Files
summercms/tide/normalize_test.go
Jakub Zych 22f02eed59 fix(02-03): mask OAuth client_id and unix issued_at
RFC 7591 registration returns a string client_id and unix client_id_issued_at; treating those as Carbon/integer foreign keys would fail PHP self-replay of MCP OAuth.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 13:36:30 +02:00

60 lines
3.0 KiB
Go

package tide
import (
"strings"
"testing"
)
func TestNormalizeDateIDAndDisable(t *testing.T) {
step := Step{ID: "n"}
want := []byte(`{"id":1,"created_at":"2026-01-01T00:00:00+00:00","slug":"keep-me"}`)
gotOK := []byte(`{"id":9,"created_at":"2026-02-02T00:00:00+00:00","slug":"keep-me"}`)
gotZ := []byte(`{"id":9,"created_at":"2026-02-02T00:00:00Z","slug":"keep-me"}`)
gotStrID := []byte(`{"id":"9","created_at":"2026-02-02T00:00:00+00:00","slug":"keep-me"}`)
gotSlug := []byte(`{"id":9,"created_at":"2026-02-02T00:00:00+00:00","slug":"other"}`)
if diffs := compareBodies(Response{Headers: jsonCT(), Body: Body(want)}, Response{Headers: jsonCT(), Body: Body(gotOK)}, step); len(diffs) != 0 {
t.Fatalf("masked date/id should pass: %+v", diffs)
}
nullID := []byte(`{"id":1,"discogs_id":null,"created_at":"2026-01-01T00:00:00+00:00","slug":"keep-me"}`)
if diffs := compareBodies(Response{Headers: jsonCT(), Body: Body(nullID)}, Response{Headers: jsonCT(), Body: Body(nullID)}, step); len(diffs) != 0 {
t.Fatalf("null *_id must pass: %+v", diffs)
}
syncA := []byte(`{"collection_key":"aaa","checkpoint":"2026-01-01T00:00:00+00:00","total_estimate":0}`)
syncB := []byte(`{"collection_key":"bbb","checkpoint":"2026-02-02T00:00:00+00:00","total_estimate":0}`)
if diffs := compareBodies(Response{Headers: jsonCT(), Body: Body(syncA)}, Response{Headers: jsonCT(), Body: Body(syncB)}, step); len(diffs) != 0 {
t.Fatalf("collection_key/checkpoint must mask: %+v", diffs)
}
zdiffs := compareBodies(Response{Headers: jsonCT(), Body: Body(want)}, Response{Headers: jsonCT(), Body: Body(gotZ)}, step)
if len(zdiffs) == 0 {
t.Fatal("Z date must fail")
}
if !strings.Contains(zdiffs[0].Path, "created_at") {
t.Fatalf("Z path %s", zdiffs[0].Path)
}
idDiffs := compareBodies(Response{Headers: jsonCT(), Body: Body(want)}, Response{Headers: jsonCT(), Body: Body(gotStrID)}, step)
if len(idDiffs) == 0 || !strings.Contains(idDiffs[0].Path, "id") {
t.Fatalf("string id: %+v", idDiffs)
}
slugDiffs := compareBodies(Response{Headers: jsonCT(), Body: Body(want)}, Response{Headers: jsonCT(), Body: Body(gotSlug)}, step)
if len(slugDiffs) == 0 || !strings.Contains(slugDiffs[0].Path, "slug") {
t.Fatalf("slug must stay exact: %+v", slugDiffs)
}
issuedA := []byte(`{"client_id":"aaa","client_id_issued_at":111}`)
issuedB := []byte(`{"client_id":"bbb","client_id_issued_at":222}`)
if diffs := compareBodies(Response{Headers: jsonCT(), Body: Body(issuedA)}, Response{Headers: jsonCT(), Body: Body(issuedB)}, step); len(diffs) != 0 {
t.Fatalf("oauth client_id/issued_at must mask: %+v", diffs)
}
disabled := Step{ID: "n", Normalize: []NormalizeRule{{Path: "created_at", Disable: true}}}
dDiffs := compareBodies(Response{Headers: jsonCT(), Body: Body(want)}, Response{Headers: jsonCT(), Body: Body(gotOK)}, disabled)
if len(dDiffs) == 0 {
t.Fatal("disabled date mask must compare raw timestamps")
}
}
func jsonCT() map[string]string {
return map[string]string{"Content-Type": "application/json"}
}