Something went wrong. Try again.
A local-first event pipeline for independent agents, built on Jazz.
Something went wrong. Try again.
6.0 kB · 84 lines
TypeScript
12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485import fs from "node:fs/promises";import path from "node:path";import { describe, expect, test } from "vitest";
const root = process.cwd();
describe("public web deployment contract", () => { test("rate-limits OAuth routes, strips query strings from access logs, and canonicalizes www before proxying", async () => { const nginx = await fs.readFile(path.join(root, "deploy/nginx/thought.stream.conf"), "utf8"); expect(nginx).toContain("limit_req_zone $binary_remote_addr zone=thoughtstream_oauth_login"); expect(nginx).toContain("limit_req_zone $binary_remote_addr zone=thoughtstream_oauth_callback"); expect(nginx).toContain("limit_req_zone $binary_remote_addr zone=thoughtstream_review"); expect(nginx).toContain("limit_req_zone $binary_remote_addr zone=thoughtstream_course_chat"); const logFormat = nginx.split("\n").find((line) => line.startsWith("log_format thoughtstream_no_query")); expect(logFormat).toContain("$request_method $uri $server_protocol"); expect(logFormat).not.toContain("$request_uri"); expect(logFormat).not.toContain('"$request"'); expect(logFormat).not.toContain("$http_referer"); expect(logFormat).not.toContain("$http_user_agent"); expect(nginx.match(/server_name thought\.stream www\.thought\.stream;([\s\S]*?)\n\}/)?.[1]).toContain("thoughtstream_no_query");
const callback = nginx.match(/location = \/oauth\/callback \{([\s\S]*?)\n \}/)?.[1]; expect(callback).toContain("access_log off;"); expect(callback).toContain("error_log /dev/null crit;"); expect(callback).toContain("limit_req zone=thoughtstream_oauth_callback"); const login = nginx.match(/location = \/oauth\/login \{([\s\S]*?)\n \}/)?.[1]; expect(login).toContain("limit_req zone=thoughtstream_oauth_login"); const logout = nginx.match(/location = \/oauth\/logout \{([\s\S]*?)\n \}/)?.[1]; expect(logout).toContain("limit_except GET HEAD POST"); const catchAll = nginx.match(/location \/ \{([\s\S]*?)\n \}/)?.[1]; expect(catchAll).toContain("limit_except GET HEAD"); expect(catchAll).not.toContain("GET HEAD POST"); const review = nginx.match(/location ~ \^\/inspector\/api\/reviews\/\[\^\/\]\+\/decisions\$ \{([\s\S]*?)\n \}/)?.[1]; expect(review).toContain("limit_req zone=thoughtstream_review"); expect(review).toContain("limit_except POST"); expect(review).toContain("client_max_body_size 100k"); const courseChat = nginx.match(/location = \/inspector\/api\/courses\/post-training\/questions \{([\s\S]*?)\n \}/)?.[1]; expect(courseChat).toContain("limit_req zone=thoughtstream_course_chat"); expect(courseChat).toContain("limit_except POST"); expect(courseChat).toContain("client_max_body_size 4k");
const wwwServer = nginx.match(/server \{[\s\S]*?listen 443 ssl http2;[\s\S]*?server_name www\.thought\.stream;([\s\S]*?)\n\}/)?.[1]; expect(wwwServer).toContain("return 308 https://thought.stream$request_uri;"); expect(wwwServer).toContain("error_log /dev/null crit;"); expect(wwwServer).not.toContain("proxy_pass"); expect(nginx).toContain("server_name thought.stream;\n"); });
test("keeps one singleton proxy process, Basic fallback separate and optional, and one shared Review capability file", async () => { const unit = await fs.readFile(path.join(root, "deploy/systemd/thoughtstream-inspector-proxy.service"), "utf8"); const inspectorUnit = await fs.readFile(path.join(root, "deploy/systemd/thoughtstream-inspector.service"), "utf8"); expect(unit.match(/^ExecStart=/gm)).toHaveLength(1); expect(unit).toContain("EnvironmentFile=-%h/.config/thoughtstream/credentials/inspector-basic.env"); expect(unit).not.toContain("inspector-proxy.env"); expect(unit).toContain("EnvironmentFile=-%h/.config/thoughtstream/credentials/inspector-oauth.env"); expect(unit).toContain("EnvironmentFile=-%h/.config/thoughtstream/credentials/inspector-review.env"); expect(unit).toContain("EnvironmentFile=-%h/.config/thoughtstream/credentials/inspector-course-chat.env"); expect(inspectorUnit).toContain("EnvironmentFile=-%h/.config/thoughtstream/credentials/inspector-review.env"); expect(inspectorUnit).toContain("EnvironmentFile=-%h/.config/thoughtstream/credentials/inspector-course-chat.env"); expect(unit).toContain("ReadWritePaths=-%h/.local/share/thoughtstream-inspector-auth");
const basicConfig = await fs.readFile(path.join(root, "scripts/configure-inspector-credentials.sh"), "utf8"); const oauthConfig = await fs.readFile(path.join(root, "scripts/configure-inspector-oauth.ts"), "utf8"); expect(basicConfig).toContain("inspector-basic.env"); expect(basicConfig).not.toContain("inspector-proxy.env"); expect(basicConfig).toContain("PROXY_BASIC_FALLBACK_ENABLED=1"); expect(oauthConfig).not.toContain("PROXY_BASIC_FALLBACK_ENABLED"); expect(oauthConfig).toContain("Basic fallback configuration is independent and defaults to disabled when absent."); expect(oauthConfig).toContain("THOUGHTSTREAM_OAUTH_STORE_DIR is unsupported"); expect(oauthConfig).toContain('path.join(os.homedir(), ".local", "share", "thoughtstream-inspector-auth")'); const reviewConfig = await fs.readFile(path.join(root, "scripts/configure-inspector-review.ts"), "utf8"); expect(reviewConfig).toContain("randomBytes(32)"); expect(reviewConfig).toContain("inspector-review.env"); expect(reviewConfig).not.toContain("console.log"); const courseConfig = await fs.readFile(path.join(root, "scripts/configure-inspector-course-chat.ts"), "utf8"); expect(courseConfig).toContain("randomBytes(32)"); expect(courseConfig).toContain("inspector-course-chat.env"); expect(courseConfig).not.toContain("console.log");
const threatModel = await fs.readFile(path.join(root, "spec/web-auth.md"), "utf8"); expect(threatModel).toContain("single process"); expect(threatModel).toContain("Basic fallback"); });});