Both tests read a value that is usually one thing and occasionally another, with a race deciding which. ReloadTests: EndpointSecurityOptions.SecurityIsEnabled is a process- global static, and ShellsApiTestBase saved/set/restored it per test method. ReloadTests and ReloadAllTests carry no [Collection], so xUnit runs them in parallel. FastEndpoints reads that global once per host while UseFastEndpoints() configures the endpoints, so when one class's DisposeAsync restores true inside another class's set-false -> UseFastEndpoints() window, that host's endpoints get authorization metadata in a pipeline with no UseAuthorization, and every request to them throws. Every test in the assembly wants security off, so set it once in a module initializer and stop mutating it per test. PublishEvent_WithPayload_TransmitsPayloadToConsumer: the payload's representation is not stable. While it is still the original CLR object its properties are PascalCase; once it has been through JsonWorkflowStateSerializer it is an ExpandoObject whose keys were camelCased by that serializer's naming policy. Which one the test sees depends on whether GetSingleWorkflowInstanceAsync returned the live in-memory instance or one read back from the store, and TryGetProperty is case-sensitive. Assert the payload's content through a DTO with PropertyNameCaseInsensitive instead of one of the two representations. Also require a terminal instance at both exits of GetSingleWorkflowInstanceAsync: it accepted any save, and an instance is saved several times over its lifetime, so it could hand a caller that asserts Finished an instance that is still running. Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
20 lines
1 KiB
C#
20 lines
1 KiB
C#
using System.Runtime.CompilerServices;
|
|
|
|
namespace Elsa.Shells.Api.Tests;
|
|
|
|
/// <summary>
|
|
/// <see cref="EndpointSecurityOptions.SecurityIsEnabled"/> is process-global mutable state that FastEndpoints reads
|
|
/// once per host, while <c>UseFastEndpoints()</c> configures the endpoints. xUnit runs the test classes in this
|
|
/// assembly in parallel, so a per-test save/restore of that global races: one class restoring the flag to
|
|
/// <c>true</c> between another class's write and its <c>UseFastEndpoints()</c> call produces endpoints carrying
|
|
/// authorization metadata in a pipeline that has no <c>UseAuthorization</c>, which fails the request with
|
|
/// "contains authorization metadata, but a middleware was not found that supports authorization".
|
|
///
|
|
/// Every test in this assembly wants security disabled, so set it once before any test runs and never touch it again.
|
|
/// </summary>
|
|
internal static class TestSecurityDefaults
|
|
{
|
|
[ModuleInitializer]
|
|
internal static void DisableEndpointSecurity() => EndpointSecurityOptions.SecurityIsEnabled = false;
|
|
}
|