summaryrefslogtreecommitdiff
path: root/internal/adminapi/bootstrap_test.go
blob: b0f0e900438aac23894650102dedd98d8183b8b2 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
package adminapi

import (
	"encoding/json"
	"net/http"
	"net/http/httptest"
	"testing"

	"aigw/internal/controlplane"
)

func TestBootstrapActorHasNoDatabaseUserID(t *testing.T) {
	handler := New(Options{Token: "bootstrap-secret", Prefix: "/admin"}).Handler()

	request := httptest.NewRequest(http.MethodGet, "/admin/api/me", nil)
	request.Header.Set("Authorization", "Bearer bootstrap-secret")
	response := httptest.NewRecorder()
	handler.ServeHTTP(response, request)
	if response.Code != http.StatusOK {
		t.Fatalf("bootstrap me status = %d, body = %s", response.Code, response.Body.String())
	}
	var payload struct {
		Actor controlplane.ConsoleActor `json:"actor"`
	}
	if err := json.Unmarshal(response.Body.Bytes(), &payload); err != nil {
		t.Fatal(err)
	}
	if !payload.Actor.Bootstrap || payload.Actor.ID != "" || payload.Actor.Role != controlplane.RolePlatformAdmin {
		t.Fatalf("unexpected bootstrap actor: %+v", payload.Actor)
	}
}

func TestBootstrapSecurityEndpointsDoNotQueryUserUUID(t *testing.T) {
	handler := New(Options{Token: "bootstrap-secret", Prefix: "/admin"}).Handler()
	for _, test := range []struct {
		path       string
		wantStatus int
	}{
		{path: "/admin/api/auth/mfa", wantStatus: http.StatusBadRequest},
		{path: "/admin/api/auth/sessions", wantStatus: http.StatusOK},
	} {
		request := httptest.NewRequest(http.MethodGet, test.path, nil)
		request.Header.Set("Authorization", "Bearer bootstrap-secret")
		response := httptest.NewRecorder()
		handler.ServeHTTP(response, request)
		if response.Code != test.wantStatus {
			t.Fatalf("%s status = %d, want %d; body = %s", test.path, response.Code, test.wantStatus, response.Body.String())
		}
	}
}

func TestBootstrapBillingResolutionActorUsesTextEvidenceID(t *testing.T) {
	actor := billingResolutionActor(controlplane.ConsoleActor{Bootstrap: true, Role: controlplane.RolePlatformAdmin}, "bootstrap")
	if actor.ID != "bootstrap" || actor.Type != "bootstrap" {
		t.Fatalf("unexpected resolution actor: %+v", actor)
	}
}