import { afterAll, beforeAll, describe, expect, test } from "bun:test"; import { banDid, getWiki, hideWiki, unbanDid, unhideWiki, } from "../../src/server/db/queries/index.ts"; import { resolveCollabAccess } from "../../src/server/routes/collab.ts"; import { cleanupWikiAndDependents } from "../helpers/cleanup.ts"; import { ALICE, createDiff, emitNote, emitRevision, emitWiki, } from "./helpers.ts"; import { fetch, loginCookie } from "./http-helpers.ts"; const WIKI_SLUG = "mod-takedown-wiki"; const NOTE_SLUG = "mod-note"; let wikiAtUri: string; beforeAll(() => { cleanupWikiAndDependents(WIKI_SLUG); const wiki = emitWiki(ALICE.did, "Takedown Wiki", "public", WIKI_SLUG); wikiAtUri = wiki.uri; const note = emitNote(ALICE.did, NOTE_SLUG, "Mod Note", wikiAtUri); emitRevision(ALICE.did, note.uri, createDiff("", "secret content")); }); afterAll(() => { unhideWiki(wikiAtUri); unbanDid(ALICE.did); cleanupWikiAndDependents(WIKI_SLUG); }); const wikiUrl = `/@${ALICE.handle}/${WIKI_SLUG}`; const noteUrl = `/@${ALICE.handle}/${WIKI_SLUG}/${NOTE_SLUG}`; describe("wiki takedown via hideWiki", () => { test("wiki and note are reachable before takedown", async () => { expect((await fetch("GET", wikiUrl)).status).toBe(200); expect((await fetch("GET", noteUrl)).status).toBe(200); }); test("hidden wiki returns a 410 HTML tombstone on every direct route", async () => { hideWiki(wikiAtUri, "abuse", "test"); const wikiRes = await fetch("GET", wikiUrl); expect(wikiRes.status).toBe(410); expect(wikiRes.headers.get("content-type")).toContain("text/html"); expect((await fetch("GET", noteUrl)).status).toBe(410); expect((await fetch("GET", `${noteUrl}/edit`)).status).toBe(410); expect((await fetch("GET", `${wikiUrl}/-/settings`)).status).toBe(410); }); test("takedown blocks the owner too", async () => { const cookie = await loginCookie(ALICE.handle); expect((await fetch("GET", wikiUrl, { cookie })).status).toBe(410); }); test("the collab socket refuses a hidden wiki", async () => { // The editor's transport never reaches resolveRequestContext, so it has // to re-check moderation itself or it hands out the note body. const connect = () => resolveCollabAccess(ALICE.handle, WIKI_SLUG, NOTE_SLUG, ALICE.did); unhideWiki(wikiAtUri); expect(await connect()).not.toBeNull(); hideWiki(wikiAtUri, "abuse", "test"); expect(await connect()).toBeNull(); }); test("unhide restores access", async () => { unhideWiki(wikiAtUri); expect((await fetch("GET", wikiUrl)).status).toBe(200); expect((await fetch("GET", noteUrl)).status).toBe(200); }); }); describe("DID ban via banDid", () => { test("bans hide the owner's wiki, unban restores it", async () => { expect(getWiki(ALICE.did, WIKI_SLUG)).not.toBeNull(); banDid(ALICE.did, "operator", "test"); expect((await fetch("GET", wikiUrl)).status).toBe(410); unbanDid(ALICE.did); expect((await fetch("GET", wikiUrl)).status).toBe(200); }); }); describe("discovery surfaces exclude a hidden wiki", () => { beforeAll(() => { hideWiki(wikiAtUri, "abuse", "test"); }); afterAll(() => { unhideWiki(wikiAtUri); }); test("absent from explore", async () => { const body = await (await fetch("GET", "/explore")).text(); expect(body).not.toContain("Takedown Wiki"); }); test("absent from wiki search", async () => { const body = await (await fetch("GET", "/search?q=Takedown")).text(); expect(body).not.toContain("Takedown Wiki"); }); test("note search within the hidden wiki returns empty", async () => { const res = await fetch( "GET", `/search?wiki_uri=${encodeURIComponent(wikiAtUri)}&q=secret`, ); expect((await res.text()).trim()).toBe(""); }); test("absent from the sitemap", async () => { const body = await (await fetch("GET", "/sitemap.xml")).text(); expect(body).not.toContain(WIKI_SLUG); }); test("absent from the owner's profile", async () => { const body = await (await fetch("GET", `/@${ALICE.handle}`)).text(); expect(body).not.toContain("Takedown Wiki"); }); test("OG card 404s (no sharp render reached)", async () => { const res = await fetch("GET", `/og/@${ALICE.handle}/${WIKI_SLUG}`); expect(res.status).toBe(404); }); }); describe("discovery surfaces restore when un-hidden", () => { test("explore lists the wiki again", async () => { const body = await (await fetch("GET", "/explore")).text(); expect(body).toContain("Takedown Wiki"); }); });