from fastapi import FastAPI from fastapi.testclient import TestClient from app.api.schwab_auth import router def client() -> TestClient: app = FastAPI() app.include_router(router) return TestClient(app) def test_callback_needs_no_chart_token(): # Schwab redirects a browser here and cannot attach the token, so this # endpoint has to stay open the way /health and /version do. assert client().get("/api/qt").status_code == 200 def test_page_does_not_name_the_brokerage(): # The path is neutral so the host does not advertise who it trades with; # the page saying it anyway would defeat that. assert "chwab" not in client().get("/api/qt").text def test_landing_here_directly_explains_itself(): body = client().get("/api/qt").text assert "Register this exact URL" in body assert "code" not in body.split("