CodeIssuesDiscussionsWikiPull RequestsProjectsCommitsActionsReleasesContributorsPulse● GatesSecuritySettingsDeploymentsPipelineInsightsAgents✨ Explain✨ Ask AI✨ Workspace✨ Spec✨ Tests▓ Debt Map✨ NL Search🏛 Archaeology
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 | /**
* Block F3 — Admin panel smoke tests.
*
* Exercises the auth gate on every admin route + the lib exports. Doesn't
* mutate DB; `isSiteAdmin(null)` and `getFlag` against a non-existent key
* degrade gracefully and are safe to call in any environment.
*/
import { describe, it, expect } from "bun:test";
import app from "../app";
import {
isSiteAdmin,
KNOWN_FLAGS,
getFlag,
} from "../lib/admin";
describe("admin — auth gate", () => {
it("GET /admin without auth → 302 /login", async () => {
const res = await app.request("/admin");
expect(res.status).toBe(302);
expect(res.headers.get("location") || "").toContain("/login");
});
it("GET /admin/users without auth → 302 /login", async () => {
const res = await app.request("/admin/users");
expect(res.status).toBe(302);
expect(res.headers.get("location") || "").toContain("/login");
});
it("GET /admin/repos without auth → 302 /login", async () => {
const res = await app.request("/admin/repos");
expect(res.status).toBe(302);
expect(res.headers.get("location") || "").toContain("/login");
});
it("GET /admin/flags without auth → 302 /login", async () => {
const res = await app.request("/admin/flags");
expect(res.status).toBe(302);
expect(res.headers.get("location") || "").toContain("/login");
});
it("POST /admin/flags without auth → 302 /login", async () => {
const res = await app.request("/admin/flags", {
method: "POST",
body: new URLSearchParams({ registration_locked: "1" }),
headers: { "content-type": "application/x-www-form-urlencoded" },
});
expect(res.status).toBe(302);
expect(res.headers.get("location") || "").toContain("/login");
});
});
describe("admin — isSiteAdmin", () => {
it("returns false for null/undefined user", async () => {
expect(await isSiteAdmin(null)).toBe(false);
expect(await isSiteAdmin(undefined)).toBe(false);
expect(await isSiteAdmin("")).toBe(false);
});
it("returns false for non-existent user id", async () => {
const result = await isSiteAdmin("00000000-0000-0000-0000-000000000000");
expect(typeof result).toBe("boolean");
});
});
describe("admin — KNOWN_FLAGS", () => {
it("exposes registration_locked, site_banner_text, site_banner_level, read_only_mode", () => {
expect(KNOWN_FLAGS).toHaveProperty("registration_locked");
expect(KNOWN_FLAGS).toHaveProperty("site_banner_text");
expect(KNOWN_FLAGS).toHaveProperty("site_banner_level");
expect(KNOWN_FLAGS).toHaveProperty("read_only_mode");
});
it("defaults registration_locked to '0' (unlocked)", () => {
expect(KNOWN_FLAGS.registration_locked).toBe("0");
});
});
describe("admin — getFlag", () => {
it("returns null for unknown keys and never throws", async () => {
const v = await getFlag("nonexistent_flag_xyz");
expect(v === null || typeof v === "string").toBe(true);
});
});
describe("admin — lib exports", () => {
it("exports full admin surface", async () => {
const mod = await import("../lib/admin");
expect(typeof mod.isSiteAdmin).toBe("function");
expect(typeof mod.listSiteAdmins).toBe("function");
expect(typeof mod.grantSiteAdmin).toBe("function");
expect(typeof mod.revokeSiteAdmin).toBe("function");
expect(typeof mod.getFlag).toBe("function");
expect(typeof mod.setFlag).toBe("function");
expect(typeof mod.listFlags).toBe("function");
expect(mod.KNOWN_FLAGS).toBeDefined();
});
});
|