Files
ThothII/backend/test/routes-settings.test.ts
T
marcopanandClaude Opus 4.8 f59d6d1478 fix(backend): allow PUT in CORS methods so browser can save settings
Found via live browser test: PUT /settings preflight was rejected because
@fastify/cors default methods omit PUT. GET/POST were unaffected.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-28 16:54:30 +02:00

96 lines
3.6 KiB
TypeScript

import { test, expect } from "vitest";
import { mkdtempSync, rmSync } from "node:fs";
import { tmpdir } from "node:os";
import { join } from "node:path";
import { buildApp } from "../src/app.js";
import { loadConfig } from "../src/config.js";
function appWithTmpSettings(extraEnv: Record<string, string> = {}, deps = {}) {
const dir = mkdtempSync(join(tmpdir(), "tht-set-route-"));
const app = buildApp(
loadConfig({ THT_HARNESS_DIR: "../harness", SETTINGS_FILE: join(dir, "settings.json"), ...extraEnv }),
{ thtRunner: {} as any, ...deps },
);
return { app, dir };
}
test("GET /settings returns effective defaults (env provider/model/thinking, first workspace)", async () => {
const { app, dir } = appWithTmpSettings({ PI_PROVIDER: "zai", PI_MODEL: "glm-5.2", PI_THINKING: "medium" }, {
listModels: async () => [{ provider: "zai", id: "glm-5.2", name: "GLM 5.2", reasoning: true }],
});
try {
const res = await app.inject({ method: "GET", url: "/settings" });
expect(res.statusCode).toBe(200);
const body = res.json();
expect(body.provider).toBe("zai");
expect(body.model).toBe("glm-5.2");
expect(body.thinking).toBe("medium");
expect(typeof body.workspace).toBe("string"); // first workspace from ../harness/workspaces
} finally {
rmSync(dir, { recursive: true, force: true });
}
});
test("PUT /settings persists and GET reads it back", async () => {
const { app, dir } = appWithTmpSettings({}, {
listModels: async () => [{ provider: "zai", id: "glm-5.2", name: "GLM 5.2", reasoning: true }],
});
try {
const put = await app.inject({
method: "PUT", url: "/settings",
payload: { workspace: "psd", provider: "zai", model: "glm-5.2", thinking: "high" },
});
expect(put.statusCode).toBe(200);
const got = await app.inject({ method: "GET", url: "/settings" });
expect(got.json()).toMatchObject({ workspace: "psd", provider: "zai", model: "glm-5.2", thinking: "high" });
} finally {
rmSync(dir, { recursive: true, force: true });
}
});
test("PUT /settings rejects an unknown model when a model list is available", async () => {
const { app, dir } = appWithTmpSettings({}, {
listModels: async () => [{ provider: "zai", id: "glm-5.2", name: "GLM 5.2", reasoning: true }],
});
try {
const put = await app.inject({
method: "PUT", url: "/settings",
payload: { workspace: "psd", provider: "zai", model: "does-not-exist", thinking: "low" },
});
expect(put.statusCode).toBe(400);
expect(put.json()).toMatchObject({ error: expect.stringMatching(/model/i) });
} finally {
rmSync(dir, { recursive: true, force: true });
}
});
test("PUT /settings allows any model when model list is empty (Pi unavailable)", async () => {
const { app, dir } = appWithTmpSettings({}, { listModels: async () => [] });
try {
const put = await app.inject({
method: "PUT", url: "/settings",
payload: { workspace: "psd", model: "whatever", thinking: "low" },
});
expect(put.statusCode).toBe(200);
} finally {
rmSync(dir, { recursive: true, force: true });
}
});
test("CORS preflight allows PUT /settings (browser can save settings)", async () => {
const app = buildApp(loadConfig({ THT_HARNESS_DIR: "../harness" }), {
thtRunner: {} as any,
listModels: async () => [],
});
const res = await app.inject({
method: "OPTIONS",
url: "/settings",
headers: {
origin: "http://localhost:5173",
"access-control-request-method": "PUT",
},
});
// @fastify/cors answers the preflight; PUT must be in the allowed methods.
expect(res.headers["access-control-allow-methods"]).toMatch(/PUT/);
});