feat(api): список событий безопасности аккаунта

GET /users/@me/security-events отдаёт последние входы, неудачные попытки,
смены пароля и изменения 2FA (AGENT.md 7.1: уведомления о новых входах —
основа для настроек безопасности в клиенте).
This commit is contained in:
2026-09-19 21:55:52 +03:00
parent bf0d130ee8
commit b189b3592b
2 changed files with 70 additions and 0 deletions
+21
View File
@@ -154,6 +154,27 @@ func TestProfileUpdateFlow(t *testing.T) {
}
}
func TestSecurityEventsListed(t *testing.T) {
srv, _ := newTestServer(t)
cookie := registerAndLogin(t, srv, "events_user", "events@example.com")
rec := doJSON(t, srv, http.MethodGet, "/api/v1/users/@me/security-events", "", cookie)
if rec.Code != http.StatusOK {
t.Fatalf("security events = %d, body = %s", rec.Code, rec.Body.String())
}
payload := decodeResponse[struct {
Events []struct {
Type string `json:"type"`
} `json:"events"`
}](t, rec)
if len(payload.Events) == 0 {
t.Fatal("registration must leave a security event")
}
if payload.Events[0].Type != "register" {
t.Fatalf("first event = %q, want register", payload.Events[0].Type)
}
}
func TestGuildLifecycleAndPermissions(t *testing.T) {
srv, _ := newTestServer(t)
ownerCookie := registerAndLogin(t, srv, "guild_owner", "owner@example.com")