package hostapi import ( "context" "net/http" "net/http/httptest" "strings" "testing" "time" "github.com/itworx/pulse/internal/auth" "github.com/itworx/pulse/internal/host" ) type provider struct{ snapshot host.Snapshot } func (p provider) Snapshot(context.Context) (host.Snapshot, error) { return p.snapshot, nil } func authenticatedRequest(method, path string) *http.Request { request := httptest.NewRequest(method, path, nil) return request.WithContext(auth.WithPrincipal(request.Context(), auth.Principal{Subject: "viewer", Role: auth.RoleViewer})) } func TestHandlerRequiresAuthenticationAndExposesUnknownFallback(t *testing.T) { unauthenticated := httptest.NewRecorder() Handler{}.ServeHTTP(unauthenticated, httptest.NewRequest(http.MethodGet, "/api/v1/host", nil)) if unauthenticated.Code != http.StatusUnauthorized { t.Fatalf("status=%d body=%s", unauthenticated.Code, unauthenticated.Body.String()) } response := httptest.NewRecorder() Handler{}.ServeHTTP(response, authenticatedRequest(http.MethodGet, "/api/v1/host")) if response.Code != http.StatusOK || !strings.Contains(response.Body.String(), `"state":"unknown"`) { t.Fatalf("status=%d body=%s", response.Code, response.Body.String()) } } func TestHandlerReturnsProviderSnapshotAndRejectsOtherRoutes(t *testing.T) { snapshot := host.UnknownSnapshot(time.Date(2026, 8, 1, 12, 0, 0, 0, time.UTC), "agent-1", "agent", "fixture") response := httptest.NewRecorder() Handler{Provider: provider{snapshot: snapshot}}.ServeHTTP(response, authenticatedRequest(http.MethodGet, "/api/v1/host")) if response.Code != http.StatusOK || !strings.Contains(response.Body.String(), `"id":"agent-1"`) { t.Fatalf("status=%d body=%s", response.Code, response.Body.String()) } other := httptest.NewRecorder() Handler{}.ServeHTTP(other, authenticatedRequest(http.MethodPost, "/api/v1/host")) if other.Code != http.StatusNotFound { t.Fatalf("status=%d", other.Code) } }