chart/tests
Chris Amow 7590d53b13 Put diagnostic capture retrieval behind the same auth as everything else
Uploading a capture required a token; retrieving one did not. That was a
deliberate capability-URL design with a test asserting it, and the reasoning
held: it lets whoever is debugging fetch a capture without the chart password.

Changed because of what a capture contains. getDisplayMedia returns a picture of
someone's screen, and preferCurrentTab is a preference rather than a constraint,
so a mis-click shares a different window. An unguessable id stops guessing but
not leakage: capability URLs escape through proxy logs, browser history and
pasted links.

Retrieval now uses the dependency the rest of the API uses, which already
accepts the session cookie — so a logged-in browser needs nothing extra, which
was the condition for making this change at all. An agent on the server reads
the capture directory directly; one working over HTTP sends the API token.

Both handlers moved from meta.py to routes.py. meta.py is the deliberately open
router — health, version, login, logout — and a screenshot endpoint did not
belong there. The existing test now asserts 401 without credentials, and a new
one covers the browser path: log in, then retrieve with only the cookie.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 17:24:04 -05:00
..
e2e diagnostic capture feature 2026-08-11 16:08:32 -05:00
fixtures Add implementation plan for /ES multi-timeframe confluence chart 2026-08-09 20:31:40 -05:00
test_aggregator.py Expand regression coverage and document next steps 2026-08-11 03:22:00 -05:00
test_alert_state.py Persist alert cooldowns across restarts so deploys stop re-firing every zone 2026-08-11 19:46:11 +00:00
test_alerts.py Stop re-alerting when price crosses a level 2026-08-10 01:51:54 -05:00
test_asset_versioning.py Version static assets so a fixed bug stops reproducing in an open tab 2026-08-10 04:29:56 -05:00
test_auth.py Put diagnostic capture retrieval behind the same auth as everything else 2026-08-11 17:24:04 -05:00
test_bar_space.py Price trendlines across bars, add one-shot alerts, collapse layers, drop 1h MAs 2026-08-10 04:15:05 -05:00
test_confluence.py Fix trendline deletion while typing, audio leak, prefs drift, cluster payload 2026-08-10 00:17:40 -05:00
test_horizontals.py Add prior-day levels and session VWAP; fix alert repetition they exposed 2026-08-10 00:36:21 -05:00
test_manual_lines.py better default names 2026-08-11 14:36:58 -05:00
test_moving_averages.py Implement M3 projected daily moving averages 2026-08-09 20:44:11 -05:00
test_price_alerts.py Add a price alert input 2026-08-10 02:09:14 -05:00
test_replay.py Implement M0 Yahoo market data and replay 2026-08-09 20:36:13 -05:00
test_runtime_alerts.py Post cross-thread events through the loop, and measure how late it runs 2026-08-11 15:30:45 -05:00
test_runtime_start.py Unify chart geometry and deepen 30m history 2026-08-11 04:08:02 -05:00
test_schwab_callback.py Add the OAuth callback endpoint at /api/qt 2026-08-10 04:45:31 -05:00
test_schwab_source.py Stop a zero-price tick and a late exchange bar corrupting the store 2026-08-10 17:10:24 -05:00
test_session.py Expand regression coverage and document next steps 2026-08-11 03:22:00 -05:00
test_store.py Stop a zero-price tick and a late exchange bar corrupting the store 2026-08-10 17:10:24 -05:00
test_vwap.py Add prior-day levels and session VWAP; fix alert repetition they exposed 2026-08-10 00:36:21 -05:00
test_ws_preferences.py Expand regression coverage and document next steps 2026-08-11 03:22:00 -05:00
test_yahoo.py Unify chart geometry and deepen 30m history 2026-08-11 04:08:02 -05:00