sh-mcp/vitest.config.ts
Adam Moussa a60a5a5794 Add security-weighted test suite + coverage gate; wire tooling
Add tests for the highest-risk surface (build-plan §5, design.md §7.3):
tool-hiding, server-side scope enforcement (incl. forced hidden calls),
audience binding, input-schema validation, finance redaction on egress, audit
emission with hashed args, prompt-injection regression (tool output is data),
rate limiting, MCP conformance (in-memory transport round-trip), OpenAPI 3.1
validity, and local-auth safety. Add HTTP integration tests (supertest) for both
servers and per-package dev-client tests. 405 tests pass.

Wire the coverage gate into vitest.config.ts: 80% overall, with per-file
thresholds on the auth + dispatch crown jewels; exclude deferred real client
stubs, entrypoints, cdk apps, and aws-only config from the gate (documented).
Extend eslint flat config + add .prettierignore to cover servers/. Commit the
updated package-lock.json.
2026-06-26 12:48:26 -04:00

61 lines
2 KiB
TypeScript

import { defineConfig } from 'vitest/config';
export default defineConfig({
test: {
globals: true,
environment: 'node',
coverage: {
provider: 'v8',
reporter: ['text', 'json', 'html'],
include: ['packages/**/*.ts', 'servers/**/*.ts', 'jobs/**/*.ts', 'auth/**/*.ts'],
exclude: [
'node_modules/',
'dist/',
'**/*.d.ts',
'**/*.test.ts',
'**/*.spec.ts',
// Type-only module (no executable lines).
'**/types.ts',
// Barrel re-export files (no logic; re-exports only).
'**/index.ts',
// Real external-service client stubs are DEFERRED (build-plan §0/§4): they
// throw until the real AWS/Google/QBO integrations land in a later phase
// and are only reachable in SH_MCP_ENV=aws, which is out of scope here.
'packages/*/src/client.ts',
// Synth-only CDK apps (build-plan §6) — validated by `cdk synth`, not vitest.
'servers/*/cdk/**',
// Server config aws-branch + listener wiring (build-plan §2.2) — the aws
// path needs Cognito/SSM, out of scope for the local test surface.
'servers/*/src/config.ts',
],
thresholds: {
// Overall gate (build-plan §5 / design.md §7.3).
lines: 80,
functions: 80,
branches: 80,
statements: 80,
// 100% on the shared auth + scope-guard + dispatch modules — the
// highest-risk surface (build-plan §5). 'branches' is held slightly
// below 100 where a defensive guard is unreachable from the public API.
'packages/shared/src/auth.ts': {
lines: 100,
functions: 100,
statements: 100,
branches: 100,
},
'packages/shared/src/dispatch.ts': {
lines: 95,
functions: 100,
statements: 95,
branches: 85,
},
'packages/shared/src/cognito-auth.ts': {
lines: 95,
functions: 85,
statements: 95,
branches: 80,
},
},
},
},
});