aafdd46a4b
Server-rendered admin console in the backend at /_gm (internal/adminconsole), fronted on the gateway's public listener by Basic-Auth + a verbatim reverse proxy (mounted on the edge mux below the h2c wrap). A same-origin check guards its POSTs; no operator identity is tracked. This supersedes the Stage 6 gateway-fronts- /api/v1/admin model: GATEWAY_ADMIN_ADDR and the backend /api/v1/admin ping are dropped and gateway/internal/admin is repurposed to the verbatim proxy. - Complaints: migration 00008 (+ jetgen) adds disposition/resolution_note/ resolved_at/applied_in_version + the deferred status CHECK; resolution feeds a query-derived pending dictionary-change pipeline (marked applied after a reload). - Dictionary hot-reload: per-version subdir BACKEND_DICT_DIR/<version>/ via the new Registry.LoadAvailable; engine.OpenWithVersions restores resident versions on restart. Partially addresses TODO-2. - Broadcasts: a backend Telegram-connector client (internal/connector, BACKEND_CONNECTOR_ADDR) for SendToUser / SendToGameChannel (discharges the Stage 9 forward-note). - Admin reads: account.ListAccounts/CountAccounts/Identities and game.ListGames/CountGames/GameByID/ListComplaints/GetComplaint/CountComplaints/ ResolveComplaint/DictionaryChanges/MarkChangesApplied. - Tests: adminconsole render, engine reload, same-origin guard, gateway verbatim proxy + h2c console mount, inttest complaint pipeline + list/count + /_gm console. - Docs: PLAN (Stage 10 done + refinements + TODO-2), ARCHITECTURE §1/§5/§6/§12/§13, FUNCTIONAL (+_ru), TESTING, backend/gateway READMEs.
76 lines
2.3 KiB
Go
76 lines
2.3 KiB
Go
package server
|
|
|
|
import (
|
|
"net/http"
|
|
"net/http/httptest"
|
|
"strings"
|
|
"testing"
|
|
|
|
"github.com/google/uuid"
|
|
|
|
"scrabble/backend/internal/account"
|
|
"scrabble/backend/internal/game"
|
|
"scrabble/backend/internal/session"
|
|
)
|
|
|
|
// newRoutingServer builds a Server with non-nil (zero-value) services so the
|
|
// routes register. The tests below exercise only the request-validation and
|
|
// routing layers, which return before any service method is called; full
|
|
// endpoint behaviour against real services is covered by the integration suite.
|
|
func newRoutingServer() *Server {
|
|
return New(":0", Deps{
|
|
Sessions: &session.Service{},
|
|
Accounts: &account.Store{},
|
|
Games: &game.Service{},
|
|
})
|
|
}
|
|
|
|
func do(t *testing.T, s *Server, method, path, body string, headers map[string]string) *httptest.ResponseRecorder {
|
|
t.Helper()
|
|
var rdr *strings.Reader
|
|
if body != "" {
|
|
rdr = strings.NewReader(body)
|
|
} else {
|
|
rdr = strings.NewReader("")
|
|
}
|
|
req := httptest.NewRequest(method, path, rdr)
|
|
req.Header.Set("Content-Type", "application/json")
|
|
for k, v := range headers {
|
|
req.Header.Set(k, v)
|
|
}
|
|
rec := httptest.NewRecorder()
|
|
s.Handler().ServeHTTP(rec, req)
|
|
return rec
|
|
}
|
|
|
|
func TestProfileRequiresUserID(t *testing.T) {
|
|
rec := do(t, newRoutingServer(), http.MethodGet, "/api/v1/user/profile", "", nil)
|
|
if rec.Code != http.StatusUnauthorized {
|
|
t.Fatalf("profile without X-User-ID = %d, want 401", rec.Code)
|
|
}
|
|
}
|
|
|
|
func TestResolveSessionRejectsEmptyToken(t *testing.T) {
|
|
rec := do(t, newRoutingServer(), http.MethodPost, "/api/v1/internal/sessions/resolve", `{}`, nil)
|
|
if rec.Code != http.StatusBadRequest {
|
|
t.Fatalf("resolve with empty token = %d, want 400", rec.Code)
|
|
}
|
|
}
|
|
|
|
func TestSubmitPlayRejectsBadDirection(t *testing.T) {
|
|
headers := map[string]string{"X-User-ID": uuid.New().String()}
|
|
path := "/api/v1/user/games/" + uuid.New().String() + "/play"
|
|
rec := do(t, newRoutingServer(), http.MethodPost, path, `{"dir":"X","tiles":[]}`, headers)
|
|
if rec.Code != http.StatusBadRequest {
|
|
t.Fatalf("submit play bad dir = %d, want 400", rec.Code)
|
|
}
|
|
}
|
|
|
|
func TestSubmitPlayRejectsBadGameID(t *testing.T) {
|
|
headers := map[string]string{"X-User-ID": uuid.New().String()}
|
|
rec := do(t, newRoutingServer(), http.MethodPost, "/api/v1/user/games/not-a-uuid/play", `{"dir":"H"}`, headers)
|
|
if rec.Code != http.StatusBadRequest {
|
|
t.Fatalf("submit play bad game id = %d, want 400", rec.Code)
|
|
}
|
|
}
|