diff --git a/apps/api/app/api/routes/auth_simple.py b/apps/api/app/api/routes/auth_simple.py deleted file mode 100644 index 67c6df8f1..000000000 --- a/apps/api/app/api/routes/auth_simple.py +++ /dev/null @@ -1,18 +0,0 @@ -""" -Backward-compatible import shim for the canonical auth routes. - -New code should import `app.api.routes.auth`; this module remains so older tests -or clients that import `auth_simple` continue to resolve the same router. -""" - -from app.api.routes.auth import ( # noqa: F401 - CurrentUserResponse, - LoginRequest, - LoginResponse, - RegisterRequest, - RegisterResponse, - get_current_user_info, - login, - register, - router, -) diff --git a/docs/全面代码审计报告-2026-06-21.md b/docs/全面代码审计报告-2026-06-21.md index d2607e5b4..6ff2ca58c 100644 --- a/docs/全面代码审计报告-2026-06-21.md +++ b/docs/全面代码审计报告-2026-06-21.md @@ -290,11 +290,11 @@ python -m pytest tests/unit/test_login_use_case.py tests/unit/test_register_user 已完成: - `auth.py` 不再是 disabled skeleton,也不依赖缺失的 `get_container()`。 - `api/router.py` 直接挂载 `app.api.routes.auth`。 -- `auth_simple.py` 降级为兼容 import shim,避免旧测试或外部导入立即失败。 +- `auth_simple.py` 兼容 shim 已删除,认证入口只保留 `auth.py`。 - 登录/注册/当前用户均通过 `UserRepository + UseCase + app.auth`,route 层不再承载认证业务逻辑。 剩余建议: -1. 后续确认无外部 import 后删除 `auth_simple.py` shim。 +1. 持续用 grep/架构测试防止 `auth_simple.py` 路径回流。 2. 根据产品需要补齐 password reset / verify email 的正式 route。 3. 接入真实邮件 adapter 前继续保持 no-op email delivery。 @@ -334,13 +334,13 @@ python -m pytest tests/unit/test_login_use_case.py tests/unit/test_register_user ### P2:临时代码仍在主线 发现: -- `auth_simple.py` 已降级为兼容 shim,但文件名仍体现历史临时方案。 +- `auth_simple.py` shim 已删除。 - 部分测试和文档仍引用旧 MinIO/OSS 混合术语。 - `__pycache__` 文件出现在工作树扫描中,需确认 `.gitignore` 和仓库状态。 ## 五、下一步建议修复顺序 -1. 删除死代码:确认无外部依赖后移除 `auth_simple.py` shim 和旧 postgres adapters。 +1. 删除死代码:继续移除旧 postgres adapters。 2. 补齐认证扩展:password reset / verify email 正式 route。 3. 外部服务 adapter 化收尾:接入真实 Redis session / SMTP email 生产配置。 4. Repository 统一收尾:继续清理 remaining legacy imports。 diff --git a/tests/unit/test_architecture_boundaries.py b/tests/unit/test_architecture_boundaries.py index 253c33e11..95fecb24c 100644 --- a/tests/unit/test_architecture_boundaries.py +++ b/tests/unit/test_architecture_boundaries.py @@ -43,6 +43,21 @@ def test_runtime_code_does_not_import_deprecated_postgres_adapters(): assert offenders == [] +def test_canonical_auth_route_has_no_auth_simple_runtime_path(): + assert not Path("apps/api/app/api/routes/auth_simple.py").exists() + + offenders: list[str] = [] + for root in [Path("apps"), Path("packages"), Path("tests")]: + for path in root.rglob("*.py"): + if path.resolve() == Path(__file__).resolve(): + continue + text = path.read_text(encoding="utf-8") + if "auth_simple" in text or "routes.auth_simple" in text: + offenders.append(str(path)) + + assert offenders == [] + + def test_legacy_sql_schema_files_are_not_runtime_entrypoints(): init_tables = Path("init-tables.sql").read_text(encoding="utf-8") diff --git a/tests/unit/test_auth_simple.py b/tests/unit/test_auth.py similarity index 100% rename from tests/unit/test_auth_simple.py rename to tests/unit/test_auth.py