Files
kite/backend/load_tests
curo1305andClaude Sonnet 4.6 c38c6b1c01 feat(07.1): session revocation on privilege change — CR-01/CR-02/CR-03
- revoke_all_refresh_tokens: add skip_token_hash optional param (exclude
  current session while revoking others)
- change_password, enable_totp, disable_totp: call revoke with skip hash
  derived from refresh cookie; return sessions_revoked in response and
  write to audit log metadata_
- 3 new tests: test_{change_password,enable_totp,disable_totp}_revokes_other_sessions
  — all PASSED; 373 total passing, 0 regressions
- Frontend toasts: SettingsAccountTab + TotpEnrollment show
  "Other sessions have been terminated." when sessions_revoked > 0
- Companion fixes: rate_limiting get_client_ip refactor, deps/auth.py
  request.state.current_user, locustfile refresh-token task removal
- Version bump: 0.1.0 → 0.1.1

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-05 12:47:16 +02:00
..

DocuVault Load Tests

Phase 6 load test suite targeting the D-04/D-05/D-06 SLA requirements.

Prerequisites

  1. Install load-test dependencies (host or dedicated venv — not the production container):

    pip install -r backend/requirements-dev.txt
    
  2. Start the full stack:

    docker compose up
    

    Backend, PostgreSQL, and MinIO must all be healthy before running.

Running the load test

locust --headless \
       --users 50 \
       --spawn-rate 10 \
       --run-time 5m \
       --host http://localhost:8000 \
       --csv backend/load_tests/results \
       -f backend/load_tests/locustfile.py

Exit code 0 = SLA targets met. Exit code 1 = at least one threshold breached.

Environment variables

Variable Default Description
LOAD_TEST_EMAIL loadtest@example.com Email used to register/login the load-test user
LOAD_TEST_PASSWORD Loadtest123!@# Password for the load-test account (meets AUTH-01 strength rules)

Override before running:

LOAD_TEST_EMAIL=mytest@staging.example.com \
LOAD_TEST_PASSWORD='MyS3cure!Pass' \
locust --headless ...

SLA thresholds (D-06)

Metric Threshold On breach
p95 response time < 200 ms exit code 1
p99 response time < 500 ms exit code 1
Error ratio ≤ 1% exit code 1

Task weights (D-05 realistic session)

Task Weight Endpoint
List documents 5 GET /api/documents/
Get document 3 GET /api/documents/{id}
Upload document 2 POST /api/documents/upload (direct multipart, target_backend=minio)
Refresh token 1 POST /api/auth/refresh

Credential strategy

on_start() uses self-bootstrapping (Option A): it calls POST /api/auth/register first (idempotent — 409 is silently ignored if the user already exists), then logs in. No manual seeding step required.

Cleanup

Remove the load-test user from the database when no longer needed:

docker compose exec postgres psql -U docuvault -c \
    "DELETE FROM users WHERE email='loadtest@example.com';"

Results

CSV files are written to backend/load_tests/results_*.csv by the --csv flag. These files are gitignored. To view a summary after a headless run, add --html backend/load_tests/report.html.

Notes

  • Load tests run outside the production container — install on the host or a test venv.
  • Do not run against a production URL without an explicit --host override and stakeholder sign-off.
  • The synthetic upload file (_FAKE_PDF) is a minimal valid PDF — it will be stored in MinIO during the run and cleared when the load-test user is deleted.