресу", "author": "Преподаватель"}],
|
|||
|
|
"score_auto": 70,
|
|||
|
|
"score_final": 75,
|
|||
|
|
"overridden_by": "Преподаватель",
|
|||
|
|
"override_comment": "Ручная корректировка",
|
|||
|
|
})
|
|||
|
|
|
|||
|
|
|
|||
|
|
def test_csv_contains_sections_and_blocks_formula_injection():
|
|||
|
|
rows = list(csv.reader(io.StringIO(to_csv(sample_report()).decode("utf-8-sig"))))
|
|||
|
|
assert rows[0] == ["Раздел", "№", "Поле", "Значение", "Дополнительно"]
|
|||
|
|
assert any(row[0] == "Транскрипт" and row[3] == "<вопрос> \t=cmd" for row in rows)
|
|||
|
|
assert any(row[0] == "Занятие" and row[3] == "'=1+1" for row in rows)
|
|||
|
|
assert any(row[0] == "Ошибки" and row[3] == "'+HYPERLINK(\"x\")" for row in rows)
|
|||
|
|
assert any(row[0] == "Самооценка" and row[3] == "'@SUM(1,2)" for row in rows)
|
|||
|
|
assert _cell(" =cmd") == "' =cmd"
|
|||
|
|
assert _cell("\tОбычный текст") == "'\tОбычный текст"
|
|||
|
|
|
|||
|
|
|
|||
|
|
def test_pdf_supports_cyrillic_and_spans_pages(tmp_path):
|
|||
|
|
data = to_pdf(sample_report(long=True))
|
|||
|
|
assert data.startswith(b"%PDF-")
|
|||
|
|
path = tmp_path / "report.pdf"
|
|||
|
|
path.write_bytes(data)
|
|||
|
|
# Poppler даёт проверку извлекаемого текста, не только сигнатуры файла.
|
|||
|
|
import shutil
|
|||
|
|
import subprocess
|
|||
|
|
|
|||
|
|
if shutil.which("pdftotext") and shutil.which("pdfinfo"):
|
|||
|
|
info = subprocess.check_output(["pdfinfo", str(path)], text=True)
|
|||
|
|
pages = int(next(line.split(":", 1)[1].strip() for line in info.splitlines() if line.startswith("Pages:")))
|
|||
|
|
assert pages >= 2
|
|||
|
|
extracted = subprocess.check_output(["pdftotext", str(path), "-"], text=True)
|
|||
|
|
assert "Отчёт по учебному занятию" in extracted
|
|||
|
|
assert "Адрес должен быть уточнён" in extracted
|
|||
|
|
assert "Заявитель сообщает о дыме" in extracted
|
|||
|
|
|
|||
|
|
|
|||
|
|
@pytest.fixture
|
|||
|
|
def client(monkeypatch):
|
|||
|
|
report = sample_report()
|
|||
|
|
state = SimpleNamespace(score={"score_auto": 70}, trainee_id=uuid4())
|
|||
|
|
monkeypatch.setattr(sessions, "_live", lambda session_id: (state, object()))
|
|||
|
|
monkeypatch.setattr(sessions, "build_report", lambda session_id, state, scenario: report)
|
|||
|
|
with TestClient(app) as test_client:
|
|||
|
|
test_client.post("/api/auth/dev-token")
|
|||
|
|
yield test_client, state, report
|
|||
|
|
|
|||
|
|
|
|||
|
|
def test_export_routes_return_downloads_with_json_report_rights(client):
|
|||
|
|
browser, state, report = client
|
|||
|
|
csv_response = browser.get(f"/api/sessions/{report.session_id}/report.csv")
|
|||
|
|
assert csv_response.status_code == 200
|
|||
|
|
assert csv_response.headers["content-type"].startswith("text/csv")
|
|||
|
|
assert csv_response.content.startswith(b"\xef\xbb\xbf")
|
|||
|
|
assert "attachment" in csv_response.headers["content-disposition"]
|
|||
|
|
|
|||
|
|
pdf_response = browser.get(f"/api/sessions/{report.session_id}/report.pdf")
|
|||
|
|
assert pdf_response.status_code == 200
|
|||
|
|
assert pdf_response.headers["content-type"] == "application/pdf"
|
|||
|
|
assert pdf_response.content.startswith(b"%PDF-")
|
|||
|
|
|
|||
|
|
state.score = None
|
|||
|
|
assert browser.get(f"/api/sessions/{report.session_id}/report.csv").status_code == 409
|
|||
|
|
assert browser.get(f"/api/sessions/{report.session_id}/report.pdf").status_code == 409
|
|||
|
|
|
|||
|
|
|
|||
|
|
def test_trainee_cannot_export_another_persons_report(client, monkeypatch):
|
|||
|
|
browser, state, report = client
|
|||
|
|
monkeypatch.setattr(
|
|||
|
|
sessions, "require",
|
|||
|
|
lambda request: Principal(login="trainee", full_name="Учебный", role=Role.TRAINEE, trainee_id=uuid4()),
|
|||
|
|
)
|
|||
|
|
for suffix in ("csv", "pdf"):
|
|||
|
|
assert browser.get(f"/api/sessions/{report.session_id}/report.{suffix}").status_code == 403
|