summaryrefslogtreecommitdiff
path: root/internal/adminapi/bootstrap_test.go
diff options
context:
space:
mode:
authorChia <Chia@93.nz>2026-08-06 15:58:57 +1200
committerChia <Chia@93.nz>2026-08-06 15:58:57 +1200
commit3f702084d20b3c3a3ea916f3110e99b22bda60b3 (patch)
tree517f76c51025ce1ee085ea4898c60f799e5c37ea /internal/adminapi/bootstrap_test.go
parent41e322c53d7b4b796eb377d0df9c29ecd10ba431 (diff)
feat: complete commercial developer workflowspublish-commercial-control-plane
Add tenant-safe usage observability, prepaid billing controls, API key lifecycle management, Embeddings metering, configurable billing alerts, and resilient provider health propagation. Harden Stripe failure handling, migrations, readiness, and the authenticated control-plane UI with end-to-end verification evidence.
Diffstat (limited to 'internal/adminapi/bootstrap_test.go')
-rw-r--r--internal/adminapi/bootstrap_test.go57
1 files changed, 57 insertions, 0 deletions
diff --git a/internal/adminapi/bootstrap_test.go b/internal/adminapi/bootstrap_test.go
new file mode 100644
index 0000000..b0f0e90
--- /dev/null
+++ b/internal/adminapi/bootstrap_test.go
@@ -0,0 +1,57 @@
+package adminapi
+
+import (
+ "encoding/json"
+ "net/http"
+ "net/http/httptest"
+ "testing"
+
+ "aigw/internal/controlplane"
+)
+
+func TestBootstrapActorHasNoDatabaseUserID(t *testing.T) {
+ handler := New(Options{Token: "bootstrap-secret", Prefix: "/admin"}).Handler()
+
+ request := httptest.NewRequest(http.MethodGet, "/admin/api/me", nil)
+ request.Header.Set("Authorization", "Bearer bootstrap-secret")
+ response := httptest.NewRecorder()
+ handler.ServeHTTP(response, request)
+ if response.Code != http.StatusOK {
+ t.Fatalf("bootstrap me status = %d, body = %s", response.Code, response.Body.String())
+ }
+ var payload struct {
+ Actor controlplane.ConsoleActor `json:"actor"`
+ }
+ if err := json.Unmarshal(response.Body.Bytes(), &payload); err != nil {
+ t.Fatal(err)
+ }
+ if !payload.Actor.Bootstrap || payload.Actor.ID != "" || payload.Actor.Role != controlplane.RolePlatformAdmin {
+ t.Fatalf("unexpected bootstrap actor: %+v", payload.Actor)
+ }
+}
+
+func TestBootstrapSecurityEndpointsDoNotQueryUserUUID(t *testing.T) {
+ handler := New(Options{Token: "bootstrap-secret", Prefix: "/admin"}).Handler()
+ for _, test := range []struct {
+ path string
+ wantStatus int
+ }{
+ {path: "/admin/api/auth/mfa", wantStatus: http.StatusBadRequest},
+ {path: "/admin/api/auth/sessions", wantStatus: http.StatusOK},
+ } {
+ request := httptest.NewRequest(http.MethodGet, test.path, nil)
+ request.Header.Set("Authorization", "Bearer bootstrap-secret")
+ response := httptest.NewRecorder()
+ handler.ServeHTTP(response, request)
+ if response.Code != test.wantStatus {
+ t.Fatalf("%s status = %d, want %d; body = %s", test.path, response.Code, test.wantStatus, response.Body.String())
+ }
+ }
+}
+
+func TestBootstrapBillingResolutionActorUsesTextEvidenceID(t *testing.T) {
+ actor := billingResolutionActor(controlplane.ConsoleActor{Bootstrap: true, Role: controlplane.RolePlatformAdmin}, "bootstrap")
+ if actor.ID != "bootstrap" || actor.Type != "bootstrap" {
+ t.Fatalf("unexpected resolution actor: %+v", actor)
+ }
+}