File size: 15,901 Bytes
1f5ea39
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
/**
 * Unit tests for collabService β€” COLLAB-SVC-001 to COLLAB-SVC-030.
 * Covers votePoll edge cases, listMessages pagination, deleteMessage ownership,
 * updateNote partial fields, fetchLinkPreview, avatarUrl, createMessage reply validation.
 */
import { describe, it, expect, vi, beforeAll, beforeEach, afterAll, afterEach } from 'vitest';

// ── DB setup ─────────────────────────────────────────────────────────────────

const { testDb, dbMock } = vi.hoisted(() => {
  const Database = require('better-sqlite3');
  const db = new Database(':memory:');
  db.exec('PRAGMA journal_mode = WAL');
  db.exec('PRAGMA foreign_keys = ON');
  db.exec('PRAGMA busy_timeout = 5000');
  const mock = {
    db,
    closeDb: () => {},
    reinitialize: () => {},
    getPlaceWithTags: () => null,
    canAccessTrip: (tripId: any, userId: number) =>
      db.prepare(`
        SELECT t.id FROM trips t
        LEFT JOIN trip_members m ON m.trip_id = t.id AND m.user_id = ?
        WHERE t.id = ? AND (t.user_id = ? OR m.user_id IS NOT NULL)
      `).get(userId, tripId, userId),
    isOwner: (tripId: any, userId: number) =>
      !!db.prepare('SELECT id FROM trips WHERE id = ? AND user_id = ?').get(tripId, userId),
  };
  return { testDb: db, dbMock: mock };
});

vi.mock('../../../src/db/database', () => dbMock);
vi.mock('../../../src/config', () => ({
  JWT_SECRET: 'test-jwt-secret-for-trek-testing-only',
  ENCRYPTION_KEY: 'a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6a7b8c9d0e1f2a3b4c5d6a7b8c9d0e1f2',
  updateJwtSecret: () => {},
}));

// Stub checkSsrf so fetchLinkPreview tests can control SSRF behaviour
const { mockCheckSsrf, mockCreatePinnedDispatcher } = vi.hoisted(() => ({
  mockCheckSsrf: vi.fn(async () => ({ allowed: true, resolvedIp: '93.184.216.34' })),
  mockCreatePinnedDispatcher: vi.fn(() => ({})),
}));
vi.mock('../../../src/utils/ssrfGuard', () => ({
  checkSsrf: mockCheckSsrf,
  createPinnedDispatcher: mockCreatePinnedDispatcher,
}));

import { createTables } from '../../../src/db/schema';
import { runMigrations } from '../../../src/db/migrations';
import { resetTestDb } from '../../helpers/test-db';
import { createUser, createTrip } from '../../helpers/factories';
import {
  avatarUrl,
  votePoll,
  listMessages,
  createMessage,
  deleteMessage,
  updateNote,
  createNote,
  createPoll,
  closePoll,
  fetchLinkPreview,
} from '../../../src/services/collabService';

beforeAll(() => {
  createTables(testDb);
  runMigrations(testDb);
});

beforeEach(() => {
  resetTestDb(testDb);
  mockCheckSsrf.mockResolvedValue({ allowed: true, resolvedIp: '93.184.216.34' });
});

afterAll(() => {
  testDb.close();
});

afterEach(() => {
  vi.unstubAllGlobals();
  mockCheckSsrf.mockReset();
  mockCheckSsrf.mockResolvedValue({ allowed: true, resolvedIp: '93.184.216.34' });
});

// ── Helpers ───────────────────────────────────────────────────────────────────

function setup() {
  const { user: user1 } = createUser(testDb);
  const { user: user2 } = createUser(testDb);
  const trip = createTrip(testDb, user1.id);
  return { user1, user2, trip };
}

// ── avatarUrl ─────────────────────────────────────────────────────────────────

describe('avatarUrl', () => {
  it('COLLAB-SVC-001: returns null when avatar is null', () => {
    expect(avatarUrl({ avatar: null })).toBeNull();
  });

  it('COLLAB-SVC-002: returns upload path when avatar is set', () => {
    expect(avatarUrl({ avatar: 'abc.jpg' })).toBe('/uploads/avatars/abc.jpg');
  });

  it('COLLAB-SVC-003: returns null when avatar is empty string', () => {
    expect(avatarUrl({ avatar: '' })).toBeNull();
  });
});

// ── votePoll ──────────────────────────────────────────────────────────────────

describe('votePoll', () => {
  it('COLLAB-SVC-004: returns error "closed" when poll is closed', () => {
    const { user1, trip } = setup();
    const poll = createPoll(trip.id, user1.id, { question: 'Q?', options: ['A', 'B'] });
    closePoll(trip.id, poll!.id);

    const result = votePoll(trip.id, poll!.id, user1.id, 0);
    expect(result.error).toBe('closed');
  });

  it('COLLAB-SVC-005: returns error "invalid_index" for negative index', () => {
    const { user1, trip } = setup();
    const poll = createPoll(trip.id, user1.id, { question: 'Q?', options: ['A', 'B'] });

    const result = votePoll(trip.id, poll!.id, user1.id, -1);
    expect(result.error).toBe('invalid_index');
  });

  it('COLLAB-SVC-006: returns error "invalid_index" for out-of-range index', () => {
    const { user1, trip } = setup();
    const poll = createPoll(trip.id, user1.id, { question: 'Q?', options: ['A', 'B'] });

    const result = votePoll(trip.id, poll!.id, user1.id, 5);
    expect(result.error).toBe('invalid_index');
  });

  it('COLLAB-SVC-007: returns error "not_found" for nonexistent poll', () => {
    const { user1, trip } = setup();
    const result = votePoll(trip.id, 9999, user1.id, 0);
    expect(result.error).toBe('not_found');
  });

  it('COLLAB-SVC-008: successfully votes and returns poll with voters', () => {
    const { user1, trip } = setup();
    const poll = createPoll(trip.id, user1.id, { question: 'Q?', options: ['Yes', 'No'] });

    const result = votePoll(trip.id, poll!.id, user1.id, 0);
    expect(result.error).toBeUndefined();
    expect(result.poll).toBeDefined();
    expect(result.poll!.options[0].voters).toHaveLength(1);
  });

  it('COLLAB-SVC-009: toggles vote off when voted again on same option', () => {
    const { user1, trip } = setup();
    const poll = createPoll(trip.id, user1.id, { question: 'Q?', options: ['Yes', 'No'] });

    votePoll(trip.id, poll!.id, user1.id, 0);
    const result = votePoll(trip.id, poll!.id, user1.id, 0);
    expect(result.poll!.options[0].voters).toHaveLength(0);
  });
});

// ── listMessages with before cursor ──────────────────────────────────────────

describe('listMessages', () => {
  it('COLLAB-SVC-010: returns all messages when no before cursor', () => {
    const { user1, trip } = setup();
    createMessage(trip.id, user1.id, 'Hello');
    createMessage(trip.id, user1.id, 'World');

    const msgs = listMessages(trip.id);
    expect(msgs).toHaveLength(2);
  });

  it('COLLAB-SVC-011: paginates using before cursor (returns messages with id < before)', () => {
    const { user1, trip } = setup();
    const r1 = createMessage(trip.id, user1.id, 'First');
    const r2 = createMessage(trip.id, user1.id, 'Second');
    const r3 = createMessage(trip.id, user1.id, 'Third');

    const id3 = r3.message!.id;
    const msgs = listMessages(trip.id, id3);
    expect(msgs.length).toBe(2);
    const texts = msgs.map(m => m.text);
    expect(texts).toContain('First');
    expect(texts).toContain('Second');
    expect(texts).not.toContain('Third');
  });

  it('COLLAB-SVC-012: returns messages in ascending order (reversed after DESC query)', () => {
    const { user1, trip } = setup();
    createMessage(trip.id, user1.id, 'A');
    createMessage(trip.id, user1.id, 'B');
    createMessage(trip.id, user1.id, 'C');

    const msgs = listMessages(trip.id);
    expect(msgs[0].text).toBe('A');
    expect(msgs[2].text).toBe('C');
  });

  it('COLLAB-SVC-013: includes reactions grouped by emoji', () => {
    const { user1, trip } = setup();
    const r = createMessage(trip.id, user1.id, 'React me');
    const msgId = r.message!.id;
    testDb.prepare('INSERT INTO collab_message_reactions (message_id, user_id, emoji) VALUES (?, ?, ?)').run(msgId, user1.id, 'πŸ‘');

    const msgs = listMessages(trip.id);
    expect(msgs[0].reactions).toBeDefined();
    expect(msgs[0].reactions).toHaveLength(1);
    expect(msgs[0].reactions[0].emoji).toBe('πŸ‘');
  });
});

// ── createMessage with invalid replyTo ───────────────────────────────────────

describe('createMessage', () => {
  it('COLLAB-SVC-014: returns error when replyTo message does not exist', () => {
    const { user1, trip } = setup();
    const result = createMessage(trip.id, user1.id, 'Reply to nothing', 9999);
    expect(result.error).toBe('reply_not_found');
  });

  it('COLLAB-SVC-015: creates message with valid replyTo', () => {
    const { user1, trip } = setup();
    const r1 = createMessage(trip.id, user1.id, 'Original');
    const r2 = createMessage(trip.id, user1.id, 'Reply', r1.message!.id);
    expect(r2.error).toBeUndefined();
    expect(r2.message!.reply_to).toBe(r1.message!.id);
  });
});

// ── deleteMessage ownership check ─────────────────────────────────────────────

describe('deleteMessage', () => {
  it('COLLAB-SVC-016: returns error "not_owner" when user does not own message', () => {
    const { user1, user2, trip } = setup();
    const r = createMessage(trip.id, user1.id, 'My message');

    const result = deleteMessage(trip.id, r.message!.id, user2.id);
    expect(result.error).toBe('not_owner');
  });

  it('COLLAB-SVC-017: returns error "not_found" for nonexistent message', () => {
    const { user1, trip } = setup();
    const result = deleteMessage(trip.id, 9999, user1.id);
    expect(result.error).toBe('not_found');
  });

  it('COLLAB-SVC-018: marks message as deleted when owner deletes it', () => {
    const { user1, trip } = setup();
    const r = createMessage(trip.id, user1.id, 'Delete me');

    const result = deleteMessage(trip.id, r.message!.id, user1.id);
    expect(result.error).toBeUndefined();

    const row = testDb.prepare('SELECT deleted FROM collab_messages WHERE id = ?').get(r.message!.id) as any;
    expect(row.deleted).toBe(1);
  });
});

// ── updateNote partial fields ─────────────────────────────────────────────────

describe('updateNote', () => {
  it('COLLAB-SVC-019: updates only title when other fields are undefined', () => {
    const { user1, trip } = setup();
    const note = createNote(trip.id, user1.id, { title: 'Original', content: 'Some content', website: 'https://example.com' });

    updateNote(trip.id, note.id, { title: 'Updated' });

    const updated = testDb.prepare('SELECT * FROM collab_notes WHERE id = ?').get(note.id) as any;
    expect(updated.title).toBe('Updated');
    expect(updated.content).toBe('Some content'); // unchanged
    expect(updated.website).toBe('https://example.com'); // unchanged
  });

  it('COLLAB-SVC-020: clears content when content is explicitly set to empty string', () => {
    const { user1, trip } = setup();
    const note = createNote(trip.id, user1.id, { title: 'T', content: 'Old content' });

    updateNote(trip.id, note.id, { content: '' });

    const updated = testDb.prepare('SELECT * FROM collab_notes WHERE id = ?').get(note.id) as any;
    expect(updated.content).toBe('');
  });

  it('COLLAB-SVC-021: updates website when website is defined', () => {
    const { user1, trip } = setup();
    const note = createNote(trip.id, user1.id, { title: 'T' });

    updateNote(trip.id, note.id, { website: 'https://new.example.com' });

    const updated = testDb.prepare('SELECT * FROM collab_notes WHERE id = ?').get(note.id) as any;
    expect(updated.website).toBe('https://new.example.com');
  });

  it('COLLAB-SVC-022: clears website when website is explicitly set to empty string', () => {
    const { user1, trip } = setup();
    const note = createNote(trip.id, user1.id, { title: 'T', website: 'https://old.com' });

    updateNote(trip.id, note.id, { website: '' });

    const updated = testDb.prepare('SELECT * FROM collab_notes WHERE id = ?').get(note.id) as any;
    expect(updated.website).toBe('');
  });

  it('COLLAB-SVC-023: returns null when note does not exist', () => {
    const { trip } = setup();
    const result = updateNote(trip.id, 9999, { title: 'Ghost' });
    expect(result).toBeNull();
  });

  it('COLLAB-SVC-024: updates pinned flag', () => {
    const { user1, trip } = setup();
    const note = createNote(trip.id, user1.id, { title: 'T', pinned: false });

    updateNote(trip.id, note.id, { pinned: true });

    const updated = testDb.prepare('SELECT * FROM collab_notes WHERE id = ?').get(note.id) as any;
    expect(updated.pinned).toBe(1);
  });
});

// ── fetchLinkPreview ──────────────────────────────────────────────────────────

describe('fetchLinkPreview', () => {
  afterEach(() => {
    vi.unstubAllGlobals();
  });

  it('COLLAB-SVC-025: returns OG title and description from HTML', async () => {
    vi.stubGlobal('fetch', vi.fn().mockResolvedValue({
      ok: true,
      text: async () => `
        <html>
          <head>
            <meta property="og:title" content="Test Title" />
            <meta property="og:description" content="Test Description" />
            <meta property="og:image" content="https://example.com/image.jpg" />
            <meta property="og:site_name" content="Example" />
          </head>
        </html>
      `,
    }));

    const result = await fetchLinkPreview('https://example.com/page');
    expect(result.title).toBe('Test Title');
    expect(result.description).toBe('Test Description');
    expect(result.image).toBe('https://example.com/image.jpg');
    expect(result.url).toBe('https://example.com/page');
  });

  it('COLLAB-SVC-026: falls back to <title> tag when no og:title', async () => {
    vi.stubGlobal('fetch', vi.fn().mockResolvedValue({
      ok: true,
      text: async () => `<html><head><title>Page Title</title></head></html>`,
    }));

    const result = await fetchLinkPreview('https://example.com/');
    expect(result.title).toBe('Page Title');
  });

  it('COLLAB-SVC-027: returns fallback when fetch response is not ok', async () => {
    vi.stubGlobal('fetch', vi.fn().mockResolvedValue({
      ok: false,
      text: async () => '',
    }));

    const result = await fetchLinkPreview('https://example.com/bad');
    expect(result.title).toBeNull();
    expect(result.description).toBeNull();
    expect(result.url).toBe('https://example.com/bad');
  });

  it('COLLAB-SVC-028: returns fallback when SSRF check blocks the URL', async () => {
    mockCheckSsrf.mockResolvedValue({ allowed: false, error: 'SSRF blocked' });

    const result = await fetchLinkPreview('https://169.254.169.254/');
    expect(result.title).toBeNull();
  });

  it('COLLAB-SVC-029: returns fallback when fetch throws (network error)', async () => {
    vi.stubGlobal('fetch', vi.fn().mockRejectedValue(new Error('Network error')));

    const result = await fetchLinkPreview('https://example.com/net-error');
    expect(result.title).toBeNull();
    expect(result.url).toBe('https://example.com/net-error');
  });

  it('COLLAB-SVC-030: falls back to meta description tag when no og:description', async () => {
    vi.stubGlobal('fetch', vi.fn().mockResolvedValue({
      ok: true,
      text: async () => `
        <html><head>
          <meta name="description" content="Meta description here" />
        </head></html>
      `,
    }));

    const result = await fetchLinkPreview('https://example.com/meta');
    expect(result.description).toBe('Meta description here');
  });
});