CodeIssuesDiscussionsWikiPull RequestsProjectsCommitsActionsReleasesContributorsPulse● GatesSecuritySettingsDeploymentsPipelineInsightsAgents✨ Explain✨ Ask AI✨ Workspace✨ Spec✨ Tests▓ Debt Map✨ NL Search🏛 Archaeology
Blame · Line-by-line history
vapron-deploy.test.ts
Each line is annotated with the commit that last touched it. Click any SHA to jump to that commit and see the surrounding change.
| 43cf9b0 | 1 | /** |
| 9ecf5a4 | 2 | * BLK-016 — Vapron deploy webhook sender. |
| 43cf9b0 | 3 | * |
| 9ecf5a4 | 4 | * Asserts that `triggerVapronDeploy` (in `src/hooks/post-receive.ts`) |
| ba93444 | 5 | * matches the wire contract documented at the top of that helper, which |
| 9ecf5a4 | 6 | * is the inbound contract for Vapron's |
| ba93444 | 7 | * `apps/api/src/webhooks/gluecron-push.ts` receiver: |
| 43cf9b0 | 8 | * |
| 9ecf5a4 | 9 | * POST https://vapron.ai/api/webhooks/gluecron-push |
| 43cf9b0 | 10 | * Content-Type: application/json |
| ba93444 | 11 | * X-Gluecron-Signature: sha256=<hex(hmac-sha256(body, secret))> |
| 12 | * | |
| 13 | * body = { | |
| 14 | * event: "push", | |
| 15 | * repository: { full_name }, | |
| 16 | * ref, after, before, | |
| 17 | * pusher: { name, email }, | |
| 18 | * commits: [...] | |
| 19 | * } | |
| 20 | * | |
| 21 | * Plus at-least-once delivery: 5 attempts on 5xx with exponential backoff, | |
| 22 | * stop on first 2xx or unrecoverable 4xx. | |
| 43cf9b0 | 23 | * |
| 24 | * The helper swallows DB errors, so these tests work without a real DB. | |
| 25 | */ | |
| 26 | ||
| 27 | import { afterEach, beforeEach, describe, expect, it } from "bun:test"; | |
| ba93444 | 28 | import { createHmac } from "crypto"; |
| 43cf9b0 | 29 | import { __test } from "../hooks/post-receive"; |
| 9ecf5a4 | 30 | import { config } from "../lib/config"; |
| 43cf9b0 | 31 | |
| 9ecf5a4 | 32 | const { triggerVapronDeploy, signBody } = __test; |
| 43cf9b0 | 33 | |
| 34 | interface CapturedCall { | |
| 35 | url: string; | |
| 36 | init: RequestInit; | |
| 37 | } | |
| 38 | ||
| 39 | const origSecret = process.env.GLUECRON_WEBHOOK_SECRET; | |
| 9ecf5a4 | 40 | const origUrl = process.env.VAPRON_DEPLOY_URL; |
| 41 | const origRepo = process.env.VAPRON_REPO; | |
| ba93444 | 42 | |
| 43 | const NULL_REPO_ID = "00000000-0000-0000-0000-000000000000"; | |
| 44 | const ZERO_SHA = "0000000000000000000000000000000000000000"; | |
| 43cf9b0 | 45 | |
| ba93444 | 46 | function makeArgs(overrides: Partial<{ |
| 47 | owner: string; | |
| 48 | repo: string; | |
| 49 | before: string; | |
| 50 | after: string; | |
| 51 | ref: string; | |
| 52 | branch: string; | |
| 53 | repositoryId: string; | |
| 54 | }> = {}) { | |
| 55 | return { | |
| 56 | owner: "ccantynz-alt", | |
| 9ecf5a4 | 57 | repo: "vapron", |
| ba93444 | 58 | before: ZERO_SHA, |
| 59 | after: "a".repeat(40), | |
| 60 | ref: "refs/heads/Main", | |
| 61 | branch: "Main", | |
| 62 | repositoryId: NULL_REPO_ID, | |
| 63 | ...overrides, | |
| 64 | }; | |
| 65 | } | |
| 43cf9b0 | 66 | |
| ba93444 | 67 | function captureFetch( |
| 68 | responder: (callIdx: number) => Response | Promise<Response> = () => | |
| 43cf9b0 | 69 | new Response( |
| ba93444 | 70 | JSON.stringify({ ok: true, deploymentId: "d1" }), |
| 43cf9b0 | 71 | { status: 200, headers: { "Content-Type": "application/json" } } |
| 72 | ) | |
| ba93444 | 73 | ): { calls: CapturedCall[]; fn: typeof fetch } { |
| 43cf9b0 | 74 | const calls: CapturedCall[] = []; |
| ba93444 | 75 | const fn = (async ( |
| 43cf9b0 | 76 | input: RequestInfo | URL, |
| 77 | init: RequestInit = {} | |
| 78 | ): Promise<Response> => { | |
| ba93444 | 79 | const i = calls.length; |
| 43cf9b0 | 80 | calls.push({ url: String(input), init }); |
| ba93444 | 81 | return responder(i); |
| 82 | }) as unknown as typeof fetch; | |
| 83 | return { calls, fn }; | |
| 43cf9b0 | 84 | } |
| 85 | ||
| ba93444 | 86 | const noSleep = async (_ms: number) => {}; |
| 87 | ||
| 88 | describe("hooks/post-receive — signBody", () => { | |
| 89 | it("returns null when no secret", () => { | |
| 90 | expect(signBody("any body", "")).toBeNull(); | |
| 91 | }); | |
| 92 | ||
| 93 | it("produces sha256=<hex hmac>", () => { | |
| 94 | const body = '{"event":"push"}'; | |
| 95 | const secret = "topsecret"; | |
| 96 | const expected = | |
| 97 | "sha256=" + createHmac("sha256", secret).update(body).digest("hex"); | |
| 98 | expect(signBody(body, secret)).toBe(expected); | |
| 99 | }); | |
| 100 | ||
| 101 | it("is deterministic for the same input", () => { | |
| 102 | const a = signBody("body", "k"); | |
| 103 | const b = signBody("body", "k"); | |
| 104 | expect(a).toBe(b); | |
| 105 | }); | |
| 43cf9b0 | 106 | |
| ba93444 | 107 | it("changes when the body changes", () => { |
| 108 | const a = signBody("body1", "k"); | |
| 109 | const b = signBody("body2", "k"); | |
| 110 | expect(a).not.toBe(b); | |
| 111 | }); | |
| 112 | }); | |
| 43cf9b0 | 113 | |
| 9ecf5a4 | 114 | describe("hooks/post-receive — triggerVapronDeploy (BLK-016 sender)", () => { |
| 43cf9b0 | 115 | beforeEach(() => { |
| 116 | delete process.env.GLUECRON_WEBHOOK_SECRET; | |
| 9ecf5a4 | 117 | delete process.env.VAPRON_DEPLOY_URL; |
| 118 | delete process.env.VAPRON_REPO; | |
| 119 | delete process.env.VAPRON_HMAC_SECRET; | |
| 120 | // legacy names must not leak into the default-URL assertions | |
| 43cf9b0 | 121 | delete process.env.CRONTECH_DEPLOY_URL; |
| ba93444 | 122 | delete process.env.CRONTECH_REPO; |
| 9ecf5a4 | 123 | delete process.env.CRONTECH_HMAC_SECRET; |
| 43cf9b0 | 124 | }); |
| 125 | ||
| 126 | afterEach(() => { | |
| 127 | if (origSecret === undefined) delete process.env.GLUECRON_WEBHOOK_SECRET; | |
| 128 | else process.env.GLUECRON_WEBHOOK_SECRET = origSecret; | |
| 9ecf5a4 | 129 | if (origUrl === undefined) delete process.env.VAPRON_DEPLOY_URL; |
| 130 | else process.env.VAPRON_DEPLOY_URL = origUrl; | |
| 131 | if (origRepo === undefined) delete process.env.VAPRON_REPO; | |
| 132 | else process.env.VAPRON_REPO = origRepo; | |
| 43cf9b0 | 133 | }); |
| 134 | ||
| 135 | it("is exported from __test", () => { | |
| 9ecf5a4 | 136 | expect(typeof triggerVapronDeploy).toBe("function"); |
| 43cf9b0 | 137 | }); |
| 138 | ||
| 9ecf5a4 | 139 | it("POSTs to /api/webhooks/gluecron-push (matches Vapron receiver path)", async () => { |
| ba93444 | 140 | const { calls, fn } = captureFetch(); |
| 43cf9b0 | 141 | |
| 9ecf5a4 | 142 | await triggerVapronDeploy(makeArgs(), { fetchImpl: fn, sleep: noSleep }); |
| 43cf9b0 | 143 | |
| 144 | expect(calls.length).toBe(1); | |
| 145 | expect(calls[0]!.url).toBe( | |
| 9ecf5a4 | 146 | "https://vapron.ai/api/webhooks/gluecron-push" |
| 43cf9b0 | 147 | ); |
| ba93444 | 148 | expect(calls[0]!.url).not.toContain("/api/hooks/gluecron/push"); |
| 43cf9b0 | 149 | expect(calls[0]!.init.method).toBe("POST"); |
| 150 | }); | |
| 151 | ||
| 5164fab | 152 | it("posts a GitHub-shaped push payload (event, repository, ref, before/after, pusher, commits, sent_at, source)", async () => { |
| 153 | const after = "b".repeat(40); | |
| 154 | const before = "c".repeat(40); | |
| 155 | const { calls, fn } = captureFetch(); | |
| 43cf9b0 | 156 | |
| 9ecf5a4 | 157 | await triggerVapronDeploy( |
| ba93444 | 158 | makeArgs({ |
| 159 | owner: "acme", | |
| 160 | repo: "api", | |
| 161 | after, | |
| 162 | before, | |
| 163 | ref: "refs/heads/Main", | |
| 164 | branch: "Main", | |
| 165 | }), | |
| 166 | { fetchImpl: fn, sleep: noSleep } | |
| 43cf9b0 | 167 | ); |
| 168 | ||
| ba93444 | 169 | const body = JSON.parse(String(calls[0]!.init.body)); |
| 170 | expect(body.event).toBe("push"); | |
| 171 | expect(body.repository).toEqual({ full_name: "acme/api" }); | |
| 172 | expect(body.ref).toBe("refs/heads/Main"); | |
| 173 | expect(body.after).toBe(after); | |
| 174 | expect(body.before).toBe(before); | |
| 175 | expect(body.pusher).toBeDefined(); | |
| 176 | expect(typeof body.pusher.name).toBe("string"); | |
| 177 | expect(typeof body.pusher.email).toBe("string"); | |
| 178 | expect(Array.isArray(body.commits)).toBe(true); | |
| 179 | expect(typeof body.sent_at).toBe("string"); | |
| 180 | expect(new Date(body.sent_at).toString()).not.toBe("Invalid Date"); | |
| 181 | expect(body.source).toBe("gluecron"); | |
| 182 | }); | |
| 183 | ||
| 184 | it("signs the body with HMAC-SHA256 in X-Gluecron-Signature when secret is set", async () => { | |
| 185 | process.env.GLUECRON_WEBHOOK_SECRET = "shared-vultr-secret"; | |
| 186 | const { calls, fn } = captureFetch(); | |
| 187 | ||
| 9ecf5a4 | 188 | await triggerVapronDeploy(makeArgs(), { fetchImpl: fn, sleep: noSleep }); |
| ba93444 | 189 | |
| 43cf9b0 | 190 | const headers = calls[0]!.init.headers as Record<string, string>; |
| ba93444 | 191 | const sentBody = String(calls[0]!.init.body); |
| 192 | const expected = | |
| 193 | "sha256=" + | |
| 194 | createHmac("sha256", "shared-vultr-secret") | |
| 195 | .update(sentBody) | |
| 196 | .digest("hex"); | |
| 197 | expect(headers["X-Gluecron-Signature"]).toBe(expected); | |
| 43cf9b0 | 198 | expect(headers["Content-Type"]).toBe("application/json"); |
| 199 | }); | |
| 200 | ||
| ba93444 | 201 | it("omits X-Gluecron-Signature when no secret is configured", async () => { |
| 202 | const { calls, fn } = captureFetch(); | |
| 43cf9b0 | 203 | |
| 9ecf5a4 | 204 | await triggerVapronDeploy(makeArgs(), { fetchImpl: fn, sleep: noSleep }); |
| 43cf9b0 | 205 | |
| 206 | const headers = calls[0]!.init.headers as Record<string, string>; | |
| ba93444 | 207 | expect(headers["X-Gluecron-Signature"]).toBeUndefined(); |
| 43cf9b0 | 208 | }); |
| 209 | ||
| ba93444 | 210 | it("attaches X-Gluecron-Event=push and a non-empty X-Gluecron-Delivery id", async () => { |
| 211 | const { calls, fn } = captureFetch(); | |
| 212 | ||
| 9ecf5a4 | 213 | await triggerVapronDeploy(makeArgs(), { fetchImpl: fn, sleep: noSleep }); |
| ba93444 | 214 | |
| 215 | const headers = calls[0]!.init.headers as Record<string, string>; | |
| 216 | expect(headers["X-Gluecron-Event"]).toBe("push"); | |
| 217 | expect(headers["X-Gluecron-Delivery"]).toBeDefined(); | |
| 218 | expect(headers["X-Gluecron-Delivery"]!.length).toBeGreaterThan(0); | |
| 219 | }); | |
| 220 | ||
| 221 | it("ref carries the actual case of the branch (Main, not main)", async () => { | |
| 222 | const { calls, fn } = captureFetch(); | |
| 43cf9b0 | 223 | |
| 9ecf5a4 | 224 | await triggerVapronDeploy( |
| ba93444 | 225 | makeArgs({ ref: "refs/heads/Main", branch: "Main" }), |
| 226 | { fetchImpl: fn, sleep: noSleep } | |
| 43cf9b0 | 227 | ); |
| 228 | ||
| 229 | const body = JSON.parse(String(calls[0]!.init.body)); | |
| ba93444 | 230 | expect(body.ref).toBe("refs/heads/Main"); |
| 231 | expect(body.ref).not.toBe("refs/heads/main"); | |
| 43cf9b0 | 232 | }); |
| 233 | ||
| ba93444 | 234 | it("retries on 5xx with provided backoff schedule, stops on first 2xx", async () => { |
| 235 | const responses = [ | |
| 236 | new Response("", { status: 502 }), | |
| 237 | new Response("", { status: 503 }), | |
| 238 | new Response("", { status: 200 }), | |
| 239 | ]; | |
| 240 | const { calls, fn } = captureFetch((i) => responses[i]!); | |
| 241 | const sleeps: number[] = []; | |
| 43cf9b0 | 242 | |
| 9ecf5a4 | 243 | await triggerVapronDeploy(makeArgs(), { |
| ba93444 | 244 | fetchImpl: fn, |
| 245 | sleep: async (ms) => { sleeps.push(ms); }, | |
| 246 | retryDelaysMs: [10, 20, 30, 40, 50], | |
| 247 | }); | |
| 248 | ||
| 249 | expect(calls.length).toBe(3); | |
| 250 | // Two waits — between attempt 1→2 and 2→3. None after the successful 3rd. | |
| 251 | expect(sleeps).toEqual([10, 20]); | |
| 252 | }); | |
| 253 | ||
| 254 | it("gives up after the configured number of attempts on persistent 5xx", async () => { | |
| 255 | const { calls, fn } = captureFetch(() => new Response("", { status: 500 })); | |
| 256 | const sleeps: number[] = []; | |
| 257 | ||
| 9ecf5a4 | 258 | await triggerVapronDeploy(makeArgs(), { |
| ba93444 | 259 | fetchImpl: fn, |
| 260 | sleep: async (ms) => { sleeps.push(ms); }, | |
| 261 | retryDelaysMs: [1, 2, 3, 4, 5], | |
| 262 | }); | |
| 263 | ||
| 264 | // 5 delays + 1 initial = 6 total attempts (consistent with at-least-once). | |
| 265 | expect(calls.length).toBe(6); | |
| 266 | expect(sleeps).toEqual([1, 2, 3, 4, 5]); | |
| 267 | }); | |
| 268 | ||
| 269 | it("does not retry on unrecoverable 4xx (e.g. 401 invalid signature)", async () => { | |
| 270 | const { calls, fn } = captureFetch(() => new Response("", { status: 401 })); | |
| 271 | const sleeps: number[] = []; | |
| 272 | ||
| 9ecf5a4 | 273 | await triggerVapronDeploy(makeArgs(), { |
| ba93444 | 274 | fetchImpl: fn, |
| 275 | sleep: async (ms) => { sleeps.push(ms); }, | |
| 276 | retryDelaysMs: [1, 2, 3, 4, 5], | |
| 277 | }); | |
| 43cf9b0 | 278 | |
| 279 | expect(calls.length).toBe(1); | |
| ba93444 | 280 | expect(sleeps).toEqual([]); |
| 43cf9b0 | 281 | }); |
| 282 | ||
| ba93444 | 283 | it("does retry 408 (request timeout) and 429 (rate limit)", async () => { |
| 284 | const responses = [ | |
| 285 | new Response("", { status: 429 }), | |
| 286 | new Response("", { status: 408 }), | |
| 287 | new Response("", { status: 200 }), | |
| 288 | ]; | |
| 289 | const { calls, fn } = captureFetch((i) => responses[i]!); | |
| 290 | ||
| 9ecf5a4 | 291 | await triggerVapronDeploy(makeArgs(), { |
| ba93444 | 292 | fetchImpl: fn, |
| 293 | sleep: noSleep, | |
| 294 | retryDelaysMs: [1, 2, 3, 4, 5], | |
| 295 | }); | |
| 296 | ||
| 297 | expect(calls.length).toBe(3); | |
| 298 | }); | |
| 299 | ||
| 300 | it("retries on network errors (fetch throws)", async () => { | |
| 301 | let callCount = 0; | |
| 302 | const fn = (async () => { | |
| 303 | callCount++; | |
| 304 | if (callCount < 3) throw new Error("ECONNREFUSED"); | |
| 305 | return new Response("", { status: 200 }); | |
| 306 | }) as unknown as typeof fetch; | |
| 307 | ||
| 9ecf5a4 | 308 | await triggerVapronDeploy(makeArgs(), { |
| ba93444 | 309 | fetchImpl: fn, |
| 310 | sleep: noSleep, | |
| 311 | retryDelaysMs: [1, 2, 3, 4, 5], | |
| 312 | }); | |
| 313 | ||
| 314 | expect(callCount).toBe(3); | |
| 43cf9b0 | 315 | }); |
| 316 | ||
| ba93444 | 317 | it("does not throw when receiver responds 401 (unconfigured-secret path)", async () => { |
| 318 | const { fn } = captureFetch(() => new Response("", { status: 401 })); | |
| 43cf9b0 | 319 | await expect( |
| 9ecf5a4 | 320 | triggerVapronDeploy(makeArgs(), { fetchImpl: fn, sleep: noSleep }) |
| 43cf9b0 | 321 | ).resolves.toBeUndefined(); |
| ba93444 | 322 | }); |
| 323 | ||
| 324 | it("uses a default exponential-backoff schedule of 1s/4s/16s/64s/256s", () => { | |
| 325 | expect(__test.RETRY_DELAYS_MS).toEqual([1_000, 4_000, 16_000, 64_000, 256_000]); | |
| 43cf9b0 | 326 | }); |
| 327 | }); | |
| 9ecf5a4 | 328 | |
| 329 | describe("vapron config — legacy CRONTECH_* env fallback", () => { | |
| 330 | const KEYS = [ | |
| 331 | "VAPRON_DEPLOY_URL", "CRONTECH_DEPLOY_URL", | |
| 332 | "VAPRON_REPO", "CRONTECH_REPO", | |
| 333 | "VAPRON_HMAC_SECRET", "CRONTECH_HMAC_SECRET", "GLUECRON_WEBHOOK_SECRET", | |
| 334 | ] as const; | |
| 335 | const saved: Record<string, string | undefined> = {}; | |
| 336 | beforeEach(() => { | |
| 337 | for (const k of KEYS) { saved[k] = process.env[k]; delete process.env[k]; } | |
| 338 | }); | |
| 339 | afterEach(() => { | |
| 340 | for (const k of KEYS) { | |
| 341 | if (saved[k] === undefined) delete process.env[k]; | |
| 342 | else process.env[k] = saved[k]!; | |
| 343 | } | |
| 344 | }); | |
| 345 | ||
| 346 | it("defaults to the vapron.ai webhook URL and ccantynz-alt/vapron repo", () => { | |
| 347 | expect(config.vapronDeployUrl).toBe("https://vapron.ai/api/webhooks/gluecron-push"); | |
| 348 | expect(config.vapronRepo).toBe("ccantynz-alt/vapron"); | |
| 349 | }); | |
| 350 | ||
| 351 | it("VAPRON_* wins over legacy CRONTECH_*", () => { | |
| 352 | process.env.VAPRON_DEPLOY_URL = "https://vapron.ai/hook-a"; | |
| 353 | process.env.CRONTECH_DEPLOY_URL = "https://crontech.ai/hook-b"; | |
| 354 | process.env.VAPRON_REPO = "o/new"; | |
| 355 | process.env.CRONTECH_REPO = "o/old"; | |
| 356 | process.env.VAPRON_HMAC_SECRET = "new-secret"; | |
| 357 | process.env.CRONTECH_HMAC_SECRET = "old-secret"; | |
| 358 | expect(config.vapronDeployUrl).toBe("https://vapron.ai/hook-a"); | |
| 359 | expect(config.vapronRepo).toBe("o/new"); | |
| 360 | expect(config.vapronHmacSecret).toBe("new-secret"); | |
| 361 | }); | |
| 362 | ||
| 363 | it("legacy CRONTECH_* still works when VAPRON_* is unset", () => { | |
| 364 | process.env.CRONTECH_DEPLOY_URL = "https://crontech.ai/hook-b"; | |
| 365 | process.env.CRONTECH_REPO = "o/old"; | |
| 366 | process.env.CRONTECH_HMAC_SECRET = "old-secret"; | |
| 367 | expect(config.vapronDeployUrl).toBe("https://crontech.ai/hook-b"); | |
| 368 | expect(config.vapronRepo).toBe("o/old"); | |
| 369 | expect(config.vapronHmacSecret).toBe("old-secret"); | |
| 370 | }); | |
| 371 | ||
| 372 | it("HMAC secret falls back to GLUECRON_WEBHOOK_SECRET last", () => { | |
| 373 | process.env.GLUECRON_WEBHOOK_SECRET = "oldest-secret"; | |
| 374 | expect(config.vapronHmacSecret).toBe("oldest-secret"); | |
| 375 | }); | |
| 376 | }); |