Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions app/services/billing_client.py
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
one cross-service call it needs -- omnibioai-billing owns subscription
state, omnibioai-auth doesn't duplicate it.

Calls omnibioai-billing's existing GET /organizations/{id}/subscription
Calls omnibioai-billing's existing GET /billing/organizations/{id}/subscription
(no new billing-service endpoint, no new shared secret): that route
already accepts any validly-signed platform JWT whose org_id claim
matches the organization being queried (see omnibioai-billing's
Expand Down Expand Up @@ -52,7 +52,7 @@ def organization_has_active_plan(organization_id: int) -> bool:
})
try:
resp = httpx.get(
f"{settings.BILLING_SERVICE_URL}/organizations/{organization_id}/subscription",
f"{settings.BILLING_SERVICE_URL}/billing/organizations/{organization_id}/subscription",
headers={"Authorization": f"Bearer {token}"},
timeout=3,
)
Expand Down
19 changes: 17 additions & 2 deletions tests/test_billing_client.py
Original file line number Diff line number Diff line change
@@ -1,12 +1,19 @@
"""app/services/billing_client.py: the one cross-service call behind
design audit gap #9's "self-service key creation gated on an active
billing plan." Mocks httpx.get directly -- no real omnibioai-billing
call is ever made in this suite.
call is ever made in this suite. See
test_sends_a_token_scoped_to_the_requested_organization's own comment
for why that one assertion is an exact match, not endswith -- a
real-stack smoke test (not this mocked suite) is what actually caught
the URL this module originally called being wrong (missing billing-
service's own /billing router prefix), so every call it ever made 404'd
in production despite this whole suite passing throughout.

Developer: Manish Kumar <manish@omnibioai.org>
"""
from unittest.mock import MagicMock, patch

from app.core.config import settings
from app.services import billing_client


Expand Down Expand Up @@ -78,7 +85,15 @@ def fake_get(url, headers=None, timeout=None):
with patch.object(billing_client.httpx, "get", side_effect=fake_get):
billing_client.organization_has_active_plan(99)

assert captured["url"].endswith("/organizations/99/subscription")
# Exact match, not endswith: billing-service's router is mounted at
# /billing (app/routers/billing.py's own APIRouter(prefix="/billing")
# in omnibioai-billing) -- a bare /organizations/99/subscription
# also satisfies endswith(".../organizations/99/subscription") while
# actually 404ing against the real service, which is exactly the bug
# this exact-match assertion exists to catch (found via a live
# integration check against the real billing-service, not by any
# mocked unit test -- see this module's own git history).
assert captured["url"] == f"{settings.BILLING_SERVICE_URL}/billing/organizations/99/subscription"
claims = decode_token(captured["token"])
assert claims["org_id"] == 99
assert claims["type"] == "access"
Loading