mirror of
https://github.com/Sea-Haven-Industries/seahaven-ap.git
synced 2026-10-05 22:21:57 +00:00
110 lines
3.2 KiB
TypeScript
110 lines
3.2 KiB
TypeScript
|
|
import { describe, expect, it, vi } from "vitest";
|
||
|
|
import { createApp } from "./app.js";
|
||
|
|
import type { Db } from "./db/client.js";
|
||
|
|
import { loadEnv } from "./env.js";
|
||
|
|
import type { AuthUser } from "./auth/upsert-user.js";
|
||
|
|
|
||
|
|
const sampleUser: AuthUser = {
|
||
|
|
id: "11111111-1111-4111-8111-111111111111",
|
||
|
|
cognitoSub: "seed-sub-admin",
|
||
|
|
email: "admin@seahavenind.com",
|
||
|
|
name: "Dev Admin",
|
||
|
|
role: "admin",
|
||
|
|
};
|
||
|
|
|
||
|
|
function createTestDb(options?: { pingFails?: boolean }): Db {
|
||
|
|
const userRow = {
|
||
|
|
id: sampleUser.id,
|
||
|
|
cognitoSub: sampleUser.cognitoSub,
|
||
|
|
email: sampleUser.email,
|
||
|
|
name: sampleUser.name,
|
||
|
|
role: sampleUser.role,
|
||
|
|
createdAt: new Date(),
|
||
|
|
updatedAt: new Date(),
|
||
|
|
};
|
||
|
|
|
||
|
|
const db = {
|
||
|
|
execute: vi.fn(async () => {
|
||
|
|
if (options?.pingFails) {
|
||
|
|
throw new Error("db down");
|
||
|
|
}
|
||
|
|
return [];
|
||
|
|
}),
|
||
|
|
query: {
|
||
|
|
users: {
|
||
|
|
findFirst: vi.fn(async () => userRow),
|
||
|
|
},
|
||
|
|
},
|
||
|
|
update: vi.fn(() => ({
|
||
|
|
set: vi.fn(() => ({
|
||
|
|
where: vi.fn(() => ({
|
||
|
|
returning: vi.fn(async () => [userRow]),
|
||
|
|
})),
|
||
|
|
})),
|
||
|
|
})),
|
||
|
|
insert: vi.fn(() => ({
|
||
|
|
values: vi.fn(() => ({
|
||
|
|
returning: vi.fn(async () => [userRow]),
|
||
|
|
})),
|
||
|
|
})),
|
||
|
|
};
|
||
|
|
|
||
|
|
return {
|
||
|
|
driver: "postgres",
|
||
|
|
pool: { end: vi.fn(async () => undefined) } as never,
|
||
|
|
db: db as never,
|
||
|
|
};
|
||
|
|
}
|
||
|
|
|
||
|
|
describe("createApp smoke routes", () => {
|
||
|
|
const env = loadEnv({
|
||
|
|
NODE_ENV: "test",
|
||
|
|
DEV_AUTH_BYPASS: "true",
|
||
|
|
DEV_AUTH_SUB: sampleUser.cognitoSub,
|
||
|
|
DEV_AUTH_EMAIL: sampleUser.email,
|
||
|
|
DEV_AUTH_NAME: sampleUser.name,
|
||
|
|
DEV_AUTH_ROLE: sampleUser.role,
|
||
|
|
});
|
||
|
|
|
||
|
|
it("GET /health returns ok when the database pings", async () => {
|
||
|
|
const app = createApp(env, createTestDb());
|
||
|
|
const response = await app.request("/health");
|
||
|
|
expect(response.status).toBe(200);
|
||
|
|
await expect(response.json()).resolves.toEqual({ status: "ok", database: "up" });
|
||
|
|
});
|
||
|
|
|
||
|
|
it("GET /health returns error payload when the database is down", async () => {
|
||
|
|
const app = createApp(env, createTestDb({ pingFails: true }));
|
||
|
|
const response = await app.request("/health");
|
||
|
|
expect(response.status).toBe(503);
|
||
|
|
await expect(response.json()).resolves.toEqual({ error: "Database is unavailable." });
|
||
|
|
});
|
||
|
|
|
||
|
|
it("GET /api/me returns the upserted caller under DEV_AUTH_BYPASS", async () => {
|
||
|
|
const app = createApp(env, createTestDb());
|
||
|
|
const response = await app.request("/api/me");
|
||
|
|
expect(response.status).toBe(200);
|
||
|
|
await expect(response.json()).resolves.toEqual({
|
||
|
|
id: sampleUser.id,
|
||
|
|
email: sampleUser.email,
|
||
|
|
name: sampleUser.name,
|
||
|
|
role: sampleUser.role,
|
||
|
|
});
|
||
|
|
});
|
||
|
|
|
||
|
|
it("GET /api/me rejects missing bearer token when bypass is off", async () => {
|
||
|
|
const secureEnv = loadEnv({
|
||
|
|
NODE_ENV: "test",
|
||
|
|
DEV_AUTH_BYPASS: "false",
|
||
|
|
COGNITO_ISSUER: "https://cognito-idp.us-east-1.amazonaws.com/test",
|
||
|
|
COGNITO_AUDIENCE: "test-audience",
|
||
|
|
});
|
||
|
|
const app = createApp(secureEnv, createTestDb());
|
||
|
|
const response = await app.request("/api/me");
|
||
|
|
expect(response.status).toBe(401);
|
||
|
|
await expect(response.json()).resolves.toEqual({
|
||
|
|
error: "Missing or invalid Authorization header.",
|
||
|
|
});
|
||
|
|
});
|
||
|
|
});
|