Chat — Tests¶
Overview¶
The chat app includes a comprehensive test suite covering:
- REST API endpoints
- websocket behavior
- attachment workflows
- participant access control
- message lifecycle (create, edit, delete)
- read state tracking
The tests validate both:
- functional correctness
- security boundaries (who is allowed to do what)
Test structure¶
The tests are grouped into:
test_resttest_featurestest_chat_ws
Each group focuses on a specific layer of the system.
REST API tests¶
Conversations¶
Tests verify:
- internal conversation listing requires org context
- customer conversation listing requires customer org context
- conversations are returned correctly for both sides
- conversation creation:
- fails without a valid customer link
- succeeds when link exists
- automatically adds creator as participant
Messages¶
Tests verify:
- only participants can access messages
- non-participants receive
403 - message list response shape:
- contains
items - contains
next_before - pagination behavior is correct
Participants¶
Tests verify:
- only existing participants can add new participants
- adding participant fails for unauthorized users
- removing participants updates their active state
Message actions¶
Tests verify:
- only the sender can edit a message
- only the sender can delete a message
- non-senders receive
403 - editing updates:
- message body
edited_at- deleting sets:
deleted_at
Read state¶
Tests verify:
- marking a conversation as read updates
last_read_at - only participants can update read state
Attachments¶
Tests verify:
- upload returns:
- attachment ID
- metadata
- upload fails for non-participants
- uploaded attachment is persisted in database
- content type restrictions are enforced
Feature tests¶
Feature tests validate multi-step workflows.
Attachment + message linking¶
Tests verify:
- attachments can be uploaded before message creation
- websocket message includes attachment IDs
- backend links attachments to the message
- attachment records are updated with
message_id
Pagination shape¶
Tests verify:
- message list response structure is stable
- frontend can rely on consistent keys
Websocket tests¶
Websocket tests use:
channels.testing.WebsocketCommunicator- async pytest support
Connection behavior¶
Tests verify:
- anonymous users are rejected
- non-participants are rejected
- valid participants can connect successfully
Message flow¶
Tests verify:
- sending a message via websocket:
- persists the message in database
- broadcasts message payload
- response contains:
- body
- conversation_id
- message is queryable after send
Attachment linking via websocket¶
Tests verify:
- uploaded attachment IDs can be passed in websocket message
- attachments are linked to created message
- database reflects the correct relationship
Security tests¶
The test suite ensures strict access control:
Participant enforcement¶
- only participants can:
- view messages
- upload attachments
- connect via websocket
Sender restrictions¶
- only sender can:
- edit message
- delete message
Org and customer boundaries¶
- conversations require valid org context
- customer conversations require customer org context
- conversation creation requires valid org link
Data integrity tests¶
Tests validate:
- attachments are properly linked
- messages are persisted correctly
- participant states are respected
- read timestamps are updated
Async test considerations¶
Websocket tests:
- use
pytest.mark.asyncio - use
database_sync_to_asyncfor DB access - run with transaction support
This ensures:
- correct async execution
- safe database interaction
Coverage summary¶
The test suite covers:
- REST endpoints
- websocket flows
- permissions and access control
- data persistence
- attachment lifecycle
- participant lifecycle
- message lifecycle
Known gaps¶
Potential areas for future testing:
- notification dispatch behavior
- typing event behavior (currently not asserted)
- large conversation performance
- attachment cleanup task
- multi-user concurrent websocket scenarios
- read/unread count accuracy under load
Best practices¶
- always test both success and failure paths
- explicitly test permission boundaries
- include websocket tests for realtime features
- validate response shape stability
- ensure database state matches expected outcomes
Summary¶
The chat app test suite ensures:
- correctness of chat workflows
- strict access control
- reliable realtime behavior
- consistent API contracts
It provides a strong foundation for safely integrating the chat system into frontend clients.