File size: 6,030 Bytes
1f5ea39
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
/**
 * Share-link e2e — exercises the migrated /api/trips/:tripId/share-link and the
 * public /api/shared/:token endpoints through the real JwtAuthGuard against a
 * temp SQLite db. The share service + permission check are mocked; this focuses
 * on auth, trip-access 404, permission 403, the create-201-vs-update-200 split
 * and the unguarded public read.
 */
import { describe, it, expect, beforeAll, afterAll, beforeEach, vi } from 'vitest';
import request from 'supertest';
import cookieParser from 'cookie-parser';
import os from 'node:os';
import path from 'node:path';
import fs from 'node:fs';
import type { Server } from 'http';
import { Test } from '@nestjs/testing';
import { seedUser, sessionCookie } from './harness';

const { db, canAccessTrip } = vi.hoisted(() => {
  // eslint-disable-next-line @typescript-eslint/no-require-imports
  const Database = require('better-sqlite3');
  const tmp = new Database(':memory:');
  tmp.exec('PRAGMA journal_mode = WAL');
  tmp.exec(`CREATE TABLE users (id INTEGER PRIMARY KEY AUTOINCREMENT, username TEXT NOT NULL,
    email TEXT NOT NULL UNIQUE, role TEXT NOT NULL DEFAULT 'user', password_version INTEGER NOT NULL DEFAULT 0);`);
  return { db: tmp, canAccessTrip: vi.fn() };
});

vi.mock('../../src/db/database', () => ({ db, canAccessTrip, closeDb: () => {}, reinitialize: () => {} }));

const { checkPermission } = vi.hoisted(() => ({ checkPermission: vi.fn() }));
vi.mock('../../src/services/permissions', () => ({ checkPermission }));

const { shareSvc } = vi.hoisted(() => ({
  shareSvc: { createOrUpdateShareLink: vi.fn(), getShareLink: vi.fn(), deleteShareLink: vi.fn(), getSharedTripData: vi.fn(), getSharedPlacePhotoPath: vi.fn() },
}));
vi.mock('../../src/services/shareService', () => shareSvc);

import { ShareModule } from '../../src/nest/share/share.module';
import { TrekExceptionFilter } from '../../src/nest/common/trek-exception.filter';

describe('Share-link e2e (real auth guard + temp SQLite)', () => {
  let server: Server;
  let app: Awaited<ReturnType<typeof build>>;

  async function build() {
    const moduleRef = await Test.createTestingModule({ imports: [ShareModule] }).compile();
    const nest = moduleRef.createNestApplication();
    nest.use(cookieParser());
    nest.useGlobalFilters(new TrekExceptionFilter());
    await nest.init();
    return nest;
  }

  beforeAll(async () => {
    seedUser(db as never, { id: 1 });
    app = await build();
    server = app.getHttpServer();
    shareSvc.getSharedTripData.mockReturnValue({ trip: { id: 9 } });
  });

  beforeEach(() => {
    canAccessTrip.mockReturnValue({ user_id: 1 });
    checkPermission.mockReturnValue(true);
  });

  afterAll(async () => {
    await app.close();
  });

  it('401 without a session cookie', async () => {
    expect((await request(server).get('/api/trips/5/share-link')).status).toBe(401);
  });

  it('201 on first create, 200 on a subsequent update', async () => {
    shareSvc.createOrUpdateShareLink.mockReturnValueOnce({ token: 't', created: true });
    const created = await request(server).post('/api/trips/5/share-link').set('Cookie', sessionCookie(1)).send({ share_map: true });
    expect(created.status).toBe(201);
    expect(created.body).toEqual({ token: 't' });

    shareSvc.createOrUpdateShareLink.mockReturnValueOnce({ token: 't', created: false });
    const updated = await request(server).post('/api/trips/5/share-link').set('Cookie', sessionCookie(1)).send({});
    expect(updated.status).toBe(200);
    expect(updated.body).toEqual({ token: 't' });
  });

  it('403 without share_manage', async () => {
    checkPermission.mockReturnValue(false);
    const res = await request(server).post('/api/trips/5/share-link').set('Cookie', sessionCookie(1)).send({});
    expect(res.status).toBe(403);
    expect(res.body).toEqual({ error: 'No permission' });
  });

  it('404 when the trip is not accessible', async () => {
    canAccessTrip.mockReturnValue(undefined);
    const res = await request(server).get('/api/trips/5/share-link').set('Cookie', sessionCookie(1));
    expect(res.status).toBe(404);
    expect(res.body).toEqual({ error: 'Trip not found' });
  });

  it('public shared read is unguarded (200, no cookie)', async () => {
    const res = await request(server).get('/api/shared/tok');
    expect(res.status).toBe(200);
    expect(res.body).toEqual({ trip: { id: 9 } });
  });

  it('public shared read 404 for an invalid token', async () => {
    shareSvc.getSharedTripData.mockReturnValueOnce(null);
    const res = await request(server).get('/api/shared/bad');
    expect(res.status).toBe(404);
    expect(res.body).toEqual({ error: 'Invalid or expired link' });
  });

  describe('public place-photo proxy (/api/shared/:token/place-photo/:placeId/bytes)', () => {
    const photoFile = path.join(os.tmpdir(), 'trek-share-photo.e2e.jpg');
    const photoBytes = Buffer.from([0xff, 0xd8, 0xff, 0xe0, 0x00, 0x10]); // JPEG-ish header

    beforeAll(() => fs.writeFileSync(photoFile, photoBytes));
    afterAll(() => { try { fs.unlinkSync(photoFile); } catch { /* ignore */ } });

    it('streams cached bytes with no cookie (unguarded) for a valid token + place', async () => {
      shareSvc.getSharedPlacePhotoPath.mockReturnValueOnce(photoFile);
      const res = await request(server).get('/api/shared/tok/place-photo/ChIJabc/bytes');
      expect(res.status).toBe(200);
      expect(res.headers['content-type']).toContain('image/jpeg');
      expect(res.headers['cache-control']).toContain('immutable');
      expect(Buffer.from(res.body)).toEqual(photoBytes);
      expect(shareSvc.getSharedPlacePhotoPath).toHaveBeenCalledWith('tok', 'ChIJabc');
    });

    it('404 when the token/place does not resolve to a cached photo', async () => {
      shareSvc.getSharedPlacePhotoPath.mockReturnValueOnce(null);
      const res = await request(server).get('/api/shared/bad/place-photo/ChIJabc/bytes');
      expect(res.status).toBe(404);
      expect(res.body).toEqual({ error: 'Photo not cached' });
    });
  });
});