sh-mcp/packages/payments/test/dev-client.test.ts
Adam Moussa a60a5a5794 Add security-weighted test suite + coverage gate; wire tooling
Add tests for the highest-risk surface (build-plan §5, design.md §7.3):
tool-hiding, server-side scope enforcement (incl. forced hidden calls),
audience binding, input-schema validation, finance redaction on egress, audit
emission with hashed args, prompt-injection regression (tool output is data),
rate limiting, MCP conformance (in-memory transport round-trip), OpenAPI 3.1
validity, and local-auth safety. Add HTTP integration tests (supertest) for both
servers and per-package dev-client tests. 405 tests pass.

Wire the coverage gate into vitest.config.ts: 80% overall, with per-file
thresholds on the auth + dispatch crown jewels; exclude deferred real client
stubs, entrypoints, cdk apps, and aws-only config from the gate (documented).
Extend eslint flat config + add .prettierignore to cover servers/. Commit the
updated package-lock.json.
2026-06-26 12:48:26 -04:00

66 lines
2.6 KiB
TypeScript

import { describe, it, expect } from 'vitest';
import { InMemoryPaymentsClient } from '../src/dev-client.js';
describe('InMemoryPaymentsClient', () => {
describe('getByVendor', () => {
it('matches case-insensitively on a substring of the vendor name', async () => {
const client = new InMemoryPaymentsClient();
const results = await client.getByVendor('harbor electric');
expect(results.map((p) => p.paymentId)).toEqual(['PAY-9001']);
});
it('returns the raw record with sensitive fields present (no redaction at client layer)', async () => {
const client = new InMemoryPaymentsClient();
const [payment] = await client.getByVendor('Harbor Electric Co.');
expect(payment.bankAccountNumber).toBe('123456789012');
expect(payment.bankRoutingNumber).toBe('021000021');
expect(payment.cardNumber).toBe('4111111111111111');
});
it('respects opts.limit', async () => {
const client = new InMemoryPaymentsClient();
const results = await client.getByVendor('', { limit: 2 });
expect(results).toHaveLength(2);
});
});
describe('getByInvoice', () => {
it('returns the matching payment by exact invoice number', async () => {
const client = new InMemoryPaymentsClient();
const results = await client.getByInvoice('INV-3310');
expect(results.map((p) => p.paymentId)).toEqual(['PAY-9002']);
expect(results[0].bankAccountNumber).toBe('987654321098');
});
it('returns an empty list for an unknown invoice', async () => {
const client = new InMemoryPaymentsClient();
expect(await client.getByInvoice('INV-0000')).toEqual([]);
});
it('respects opts.limit', async () => {
const client = new InMemoryPaymentsClient();
const results = await client.getByInvoice('INV-3310', { limit: 0 });
expect(results).toHaveLength(0);
});
});
describe('getByCheck', () => {
it('returns the matching payment by exact check number', async () => {
const client = new InMemoryPaymentsClient();
const results = await client.getByCheck('2089');
expect(results.map((p) => p.paymentId)).toEqual(['PAY-9003']);
expect(results[0].cardNumber).toBe('340000000000009');
});
it('returns an empty list for an unknown check', async () => {
const client = new InMemoryPaymentsClient();
expect(await client.getByCheck('0000')).toEqual([]);
});
it('respects opts.limit', async () => {
const client = new InMemoryPaymentsClient();
const results = await client.getByCheck('2089', { limit: 1 });
expect(results).toHaveLength(1);
});
});
});