1 Commits
Author SHA1 Message Date
clawbot 3bba2df314 Re-vendor the shared files from sneak/prompts at dd4027b (closes #504)
check / check (push) Failing after 6s
Fetches the shared files unchanged from sneak/prompts commit dd4027b and
adds .prettierignore; .dockerignore keeps this repository's anchored host
artifacts at its end.

Linting moves into the Dockerfile's lint phase on the golangci-lint
v2.14.0 image, which also runs the js-lint stage, and Dockerfile.lint is
gone. Tests move into a test phase on the golang bookworm image.
script/lint, test, docker and cibuild are the model scripts, every docker
build in script/ passes --no-cache, and the .ci-fingerprint barrier is
gone. The workflow no longer calls script/ci-mark-superseded, so it and
its tests are removed. make build passes -trimpath and -s -w.

Model: opus-5-5
2026-10-06 01:27:27 +00:00
47 changed files with 347 additions and 444 deletions
-6
View File
@@ -76,9 +76,3 @@
# build extracts its own).
/bin
/static/js/alpine.min.js
# SQLite databases, which hold the session key and webhook payloads, at
# any depth.
**/*.db
**/*.sqlite
**/*.sqlite3
-3
View File
@@ -10,6 +10,3 @@ insert_final_newline = true
[Makefile]
indent_style = tab
[*.go]
indent_style = tab
-36
View File
@@ -45,39 +45,3 @@ node_modules/
[iI][dD]_[eE][cC][dD][sS][aA]_[sS][kK]
[iI][dD]_[eE][dD]25519
[iI][dD]_[eE][dD]25519_[sS][kK]
# This repository's own entries, after the shared content above.
# Binaries
*.exe
*.dll
*.so
*.dylib
bin/
/webhooker
# Test binary, built with `go test -c`
*.test
# Output of the go coverage tool
*.out
# Go vendor directory
vendor/
# Data directory (SQLite databases)
data/
*.db
*.sqlite
*.sqlite3
# Log files
*.log
# Temporary files
tmp/
temp/
# Alpine.js, extracted by `make assets` from its tarball in 3p/, which is
# what is committed.
/static/js/alpine.min.js
-6
View File
@@ -61,12 +61,6 @@ linters:
desc: >-
Test-support code belongs in test files and in packages whose
directory name ends in test, not in the shipped binary.
- pkg: sneak.berlin/go/webhooker/internal/config/configtest
desc: test support; a file that is not a test must not import it
- pkg: sneak.berlin/go/webhooker/internal/database/databasetest
desc: test support; a file that is not a test must not import it
- pkg: sneak.berlin/go/webhooker/internal/middleware/middlewaretest
desc: test support; a file that is not a test must not import it
# Only decisions already recorded in the Go package defaults are
# listed here. Every entry matches the module path exactly.
gomodguard_v2:
+1 -8
View File
@@ -147,16 +147,9 @@ RUN script/assets
# shown in full, so there is nothing to rerun. The step fails after the rerun
# whatever its result: the first run already showed the suite is broken.
#
# TMPDIR, where the tests keep their SQLite databases, is a tmpfs: SQLite
# waits for the disk at every commit, and on a busy host that waiting was
# about 40% of the slowest package's run time. GOTMPDIR keeps go's own
# build files, the test binaries among them, on disk.
#
# bash with pipefail, so that the first run's status is go test's, not tee's.
SHELL ["/bin/bash", "-o", "pipefail", "-c"]
RUN --mount=type=tmpfs,target=/tmp/tests,size=512m \
export TMPDIR=/tmp/tests GOTMPDIR=/tmp; \
go test -race -cover -p 4 -parallel 8 -timeout 90s ./... 2>&1 | tee /tmp/go-test.log && exit 0; \
RUN go test -race -cover -p 4 -parallel 8 -timeout 90s ./... 2>&1 | tee /tmp/go-test.log && exit 0; \
tests="$(awk '/^--- FAIL: / { print $3 }' /tmp/go-test.log | paste -s -d '|' -)"; \
packages="$(awk '/^FAIL\t/ { print $2 }' /tmp/go-test.log)"; \
if [ -n "$tests" ]; then \
+7 -6
View File
@@ -44,7 +44,7 @@ make check
# Run the server from the clone. DATA_DIR defaults to
# /var/lib/webhooker in every environment, so set it (in .env or the
# shell) to a writable directory outside the clone: the databases hold
# the session key.
# the session key, and git does not ignore them.
DATA_DIR=../webhooker-data make dev
# Build Docker image
@@ -2984,7 +2984,7 @@ webhooker/
│ │ └── resetpw.go # `webhooker resetpw`: set an account's password, stopped deployments only
│ ├── config/
│ │ ├── config.go # Configuration loading from environment variables
│ │ └── configtest/ # Test support: ClearEnv, an empty environment for one test
│ │ └── testing.go # ClearEnvForTest: an empty environment for one test
│ ├── database/
│ │ ├── base_model.go # BaseModel with UUID primary keys
│ │ ├── database.go # GORM connection, migrations, admin seed
@@ -3001,8 +3001,8 @@ webhooker/
│ │ ├── model_apikey.go # APIKey entity
│ │ ├── password.go # Argon2id hashing and verification
│ │ ├── retention.go # Retention reaper (per-webhook event expiry)
│ │ ├── webhook_db_manager.go # Per-webhook DB lifecycle manager
│ │ └── databasetest/ # Test support: a WebhookDBManager for tests in other packages
│ │ ├── testing.go # NewTestDatabase: wrapper for tests, no fx lifecycle
│ │ └── webhook_db_manager.go # Per-webhook DB lifecycle manager
│ ├── datadir/
│ │ └── lock.go # Exclusive advisory lock on DATA_DIR (one instance)
│ ├── globals/
@@ -3063,7 +3063,7 @@ webhooker/
│ │ ├── csrf.go # CSRF protection middleware (gorilla/csrf)
│ │ ├── ratelimit.go # Per-IP rate limiting middleware (go-chi/httprate)
│ │ ├── loginguard.go # Login failure counters and the Argon2id verification semaphore
│ │ └── middlewaretest/ # Test support: a Middleware for tests in other packages
│ │ └── testing.go # NewForTest: Middleware without the fx lifecycle
│ ├── reqtls/
│ │ └── reqtls.go # IsTLS: the one TLS predicate, r.TLS or X-Forwarded-Proto
│ ├── server/
@@ -3071,7 +3071,8 @@ webhooker/
│ │ ├── http.go # HTTP server setup with timeouts
│ │ └── routes.go # All route definitions
│ ├── session/
│ │ └── session.go # Cookie-based session management
│ │ ├── session.go # Cookie-based session management
│ │ └── testing.go # NewForTest: Session without the fx lifecycle
│ └── versionscript/
│ └── doc.go # Tests for script/version and the build files that use it
├── static/
-4
View File
@@ -4,7 +4,6 @@ package main
import (
"fmt"
"io"
"log/slog"
"os"
"time"
@@ -188,9 +187,6 @@ func newApp() *fx.App {
fx.Provide(
globals.New,
logger.New,
// The plain logger the session, the middleware and the
// webhook database manager take.
func(l *logger.Logger) *slog.Logger { return l.Get() },
config.New,
database.New,
database.NewWebhookDBManager,
+3 -3
View File
@@ -14,7 +14,7 @@ import (
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
"sneak.berlin/go/webhooker/internal/config/configtest"
"sneak.berlin/go/webhooker/internal/config"
"sneak.berlin/go/webhooker/internal/datadir"
"sneak.berlin/go/webhooker/internal/resetpw"
"sneak.berlin/go/webhooker/internal/server"
@@ -37,7 +37,7 @@ const dockerStopGrace = 10 * time.Second
// fx.New applies options before it executes invokes, so the timeout
// is set whether or not the graph itself can be constructed here.
func TestNewApp_StopTimeout(t *testing.T) {
configtest.ClearEnv(t)
config.ClearEnvForTest(t)
t.Setenv("DATA_DIR", t.TempDir())
got := newApp().StopTimeout()
@@ -75,7 +75,7 @@ func freePort(t *testing.T) int {
// anything is built, and the run of logger.New, which happens before
// the configuration sets the level.
func TestNewApp_SendsFxEventsToTheLogger(t *testing.T) {
configtest.ClearEnv(t)
config.ClearEnvForTest(t)
t.Setenv("DATA_DIR", t.TempDir())
t.Setenv("PORT", strconv.Itoa(freePort(t)))
t.Setenv("DEBUG", "true")
+10 -11
View File
@@ -11,7 +11,6 @@ import (
"go.uber.org/fx"
"go.uber.org/fx/fxtest"
"sneak.berlin/go/webhooker/internal/config"
"sneak.berlin/go/webhooker/internal/config/configtest"
"sneak.berlin/go/webhooker/internal/globals"
"sneak.berlin/go/webhooker/internal/logger"
)
@@ -71,7 +70,7 @@ func TestEnvironmentConfig(t *testing.T) {
t.Run(tt.name, func(t *testing.T) {
// Cannot use t.Parallel() here because t.Setenv
// is incompatible with parallel subtests.
configtest.ClearEnv(t)
config.ClearEnvForTest(t)
if tt.envValue != "" {
t.Setenv(
@@ -197,7 +196,7 @@ func TestRetentionSweepInterval(t *testing.T) {
t.Run(tt.name, func(t *testing.T) {
// Cannot use t.Parallel() here because t.Setenv
// is incompatible with parallel subtests.
configtest.ClearEnv(t)
config.ClearEnvForTest(t)
t.Setenv("WEBHOOKER_ENVIRONMENT", "dev")
if tt.set {
@@ -336,7 +335,7 @@ func TestSessionIdleTimeout(t *testing.T) {
t.Run(tt.name, func(t *testing.T) {
// Cannot use t.Parallel() here because t.Setenv
// is incompatible with parallel subtests.
configtest.ClearEnv(t)
config.ClearEnvForTest(t)
t.Setenv("WEBHOOKER_ENVIRONMENT", "dev")
if tt.set {
@@ -389,7 +388,7 @@ func TestDefaultDataDir(t *testing.T) {
t.Run("env="+name, func(t *testing.T) {
// Cannot use t.Parallel() here because t.Setenv
// is incompatible with parallel subtests.
configtest.ClearEnv(t)
config.ClearEnvForTest(t)
if env != "" {
t.Setenv("WEBHOOKER_ENVIRONMENT", env)
@@ -434,7 +433,7 @@ func TestDataDirHelper(t *testing.T) {
t.Run(name, func(t *testing.T) {
// Cannot use t.Parallel() here because t.Setenv
// is incompatible with parallel subtests.
configtest.ClearEnv(t)
config.ClearEnvForTest(t)
if set != "" {
t.Setenv("DATA_DIR", set)
@@ -499,7 +498,7 @@ func TestReceiverRateLimit(t *testing.T) {
t.Run(tt.name, func(t *testing.T) {
// Cannot use t.Parallel() here because t.Setenv
// is incompatible with parallel subtests.
configtest.ClearEnv(t)
config.ClearEnvForTest(t)
t.Setenv("WEBHOOKER_ENVIRONMENT", "dev")
if tt.set {
@@ -615,7 +614,7 @@ func TestTrustedProxies(t *testing.T) {
t.Run(tt.name, func(t *testing.T) {
// Cannot use t.Parallel() here because t.Setenv
// is incompatible with parallel subtests.
configtest.ClearEnv(t)
config.ClearEnvForTest(t)
t.Setenv("WEBHOOKER_ENVIRONMENT", "dev")
if tt.set {
@@ -726,7 +725,7 @@ func TestAllowedEgressCIDRs(t *testing.T) {
t.Run(tt.name, func(t *testing.T) {
// Cannot use t.Parallel() here because t.Setenv
// is incompatible with parallel subtests.
configtest.ClearEnv(t)
config.ClearEnvForTest(t)
t.Setenv("WEBHOOKER_ENVIRONMENT", "dev")
if tt.set {
@@ -798,7 +797,7 @@ func TestEgressAllowlistWarning(t *testing.T) {
t.Run(tt.name, func(t *testing.T) {
// Cannot use t.Parallel() here because t.Setenv
// is incompatible with parallel subtests.
configtest.ClearEnv(t)
config.ClearEnvForTest(t)
t.Setenv("WEBHOOKER_ENVIRONMENT", config.EnvironmentDev)
if tt.allowed != "" {
@@ -934,7 +933,7 @@ func TestMetricsAuthConfig(t *testing.T) {
t.Run(tt.name, func(t *testing.T) {
// Cannot use t.Parallel() here because t.Setenv
// is incompatible with parallel subtests.
configtest.ClearEnv(t)
config.ClearEnvForTest(t)
if tt.username.set {
t.Setenv("METRICS_USERNAME", tt.username.value)
+7 -8
View File
@@ -8,7 +8,6 @@ import (
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
"sneak.berlin/go/webhooker/internal/config"
"sneak.berlin/go/webhooker/internal/config/configtest"
)
// dotEnvKey is a throwaway variable name the .env tests write and
@@ -40,9 +39,9 @@ func writeDotEnv(t *testing.T, contents string) string {
// normally rather than be refused for a file it was never meant to
// have.
//
//nolint:paralleltest // ClearEnv uses t.Setenv.
//nolint:paralleltest // ClearEnvForTest uses t.Setenv.
func TestLoadDotEnv_MissingFileIsFine(t *testing.T) {
configtest.ClearEnv(t)
config.ClearEnvForTest(t)
absent := filepath.Join(t.TempDir(), config.DotEnvPath)
require.NoError(t, config.LoadDotEnvFileForTest(absent))
@@ -55,9 +54,9 @@ func TestLoadDotEnv_MissingFileIsFine(t *testing.T) {
// reaches the environment, which is the whole reason the file is read
// at all.
//
//nolint:paralleltest // ClearEnv uses t.Setenv.
//nolint:paralleltest // ClearEnvForTest uses t.Setenv.
func TestLoadDotEnv_AppliesValues(t *testing.T) {
configtest.ClearEnv(t)
config.ClearEnvForTest(t)
path := writeDotEnv(t, "# a comment\n"+dotEnvKey+"=from-dot-env\n")
@@ -83,9 +82,9 @@ func TestLoadDotEnv_RealEnvironmentWins(t *testing.T) {
// reverts to its default; the process used to start that way with no
// log line naming the file at all.
//
//nolint:paralleltest // ClearEnv uses t.Setenv.
//nolint:paralleltest // ClearEnvForTest uses t.Setenv.
func TestLoadDotEnv_MalformedFileAborts(t *testing.T) {
configtest.ClearEnv(t)
config.ClearEnvForTest(t)
path := writeDotEnv(
t, malformedDotEnv+dotEnvKey+"=from-dot-env\n",
@@ -133,7 +132,7 @@ func TestLoadDotEnv_UnreadableFileAborts(t *testing.T) {
//
//nolint:paralleltest // t.Chdir moves the whole process.
func TestLoadDotEnv_ReadsTheWorkingDirectory(t *testing.T) {
configtest.ClearEnv(t)
config.ClearEnvForTest(t)
dir := t.TempDir()
require.NoError(t, os.WriteFile(
+5 -6
View File
@@ -7,7 +7,6 @@ import (
"github.com/stretchr/testify/require"
"go.uber.org/fx"
"sneak.berlin/go/webhooker/internal/config"
"sneak.berlin/go/webhooker/internal/config/configtest"
"sneak.berlin/go/webhooker/internal/globals"
"sneak.berlin/go/webhooker/internal/logger"
)
@@ -121,7 +120,7 @@ func TestEnvBool(t *testing.T) {
t.Run(tt.name, func(t *testing.T) {
// Cannot use t.Parallel() here because t.Setenv
// is incompatible with parallel subtests.
configtest.ClearEnv(t)
config.ClearEnvForTest(t)
if tt.set {
t.Setenv(testEnvKey, tt.value)
@@ -170,7 +169,7 @@ func runEnvIntCases(
t.Run(tt.name, func(t *testing.T) {
// Cannot use t.Parallel() here because t.Setenv
// is incompatible with parallel subtests.
configtest.ClearEnv(t)
config.ClearEnvForTest(t)
if tt.set {
t.Setenv(testEnvKey, tt.value)
@@ -311,7 +310,7 @@ func TestEnvBindAddress(t *testing.T) {
t.Run(tt.name, func(t *testing.T) {
// Cannot use t.Parallel() here because t.Setenv
// is incompatible with parallel subtests.
configtest.ClearEnv(t)
config.ClearEnvForTest(t)
if tt.set {
t.Setenv(testEnvKey, tt.value)
@@ -477,7 +476,7 @@ func TestNewRejectsBadEnvValues(t *testing.T) {
t.Run(tt.name, func(t *testing.T) {
// Cannot use t.Parallel() here because t.Setenv
// is incompatible with parallel subtests.
configtest.ClearEnv(t)
config.ClearEnvForTest(t)
t.Setenv("WEBHOOKER_ENVIRONMENT", "dev")
t.Setenv(tt.key, tt.value)
@@ -639,7 +638,7 @@ func sentryEnvValueCases() []badEnvValueCase {
// break the legitimate unset case: absent variables still get their
// documented defaults.
func TestNewUsesDefaultsWhenUnset(t *testing.T) {
configtest.ClearEnv(t)
config.ClearEnvForTest(t)
t.Setenv("WEBHOOKER_ENVIRONMENT", "dev")
cfg, err := buildConfig(t)
+1 -2
View File
@@ -6,7 +6,6 @@ import (
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
"sneak.berlin/go/webhooker/internal/config"
"sneak.berlin/go/webhooker/internal/config/configtest"
)
// envKeySentryDSN is the variable envSentryDSN reads in production.
@@ -101,7 +100,7 @@ func TestEnvSentryDSN(t *testing.T) {
t.Run(tt.name, func(t *testing.T) {
// Cannot use t.Parallel() here because t.Setenv
// is incompatible with parallel subtests.
configtest.ClearEnv(t)
config.ClearEnvForTest(t)
if tt.set {
t.Setenv(envKeySentryDSN, tt.value)
@@ -1,6 +1,4 @@
// Package configtest holds test support for code that reads the
// process environment.
package configtest
package config
import (
"os"
@@ -8,12 +6,12 @@ import (
"testing"
)
// ClearEnv unsets every variable in the process environment
// ClearEnvForTest unsets every variable in the process environment
// for the rest of the test, so a test sees only the variables it sets
// itself, not whatever the developer's shell exports. When the test
// ends it leaves the environment exactly as it found it: each variable
// it unset is put back, and any variable added since is removed.
func ClearEnv(t *testing.T) {
func ClearEnvForTest(t *testing.T) {
t.Helper()
present := make(map[string]bool)
@@ -7,22 +7,21 @@ import (
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
"sneak.berlin/go/webhooker/internal/config"
"sneak.berlin/go/webhooker/internal/config/configtest"
)
// TestClearEnv_RemovesAddedVariables pins that a variable set
// TestClearEnvForTest_RemovesAddedVariables pins that a variable set
// after the clear other than through t.Setenv, as a test's .env file
// sets one, is gone once the test ends, so it cannot reach the tests
// that run after it.
//
//nolint:paralleltest // ClearEnv uses t.Setenv.
func TestClearEnv_RemovesAddedVariables(t *testing.T) {
//nolint:paralleltest // ClearEnvForTest uses t.Setenv.
func TestClearEnvForTest_RemovesAddedVariables(t *testing.T) {
// The outer clear keeps a value of the key exported in the shell
// from making it a variable the inner clear has to put back.
configtest.ClearEnv(t)
config.ClearEnvForTest(t)
t.Run("loads a .env file after the clear", func(t *testing.T) {
configtest.ClearEnv(t)
config.ClearEnvForTest(t)
path := writeDotEnv(t, dotEnvKey+"=from-dot-env\n")
require.NoError(t, config.LoadDotEnvFileForTest(path))
@@ -1,55 +0,0 @@
// Package databasetest builds a WebhookDBManager for tests in other
// packages.
package databasetest
import (
"log/slog"
"os"
"testing"
"github.com/stretchr/testify/require"
"go.uber.org/fx/fxtest"
"sneak.berlin/go/webhooker/internal/config"
"sneak.berlin/go/webhooker/internal/database"
)
// NewWebhookDBManager creates a WebhookDBManager backed by the given
// data directory, logging at DEBUG to standard error.
func NewWebhookDBManager(
t *testing.T, dataDir string,
) *database.WebhookDBManager {
t.Helper()
return NewWebhookDBManagerWithLogger(
t,
dataDir,
slog.New(slog.NewTextHandler(
os.Stderr,
&slog.HandlerOptions{Level: slog.LevelDebug},
)),
)
}
// NewWebhookDBManagerWithLogger is NewWebhookDBManager with the
// logger supplied by the caller. The per-webhook databases this manager
// opens hand that logger to gormlog, so a test that needs to see the SQL
// the service emits can capture it.
//
// It is built through database.NewWebhookDBManager on a lifecycle that
// is never started, so nothing closes its databases but the caller.
func NewWebhookDBManagerWithLogger(
t *testing.T, dataDir string, log *slog.Logger,
) *database.WebhookDBManager {
t.Helper()
mgr, err := database.NewWebhookDBManager(
fxtest.NewLifecycle(t),
database.WebhookDBManagerParams{
Config: &config.Config{DataDir: dataDir},
Logger: log,
},
)
require.NoError(t, err)
return mgr
}
+11 -12
View File
@@ -13,7 +13,6 @@ import (
"github.com/stretchr/testify/require"
_ "modernc.org/sqlite"
"sneak.berlin/go/webhooker/internal/database"
"sneak.berlin/go/webhooker/internal/database/databasetest"
)
// testDataDirPerm is the mode the test data directory is created
@@ -134,7 +133,7 @@ func TestOpenPurgesLeakedTargetRows(t *testing.T) {
// Create the file the way the application does, so the targets
// table has exactly the shape AutoMigrate gives it, then write
// a leaked row into it the way the association upsert did.
initial := databasetest.NewWebhookDBManager(t, dataDir)
initial := database.NewTestWebhookDBManager(dataDir)
_, err := initial.GetDB(webhookID)
require.NoError(t, err)
@@ -157,7 +156,7 @@ func TestOpenPurgesLeakedTargetRows(t *testing.T) {
clearEventDBSweptMarker(t, seed)
require.NoError(t, seed.Close())
mgr := databasetest.NewWebhookDBManager(t, dataDir)
mgr := database.NewTestWebhookDBManager(dataDir)
_, err = mgr.GetDB(webhookID)
require.NoError(t, err)
@@ -173,7 +172,7 @@ func TestOpenPurgesLeakedTargetRows(t *testing.T) {
// Idempotent: a second open leaves it at zero and does not
// error.
again := databasetest.NewWebhookDBManager(t, dataDir)
again := database.NewTestWebhookDBManager(dataDir)
_, err = again.GetDB(webhookID)
require.NoError(t, err)
@@ -196,7 +195,7 @@ func TestOpenPurgeRemovesCredentialBytes(t *testing.T) {
webhookID := uuid.New().String()
credential := "T00000000/B00000000/" + uuid.New().String()
initial := databasetest.NewWebhookDBManager(t, dataDir)
initial := database.NewTestWebhookDBManager(dataDir)
_, err := initial.GetDB(webhookID)
require.NoError(t, err)
@@ -231,7 +230,7 @@ func TestOpenPurgeRemovesCredentialBytes(t *testing.T) {
"seeded credential is not in the file, so this test proves nothing",
)
mgr := databasetest.NewWebhookDBManager(t, dataDir)
mgr := database.NewTestWebhookDBManager(dataDir)
_, err = mgr.GetDB(webhookID)
require.NoError(t, err)
@@ -259,7 +258,7 @@ func TestOpenRevacuumsAfterIncompleteSweep(t *testing.T) {
webhookID := uuid.New().String()
credential := "T00000000/B00000000/" + uuid.New().String()
initial := databasetest.NewWebhookDBManager(t, dataDir)
initial := database.NewTestWebhookDBManager(dataDir)
_, err := initial.GetDB(webhookID)
require.NoError(t, err)
@@ -299,7 +298,7 @@ func TestOpenRevacuumsAfterIncompleteSweep(t *testing.T) {
"test proves nothing",
)
mgr := databasetest.NewWebhookDBManager(t, dataDir)
mgr := database.NewTestWebhookDBManager(dataDir)
_, err = mgr.GetDB(webhookID)
require.NoError(t, err)
@@ -326,7 +325,7 @@ func TestOpenSkipsSweptDatabase(t *testing.T) {
dataDir := eventDBDataDir(t)
webhookID := uuid.New().String()
mgr := databasetest.NewWebhookDBManager(t, dataDir)
mgr := database.NewTestWebhookDBManager(dataDir)
_, err := mgr.GetDB(webhookID)
require.NoError(t, err)
@@ -348,7 +347,7 @@ func TestOpenSkipsSweptDatabase(t *testing.T) {
require.NoError(t, err)
require.NoError(t, marked.Close())
again := databasetest.NewWebhookDBManager(t, dataDir)
again := database.NewTestWebhookDBManager(dataDir)
_, err = again.GetDB(webhookID)
require.NoError(t, err)
@@ -379,7 +378,7 @@ func TestOpenSucceedsWithoutTargetsTable(t *testing.T) {
require.NoError(t, err)
require.NoError(t, seed.Close())
mgr := databasetest.NewWebhookDBManager(t, dataDir)
mgr := database.NewTestWebhookDBManager(dataDir)
db, err := mgr.GetDB(webhookID)
require.NoError(t, err)
@@ -397,7 +396,7 @@ func TestEventDBCreateOmitsAssociations(t *testing.T) {
dataDir := eventDBDataDir(t)
webhookID := uuid.New().String()
mgr := databasetest.NewWebhookDBManager(t, dataDir)
mgr := database.NewTestWebhookDBManager(dataDir)
db, err := mgr.GetDB(webhookID)
require.NoError(t, err)
+1 -1
View File
@@ -51,7 +51,7 @@ func setupRetentionTest(t *testing.T) *retentionTestEnv {
mgr, err := database.NewWebhookDBManager(
lc,
database.WebhookDBManagerParams{Config: cfg, Logger: l.Get()},
database.WebhookDBManagerParams{Config: cfg, Logger: l},
)
require.NoError(t, err)
+47
View File
@@ -0,0 +1,47 @@
package database
import (
"log/slog"
"os"
"gorm.io/gorm"
)
// NewTestDatabase creates a Database wrapper around a pre-opened *gorm.DB.
// Intended for use in tests that need a *database.Database without the
// full fx lifecycle. The caller is responsible for closing the underlying
// sql.DB connection.
func NewTestDatabase(db *gorm.DB) *Database {
return &Database{
db: db,
log: slog.New(slog.NewTextHandler(
os.Stderr,
&slog.HandlerOptions{Level: slog.LevelDebug},
)),
}
}
// NewTestWebhookDBManager creates a WebhookDBManager backed by the given
// data directory. Intended for use in tests without the fx lifecycle.
func NewTestWebhookDBManager(dataDir string) *WebhookDBManager {
return NewTestWebhookDBManagerWithLogger(
dataDir,
slog.New(slog.NewTextHandler(
os.Stderr,
&slog.HandlerOptions{Level: slog.LevelDebug},
)),
)
}
// NewTestWebhookDBManagerWithLogger is NewTestWebhookDBManager with the
// logger supplied by the caller. The per-webhook databases this manager
// opens hand that logger to gormlog, so a test that needs to see the SQL
// the service emits can capture it.
func NewTestWebhookDBManagerWithLogger(
dataDir string, log *slog.Logger,
) *WebhookDBManager {
return &WebhookDBManager{
dataDir: dataDir,
log: log,
}
}
+3 -2
View File
@@ -15,6 +15,7 @@ import (
"sneak.berlin/go/webhooker/internal/config"
"sneak.berlin/go/webhooker/internal/datadir"
"sneak.berlin/go/webhooker/internal/gormlog"
"sneak.berlin/go/webhooker/internal/logger"
)
// WebhookDBManagerParams holds the fx dependencies for
@@ -23,7 +24,7 @@ type WebhookDBManagerParams struct {
fx.In
Config *config.Config
Logger *slog.Logger
Logger *logger.Logger
}
// errInvalidCachedDBType indicates a type assertion failure
@@ -69,7 +70,7 @@ func NewWebhookDBManager(
) (*WebhookDBManager, error) {
m := &WebhookDBManager{
dataDir: params.Config.DataDir,
log: params.Logger,
log: params.Logger.Get(),
}
// Create data directory if it doesn't exist. datadir.DirPerm is the
+3 -6
View File
@@ -18,7 +18,6 @@ import (
"gorm.io/gorm"
"sneak.berlin/go/webhooker/internal/config"
"sneak.berlin/go/webhooker/internal/database"
"sneak.berlin/go/webhooker/internal/database/databasetest"
"sneak.berlin/go/webhooker/internal/globals"
"sneak.berlin/go/webhooker/internal/logger"
)
@@ -51,7 +50,7 @@ func setupTestWebhookDBManager(
lc,
database.WebhookDBManagerParams{
Config: cfg,
Logger: l.Get(),
Logger: l,
},
)
require.NoError(t, err)
@@ -118,8 +117,7 @@ func TestWebhookDBManager_ConcurrentFirstTouchOpensOnce(t *testing.T) {
var logs bytes.Buffer
mgr := databasetest.NewWebhookDBManagerWithLogger(
t,
mgr := database.NewTestWebhookDBManagerWithLogger(
t.TempDir(),
slog.New(slog.NewTextHandler(&logs, nil)),
)
@@ -309,8 +307,7 @@ func TestWebhookDBManager_LostDatabaseIsLogged(t *testing.T) {
var logs bytes.Buffer
mgr := databasetest.NewWebhookDBManagerWithLogger(
t,
mgr := database.NewTestWebhookDBManagerWithLogger(
t.TempDir(),
slog.New(slog.NewTextHandler(&logs, nil)),
)
+18 -4
View File
@@ -21,7 +21,6 @@ import (
"gorm.io/gorm/clause"
_ "modernc.org/sqlite" // Pure Go SQLite driver.
"sneak.berlin/go/webhooker/internal/database"
"sneak.berlin/go/webhooker/internal/database/databasetest"
"sneak.berlin/go/webhooker/internal/delivery"
"sneak.berlin/go/webhooker/internal/gormlog"
)
@@ -60,14 +59,29 @@ func setupArchiveTest(t *testing.T) *archiveEnv {
dataDir := t.TempDir()
log := archiveTestLogger()
mainDB, err := database.Open(dataDir, slog.New(slog.DiscardHandler))
sqlDB, err := sql.Open(
"sqlite",
fmt.Sprintf(
"file:%s?mode=rwc",
filepath.Join(dataDir, "main.db"),
),
)
require.NoError(t, err)
t.Cleanup(func() { _ = mainDB.Close() })
t.Cleanup(func() { _ = sqlDB.Close() })
gdb, err := gorm.Open(
sqlite.Dialector{Conn: sqlDB},
&gorm.Config{Logger: gormlog.New(slog.New(slog.DiscardHandler))},
)
require.NoError(t, err)
mainDB := database.NewTestDatabase(gdb)
require.NoError(t, mainDB.Migrate())
eng := delivery.NewTestEngineWithDB(
mainDB,
databasetest.NewWebhookDBManager(t, dataDir),
database.NewTestWebhookDBManager(dataDir),
log,
&http.Client{Timeout: 5 * time.Second},
1,
+40 -19
View File
@@ -10,6 +10,7 @@ import (
"net/http"
"net/http/httptest"
"os"
"path/filepath"
"strings"
"sync/atomic"
"testing"
@@ -18,11 +19,12 @@ import (
"github.com/google/uuid"
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
"gorm.io/driver/sqlite"
"gorm.io/gorm"
_ "modernc.org/sqlite"
"sneak.berlin/go/webhooker/internal/database"
"sneak.berlin/go/webhooker/internal/database/databasetest"
"sneak.berlin/go/webhooker/internal/delivery"
"sneak.berlin/go/webhooker/internal/gormlog"
)
// iSetup holds common integration test dependencies.
@@ -43,12 +45,12 @@ func newISetup(t *testing.T) iSetup {
wDB := iSeedWebhookDB(t, dbMgr, wID)
return iSetup{
MainDB: mainDB.DB(),
MainDB: mainDB,
DBMgr: dbMgr,
WebhookID: wID,
WebhookDB: wDB,
Engine: delivery.NewTestEngineWithDB(
mainDB,
database.NewTestDatabase(mainDB),
dbMgr,
slog.New(slog.NewTextHandler(
os.Stderr,
@@ -62,16 +64,35 @@ func newISetup(t *testing.T) iSetup {
}
}
// iMainDB opens a main database through database.Open, the way the
// service opens it, so these tests cannot pass against journal and
// locking settings production does not use.
func iMainDB(t *testing.T) *database.Database {
func iMainDB(t *testing.T) *gorm.DB {
t.Helper()
db, err := database.Open(t.TempDir(), slog.New(slog.DiscardHandler))
dbPath := filepath.Join(
t.TempDir(), "main-test.db",
)
// Opened the way the service opens the main database, so these
// tests cannot pass against journal and locking settings
// production does not use.
sqlDB, err := database.OpenSQLite(
dbPath, database.SQLiteModeCreate,
)
require.NoError(t, err)
t.Cleanup(func() { _ = db.Close() })
t.Cleanup(func() { _ = sqlDB.Close() })
db, err := gorm.Open(
sqlite.Dialector{Conn: sqlDB},
&gorm.Config{Logger: gormlog.New(slog.New(slog.DiscardHandler))},
)
require.NoError(t, err)
require.NoError(t, db.AutoMigrate(
&database.Webhook{},
&database.Target{},
&database.User{},
&database.Setting{},
))
return db
}
@@ -81,7 +102,7 @@ func iDBManager(
) *database.WebhookDBManager {
t.Helper()
return databasetest.NewWebhookDBManager(t, t.TempDir())
return database.NewTestWebhookDBManager(t.TempDir())
}
func iSeedWebhookDB(
@@ -1133,17 +1154,17 @@ func TestRecoverInFlight_ReportsAMissingWebhookDatabase(t *testing.T) {
mainDB := iMainDB(t)
webhookID := uuid.New().String()
iCreateWebhook(t, mainDB.DB(), webhookID, "lost-database")
iCreateWebhook(t, mainDB, webhookID, "lost-database")
var logs bytes.Buffer
dbMgr := databasetest.NewWebhookDBManagerWithLogger(
t, t.TempDir(), slog.New(slog.NewTextHandler(&logs, nil)),
dbMgr := database.NewTestWebhookDBManagerWithLogger(
t.TempDir(), slog.New(slog.NewTextHandler(&logs, nil)),
)
t.Cleanup(func() { _ = dbMgr.CloseAll() })
engine := delivery.NewTestEngineWithDB(
mainDB, dbMgr,
database.NewTestDatabase(mainDB), dbMgr,
slog.New(slog.DiscardHandler),
&http.Client{Timeout: 5 * time.Second}, 1,
)
@@ -1167,14 +1188,14 @@ func TestRecoverInFlight_SkipsAWebhookDeletedAfterTheListIsRead(
mainDB := iMainDB(t)
webhookID := uuid.New().String()
iCreateWebhook(t, mainDB.DB(), webhookID, "deleted-during-recovery")
iCreateWebhook(t, mainDB, webhookID, "deleted-during-recovery")
// The first query to return is recovery's read of the list of
// webhooks. Deleting the webhook right after it puts the delete
// between that read and the opening of the webhook's database.
deleted := false
require.NoError(t, mainDB.DB().Callback().Query().After("gorm:query").
require.NoError(t, mainDB.Callback().Query().After("gorm:query").
Register("delete-after-list", func(*gorm.DB) {
if deleted {
return
@@ -1182,16 +1203,16 @@ func TestRecoverInFlight_SkipsAWebhookDeletedAfterTheListIsRead(
deleted = true
require.NoError(t, mainDB.DB().Delete(
require.NoError(t, mainDB.Delete(
&database.Webhook{}, "id = ?", webhookID,
).Error)
}))
dbMgr := databasetest.NewWebhookDBManager(t, t.TempDir())
dbMgr := database.NewTestWebhookDBManager(t.TempDir())
t.Cleanup(func() { _ = dbMgr.CloseAll() })
engine := delivery.NewTestEngineWithDB(
mainDB, dbMgr,
database.NewTestDatabase(mainDB), dbMgr,
slog.New(slog.DiscardHandler),
&http.Client{Timeout: 5 * time.Second}, 1,
)
+3 -4
View File
@@ -48,9 +48,8 @@ func fSweepSetup(
//
// Every caller drives the dispatch paths synchronously and has already
// waited for them to return, so anything they queued is in the channel
// by now, and nothing is waited for. A timer here would race the queued
// tasks: on a busy host it can be due by the time select looks, and
// select picks at random among the cases that are ready.
// by now. The short grace covers nothing but scheduler jitter, and is
// kept small because one of these tests runs the drain forty times.
func fDrain(e *delivery.Engine) []delivery.Task {
var out []delivery.Task
@@ -60,7 +59,7 @@ func fDrain(e *delivery.Engine) []delivery.Task {
out = append(out, task)
case task := <-e.ExportRetryCh():
out = append(out, task)
default:
case <-time.After(25 * time.Millisecond):
return out
}
}
+26 -9
View File
@@ -5,6 +5,7 @@ import (
"context"
"log/slog"
"net/http"
"path/filepath"
"strings"
"sync"
"testing"
@@ -13,9 +14,11 @@ import (
"github.com/google/uuid"
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
"gorm.io/driver/sqlite"
"gorm.io/gorm"
"sneak.berlin/go/webhooker/internal/database"
"sneak.berlin/go/webhooker/internal/database/databasetest"
"sneak.berlin/go/webhooker/internal/delivery"
"sneak.berlin/go/webhooker/internal/gormlog"
)
// qdAggregateMarker identifies the queue-depth aggregate in the
@@ -46,13 +49,27 @@ func (q *qdSyncBuf) String() string {
// qdMainDB opens a main database whose GORM logger is the service's
// adapter, writing through log.
func qdMainDB(t *testing.T, log *slog.Logger) *database.Database {
func qdMainDB(t *testing.T, log *slog.Logger) *gorm.DB {
t.Helper()
db, err := database.Open(t.TempDir(), log)
sqlDB, err := database.OpenSQLite(
filepath.Join(t.TempDir(), "main-gormlog.db"),
database.SQLiteModeCreate,
)
require.NoError(t, err)
t.Cleanup(func() { _ = db.Close() })
t.Cleanup(func() { _ = sqlDB.Close() })
db, err := gorm.Open(
sqlite.Dialector{Conn: sqlDB},
&gorm.Config{Logger: gormlog.New(log)},
)
require.NoError(t, err)
require.NoError(t, db.AutoMigrate(
&database.Webhook{},
&database.Target{},
))
return db
}
@@ -89,18 +106,18 @@ func TestQueueDepthSample_LogsNoBoundValue(t *testing.T) {
))
mainDB := qdMainDB(t, log)
dbMgr := databasetest.NewWebhookDBManagerWithLogger(
t, t.TempDir(), log,
dbMgr := database.NewTestWebhookDBManagerWithLogger(
t.TempDir(), log,
)
webhookID := uuid.New().String()
webhookDB := iSeedWebhookDB(t, dbMgr, webhookID)
iCreateWebhook(t, mainDB.DB(), webhookID, "queue-depth-gormlog")
iCreateWebhook(t, mainDB, webhookID, "queue-depth-gormlog")
targetID := uuid.New().String()
iCreateTarget(t, mainDB.DB(), targetID, webhookID,
iCreateTarget(t, mainDB, targetID, webhookID,
"queue-depth-gormlog-target", database.TargetTypeHTTP,
iHTTPConfig("https://example.com/hook"), 3,
)
@@ -119,7 +136,7 @@ func TestQueueDepthSample_LogsNoBoundValue(t *testing.T) {
)
engine := delivery.NewTestEngineWithDB(
mainDB,
database.NewTestDatabase(mainDB),
dbMgr,
log,
&http.Client{Timeout: 5 * time.Second},
@@ -460,13 +460,8 @@ func TestArchiveExport_OneFileOpenAtATime(t *testing.T) {
}
// heapPeak is an io.Writer that discards what it is given and records
// the largest heap it saw at a write. It collects garbage twice before
// each reading, so the heap it reads is what is still held. Once is not
// enough: the libraries the export calls (regexp, under GORM's table
// names, and encoding/json among them) cache buffers in a sync.Pool,
// which keeps them through one collection, so after one the reading
// counts however many happen to be cached. That varies from run to run
// by about as much as the limit in TestArchiveExport_Streams.
// the largest heap it saw at a write. It collects garbage before each
// reading, so the heap it reads is what is still held.
type heapPeak struct {
max uint64
}
@@ -474,7 +469,6 @@ type heapPeak struct {
func (p *heapPeak) Write(b []byte) (int, error) {
var m runtime.MemStats
runtime.GC()
runtime.GC()
runtime.ReadMemStats(&m)
p.max = max(p.max, m.HeapAlloc)
@@ -504,8 +498,6 @@ func exportHeapGrowth(t *testing.T, rows, bodySize int) uint64 {
export := listExport(t, path)
// Twice, for the reason heapPeak gives.
runtime.GC()
runtime.GC()
var start runtime.MemStats
@@ -10,7 +10,6 @@ import (
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
"sneak.berlin/go/webhooker/internal/database"
"sneak.berlin/go/webhooker/internal/database/databasetest"
"sneak.berlin/go/webhooker/internal/delivery"
)
@@ -336,7 +335,7 @@ func TestArchivePathAt(t *testing.T) {
t.Parallel()
dataDir := t.TempDir()
dbMgr := databasetest.NewWebhookDBManager(t, dataDir)
dbMgr := database.NewTestWebhookDBManager(dataDir)
webhook := &database.Webhook{
BaseModel: database.BaseModel{ID: "wh-id"}, Name: "Orders",
}
+1 -4
View File
@@ -3,7 +3,6 @@ package gormlog_test
import (
"context"
"database/sql"
"log/slog"
"os"
"path/filepath"
"testing"
@@ -14,7 +13,6 @@ import (
"go.uber.org/fx/fxtest"
_ "modernc.org/sqlite" // Pure Go SQLite driver.
"sneak.berlin/go/webhooker/internal/config"
"sneak.berlin/go/webhooker/internal/config/configtest"
"sneak.berlin/go/webhooker/internal/database"
"sneak.berlin/go/webhooker/internal/globals"
"sneak.berlin/go/webhooker/internal/logger"
@@ -130,7 +128,7 @@ func readFirstBootSecrets(
func bootAtDebug(t *testing.T, dataDir string) string {
t.Helper()
configtest.ClearEnv(t)
config.ClearEnvForTest(t)
t.Setenv("DEBUG", "true")
t.Setenv("DATA_DIR", dataDir)
@@ -147,7 +145,6 @@ func bootAtDebug(t *testing.T, dataDir string) string {
fx.Provide(
globals.New,
logger.New,
func(l *logger.Logger) *slog.Logger { return l.Get() },
config.New,
database.New,
session.New,
-2
View File
@@ -5,7 +5,6 @@ import (
"errors"
"fmt"
"html/template"
"log/slog"
"net/http"
"net/http/httptest"
"sync"
@@ -250,7 +249,6 @@ func newTestAppWithConfig(
fx.Provide(
globals.New,
logger.New,
func(l *logger.Logger) *slog.Logger { return l.Get() },
func() *config.Config { return cfg },
database.New,
database.NewWebhookDBManager,
+2 -2
View File
@@ -15,7 +15,7 @@ import (
"sneak.berlin/go/webhooker/internal/database"
"sneak.berlin/go/webhooker/internal/handlers"
"sneak.berlin/go/webhooker/internal/logger"
"sneak.berlin/go/webhooker/internal/middleware/middlewaretest"
"sneak.berlin/go/webhooker/internal/middleware"
"sneak.berlin/go/webhooker/internal/session"
)
@@ -135,7 +135,7 @@ func TestUserRoute_Unauthenticated_RedirectedByMiddleware(t *testing.T) {
t.Cleanup(app.RequireStop)
mw := middlewaretest.New(t, log.Get(), cfg, sess)
mw := middleware.NewForTest(log.Get(), cfg, sess)
var handlerReached bool
@@ -15,7 +15,7 @@ import (
"github.com/stretchr/testify/require"
"sneak.berlin/go/webhooker/internal/config"
"sneak.berlin/go/webhooker/internal/database"
"sneak.berlin/go/webhooker/internal/middleware/middlewaretest"
"sneak.berlin/go/webhooker/internal/middleware"
)
// targetSecretSegments are the path segments of an incoming-webhook
@@ -65,8 +65,7 @@ func postTargetCreate(
t.Helper()
logBuf := new(bytes.Buffer)
mw := middlewaretest.New(
t,
mw := middleware.NewForTest(
slog.New(slog.NewJSONHandler(
logBuf, &slog.HandlerOptions{Level: slog.LevelInfo},
)),
+2 -3
View File
@@ -24,7 +24,7 @@ import (
"sneak.berlin/go/webhooker/internal/config"
"sneak.berlin/go/webhooker/internal/database"
"sneak.berlin/go/webhooker/internal/delivery"
"sneak.berlin/go/webhooker/internal/middleware/middlewaretest"
"sneak.berlin/go/webhooker/internal/middleware"
)
// errClientGone is the write failure of a client that has gone away.
@@ -310,8 +310,7 @@ func limitedServer(
const sendBuffer = 4 << 10
logBuf := new(bytes.Buffer)
mw := middlewaretest.New(
t,
mw := middleware.NewForTest(
slog.New(slog.NewJSONHandler(logBuf, nil)),
&config.Config{Environment: config.EnvironmentDev},
nil,
+2 -3
View File
@@ -16,7 +16,6 @@ import (
"github.com/stretchr/testify/require"
"sneak.berlin/go/webhooker/internal/config"
"sneak.berlin/go/webhooker/internal/middleware"
"sneak.berlin/go/webhooker/internal/middleware/middlewaretest"
)
// floodRequests is the number of distinct invented paths each flood
@@ -84,7 +83,7 @@ func capturingMiddleware(t *testing.T) (*middleware.Middleware, *bytes.Buffer) {
TrustedProxies: trustedProxies("192.0.2.1/32"),
}
return middlewaretest.New(t, log, cfg, nil), buf
return middleware.NewForTest(log, cfg, nil), buf
}
// capturingTextMiddleware is capturingMiddleware for the other handler
@@ -108,7 +107,7 @@ func capturingTextMiddleware(
TrustedProxies: trustedProxies("192.0.2.1/32"),
}
return middlewaretest.New(t, log, cfg, nil), buf
return middleware.NewForTest(log, cfg, nil), buf
}
// accessLogRouter mirrors the production route shapes that an
+2 -3
View File
@@ -12,7 +12,6 @@ import (
"github.com/stretchr/testify/require"
"sneak.berlin/go/webhooker/internal/config"
"sneak.berlin/go/webhooker/internal/middleware"
"sneak.berlin/go/webhooker/internal/middleware/middlewaretest"
)
const (
@@ -134,8 +133,8 @@ func clientLogLines(
TrustedProxies: trustedProxies(trustedProxyCIDR),
}
m := middlewaretest.New(
t, log, cfg, newTestSessionManager(t, cfg),
m := middleware.NewForTest(
log, cfg, newTestSessionManager(cfg, log, nil),
)
handler := m.Logging()(site.build(m))
+2 -3
View File
@@ -41,7 +41,6 @@ import (
"github.com/stretchr/testify/require"
"sneak.berlin/go/webhooker/internal/config"
"sneak.berlin/go/webhooker/internal/middleware"
"sneak.berlin/go/webhooker/internal/middleware/middlewaretest"
)
// bodyLimitBytes is the MaxBodySize cap these tests install. Any
@@ -156,9 +155,9 @@ func capturingBoundMiddleware(
ReceiverRateLimit: receiverLimitPerMinute,
}
sess := newTestSessionManager(t, cfg)
sess := newTestSessionManager(cfg, log, nil)
return middlewaretest.New(t, log, cfg, sess), buf
return middleware.NewForTest(log, cfg, sess), buf
}
// unreachable is a next-handler that fails the test if the middleware
+1 -1
View File
@@ -151,7 +151,7 @@ var _ httpmetrics.Recorder = boundedLabelRecorder{}
// Metrics returns middleware that records Prometheus HTTP metrics
// with the Middleware's one recorder, which New builds on the registry
// it is given: in the application, the one the /metrics route serves.
// the /metrics route serves and NewForTest on a registry of its own.
// Every call reuses that recorder, so any number of routers can
// install it.
func (s *Middleware) Metrics() func(http.Handler) http.Handler {
+8 -9
View File
@@ -16,7 +16,6 @@ import (
"github.com/stretchr/testify/require"
"sneak.berlin/go/webhooker/internal/config"
"sneak.berlin/go/webhooker/internal/middleware"
"sneak.berlin/go/webhooker/internal/middleware/middlewaretest"
)
const (
@@ -71,8 +70,8 @@ func metricsTestRouter(
Environment: "prod",
ReceiverRateLimit: receiverLimit,
}
m := middlewaretest.New(
t, log, cfg, newTestSessionManager(t, cfg),
m := middleware.NewForTest(
log, cfg, newTestSessionManager(cfg, log, nil),
)
reg := prometheus.NewRegistry()
@@ -456,11 +455,11 @@ func TestMetrics_StatusAndSizeStillRecorded(t *testing.T) {
)
}
// TestMetrics_WorksOnMiddlewaretestNew pins that a Middleware built
// by middlewaretest.New has a recorder of its own: its Metrics()
// serves a request instead of panicking, and a second one does not
// collide with the first.
func TestMetrics_WorksOnMiddlewaretestNew(t *testing.T) {
// TestMetrics_WorksOnNewForTestMiddleware pins that a Middleware built
// by NewForTest has a recorder of its own: its Metrics() serves a
// request instead of panicking, and a second one does not collide
// with the first.
func TestMetrics_WorksOnNewForTestMiddleware(t *testing.T) {
t.Parallel()
log := slog.New(slog.DiscardHandler)
@@ -470,7 +469,7 @@ func TestMetrics_WorksOnMiddlewaretestNew(t *testing.T) {
})
for range 2 {
h := middlewaretest.New(t, log, cfg, nil).Metrics()(ok)
h := middleware.NewForTest(log, cfg, nil).Metrics()(ok)
req := httptest.NewRequestWithContext(
t.Context(), http.MethodGet, okRoute, nil,
+9 -6
View File
@@ -22,6 +22,7 @@ import (
"sneak.berlin/go/webhooker/internal/config"
"sneak.berlin/go/webhooker/internal/globals"
"sneak.berlin/go/webhooker/internal/logfield"
"sneak.berlin/go/webhooker/internal/logger"
"sneak.berlin/go/webhooker/internal/session"
)
@@ -154,7 +155,7 @@ const (
type MiddlewareParams struct {
fx.In
Logger *slog.Logger
Logger *logger.Logger
Globals *globals.Globals
Config *config.Config
Session *session.Session
@@ -168,10 +169,12 @@ type Middleware struct {
params *MiddlewareParams
session *session.Session
// metricsRecorder records the inbound HTTP metrics on
// params.Registry. It is built once per Middleware and Metrics
// reuses it, because building it registers its collectors, and a
// second registration on the same registry panics.
// metricsRecorder records the inbound HTTP metrics. New builds
// it on the registry /metrics serves, NewForTest on a registry
// of its own. Either way it is built once per Middleware and
// Metrics reuses it, because building it registers its
// collectors, and a second registration on the same registry
// panics.
metricsRecorder httpmetrics.Recorder
// loginGuard counts failed credential verifications and bounds
@@ -190,7 +193,7 @@ func New(
) (*Middleware, error) {
s := new(Middleware)
s.params = &params
s.log = params.Logger
s.log = params.Logger.Get()
s.session = params.Session
s.metricsRecorder = prommetrics.NewRecorder(
prommetrics.Config{Registry: params.Registry},
+71 -87
View File
@@ -14,34 +14,36 @@ import (
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
"go.uber.org/fx/fxtest"
"sneak.berlin/go/webhooker/internal/config"
"sneak.berlin/go/webhooker/internal/database"
"sneak.berlin/go/webhooker/internal/middleware"
"sneak.berlin/go/webhooker/internal/middleware/middlewaretest"
"sneak.berlin/go/webhooker/internal/session"
)
const testKeySize = 32
// testMiddleware creates a Middleware with minimal dependencies
// for testing. It uses a real session.Session.
// for testing. It uses a real session.Session backed by an
// in-memory cookie store.
func testMiddleware(
t *testing.T,
env string,
) (*middleware.Middleware, *session.Session) {
t.Helper()
return testMiddlewareWithIdleTimeout(t, env, 0)
m, s, _ := testMiddlewareWithSessionClock(t, env, 0, nil)
return m, s
}
// testMiddlewareWithIdleTimeout is testMiddleware with a
// configurable session idle timeout, for the session-expiry tests.
func testMiddlewareWithIdleTimeout(
// testMiddlewareWithSessionClock is testMiddleware with a
// configurable session idle timeout and a manually advanced clock,
// for the session-expiry tests. A nil clock uses the real one.
func testMiddlewareWithSessionClock(
t *testing.T,
env string,
idleTimeout time.Duration,
) (*middleware.Middleware, *session.Session) {
clock *fakeClock,
) (*middleware.Middleware, *session.Session, *fakeClock) {
t.Helper()
log := slog.New(slog.NewTextHandler(
@@ -54,44 +56,59 @@ func testMiddlewareWithIdleTimeout(
SessionIdleTimeout: idleTimeout,
}
sessManager := newTestSessionManager(t, cfg)
sessManager := newTestSessionManager(cfg, log, clock)
m := middlewaretest.New(t, log, cfg, sessManager)
m := middleware.NewForTest(log, cfg, sessManager)
return m, sessManager
return m, sessManager, clock
}
// newTestSessionManager builds the real session.Session the
// middleware tests run against, through session.New, with its key
// in a main database of its own.
// middleware tests run against: an in-memory cookie store with a
// known key, and optionally a manually advanced clock.
func newTestSessionManager(
t *testing.T,
cfg *config.Config,
log *slog.Logger,
clock *fakeClock,
) *session.Session {
t.Helper()
key := make([]byte, testKeySize)
discard := slog.New(slog.DiscardHandler)
for i := range key {
key[i] = byte(i)
}
db, err := database.Open(t.TempDir(), discard)
require.NoError(t, err)
store := session.NewStore(key)
t.Cleanup(func() { _ = db.Close() })
var now func() time.Time
lc := fxtest.NewLifecycle(t)
if clock != nil {
now = clock.Now
}
sessManager, err := session.New(lc, session.Params{
Config: cfg,
Database: db,
Logger: discard,
})
require.NoError(t, err)
return session.NewForTest(store, cfg, log, key, now)
}
// The start hook reads the key from db and builds the cookie
// store.
lc.RequireStart()
t.Cleanup(lc.RequireStop)
// fakeClock is a manually advanced clock, so session expiry can be
// tested without sleeping.
type fakeClock struct {
t time.Time
}
return sessManager
func (c *fakeClock) Now() time.Time {
return c.t
}
func (c *fakeClock) Advance(d time.Duration) {
c.t = c.t.Add(d)
}
// newFakeClock returns a clock started at a fixed instant.
func newFakeClock() *fakeClock {
return &fakeClock{
t: time.Date(
2026, time.January, 2, 3, 4, 5, 0, time.UTC,
),
}
}
// --- Logging Middleware Tests ---
@@ -566,40 +583,6 @@ func sessionCookies(
return out
}
// aged re-issues the session cookie in cookies with both of its
// timestamps moved back by d: the cookie as it stands once d has
// passed, so session expiry can be tested without sleeping.
func aged(
t *testing.T,
sessManager *session.Session,
cookies []*http.Cookie,
d time.Duration,
) []*http.Cookie {
t.Helper()
req := httptest.NewRequestWithContext(
context.Background(), http.MethodGet, "/", nil)
for _, c := range cookies {
req.AddCookie(c)
}
sess, err := sessManager.Get(req)
require.NoError(t, err)
for _, key := range []string{session.CreatedAtKey, session.LastSeenKey} {
at, ok := sess.Values[key].(int64)
require.True(t, ok, "the session has no %s", key)
sess.Values[key] = at - int64(d/time.Second)
}
w := httptest.NewRecorder()
require.NoError(t, sessManager.Save(req, w, sess))
return sessionCookies(w)
}
func TestRequireAuth_IdleExpiredSession_RedirectsToLogin(
t *testing.T,
) {
@@ -607,11 +590,13 @@ func TestRequireAuth_IdleExpiredSession_RedirectsToLogin(
idle := time.Hour
m, sessManager := testMiddlewareWithIdleTimeout(
t, config.EnvironmentDev, idle,
m, sessManager, clock := testMiddlewareWithSessionClock(
t, config.EnvironmentDev, idle, newFakeClock(),
)
cookies := aged(t, sessManager, loginCookies(t, sessManager), idle)
cookies := loginCookies(t, sessManager)
clock.Advance(idle)
called, w := runAuthed(t, m, cookies)
@@ -636,12 +621,14 @@ func TestRequireAuth_RefreshesIdleDeadlineOnActivity(
idle := time.Hour
m, sessManager := testMiddlewareWithIdleTimeout(
t, config.EnvironmentDev, idle,
m, sessManager, clock := testMiddlewareWithSessionClock(
t, config.EnvironmentDev, idle, newFakeClock(),
)
cookies := loginCookies(t, sessManager)
// Activity halfway through the idle window.
cookies := aged(t, sessManager, loginCookies(t, sessManager), idle/2)
clock.Advance(idle / 2)
called, w := runAuthed(t, m, cookies)
require.True(t, called, "handler should run while valid")
@@ -653,22 +640,16 @@ func TestRequireAuth_RefreshesIdleDeadlineOnActivity(
)
// Past the original deadline. The refreshed cookie is still
// good; the original one is not. A minute short of the idle
// window leaves room for the real clock, which the session
// reads, to tick on while the test runs.
later := idle - time.Minute
// good; the original one is not.
clock.Advance(idle - time.Second)
calledRefreshed, _ := runAuthed(
t, m, aged(t, sessManager, refreshed, later),
)
calledRefreshed, _ := runAuthed(t, m, refreshed)
assert.True(
t, calledRefreshed,
"refreshed session should outlive the original deadline",
)
calledStale, staleW := runAuthed(
t, m, aged(t, sessManager, cookies, later),
)
calledStale, staleW := runAuthed(t, m, cookies)
assert.False(
t, calledStale,
"the pre-refresh cookie carries the old idle deadline",
@@ -681,8 +662,8 @@ func TestRequireAuth_UnauthenticatedRequestDoesNotRefresh(
) {
t.Parallel()
m, sessManager := testMiddlewareWithIdleTimeout(
t, config.EnvironmentDev, time.Hour,
m, sessManager, _ := testMiddlewareWithSessionClock(
t, config.EnvironmentDev, time.Hour, newFakeClock(),
)
// A session cookie that exists but was never authenticated.
@@ -943,9 +924,12 @@ func metricsAuthMiddleware(
MetricsPassword: "secret",
}
return middlewaretest.New(
t, log, cfg, newTestSessionManager(t, cfg),
)
key := make([]byte, testKeySize)
store := session.NewStore(key)
sessManager := session.NewForTest(store, cfg, log, key, nil)
return middleware.NewForTest(log, cfg, sessManager)
}
// runMetricsAuthRequest sends a GET /metrics request with the
@@ -1,42 +0,0 @@
// Package middlewaretest builds a Middleware for tests in other
// packages.
package middlewaretest
import (
"log/slog"
"testing"
"github.com/prometheus/client_golang/prometheus"
"github.com/stretchr/testify/require"
"go.uber.org/fx/fxtest"
"sneak.berlin/go/webhooker/internal/config"
"sneak.berlin/go/webhooker/internal/middleware"
"sneak.berlin/go/webhooker/internal/session"
)
// New builds a Middleware through middleware.New, on a
// lifecycle that is never started.
//
// Its metrics recorder writes to a fresh registry of its own, so
// Metrics() works on it and two of them never collide.
func New(
t *testing.T,
log *slog.Logger,
cfg *config.Config,
sess *session.Session,
) *middleware.Middleware {
t.Helper()
m, err := middleware.New(
fxtest.NewLifecycle(t),
middleware.MiddlewareParams{
Logger: log,
Config: cfg,
Session: sess,
Registry: prometheus.NewRegistry(),
},
)
require.NoError(t, err)
return m
}
+1 -2
View File
@@ -18,7 +18,6 @@ import (
"github.com/stretchr/testify/require"
"sneak.berlin/go/webhooker/internal/config"
"sneak.berlin/go/webhooker/internal/middleware"
"sneak.berlin/go/webhooker/internal/middleware/middlewaretest"
)
func TestPostRateLimit_AllowsGET(t *testing.T) {
@@ -199,7 +198,7 @@ func rateLimitMiddleware(
&slog.HandlerOptions{Level: slog.LevelDebug},
))
return middlewaretest.New(t, log, cfg, nil)
return middleware.NewForTest(log, cfg, nil)
}
// trustedProxies parses CIDR strings for a test Config.
+32
View File
@@ -0,0 +1,32 @@
package middleware
import (
"log/slog"
"github.com/prometheus/client_golang/prometheus"
prommetrics "github.com/slok/go-http-metrics/metrics/prometheus"
"sneak.berlin/go/webhooker/internal/config"
"sneak.berlin/go/webhooker/internal/session"
)
// NewForTest creates a Middleware with the minimum dependencies
// needed for testing. This bypasses the fx lifecycle.
//
// Its metrics recorder writes to a fresh registry of its own, so
// Metrics() works on it and two of them never collide.
func NewForTest(
log *slog.Logger,
cfg *config.Config,
sess *session.Session,
) *Middleware {
return &Middleware{
log: log,
params: &MiddlewareParams{
Config: cfg,
},
session: sess,
metricsRecorder: prommetrics.NewRecorder(
prommetrics.Config{Registry: prometheus.NewRegistry()},
),
}
}
-1
View File
@@ -174,7 +174,6 @@ func newServerApp(
fx.Provide(
globals.New,
logger.New,
func(l *logger.Logger) *slog.Logger { return l.Get() },
func() *config.Config {
return &config.Config{DataDir: dir}
},
+9 -25
View File
@@ -280,23 +280,6 @@ func click(ctx context.Context, t *testing.T, xpath string) {
))
}
// clickAndLoad clicks the link or button matching an XPath expression
// and waits, as loadPage does, for the page the click opens to load and
// for Alpine.js to start on it. Reading earlier, a check can find an
// element of the page being left, gone by the time its value is read;
// and the wait in shown is too short for a page load on a busy host.
func clickAndLoad(ctx context.Context, t *testing.T, xpath string) {
t.Helper()
_, err := chromedp.RunResponse(
ctx, chromedp.Click(xpath, chromedp.BySearch),
)
require.NoError(t, err)
require.NoError(t, chromedp.Run(
ctx, chromedp.WaitNotPresent("[x-cloak]", chromedp.ByQuery),
))
}
// checkAddEntrypoint loads a webhook page and checks that the add
// entrypoint form stays hidden until the Add button beside its heading
// is clicked. The click looks for a button element there, so it also
@@ -439,7 +422,7 @@ func checkAddTarget(
)))
}
clickAndLoad(ctx, t, saveButton)
click(ctx, t, saveButton)
assert.Truef(t, shown(ctx, `//span[text()="`+name+
`"]/following-sibling::div/span[text()="`+badge+`"]`),
"%s: the added target is not listed as %s", targetType, badge)
@@ -502,9 +485,10 @@ func checkArchiveChoices(ctx context.Context, t *testing.T, url string) {
`/following-sibling::span[text()="daily"]`),
"a database target added with daily is not listed as daily")
clickAndLoad(ctx, t, row+`//a[text()="Edit"]`)
click(ctx, t, row+`//a[text()="Edit"]`)
require.NoError(t, chromedp.Run(
ctx,
chromedp.WaitReady("#expiry", chromedp.ByQuery),
chromedp.Value("#expiry", &editedExpiry, chromedp.ByQuery),
chromedp.Value("#rotation", &editedRotation, chromedp.ByQuery),
))
@@ -539,7 +523,7 @@ func checkRefusedTarget(ctx context.Context, t *testing.T, url string) {
chromedp.Click(forwardQuery, chromedp.ByQuery),
))
clickAndLoad(ctx, t, saveButton)
click(ctx, t, saveButton)
assert.True(t, shown(ctx, reason),
"a refused target does not show the reason")
@@ -652,7 +636,7 @@ func checkRefusedEdits(
))
}
clickAndLoad(ctx, t, `//button[text()="Save Changes"]`)
click(ctx, t, `//button[text()="Save Changes"]`)
assert.Truef(t, shown(ctx, reason),
"%s: a refused save does not show the reason", edit.url)
@@ -776,7 +760,7 @@ func checkEntrypointEdit(
require.NoError(t, chromedp.Run(
ctx, chromedp.SendKeys(input, "Billing sender", chromedp.ByQuery),
))
clickAndLoad(ctx, t, saveEdit)
click(ctx, t, saveEdit)
assert.True(t, shown(ctx, `//span[text()="Billing sender"]`),
"saving the edit form does not change the description")
@@ -814,7 +798,7 @@ func checkRecentEvents(ctx context.Context, t *testing.T, url string) {
"clicking the newest event does not collapse it")
require.NoError(t, chromedp.Run(ctx, loadPage(url)))
clickAndLoad(ctx, t, newest+`/ancestor::div[@x-data][1]//a[text()="Open"]`)
click(ctx, t, newest+`/ancestor::div[@x-data][1]//a[text()="Open"]`)
assert.True(t, shown(ctx, `//h2[text()="Body"]`),
"Open does not lead to the event's own page")
@@ -1215,7 +1199,7 @@ func checkNewWebhookTargets(
`","rotation":"none"}`
}
clickAndLoad(ctx, t, createButton)
click(ctx, t, createButton)
require.Truef(t, shown(ctx, `//h1[text()="`+name+`"]`),
"%s: the new webhook's page does not open", name)
@@ -1276,7 +1260,7 @@ func checkRefusedNewWebhook(ctx context.Context, t *testing.T, url string) {
chromedp.SetValue(pruningChoice, "2160h", chromedp.BySearch),
chromedp.SetValue("#archive_rotation", "monthly", chromedp.ByQuery),
))
clickAndLoad(ctx, t, createButton)
click(ctx, t, createButton)
assert.True(t, shown(ctx, `//div[@class="alert-error"]`),
"a refused webhook does not show the reason")
-2
View File
@@ -3,7 +3,6 @@ package server_test
import (
"context"
"html"
"log/slog"
"net/http"
"net/http/httptest"
"net/url"
@@ -131,7 +130,6 @@ func newTestEnvWithConfig(
fx.Provide(
globals.New,
logger.New,
func(l *logger.Logger) *slog.Logger { return l.Get() },
func() *config.Config { return cfg },
database.New,
database.NewWebhookDBManager,
+3 -2
View File
@@ -16,6 +16,7 @@ import (
"go.uber.org/fx"
"sneak.berlin/go/webhooker/internal/config"
"sneak.berlin/go/webhooker/internal/database"
"sneak.berlin/go/webhooker/internal/logger"
"sneak.berlin/go/webhooker/internal/reqtls"
)
@@ -79,7 +80,7 @@ type Params struct {
Config *config.Config
Database *database.Database
Logger *slog.Logger
Logger *logger.Logger
}
// Session manages encrypted session storage.
@@ -179,7 +180,7 @@ func New(
params Params,
) (*Session, error) {
s := &Session{
log: params.Logger,
log: params.Logger.Get(),
idleTimeout: params.Config.SessionIdleTimeout,
now: time.Now,
}
@@ -16,7 +16,8 @@ func NewStore(key []byte) *sessions.CookieStore {
}
// NewForTest creates a Session with a pre-configured cookie store for use
// in tests. This bypasses the fx lifecycle and database dependency. The key
// in tests. This bypasses the fx lifecycle and database dependency, allowing
// middleware and handler tests to use real session functionality. The key
// parameter is the raw 32-byte authentication key used for session encryption
// and CSRF cookie signing.
//
+1 -9
View File
@@ -11,7 +11,6 @@ ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
PKGMGR=""
SUDO=""
APT_UPDATED=""
detect_pkgmgr() {
[ -n "$PKGMGR" ] && return 0
@@ -40,14 +39,7 @@ pkg_install() {
detect_pkgmgr
case "$PKGMGR" in
nix) nix-env -iA "nixpkgs.$1" ;;
apt)
# Package lists may be empty (fresh images); refresh once per run.
if [ -z "$APT_UPDATED" ]; then
$SUDO env DEBIAN_FRONTEND=noninteractive apt-get update
APT_UPDATED=1
fi
$SUDO env DEBIAN_FRONTEND=noninteractive apt-get install -y "$2"
;;
apt) $SUDO env DEBIAN_FRONTEND=noninteractive apt-get install -y "$2" ;;
brew) brew install "$3" ;;
apk) apk add --no-cache "$4" ;;
esac