Skip to content

Auth and tenancy tests

Auth and tenancy tests

Use these suites when changing login, Microsoft auth, consent, or tenant membership behavior.

Key suites

  • tests/unit/auth/test_auth.py — login success/failure branches and token response contract.
  • tests/unit/auth/test_login_throttle.py — login rate limiting.
  • tests/unit/auth/test_ms_tenant_org.py — Microsoft auth tenant creation and binding.
  • tests/unit/auth/test_auth_and_tenancy_contracts.py — combined auth/tenant invariants.
  • tests/integration/test_authentication.py — end-to-end auth flows.

What these tests prove

  • invalid credentials fail before token issuance
  • inactive accounts are rejected
  • Microsoft auth binds a user to the right internal tenant
  • consent flags are carried through auth responses
  • tenant membership gates later workspace actions

Minimal validation

Run the focused auth suite for the subsystem you changed. If the change affects workspace binding or consent, include the Microsoft auth and tenancy-contract tests in the same pass.