Pre-launch — Gluecron is in final validation. Public signups and git hosting for non-owner users open after launch review.
CodeIssuesDiscussionsWikiPull RequestsProjectsCommitsActionsReleasesContributorsPulse● GatesSecuritySettingsDeploymentsPipelineInsightsAgents✨ Explain✨ Ask AI✨ Workspace✨ Spec✨ Tests▓ Debt Map✨ NL Search🏛 Archaeology
claude/adoring-hopper-5x74bqclaude/affectionate-feynman-ykrf1hclaude/architecture-audit-design-wxprenclaude/build-status-update-3MXsfclaude/charming-meitner-mllb5rclaude/compare-gate-gluecron-s4mFQclaude/confident-faraday-tikcwbclaude/continue-work-XMTlIclaude/crontech-gluecron-deploy-7MIECclaude/crontech-platform-setup-SeKfwclaude/design-2026claude/ecstatic-ptolemy-jMdigclaude/enhance-github-integration-QNHdGclaude/fix-aa-loop-issue-PonMQclaude/fix-actions-and-processclaude/fix-desktop-errors-XqoW8claude/fix-red-workflowsclaude/fix-website-access-6FKJNclaude/gatetest-integration-hardeningclaude/github-audit-improvements-bDFr9claude/gluecron-launch-status-FoMRlclaude/hopeful-lamport-olfCTclaude/issue-to-pr-and-protectionsclaude/jolly-heisenberg-2sg1Qclaude/launch-preparation-QmTb6claude/new-session-xk1l7claude/plan-platform-architecture-kkN4yclaude/platform-analysis-roadmap-1nUGLclaude/platform-launch-assessment-8dWV8claude/polish-platform-release-AeDrUclaude/resume-previous-work-KzyLwclaude/review-crontech-handoff-qYEVqclaude/review-project-completeness-lHhS2claude/review-readme-docs-ulqPKclaude/serene-edison-rj87weclaude/setup-multi-repo-dev-BCwNQclaude/ship-fixes-and-tests-Jvz1cclaude/site-audit-competitive-pctlwgclaude/site-migration-vercel-XstpKclaude/standalone-product-repos-XHFTDcopilot/feat-smart-empty-states-keyboard-first-enhancementcopilot/feat-smart-morning-digest-review-context-restorecopilot/fix-and-process-workflowscopilot/update-ai-powered-code-reviewfeat/debt-mapfeat/push-policy-codeowners-hardeningfeat/smart-digest-contextfeat/stage-impactfeat/t1-secret-migrationfeat/u-polishfeat/w-self-hostfeat/w2-claude-configfix/agent-journey-orphan-sweepgatetest/auto-fix-1776586424172gatetest/auto-fix-1776586534814gatetest/auto-fix-1776590685143gatetest/auto-fix-1776590808199mainops/redeploy-retriggerstyle/dxt-cta-themeworktree-agent-a3377aad30d55da26worktree-agent-a7ef607b7ee1d6c74
workflows.test.ts4.8 KB · 186 lines
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
/**
 * Tests for Block C1 — Actions-equivalent workflow runner.
 *
 * Covers the pure-function parser + route-level unauthed guards. The
 * shell-executor itself is exercised by higher-level integration tests
 * once a real test DB is wired — for now we only verify that the
 * exported surface exists and the route shell is correct.
 */

import { describe, it, expect } from "bun:test";
import app from "../app";
import { parseWorkflow } from "../lib/workflow-parser";

describe("workflow parser (C1)", () => {
  it("parses a minimal workflow", () => {
    const result = parseWorkflow(`name: CI
on: [push]
jobs:
  test:
    runs-on: default
    steps:
      - run: echo hello
`);
    expect(result.ok).toBe(true);
    if (!result.ok) return;
    expect(result.workflow.name).toBe("CI");
    expect(result.workflow.on).toContain("push");
    expect(result.workflow.jobs).toHaveLength(1);
    expect(result.workflow.jobs[0].name).toBe("test");
    expect(result.workflow.jobs[0].steps).toHaveLength(1);
    expect(result.workflow.jobs[0].steps[0].run).toBe("echo hello");
  });

  it("handles scalar 'on' trigger", () => {
    const result = parseWorkflow(`name: scalar
on: push
jobs:
  test:
    steps:
      - run: pwd
`);
    expect(result.ok).toBe(true);
    if (!result.ok) return;
    expect(result.workflow.on).toEqual(["push"]);
  });

  it("handles list 'on' triggers", () => {
    const result = parseWorkflow(`name: multi
on: [push, pull_request]
jobs:
  a:
    steps:
      - run: true
`);
    expect(result.ok).toBe(true);
    if (!result.ok) return;
    expect(result.workflow.on).toContain("push");
    expect(result.workflow.on).toContain("pull_request");
  });

  it("auto-names steps that only have a run field", () => {
    const result = parseWorkflow(`name: n
on: [push]
jobs:
  test:
    steps:
      - run: echo x
`);
    expect(result.ok).toBe(true);
    if (!result.ok) return;
    expect(result.workflow.jobs[0].steps[0].name).toBeTruthy();
  });

  it("preserves explicit step names", () => {
    const result = parseWorkflow(`name: n
on: [push]
jobs:
  test:
    steps:
      - name: Install
        run: bun install
      - name: Test
        run: bun test
`);
    expect(result.ok).toBe(true);
    if (!result.ok) return;
    const names = result.workflow.jobs[0].steps.map((s) => s.name);
    expect(names).toContain("Install");
    expect(names).toContain("Test");
  });

  it("defaults runs-on to 'default' when omitted", () => {
    const result = parseWorkflow(`name: n
on: [push]
jobs:
  test:
    steps:
      - run: true
`);
    expect(result.ok).toBe(true);
    if (!result.ok) return;
    expect(result.workflow.jobs[0].runsOn).toBe("default");
  });

  it("rejects workflows with no 'on' trigger", () => {
    const result = parseWorkflow(`name: bad
jobs:
  test:
    steps:
      - run: true
`);
    expect(result.ok).toBe(false);
    if (result.ok) return;
    expect(result.error.toLowerCase()).toContain("on");
  });

  it("rejects workflows with no jobs", () => {
    const result = parseWorkflow(`name: bad
on: [push]
`);
    expect(result.ok).toBe(false);
  });

  it("rejects jobs with no steps", () => {
    const result = parseWorkflow(`name: bad
on: [push]
jobs:
  test:
    runs-on: default
`);
    expect(result.ok).toBe(false);
  });

  it("rejects steps without a 'run' command", () => {
    const result = parseWorkflow(`name: bad
on: [push]
jobs:
  test:
    steps:
      - name: no-op
`);
    expect(result.ok).toBe(false);
  });

  it("returns a default name when 'name' is missing", () => {
    const result = parseWorkflow(`on: [push]
jobs:
  test:
    steps:
      - run: true
`);
    expect(result.ok).toBe(true);
    if (!result.ok) return;
    expect(typeof result.workflow.name).toBe("string");
    expect(result.workflow.name.length).toBeGreaterThan(0);
  });

  it("never throws on malformed input", () => {
    const inputs = ["", "  ", "not:\nyaml\n-\n:", "{]}", "jobs: oh no"];
    for (const i of inputs) {
      expect(() => parseWorkflow(i)).not.toThrow();
    }
  });
});

describe("workflow routes (C1) — unauthed behaviour", () => {
  it("POST /:owner/:repo/actions/:workflowId/run requires auth", async () => {
    const res = await app.request("/alice/project/actions/abc/run", {
      method: "POST",
      headers: { "content-type": "application/x-www-form-urlencoded" },
      body: "",
    });
    // Either a redirect to /login (repo exists, auth required), or 404
    // (repo doesn't exist in DB-less tests), or 503 on DB failure.
    expect([301, 302, 303, 307, 404, 503]).toContain(res.status);
  });

  it("POST /:owner/:repo/actions/runs/:id/cancel requires auth", async () => {
    const res = await app.request("/alice/project/actions/runs/xyz/cancel", {
      method: "POST",
      headers: { "content-type": "application/x-www-form-urlencoded" },
      body: "",
    });
    expect([301, 302, 303, 307, 404, 503]).toContain(res.status);
  });
});