0Pricing
Flask Academy · บทเรียน

ทดสอบปลายทางที่ต้องยืนยันตัวตน

เข้าสู่ระบบภายในการทดสอบเพื่อเข้าถึงเส้นทางที่มีการป้องกัน

ทดสอบปลายทางที่ต้องยืนยันตัวตน เป็นบทเรียน Flask Academy ฟรีบน CoddyKit นี่คือบทเรียนที่ 4 จากทั้งหมด 4 บทเรียน คุณสามารถอ่านบทเรียนทั้งหมดด้านล่างฟรี — จากนั้นลองปฏิบัติด้วยตัวคุณเองในเบราว์เซอร์พร้อมตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7 บทเรียนนี้เป็นส่วนหนึ่งของเส้นทางการเรียน Flask Academy และความก้าวหน้าของคุณจะซิงค์ข้ามเว็บและแอป CoddyKit คอร์ส Flask Academy มีบทเรียนทั้งหมด 4 บทเรียน

บางส่วนของบทเรียนนี้ยังไม่ได้รับการแปล และแสดงเป็นภาษาอังกฤษ

The Challenge of Auth Tests

Protected routes refuse anonymous visitors. To test them, your client must first log in, just like a real user would before reaching guarded pages.

Confirm the Guard Works

Start by proving the gate is closed. Request the route logged out and assert you get a redirect or a 401 response.

resp = client.get('/dashboard')
assert resp.status_code == 302

Log In via the Login Route

The realistic way to authenticate is to post credentials to your login endpoint. The client stores the session cookie automatically.

client.post('/login', data={'email': 'a@b.com', 'password': 'pw'})

The Client Keeps Cookies

One handy detail: the test client remembers cookies between calls. After login, later requests stay authenticated with no extra work.

Reach a Protected Route

Now that you are logged in, request the guarded page again. This time assert you get a 200 and see the protected content.

resp = client.get('/dashboard')
assert resp.status_code == 200

A Helper to Log In

Repeating the login post gets noisy. Wrap it in a small helper function so every auth test reads cleanly in one line.

def login(client):
    return client.post('/login', data={'email': 'a@b.com', 'password': 'pw'})

An Authenticated Fixture

Even better, make a fixture that returns an already-logged-in client. Tests that need auth just request it and skip the setup.

@pytest.fixture
def auth_client(client):
    login(client)
    yield client

Test the Logout Flow

Auth is not done until logout works. Hit /logout, then confirm the protected route again rejects the now anonymous client.

client.get('/logout')
assert client.get('/dashboard').status_code == 302

Bypass Login for Speed

For Flask-Login apps you can skip the form and set the session directly. It is faster but tests less of the real login path.

with client.session_transaction() as sess:
    sess['_user_id'] = '1'

Test Token-Protected APIs

For JWT APIs there is no cookie. Send the token in an Authorization header on each request to reach a protected endpoint.

client.get('/api/me', headers={'Authorization': 'Bearer ' + token})

Test Both Sides of the Gate

Strong auth tests check both outcomes: anonymous users are blocked, and authenticated users are allowed. Cover the happy and the sad path.

Quick Check

You need to test a login-only dashboard. What makes it work?

Recap: Authenticated Tests

You log in through the client, lean on its cookie memory, and assert both blocked and allowed paths. Your auth is now fully covered. 🔐

คำถามที่พบบ่อย

บทเรียน “ทดสอบปลายทางที่ต้องยืนยันตัวตน” ฟรีหรือไม่

ใช่ — ข้อความเต็มของ “ทดสอบปลายทางที่ต้องยืนยันตัวตน” ฟรีให้อ่านที่นี่บนเว็บ เพื่อปฏิบัติแบบโต้ตอบ (ตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7) และปลดล็อคส่วนที่เหลือของคอร์ส Flask Academy ให้อัปเกรดเป็น CoddyKit PRO คอร์ส Flask Academy มีบทเรียนทั้งหมด 4 บทเรียน

คุณจะเรียนรู้อะไรในบทเรียน “ทดสอบปลายทางที่ต้องยืนยันตัวตน”

เข้าสู่ระบบภายในการทดสอบเพื่อเข้าถึงเส้นทางที่มีการป้องกัน คุณปฏิบัติ Flask Academy ด้วยโค้ดที่ใช้งานได้จริงที่คุณเรียกใช้โดยตรงในเบราว์เซอร์ และติวเตอร์ AI ตลอด 24/7 ตอบคำถามของคุณขณะที่คุณไปผ่านบทเรียน

คุณต้องมีประสบการณ์ก่อนที่จะเริ่มเรียน Flask Academy หรือไม่

ไม่จำเป็นต้องมีประสบการณ์มาก่อน Flask Academy บน CoddyKit ออกแบบมาสำหรับผู้เริ่มต้นไปจนถึงผู้เรียนขั้นสูง คุณสามารถเริ่มต้นที่นี่หรือเริ่มจากตัวแรกและเรียนด้วยความเร็วของคุณเอง นี่คือบทเรียนที่ 4 จากทั้งหมด 4 บทเรียน

บทเรียน “ทดสอบปลายทางที่ต้องยืนยันตัวตน” ใช้เวลานานแค่ไหน

บทเรียน CoddyKit ส่วนใหญ่ใช้เวลาประมาณ 5–10 นาที แต่ละบทเรียนจึงสั้นและเป็นแบบโต้ตอบ คุณสามารถก้าวหน้าอย่างต่อเนื่องและกลับมาเรียนต่อจากตรงที่เพิ่งหยุดบนเว็บและแอปได้เลย

ฉันเขียนและรันโค้ดในบทเรียน Flask Academy นี้ได้ไหม

ได้ บทเรียน Flask Academy ทุกบทมีตัวแก้ไขโค้ดในตัว คุณจึงเขียนและรันโค้ดจริงได้เลยในเบราว์เซอร์ และได้รับข้อเสนอแนะจาก AI ในทันที — ไม่ต้องติดตั้งในเครื่องของคุณ

บทเรียนทั้งหมดในหลักสูตรนี้

  1. ไคลเอนต์ทดสอบและอุปกรณ์ประกอบการทดสอบ
  2. ตรวจสอบเส้นทางและ JSON
  3. แยกการทดสอบด้วยฐานข้อมูลทดสอบ
  4. ทดสอบปลายทางที่ต้องยืนยันตัวตน
← กลับไปที่ Flask Academy