package adminapi import ( "encoding/json" "net/http" "net/http/httptest" "testing" "aigw/internal/controlplane" ) func TestBootstrapActorHasNoDatabaseUserID(t *testing.T) { handler := New(Options{Token: "bootstrap-secret", Prefix: "/admin"}).Handler() request := httptest.NewRequest(http.MethodGet, "/admin/api/me", nil) request.Header.Set("Authorization", "Bearer bootstrap-secret") response := httptest.NewRecorder() handler.ServeHTTP(response, request) if response.Code != http.StatusOK { t.Fatalf("bootstrap me status = %d, body = %s", response.Code, response.Body.String()) } var payload struct { Actor controlplane.ConsoleActor `json:"actor"` } if err := json.Unmarshal(response.Body.Bytes(), &payload); err != nil { t.Fatal(err) } if !payload.Actor.Bootstrap || payload.Actor.ID != "" || payload.Actor.Role != controlplane.RolePlatformAdmin { t.Fatalf("unexpected bootstrap actor: %+v", payload.Actor) } } func TestBootstrapSecurityEndpointsDoNotQueryUserUUID(t *testing.T) { handler := New(Options{Token: "bootstrap-secret", Prefix: "/admin"}).Handler() for _, test := range []struct { path string wantStatus int }{ {path: "/admin/api/auth/mfa", wantStatus: http.StatusBadRequest}, {path: "/admin/api/auth/sessions", wantStatus: http.StatusOK}, } { request := httptest.NewRequest(http.MethodGet, test.path, nil) request.Header.Set("Authorization", "Bearer bootstrap-secret") response := httptest.NewRecorder() handler.ServeHTTP(response, request) if response.Code != test.wantStatus { t.Fatalf("%s status = %d, want %d; body = %s", test.path, response.Code, test.wantStatus, response.Body.String()) } } } func TestBootstrapBillingResolutionActorUsesTextEvidenceID(t *testing.T) { actor := billingResolutionActor(controlplane.ConsoleActor{Bootstrap: true, Role: controlplane.RolePlatformAdmin}, "bootstrap") if actor.ID != "bootstrap" || actor.Type != "bootstrap" { t.Fatalf("unexpected resolution actor: %+v", actor) } }