sh-mcp/packages/internal-data/test/dev-client.test.ts
Adam Moussa a60a5a5794 Add security-weighted test suite + coverage gate; wire tooling
Add tests for the highest-risk surface (build-plan §5, design.md §7.3):
tool-hiding, server-side scope enforcement (incl. forced hidden calls),
audience binding, input-schema validation, finance redaction on egress, audit
emission with hashed args, prompt-injection regression (tool output is data),
rate limiting, MCP conformance (in-memory transport round-trip), OpenAPI 3.1
validity, and local-auth safety. Add HTTP integration tests (supertest) for both
servers and per-package dev-client tests. 405 tests pass.

Wire the coverage gate into vitest.config.ts: 80% overall, with per-file
thresholds on the auth + dispatch crown jewels; exclude deferred real client
stubs, entrypoints, cdk apps, and aws-only config from the gate (documented).
Extend eslint flat config + add .prettierignore to cover servers/. Commit the
updated package-lock.json.
2026-06-26 12:48:26 -04:00

48 lines
1.8 KiB
TypeScript

import { describe, it, expect } from 'vitest';
import { InMemoryInternalDataClient } from '../src/dev-client.js';
describe('InMemoryInternalDataClient', () => {
describe('getWorkOrder', () => {
it('returns the seeded record for a known id', async () => {
const client = new InMemoryInternalDataClient();
const wo = await client.getWorkOrder('WO-1001');
expect(wo?.workOrderId).toBe('WO-1001');
expect(wo?.title).toBe('Replace dock lighting circuit');
expect(wo?.status).toBe('in_progress');
});
it('returns null for an unknown id', async () => {
const client = new InMemoryInternalDataClient();
expect(await client.getWorkOrder('WO-9999')).toBeNull();
});
});
describe('getPurchaseOrder', () => {
it('returns the seeded record for a known id', async () => {
const client = new InMemoryInternalDataClient();
const po = await client.getPurchaseOrder('PO-2001');
expect(po?.purchaseOrderId).toBe('PO-2001');
expect(po?.vendor).toBe('Coastal Supply & Hardware');
expect(po?.totalAmount).toBe(1842.5);
});
it('returns null for an unknown id', async () => {
const client = new InMemoryInternalDataClient();
expect(await client.getPurchaseOrder('PO-9999')).toBeNull();
});
});
describe('getSite', () => {
it('returns the seeded record for a known id', async () => {
const client = new InMemoryInternalDataClient();
const site = await client.getSite('SITE-01');
expect(site?.siteId).toBe('SITE-01');
expect(site?.name).toBe('Marina Pier Complex');
});
it('returns null for an unknown id', async () => {
const client = new InMemoryInternalDataClient();
expect(await client.getSite('SITE-99')).toBeNull();
});
});
});