Backend truoc day chi co script goi httpx vao server dang chay that
(test_auth.py, test_full_api.py), khong phai pytest that. Them bo test
chay doc lap bang SQLite in-memory (khong can Postgres/Docker):
- test_rbac_deps.py: RBAC chain + regression-guard cho fix vai tro o /orders/place
- test_order_exchange_routing.py: routing dung san theo credential
- test_security_encryption.py: AES-GCM round-trip + tuong thich nguoc AES-CBC
- test_cors_config.py: CORS fail-closed khi thieu cau hinh
- test_risk_manager.py: Kelly sizing + SL/TP adaptive theo tung regime
- test_trade_executor.py: STRONG-only, dedup, reversal, volatility filter,
hybrid eviction FIFO -- toan bo quy tac mo/dong trade
- test_signal_service_scoring.py: he thong cham diem 13 thuat toan
Them .gitea/workflows/backend-tests.yml chay pytest tu dong khi push/PR
dung vao backend/** (can Gitea Actions + runner da duoc bat tren instance).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- orders.place_order: yêu cầu role trader/admin (get_current_trader_user)
thay vì bất kỳ user đã đăng nhập nào — viewer không còn đặt được lệnh thật
- orders.place_order: resolve exchange theo OrderRequest.exchange thay vì
hardcode "mexc", fallback về credential active gần nhất nếu không truyền
- security.py: mã hoá API key chuyển AES-256-CBC -> AES-256-GCM (có xác thực
toàn vẹn), giữ đường giải mã cũ để credential đã lưu trước đây không hỏng
- main_api.py: CORS_ORIGINS rỗng -> deny-all thay vì fallback "*" (kèm
allow_credentials=True là cấu hình nguy hiểm)
- docker-compose.yml: đồng bộ DB_PASSWORD giữa backend-api/scheduler và db
- frontend: OrderPanel/DashboardPage truyền kèm exchange đang chọn khi đặt lệnh
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>