sh-mcp/packages/qbo/test/dev-client.test.ts
Adam Moussa a60a5a5794 Add security-weighted test suite + coverage gate; wire tooling
Add tests for the highest-risk surface (build-plan §5, design.md §7.3):
tool-hiding, server-side scope enforcement (incl. forced hidden calls),
audience binding, input-schema validation, finance redaction on egress, audit
emission with hashed args, prompt-injection regression (tool output is data),
rate limiting, MCP conformance (in-memory transport round-trip), OpenAPI 3.1
validity, and local-auth safety. Add HTTP integration tests (supertest) for both
servers and per-package dev-client tests. 405 tests pass.

Wire the coverage gate into vitest.config.ts: 80% overall, with per-file
thresholds on the auth + dispatch crown jewels; exclude deferred real client
stubs, entrypoints, cdk apps, and aws-only config from the gate (documented).
Extend eslint flat config + add .prettierignore to cover servers/. Commit the
updated package-lock.json.
2026-06-26 12:48:26 -04:00

35 lines
1.5 KiB
TypeScript

import { describe, it, expect } from 'vitest';
import { InMemoryQboClient } from '../src/dev-client.js';
describe('InMemoryQboClient', () => {
describe('searchVendors', () => {
it('returns all seeded vendors with a totalCount for an empty query', async () => {
const client = new InMemoryQboClient();
const result = await client.searchVendors({ query: '' });
expect(result.totalCount).toBe(3);
expect(result.vendors.map((v) => v.id)).toEqual(['101', '102', '103']);
});
it('filters by case-insensitive substring on displayName', async () => {
const client = new InMemoryQboClient();
const result = await client.searchVendors({ query: 'coastal' });
expect(result.totalCount).toBe(1);
expect(result.vendors.map((v) => v.displayName)).toEqual(['Coastal Supply & Hardware']);
expect(result.vendors[0].taxId).toBe('98-7654321');
});
it('respects maxResults (totalCount reflects all matches, vendors is capped)', async () => {
const client = new InMemoryQboClient();
const result = await client.searchVendors({ query: '', maxResults: 2 });
expect(result.vendors).toHaveLength(2);
expect(result.totalCount).toBe(3);
});
it('returns an empty vendor list with zero totalCount when nothing matches', async () => {
const client = new InMemoryQboClient();
const result = await client.searchVendors({ query: 'zzz-nomatch' });
expect(result.vendors).toEqual([]);
expect(result.totalCount).toBe(0);
});
});
});