import unittest from app import create_app, db from app.models.audit_log import AuditLog from app.services.audit_service import AuditService class TestSecurityChainAndAudit(unittest.TestCase): def setUp(self): self.app = create_app() self.app.config['TESTING'] = True self.client = self.app.test_client() self.app_context = self.app.app_context() self.app_context.push() def tearDown(self): db.session.rollback() self.app_context.pop() def test_security_headers_injected(self): res = self.client.get('/login') self.assertIn('X-Content-Type-Options', res.headers) self.assertEqual(res.headers['X-Content-Type-Options'], 'nosniff') self.assertIn('X-Frame-Options', res.headers) self.assertEqual(res.headers['X-Frame-Options'], 'SAMEORIGIN') self.assertIn('X-XSS-Protection', res.headers) self.assertEqual(res.headers['X-XSS-Protection'], '1; mode=block') def test_audit_log_creation(self): entry = AuditService.log( action='TEST_ACTION', module='classrooms', entity_id=999, details={'test': True, 'desc': 'Prueba unitaria de auditoría'} ) self.assertIsNotNone(entry.id) self.assertEqual(entry.action, 'TEST_ACTION') self.assertEqual(entry.module, 'classrooms') recent = AuditService.get_recent_logs(limit=5, module='classrooms') self.assertTrue(any(e.id == entry.id for e in recent)) if __name__ == '__main__': unittest.main()