refactor: simplify auth and subscription links
This commit is contained in:
@@ -212,271 +212,6 @@ func TestTemplateDelete(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// --- GrantRepo: Get, GetSnapshot, Update, Delete, RestoreFromSnapshot ---
|
||||
|
||||
func TestGrantGet(t *testing.T) {
|
||||
db := testDB(t)
|
||||
defer db.Close()
|
||||
repo := NewGrantRepo(db)
|
||||
rec, _, _ := repo.Create("source", "src1", "mihomo", nil)
|
||||
|
||||
got, err := repo.Get(rec.ID)
|
||||
if err != nil {
|
||||
t.Fatalf("get failed: %v", err)
|
||||
}
|
||||
if got == nil {
|
||||
t.Fatal("expected non-nil grant")
|
||||
}
|
||||
if got.ResourceType != "source" {
|
||||
t.Errorf("expected resourceType source, got %s", got.ResourceType)
|
||||
}
|
||||
if got.ResourceId != "src1" {
|
||||
t.Errorf("expected resourceId src1, got %s", got.ResourceId)
|
||||
}
|
||||
}
|
||||
|
||||
func TestGrantGet_NotFound(t *testing.T) {
|
||||
db := testDB(t)
|
||||
defer db.Close()
|
||||
repo := NewGrantRepo(db)
|
||||
got, err := repo.Get("nonexistent")
|
||||
if err != nil {
|
||||
t.Fatalf("expected nil error for not found, got %v", err)
|
||||
}
|
||||
if got != nil {
|
||||
t.Error("expected nil for not found")
|
||||
}
|
||||
}
|
||||
|
||||
func TestGrantGetSnapshot(t *testing.T) {
|
||||
db := testDB(t)
|
||||
defer db.Close()
|
||||
repo := NewGrantRepo(db)
|
||||
rec, _, _ := repo.Create("source", "src1", "mihomo", nil)
|
||||
|
||||
snap, err := repo.GetSnapshot(rec.ID)
|
||||
if err != nil {
|
||||
t.Fatalf("getSnapshot failed: %v", err)
|
||||
}
|
||||
if snap == nil {
|
||||
t.Fatal("expected non-nil snapshot")
|
||||
}
|
||||
if snap["id"] != rec.ID {
|
||||
t.Errorf("expected id %s, got %v", rec.ID, snap["id"])
|
||||
}
|
||||
if snap["resourceType"] != "source" {
|
||||
t.Errorf("expected resourceType source, got %v", snap["resourceType"])
|
||||
}
|
||||
if snap["enabled"] != true {
|
||||
t.Errorf("expected enabled true, got %v", snap["enabled"])
|
||||
}
|
||||
if snap["tokenHash"] == "" {
|
||||
t.Error("expected non-empty tokenHash")
|
||||
}
|
||||
}
|
||||
|
||||
func TestGrantGetSnapshot_NotFound(t *testing.T) {
|
||||
db := testDB(t)
|
||||
defer db.Close()
|
||||
repo := NewGrantRepo(db)
|
||||
snap, err := repo.GetSnapshot("nonexistent")
|
||||
if err != nil {
|
||||
t.Fatalf("expected nil error, got %v", err)
|
||||
}
|
||||
if snap != nil {
|
||||
t.Error("expected nil snapshot for not found")
|
||||
}
|
||||
}
|
||||
|
||||
func TestGrantUpdate(t *testing.T) {
|
||||
db := testDB(t)
|
||||
defer db.Close()
|
||||
repo := NewGrantRepo(db)
|
||||
rec, _, _ := repo.Create("source", "src1", "mihomo", nil)
|
||||
|
||||
// Disable
|
||||
enabled := false
|
||||
updated, err := repo.Update(rec.ID, &enabled, nil)
|
||||
if err != nil {
|
||||
t.Fatalf("update failed: %v", err)
|
||||
}
|
||||
if updated.Enabled {
|
||||
t.Error("expected enabled false after update")
|
||||
}
|
||||
|
||||
// Set expiry
|
||||
exp := int64(9999999999000)
|
||||
updated, err = repo.Update(rec.ID, nil, &exp)
|
||||
if err != nil {
|
||||
t.Fatalf("update expiry failed: %v", err)
|
||||
}
|
||||
if updated.ExpiresAt == nil || *updated.ExpiresAt != exp {
|
||||
t.Errorf("expected expiresAt %d, got %v", exp, updated.ExpiresAt)
|
||||
}
|
||||
|
||||
// Set expiry to 0 -> treated as nil (never expire)
|
||||
zero := int64(0)
|
||||
updated, err = repo.Update(rec.ID, nil, &zero)
|
||||
if err != nil {
|
||||
t.Fatalf("update expiry zero failed: %v", err)
|
||||
}
|
||||
if updated.ExpiresAt != nil {
|
||||
t.Errorf("expected nil expiresAt for 0, got %v", updated.ExpiresAt)
|
||||
}
|
||||
}
|
||||
|
||||
func TestGrantUpdate_NotFound(t *testing.T) {
|
||||
db := testDB(t)
|
||||
defer db.Close()
|
||||
repo := NewGrantRepo(db)
|
||||
updated, err := repo.Update("nonexistent", nil, nil)
|
||||
if err != nil {
|
||||
t.Fatalf("expected nil error, got %v", err)
|
||||
}
|
||||
if updated != nil {
|
||||
t.Error("expected nil for not found")
|
||||
}
|
||||
}
|
||||
|
||||
func TestGrantDelete(t *testing.T) {
|
||||
db := testDB(t)
|
||||
defer db.Close()
|
||||
repo := NewGrantRepo(db)
|
||||
rec, _, _ := repo.Create("source", "src1", "mihomo", nil)
|
||||
|
||||
err := repo.Delete(rec.ID)
|
||||
if err != nil {
|
||||
t.Fatalf("delete failed: %v", err)
|
||||
}
|
||||
got, _ := repo.Get(rec.ID)
|
||||
if got != nil {
|
||||
t.Error("expected nil after delete")
|
||||
}
|
||||
}
|
||||
|
||||
func TestGrantRestoreFromSnapshot(t *testing.T) {
|
||||
db := testDB(t)
|
||||
defer db.Close()
|
||||
repo := NewGrantRepo(db)
|
||||
|
||||
snapshot := map[string]any{
|
||||
"id": "restored-grant",
|
||||
"tokenHash": "abc123",
|
||||
"resourceType": "collection",
|
||||
"resourceId": "col1",
|
||||
"target": "surge",
|
||||
"enabled": true,
|
||||
"createdAt": float64(1000),
|
||||
}
|
||||
err := repo.RestoreFromSnapshot(snapshot)
|
||||
if err != nil {
|
||||
t.Fatalf("restore failed: %v", err)
|
||||
}
|
||||
got, _ := repo.Get("restored-grant")
|
||||
if got == nil {
|
||||
t.Fatal("expected restored grant")
|
||||
}
|
||||
if got.ResourceType != "collection" {
|
||||
t.Errorf("expected resourceType collection, got %s", got.ResourceType)
|
||||
}
|
||||
if got.Target != "surge" {
|
||||
t.Errorf("expected target surge, got %s", got.Target)
|
||||
}
|
||||
}
|
||||
|
||||
func TestGrantRestoreFromSnapshot_DefaultsAndExpiry(t *testing.T) {
|
||||
db := testDB(t)
|
||||
defer db.Close()
|
||||
repo := NewGrantRepo(db)
|
||||
|
||||
// resourceType not "collection" -> defaults to "source"; enabled false; expiresAt positive
|
||||
snapshot := map[string]any{
|
||||
"id": "grant-defaults",
|
||||
"tokenHash": "hash2",
|
||||
"resourceType": "source",
|
||||
"resourceId": "src1",
|
||||
"target": "",
|
||||
"enabled": false,
|
||||
"expiresAt": float64(5000),
|
||||
}
|
||||
err := repo.RestoreFromSnapshot(snapshot)
|
||||
if err != nil {
|
||||
t.Fatalf("restore failed: %v", err)
|
||||
}
|
||||
got, _ := repo.Get("grant-defaults")
|
||||
if got == nil {
|
||||
t.Fatal("expected restored grant")
|
||||
}
|
||||
if got.ResourceType != "source" {
|
||||
t.Errorf("expected source, got %s", got.ResourceType)
|
||||
}
|
||||
if got.Enabled {
|
||||
t.Error("expected enabled false")
|
||||
}
|
||||
if got.ExpiresAt == nil || *got.ExpiresAt != 5000 {
|
||||
t.Errorf("expected expiresAt 5000, got %v", got.ExpiresAt)
|
||||
}
|
||||
}
|
||||
|
||||
func TestGrantRestoreFromSnapshot_NoCreatedAt(t *testing.T) {
|
||||
db := testDB(t)
|
||||
defer db.Close()
|
||||
repo := NewGrantRepo(db)
|
||||
|
||||
snapshot := map[string]any{
|
||||
"id": "grant-no-created",
|
||||
"tokenHash": "hash3",
|
||||
"resourceType": "source",
|
||||
"resourceId": "src1",
|
||||
}
|
||||
err := repo.RestoreFromSnapshot(snapshot)
|
||||
if err != nil {
|
||||
t.Fatalf("restore failed: %v", err)
|
||||
}
|
||||
got, _ := repo.Get("grant-no-created")
|
||||
if got == nil {
|
||||
t.Fatal("expected restored grant")
|
||||
}
|
||||
if got.CreatedAt == 0 {
|
||||
t.Error("expected non-zero createdAt (defaulted to now)")
|
||||
}
|
||||
}
|
||||
|
||||
func TestGrantAuthorizeScoped_EmptyToken(t *testing.T) {
|
||||
db := testDB(t)
|
||||
defer db.Close()
|
||||
repo := NewGrantRepo(db)
|
||||
if repo.AuthorizeScoped("", "source", "src1", "mihomo") {
|
||||
t.Error("expected false for empty token")
|
||||
}
|
||||
}
|
||||
|
||||
func TestGrantAuthorizeScoped_ExpiredGrant(t *testing.T) {
|
||||
db := testDB(t)
|
||||
defer db.Close()
|
||||
repo := NewGrantRepo(db)
|
||||
exp := time.Now().UnixMilli() - 1000
|
||||
rec, token, _ := repo.Create("source", "src1", "mihomo", &exp)
|
||||
_ = rec
|
||||
if repo.AuthorizeScoped(token, "source", "src1", "mihomo") {
|
||||
t.Error("expected false for expired grant")
|
||||
}
|
||||
}
|
||||
|
||||
func TestGrantAuthorizeScoped_UnrestrictedTarget(t *testing.T) {
|
||||
db := testDB(t)
|
||||
defer db.Close()
|
||||
repo := NewGrantRepo(db)
|
||||
// target = "" means unrestricted
|
||||
_, token, _ := repo.Create("source", "src1", "", nil)
|
||||
if !repo.AuthorizeScoped(token, "source", "src1", "surge") {
|
||||
t.Error("expected true for unrestricted target")
|
||||
}
|
||||
if !repo.AuthorizeScoped(token, "source", "src1", "mihomo") {
|
||||
t.Error("expected true for unrestricted target (mihomo)")
|
||||
}
|
||||
}
|
||||
|
||||
// --- RecycleRepo.parseSnapshot edge cases (via List/Get) ---
|
||||
|
||||
func TestParseSnapshot_Empty(t *testing.T) {
|
||||
|
||||
Reference in New Issue
Block a user