mirror of
https://github.com/J3vb/OwnCord.git
synced 2026-09-03 03:50:00 +03:00
Audits what actually has tests, then closes the gaps it found. Full write-up with before/after numbers in docs/audit-test-coverage-2026-07-25.md. Measurement first: `go test ./... -coverprofile` (what CI runs) instruments each package only for itself, so code exercised through another package's tests reads as uncovered — `service` reported 36.7% against a real 85%. All analysis here uses -coverpkg=./..., and both views now have Makefile targets. Features that had zero coverage at every layer: - user blocking (db + service + the /api/v1/blocks routes) - auth lockout persistence — the DB round-trip that survives a restart - plugin install/enable/disable/uninstall and the plugin KV namespace - event replay bounds (GetMaxEventSeq, PruneEventsOlderThan) - LiveKit participant_joined webhook (replayed-token guard), the room-service client, and proxyWebSocket/copyWS - ws_proxy.rs and livekit_proxy.rs — pure helpers extracted, matching the existing tofu.rs pattern, so cert-pin and header-injection checks are testable Gaps that were hidden rather than absent: - Server/admin reported 0.3% coverage with 307 tests passing. TestSpawnDetached_* re-execs the test binary; the child inherited GOCOVERDIR and the parent's stdout, clobbering the profile and printing "[no tests to run]". Now 71.4%, and CI's uploaded artifact is correct. - vitest.config.ts excluded 2.2k LOC unexplained, including two files that already had tests. Trimmed to three entries, each justified inline. - api.HandleLiveKitHealthForTest re-implemented the handler it claimed to expose, so eight call sites tested a copy. Added a hook to the real one. Two bugs found and pinned rather than silently patched: logctx.WithGroup nests req_id under the group, and drag-reorder.ts takes one listener ref per channel but releases one per sidebar, so the count never reaches zero. Coverage: client 92.93% -> 94.87% statements (3371 -> 3572 tests) even after un-excluding hidden files; Rust 47 -> 74 tests; Go zero-coverage functions ~70 -> 21, with plugin 61->77%, admin 67->86%, db 76->84%, service 85->91%. Verified: go vet, all four build-tag variants, go test -race, -tags deadlock, vitest --coverage, cargo test --lib, cargo clippy --all-targets, playwright. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AEETs3Vh6sAHHb1jMBL75g
66 lines
2.2 KiB
Go
66 lines
2.2 KiB
Go
package api
|
|
|
|
import (
|
|
"context"
|
|
"net/http"
|
|
|
|
"github.com/owncord/server/ws"
|
|
)
|
|
|
|
// HandleMetricsForTest exposes handleMetrics for use in external tests.
|
|
var HandleMetricsForTest = handleMetrics
|
|
|
|
// LiveKitHealthHandlerForTest exposes the real handleLiveKitHealth. Prefer it
|
|
// over HandleLiveKitHealthForTest, which only re-implements the same shape.
|
|
func LiveKitHealthHandlerForTest(hub *ws.Hub) http.HandlerFunc {
|
|
return handleLiveKitHealth(hub)
|
|
}
|
|
|
|
// HandleLiveKitHealthForTest re-implements handleLiveKitHealth against a
|
|
// caller-supplied health check.
|
|
//
|
|
// It does NOT exercise the production handler — the body below is a copy, so
|
|
// the two can drift and every test built on this hook would keep passing.
|
|
// It survives only because its callers predate LiveKitHealthHandlerForTest;
|
|
// new tests should use that instead, and these callers should migrate.
|
|
func HandleLiveKitHealthForTest(healthCheck func(context.Context) (bool, error)) http.HandlerFunc {
|
|
return func(w http.ResponseWriter, r *http.Request) {
|
|
ok, err := healthCheck(r.Context())
|
|
if ok {
|
|
writeJSON(w, http.StatusOK, livekitHealthResponse{
|
|
Status: "ok",
|
|
LiveKitReachable: true,
|
|
})
|
|
return
|
|
}
|
|
|
|
errMsg := "unknown"
|
|
if err != nil {
|
|
errMsg = err.Error()
|
|
}
|
|
writeJSON(w, http.StatusServiceUnavailable, livekitHealthResponse{
|
|
Status: "degraded",
|
|
LiveKitReachable: false,
|
|
Error: errMsg,
|
|
})
|
|
}
|
|
}
|
|
|
|
// IsPrivateIPForTest exposes isPrivateIP for use in external tests.
|
|
var IsPrivateIPForTest = isPrivateIP
|
|
|
|
// SetGIFUpstreamForTest points the GIF proxy at a stub upstream and returns a
|
|
// restore func. The production transport uses the SSRF-guarded dialer, which
|
|
// refuses loopback addresses, so tests must supply their own client too.
|
|
func SetGIFUpstreamForTest(baseURL string, client *http.Client) func() {
|
|
prevBase, prevClient := gifAPIBase, gifClient
|
|
gifAPIBase, gifClient = baseURL, client
|
|
return func() { gifAPIBase, gifClient = prevBase, prevClient }
|
|
}
|
|
|
|
// SecurityHeaders is SecurityHeadersWithTLS with TLS disabled (no HSTS).
|
|
// Test-only convenience — production always goes through SecurityHeadersWithTLS.
|
|
func SecurityHeaders(next http.Handler) http.Handler {
|
|
return SecurityHeadersWithTLS("")(next)
|
|
}
|