Keep test helpers out of the shipped binary (closes #506)
check / check (push) Successful in 7m57s

The test helpers lived in ordinary `testing.go` files inside the config, database, middleware and session packages, so they were built into the binary and the shared `test-support` lint rule could not see them. The four files are gone: the session's helpers move into its own `_test.go` file, and the rest into `configtest`, `databasetest` and `middlewaretest`, which the `depguard` deny list now names, so a non-test file importing them fails lint. The test-support packages build through the production constructors.

Judgement call: the session, the middleware and the webhook database manager now take the plain logger they log through, which the application wiring provides.
Judgement call: two idle-expiry tests move the stored timestamps back instead of advancing a fake clock.

Model: opus-5-5
This commit was merged in pull request #512.
This commit is contained in:
2026-10-06 14:29:47 +02:00
parent 3de345fe6f
commit 128eb1b644
39 changed files with 342 additions and 330 deletions
+87 -71
View File
@@ -14,36 +14,34 @@ import (
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
"go.uber.org/fx/fxtest"
"sneak.berlin/go/webhooker/internal/config"
"sneak.berlin/go/webhooker/internal/database"
"sneak.berlin/go/webhooker/internal/middleware"
"sneak.berlin/go/webhooker/internal/middleware/middlewaretest"
"sneak.berlin/go/webhooker/internal/session"
)
const testKeySize = 32
// testMiddleware creates a Middleware with minimal dependencies
// for testing. It uses a real session.Session backed by an
// in-memory cookie store.
// for testing. It uses a real session.Session.
func testMiddleware(
t *testing.T,
env string,
) (*middleware.Middleware, *session.Session) {
t.Helper()
m, s, _ := testMiddlewareWithSessionClock(t, env, 0, nil)
return m, s
return testMiddlewareWithIdleTimeout(t, env, 0)
}
// testMiddlewareWithSessionClock is testMiddleware with a
// configurable session idle timeout and a manually advanced clock,
// for the session-expiry tests. A nil clock uses the real one.
func testMiddlewareWithSessionClock(
// testMiddlewareWithIdleTimeout is testMiddleware with a
// configurable session idle timeout, for the session-expiry tests.
func testMiddlewareWithIdleTimeout(
t *testing.T,
env string,
idleTimeout time.Duration,
clock *fakeClock,
) (*middleware.Middleware, *session.Session, *fakeClock) {
) (*middleware.Middleware, *session.Session) {
t.Helper()
log := slog.New(slog.NewTextHandler(
@@ -56,59 +54,44 @@ func testMiddlewareWithSessionClock(
SessionIdleTimeout: idleTimeout,
}
sessManager := newTestSessionManager(cfg, log, clock)
sessManager := newTestSessionManager(t, cfg)
m := middleware.NewForTest(log, cfg, sessManager)
m := middlewaretest.New(t, log, cfg, sessManager)
return m, sessManager, clock
return m, sessManager
}
// newTestSessionManager builds the real session.Session the
// middleware tests run against: an in-memory cookie store with a
// known key, and optionally a manually advanced clock.
// middleware tests run against, through session.New, with its key
// in a main database of its own.
func newTestSessionManager(
t *testing.T,
cfg *config.Config,
log *slog.Logger,
clock *fakeClock,
) *session.Session {
key := make([]byte, testKeySize)
t.Helper()
for i := range key {
key[i] = byte(i)
}
discard := slog.New(slog.DiscardHandler)
store := session.NewStore(key)
db, err := database.Open(t.TempDir(), discard)
require.NoError(t, err)
var now func() time.Time
t.Cleanup(func() { _ = db.Close() })
if clock != nil {
now = clock.Now
}
lc := fxtest.NewLifecycle(t)
return session.NewForTest(store, cfg, log, key, now)
}
sessManager, err := session.New(lc, session.Params{
Config: cfg,
Database: db,
Logger: discard,
})
require.NoError(t, err)
// fakeClock is a manually advanced clock, so session expiry can be
// tested without sleeping.
type fakeClock struct {
t time.Time
}
// The start hook reads the key from db and builds the cookie
// store.
lc.RequireStart()
t.Cleanup(lc.RequireStop)
func (c *fakeClock) Now() time.Time {
return c.t
}
func (c *fakeClock) Advance(d time.Duration) {
c.t = c.t.Add(d)
}
// newFakeClock returns a clock started at a fixed instant.
func newFakeClock() *fakeClock {
return &fakeClock{
t: time.Date(
2026, time.January, 2, 3, 4, 5, 0, time.UTC,
),
}
return sessManager
}
// --- Logging Middleware Tests ---
@@ -583,6 +566,40 @@ func sessionCookies(
return out
}
// aged re-issues the session cookie in cookies with both of its
// timestamps moved back by d: the cookie as it stands once d has
// passed, so session expiry can be tested without sleeping.
func aged(
t *testing.T,
sessManager *session.Session,
cookies []*http.Cookie,
d time.Duration,
) []*http.Cookie {
t.Helper()
req := httptest.NewRequestWithContext(
context.Background(), http.MethodGet, "/", nil)
for _, c := range cookies {
req.AddCookie(c)
}
sess, err := sessManager.Get(req)
require.NoError(t, err)
for _, key := range []string{session.CreatedAtKey, session.LastSeenKey} {
at, ok := sess.Values[key].(int64)
require.True(t, ok, "the session has no %s", key)
sess.Values[key] = at - int64(d/time.Second)
}
w := httptest.NewRecorder()
require.NoError(t, sessManager.Save(req, w, sess))
return sessionCookies(w)
}
func TestRequireAuth_IdleExpiredSession_RedirectsToLogin(
t *testing.T,
) {
@@ -590,13 +607,11 @@ func TestRequireAuth_IdleExpiredSession_RedirectsToLogin(
idle := time.Hour
m, sessManager, clock := testMiddlewareWithSessionClock(
t, config.EnvironmentDev, idle, newFakeClock(),
m, sessManager := testMiddlewareWithIdleTimeout(
t, config.EnvironmentDev, idle,
)
cookies := loginCookies(t, sessManager)
clock.Advance(idle)
cookies := aged(t, sessManager, loginCookies(t, sessManager), idle)
called, w := runAuthed(t, m, cookies)
@@ -621,14 +636,12 @@ func TestRequireAuth_RefreshesIdleDeadlineOnActivity(
idle := time.Hour
m, sessManager, clock := testMiddlewareWithSessionClock(
t, config.EnvironmentDev, idle, newFakeClock(),
m, sessManager := testMiddlewareWithIdleTimeout(
t, config.EnvironmentDev, idle,
)
cookies := loginCookies(t, sessManager)
// Activity halfway through the idle window.
clock.Advance(idle / 2)
cookies := aged(t, sessManager, loginCookies(t, sessManager), idle/2)
called, w := runAuthed(t, m, cookies)
require.True(t, called, "handler should run while valid")
@@ -640,16 +653,22 @@ func TestRequireAuth_RefreshesIdleDeadlineOnActivity(
)
// Past the original deadline. The refreshed cookie is still
// good; the original one is not.
clock.Advance(idle - time.Second)
// good; the original one is not. A minute short of the idle
// window leaves room for the real clock, which the session
// reads, to tick on while the test runs.
later := idle - time.Minute
calledRefreshed, _ := runAuthed(t, m, refreshed)
calledRefreshed, _ := runAuthed(
t, m, aged(t, sessManager, refreshed, later),
)
assert.True(
t, calledRefreshed,
"refreshed session should outlive the original deadline",
)
calledStale, staleW := runAuthed(t, m, cookies)
calledStale, staleW := runAuthed(
t, m, aged(t, sessManager, cookies, later),
)
assert.False(
t, calledStale,
"the pre-refresh cookie carries the old idle deadline",
@@ -662,8 +681,8 @@ func TestRequireAuth_UnauthenticatedRequestDoesNotRefresh(
) {
t.Parallel()
m, sessManager, _ := testMiddlewareWithSessionClock(
t, config.EnvironmentDev, time.Hour, newFakeClock(),
m, sessManager := testMiddlewareWithIdleTimeout(
t, config.EnvironmentDev, time.Hour,
)
// A session cookie that exists but was never authenticated.
@@ -924,12 +943,9 @@ func metricsAuthMiddleware(
MetricsPassword: "secret",
}
key := make([]byte, testKeySize)
store := session.NewStore(key)
sessManager := session.NewForTest(store, cfg, log, key, nil)
return middleware.NewForTest(log, cfg, sessManager)
return middlewaretest.New(
t, log, cfg, newTestSessionManager(t, cfg),
)
}
// runMetricsAuthRequest sends a GET /metrics request with the