import { test, expect, vi } from "vitest"; import { buildApp } from "../src/app.js"; import { loadConfig } from "../src/config.js"; // --------------------------------------------------------------------------- // SQL routes // --------------------------------------------------------------------------- test("POST /sessions/:id/sql/preview returns rows from injected thtRunner stub", async () => { const previewResult = { columns: ["a"], rows: [[1]], execution_ms: 2, truncated: false, }; const app = buildApp(loadConfig({ THT_HARNESS_DIR: "../harness" }), { thtRunner: { sqlPreview: async () => previewResult, } as any, }); const res = await app.inject({ method: "POST", url: "/sessions/s1/sql/preview", payload: { limit: 10, offset: 0 }, }); expect(res.statusCode).toBe(200); expect(res.json()).toEqual(previewResult); }); test("POST /sessions/:id/sql/preview passes limit and offset to thtRunner", async () => { let captured: any; const app = buildApp(loadConfig({ THT_HARNESS_DIR: "../harness" }), { thtRunner: { sqlPreview: async (id: string, p: any) => { captured = { id, ...p }; return { columns: [], rows: [], execution_ms: 0, truncated: false }; }, } as any, }); await app.inject({ method: "POST", url: "/sessions/abc/sql/preview", payload: { limit: 25, offset: 50 }, }); expect(captured.id).toBe("abc"); expect(captured.limit).toBe(25); expect(captured.offset).toBe(50); }); test("POST /sessions/:id/sql/export returns {path} from injected thtRunner stub", async () => { const app = buildApp(loadConfig({ THT_HARNESS_DIR: "../harness" }), { thtRunner: { sqlExport: async (_id: string) => ({ path: "/tmp/export.csv" }), } as any, }); const res = await app.inject({ method: "POST", url: "/sessions/s1/sql/export", payload: {}, }); expect(res.statusCode).toBe(200); expect(res.json()).toEqual({ path: "/tmp/export.csv" }); }); test("POST /sessions/:id/sql/preview returns 500 when thtRunner throws", async () => { const app = buildApp(loadConfig({ THT_HARNESS_DIR: "../harness" }), { thtRunner: { sqlPreview: async () => { throw new Error("tht boom"); }, } as any, }); const res = await app.inject({ method: "POST", url: "/sessions/s1/sql/preview", payload: {}, }); expect(res.statusCode).toBe(500); expect(res.json()).toMatchObject({ error: /boom/ }); }); test("registry-backed SQL preview resolves and uses the session's pinned runtime revision", async () => { const activePath = `/registry/snapshots/${"a".repeat(40)}/psd-clinical.yaml`; const pinnedPath = `/registry/snapshots/${"b".repeat(40)}/psd-clinical.yaml`; const calls: string[] = []; const runner = { sessionShow: async (_id: string, workspace: string) => { calls.push(`show:${workspace}`); if (workspace === activePath) return { id: "s1", workspace_id: "psd-clinical", workspace_revision: "b".repeat(40), }; throw new Error("session not found"); }, sqlPreview: async (_id: string, _page: unknown, workspace: string) => { calls.push(`preview:${workspace}`); return { columns: [], rows: [], execution_ms: 0, truncated: false }; }, }; const app = buildApp(loadConfig({ THT_HARNESS_DIR: "../harness" }), { thtRunner: { ...runner, withPrincipal: () => runner } as any, getSettings: () => ({ workspace: "legacy-default" }) as any, workspaceRegistry: { list: async () => [{ id: "psd-clinical", commit: "a".repeat(40), blob: "c".repeat(40), snapshotPath: activePath, state: "operational", }], readPinned: async () => ({ workspace: {}, workspaceConfigPath: pinnedPath }), } as any, }); const response = await app.inject({ method: "POST", url: "/sessions/s1/sql/preview", payload: { limit: 10 }, }); expect(response.statusCode).toBe(200); expect(calls).toEqual([`show:${activePath}`, `preview:${pinnedPath}`]); }); // Workspace registry route coverage lives in routes-workspaces.test.ts. `/workspaces` no longer // reads legacy harness files: the Git registry is the single shared source of truth. test("GET /models returns {models:[...]} from injected listModels stub", async () => { const app = buildApp(loadConfig({ THT_HARNESS_DIR: "../harness" }), { thtRunner: {} as any, listModels: async () => [ { provider: "zai", id: "glm-5.2", name: "GLM 5.2", reasoning: true }, ], }); const res = await app.inject({ method: "GET", url: "/models" }); expect(res.statusCode).toBe(200); expect(res.json()).toEqual({ models: [{ provider: "zai", id: "glm-5.2", name: "GLM 5.2", reasoning: true }], }); }); test("GET /models returns {models:[]} when listModels throws (graceful fallback)", async () => { const app = buildApp(loadConfig({ THT_HARNESS_DIR: "../harness" }), { thtRunner: {} as any, listModels: async () => { throw new Error("Pi not running"); }, }); const res = await app.inject({ method: "GET", url: "/models" }); expect(res.statusCode).toBe(200); expect(res.json()).toEqual({ models: [] }); }); test("GET /models logs a sanitized warning when listing fails", async () => { const app = buildApp(loadConfig({ THT_HARNESS_DIR: "../harness" }), { thtRunner: {} as any, listModels: async () => { throw new Error("credential-value-must-not-appear"); }, }); const warn = vi.spyOn(app.log, "warn"); const res = await app.inject({ method: "GET", url: "/models" }); expect(res.json()).toEqual({ models: [] }); expect(JSON.stringify(warn.mock.calls)).not.toContain("credential-value-must-not-appear"); expect(warn).toHaveBeenCalled(); }); test("GET /models with empty listModels stub returns empty array", async () => { const app = buildApp(loadConfig({ THT_HARNESS_DIR: "../harness" }), { thtRunner: {} as any, listModels: async () => [], }); const res = await app.inject({ method: "GET", url: "/models" }); expect(res.statusCode).toBe(200); expect(res.json()).toEqual({ models: [] }); });