Some checks are pending
CI / Lint bridge (Biome) (push) Waiting to run
CI / Type-check bridge (push) Blocked by required conditions
CI / Tests unit bridge (push) Blocked by required conditions
CI / Tests integration bridge (push) Blocked by required conditions
CI / Security scan (push) Waiting to run
CI / Docker build + healthcheck (push) Blocked by required conditions
Pivot strategique : DocAdenice = produit Notion-like generique. Le bridge
est livre vide a un user qui cree ses tables Baserow comme il veut. Code
sans aucune ontologie metier.
Suppressions :
- 9 entites domain metier (Personne, Formation, Bloc, Module, Attribution,
Client, Projet, Tache, Intervention) + types.ts (Role, statuts)
- baserow-repo.ts (mega-fichier 554 LOC avec 9 repos heritant BaseRepo)
- 6 routes metier (personnes, formations, projets, modules, interventions,
attributions) + tests associes
- Lookup PersonneRepo.findByEmail dans middleware auth
- Mapping DEFAULT_ROLE_SCOPES dans middleware/scopes.ts
- Cascade rollup metier dans webhooks/baserow-handler.ts
Ajouts :
- Domain generique : Table, Row, Field, View + schemas zod refondus
- 4 repos generiques : tables / rows / fields / views
- Route unique routes/tables.ts avec 9 endpoints REST CRUD generiques
- Claim JWT acadenice_permissions[] lu directement dans le middleware auth
(alimente par RBAC dynamique cote DocAdenice en R2)
- examples/acadenice-formation-hub/ : README + seed-baserow.md schema
9 tables + example-roles.md (Formateur, Developpeur, Direction, Support,
Admin avec permissions generiques)
Refactors :
- BaserowClient etendu : listTables, getTable, listFields, listViews,
getGridViewRows
- middleware/auth.ts : extractPermissions(payload), AuthenticatedUser
remplace roles[] par permissions[]
- middleware/scopes.ts : computeOidcScopes(groups, permissions, map)
- webhooks/baserow-handler.ts : invalidation generique
bridge:tables:<tableId>:* sans cascade cross-table
- lib/cache.ts : invalidateEntity -> invalidateTable(redis, tableId, rowId?)
- container.ts : drop tableIds, RepoSet={tables, rows, fields, views}
- 501 NOT_IMPLEMENTED si DB token sur endpoints /tables qui exigent JWT
Tests : 250/250 verts (depuis 319). Coverage : domain 98.9%, adapters 89%,
auth 97.08%, rate-limit 100%, cache 100%, webhooks 100%.
Quality gates verts : typecheck, lint biome, vitest, coverage thresholds.
Refs: R1 dans le pivot strategique DocAdenice Notion-like generique.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
114 lines
3.5 KiB
TypeScript
114 lines
3.5 KiB
TypeScript
/**
|
|
* Test helper : construit une app Hono iso-prod avec un container minimal en
|
|
* memoire, puis expose les routes generiques /api/v1/tables/*.
|
|
*
|
|
* R1 — Pas de tableIds metier. Les repos sont injectes via overrides.
|
|
*/
|
|
|
|
import { Hono } from 'hono';
|
|
import { logger as honoLogger } from 'hono/logger';
|
|
import type { BaserowClient } from '../../src/adapters/baserow-client.js';
|
|
import type { RedisCache } from '../../src/adapters/redis-cache.js';
|
|
import type { Container, RepoSet } from '../../src/lib/container.js';
|
|
import { setContainer } from '../../src/lib/container.js';
|
|
import { logger } from '../../src/lib/logger.js';
|
|
import {
|
|
type ApiTokenRecord,
|
|
type AuthVariables,
|
|
authMiddleware,
|
|
} from '../../src/middleware/auth.js';
|
|
import { errorHandler } from '../../src/middleware/error-handler.js';
|
|
import { tablesRoutes } from '../../src/routes/tables.js';
|
|
import { webhooksRoutes } from '../../src/routes/webhooks.js';
|
|
|
|
export const READ_TOKEN = 'brg_read';
|
|
export const WRITE_TOKEN = 'brg_write';
|
|
export const ADMIN_TOKEN = 'brg_admin';
|
|
|
|
export const TEST_TOKENS: ApiTokenRecord[] = [
|
|
{ token: READ_TOKEN, name: 'test-read', scopes: ['read:tables'] },
|
|
{ token: WRITE_TOKEN, name: 'test-write', scopes: ['read:tables', 'write:tables'] },
|
|
{ token: ADMIN_TOKEN, name: 'test-admin', scopes: ['admin:*'] },
|
|
];
|
|
|
|
export interface TestContainerOverrides {
|
|
repos: RepoSet;
|
|
baserow?: BaserowClient;
|
|
redis?: RedisCache;
|
|
tokens?: ApiTokenRecord[];
|
|
}
|
|
|
|
/**
|
|
* Stub Redis minimal pour les tests routes : juste les methodes que les routes
|
|
* appellent (invalidatePattern + checkRateLimit). No-op qui ne refuse jamais.
|
|
*/
|
|
function buildNoopRedis(): RedisCache {
|
|
return {
|
|
invalidatePattern: async (_pattern: string) => 0,
|
|
checkRateLimit: async (_key: string, _max: number, _win: number) => true,
|
|
} as unknown as RedisCache;
|
|
}
|
|
|
|
export function installTestContainer(over: TestContainerOverrides): Container {
|
|
const tokensMap = new Map<string, ApiTokenRecord>();
|
|
for (const t of over.tokens ?? TEST_TOKENS) tokensMap.set(t.token, t);
|
|
|
|
const fakeBaserow = over.baserow ?? ({} as BaserowClient);
|
|
const fakeRedis = over.redis ?? buildNoopRedis();
|
|
|
|
const container: Container = {
|
|
config: {
|
|
nodeEnv: 'test',
|
|
port: 0,
|
|
logLevel: 'fatal',
|
|
baserowApiUrl: 'http://localhost',
|
|
baserowApiToken: 'fake',
|
|
redisUrl: 'redis://localhost',
|
|
baserowWebhookSecret: 'fake_secret_at_least_16_chars',
|
|
docmostWebhookSecret: 'fake_docmost_secret_at_least_16_chars',
|
|
bridgeApiTokens: undefined,
|
|
rateLimitGlobalMax: 10000,
|
|
rateLimitGlobalWindow: 60,
|
|
rateLimitMutationMax: 10000,
|
|
rateLimitMutationWindow: 60,
|
|
},
|
|
baserow: fakeBaserow,
|
|
redis: fakeRedis,
|
|
repos: over.repos,
|
|
tokens: tokensMap,
|
|
oidc: null,
|
|
groupsScopesMap: {},
|
|
logger,
|
|
};
|
|
setContainer(container);
|
|
return container;
|
|
}
|
|
|
|
export function resetTestContainer(): void {
|
|
setContainer(null);
|
|
}
|
|
|
|
export function buildTestApp(container: Container): Hono<{ Variables: AuthVariables }> {
|
|
const app = new Hono<{ Variables: AuthVariables }>();
|
|
app.use('*', honoLogger());
|
|
app.onError(errorHandler);
|
|
|
|
app.get('/api/health', (c) => c.json({ status: 'ok' }));
|
|
|
|
app.route('/api/webhooks', webhooksRoutes);
|
|
|
|
const v1 = new Hono<{ Variables: AuthVariables }>();
|
|
v1.use(
|
|
'*',
|
|
authMiddleware({
|
|
tokens: container.tokens,
|
|
oidc: container.oidc,
|
|
groupsScopesMap: container.groupsScopesMap,
|
|
logger,
|
|
}),
|
|
);
|
|
v1.route('/tables', tablesRoutes);
|
|
app.route('/api/v1', v1);
|
|
|
|
return app;
|
|
}
|