Files
vngeoguessr/tests/debug-access.test.js
T
tiennm99 4d25a82448 chore(ci): raise the test hook timeout, fail an empty backup
PGlite start-up alone takes about seven seconds on an ARM host, so the
10s beforeAll default failed whole files at random. The weekly backup
fails instead of uploading an empty export, and both workflows run with
read-only permissions; CI cancels superseded runs.
2026-09-28 15:01:41 +07:00

57 lines
2.2 KiB
JavaScript

import { describe, it, expect, afterEach } from 'vitest';
import { debugAccessAllowed } from '../src/lib/debug-access.js';
// The debug routes return panorama coordinates. Open anywhere but Vercel
// production, where they answer only a caller holding the configured key.
const ORIGINAL = { env: process.env.VERCEL_ENV, key: process.env.DEBUG_ACCESS_KEY };
function request(headers = {}) {
return new Request('http://localhost/api/debug/pano?id=1', { headers });
}
afterEach(() => {
process.env.VERCEL_ENV = ORIGINAL.env;
process.env.DEBUG_ACCESS_KEY = ORIGINAL.key;
if (ORIGINAL.env === undefined) delete process.env.VERCEL_ENV;
if (ORIGINAL.key === undefined) delete process.env.DEBUG_ACCESS_KEY;
});
describe('debugAccessAllowed', () => {
it('is open off production, including preview deployments', () => {
delete process.env.VERCEL_ENV;
expect(debugAccessAllowed(request())).toBe(true);
process.env.VERCEL_ENV = 'preview';
expect(debugAccessAllowed(request())).toBe(true);
});
it('treats a production build with no Vercel environment as production', () => {
delete process.env.VERCEL_ENV;
const original = process.env.NODE_ENV;
process.env.NODE_ENV = 'production';
try {
delete process.env.DEBUG_ACCESS_KEY;
expect(debugAccessAllowed(request())).toBe(false);
} finally {
// Assigning undefined would store the string "undefined".
if (original === undefined) delete process.env.NODE_ENV;
else process.env.NODE_ENV = original;
}
});
it('is closed in production with no key configured', () => {
process.env.VERCEL_ENV = 'production';
delete process.env.DEBUG_ACCESS_KEY;
expect(debugAccessAllowed(request({ 'x-debug-key': 'anything' }))).toBe(false);
});
it('opens in production to the header or the cookie carrying the key', () => {
process.env.VERCEL_ENV = 'production';
process.env.DEBUG_ACCESS_KEY = 'secret-key';
expect(debugAccessAllowed(request())).toBe(false);
expect(debugAccessAllowed(request({ 'x-debug-key': 'wrong' }))).toBe(false);
expect(debugAccessAllowed(request({ 'x-debug-key': 'secret-key' }))).toBe(true);
expect(debugAccessAllowed(request({ cookie: 'theme=dark; vng_debug=secret-key' }))).toBe(true);
});
});