Files
Felis/cmd/felis/tui_root_test.go
T
flyemoji eb5875a699 feat(felis): add Operator break-glass op behind an operation menu
When a staff account already exists, the break-glass console now opens on a
thin top-level menu (menuModel) where account operations are peers rather than
tails of one wizard: provision/reset the Owner, or add an Operator. A fresh
machine with no Owner skips the menu and goes straight to Owner bootstrap, since
minting an Operator first would create a staff account the login gate rejects.

The Operator path reuses ownerModel via a bgOperation discriminator. It is
insert-only (performAddOperator -> InsertOperator), wraps a duplicate username as
api.ErrConflict and routes back to the provision form for a retry rather than
tearing down, and deliberately never flips the global local_auth toggle the way
the Owner thread does. The post-exit summary and audit trail distinguish the two
outcomes (isOperator); only the Owner provision claims local-password login was
enabled.

Tests cover the operator-model defaults, path selection (insert vs upsert and
the local-auth gate), conflict-retry versus generic teardown, isOperator
propagation, and the root menu routing for both fresh and admin-present
machines.
2026-06-30 15:40:24 +09:00

277 lines
10 KiB
Go

package main
import (
"context"
"strings"
"testing"
tea "github.com/charmbracelet/bubbletea"
)
// These tests exercise the root wizard's state machine directly by injecting the
// inter-screen messages into rootModel.Update. They bypass all real I/O (DB,
// migrations, panel probe, provisioning) — the screens emit those messages via
// commands we don't run — so the only thing under test is the orchestration:
// which screen the root advances to, and what it records on the result. This is
// the part the dashboard→wizard refactor actually put at risk, and it needs no
// root, k3s, or database.
func drive(t *testing.T, m *rootModel, msg tea.Msg) *rootModel {
t.Helper()
next, _ := m.Update(msg)
rm, ok := next.(*rootModel)
if !ok {
t.Fatalf("Update returned %T, want *rootModel", next)
}
return rm
}
func newTestRoot(adminExists bool, mode consoleMode, accessAud string) *rootModel {
return newRootModel(
context.Background(),
&fakeOwnerStore{},
"postgres://localhost/felis",
"felis.example.com",
"admin.felis.example.com",
"panel.felis.example.com",
accessAud,
"root",
adminExists,
mode,
)
}
func TestRootSetupHappyPath(t *testing.T) {
m := newTestRoot(false, consoleModeSetup, "")
// First-run setup begins at preflight.
if m.stage != stagePreflight {
t.Fatalf("initial stage = %v, want stagePreflight", m.stage)
}
if _, ok := m.screen.(*preflightModel); !ok {
t.Fatalf("initial screen = %T, want *preflightModel", m.screen)
}
// Preflight done → Owner.
m = drive(t, m, preflightDoneMsg{})
if m.stage != stageOwner {
t.Fatalf("after preflight, stage = %v, want stageOwner", m.stage)
}
if _, ok := m.screen.(*ownerModel); !ok {
t.Fatalf("after preflight, screen = %T, want *ownerModel", m.screen)
}
// Owner provisioned → Connection chooser.
m = drive(t, m, ownerResultMsg{username: "owner", displayPassword: "hunter2"})
if m.stage != stageConnect {
t.Fatalf("after owner, stage = %v, want stageConnect", m.stage)
}
if _, ok := m.screen.(*connectChooserModel); !ok {
t.Fatalf("after owner, screen = %T, want *connectChooserModel", m.screen)
}
if !m.result.provisioned || m.result.username != "owner" || m.result.displayPassword != "hunter2" {
t.Fatalf("owner result not recorded: %+v", m.result)
}
// Reverse-proxy chosen → Summary, with the connection recorded.
guide := "caddy config…"
m = drive(t, m, connectResultMsg{
method: connectReverseProxy,
panelHostname: "panel.felis.example.com",
adminHostname: "admin.felis.example.com",
guide: guide,
})
if m.stage != stageSummary {
t.Fatalf("after connect, stage = %v, want stageSummary", m.stage)
}
sum, ok := m.screen.(*summaryModel)
if !ok {
t.Fatalf("after connect, screen = %T, want *summaryModel", m.screen)
}
if !m.result.connectConfigured {
t.Fatalf("connectConfigured not set")
}
if m.result.connectMethod != connectReverseProxy {
t.Fatalf("connectMethod = %v, want connectReverseProxy", m.result.connectMethod)
}
if m.result.reverseProxyGuide != guide {
t.Fatalf("reverseProxyGuide = %q, want %q", m.result.reverseProxyGuide, guide)
}
if want := "https://panel.felis.example.com"; sum.panelURL != want {
t.Fatalf("summary panelURL = %q, want %q", sum.panelURL, want)
}
if sum.ownerPassword != "hunter2" {
t.Fatalf("summary ownerPassword = %q, want %q", sum.ownerPassword, "hunter2")
}
if sum.alreadySetUp {
t.Fatalf("first-run summary should not be marked alreadySetUp")
}
}
func TestRootSetupLocalSummary(t *testing.T) {
m := newTestRoot(false, consoleModeSetup, "")
m = drive(t, m, preflightDoneMsg{})
m = drive(t, m, ownerResultMsg{username: "owner"})
m = drive(t, m, connectResultMsg{method: connectLocal, panelHostname: "panel.felis.example.com"})
sum, ok := m.screen.(*summaryModel)
if !ok {
t.Fatalf("screen = %T, want *summaryModel", m.screen)
}
if !sum.localHint {
t.Fatalf("local connection summary should set localHint")
}
// Local never points at the public hostname.
if sum.panelURL == "https://panel.felis.example.com" {
t.Fatalf("local summary panelURL should be the local origin, got %q", sum.panelURL)
}
}
func TestRootRerunLandsOnStatus(t *testing.T) {
// adminExists at start of a setup run = re-run: preflight should skip straight
// to the "manage in panel" status screen, never touching owner/connect.
m := newTestRoot(true, consoleModeSetup, "")
if _, ok := m.screen.(*preflightModel); !ok {
t.Fatalf("re-run initial screen = %T, want *preflightModel", m.screen)
}
m = drive(t, m, preflightDoneMsg{})
sum, ok := m.screen.(*summaryModel)
if !ok {
t.Fatalf("re-run after preflight, screen = %T, want *summaryModel", m.screen)
}
if !sum.alreadySetUp {
t.Fatalf("re-run summary should be marked alreadySetUp")
}
if m.result.provisioned {
t.Fatalf("re-run must not provision an owner")
}
}
func TestRootBreakGlassQuitsAfterOwner(t *testing.T) {
// Break-glass with a staff account present opens on the operation menu; choosing
// "provision/reset the Owner" lands on the owner screen, which must quit on
// completion without entering the connection chooser (that step is setup-only).
m := newTestRoot(true, consoleModeBreakGlass, "")
if m.stage != stageMenu {
t.Fatalf("break-glass initial stage = %v, want stageMenu", m.stage)
}
m = drive(t, m, menuChoiceMsg{op: bgProvisionOwner})
if m.stage != stageOwner {
t.Fatalf("after the menu choice, stage = %v, want stageOwner", m.stage)
}
if _, ok := m.screen.(*ownerModel); !ok {
t.Fatalf("after the menu choice, screen = %T, want *ownerModel", m.screen)
}
next, cmd := m.Update(ownerResultMsg{username: "owner", displayPassword: "pw", mode: "recovery"})
rm := next.(*rootModel)
if _, ok := rm.screen.(*connectChooserModel); ok {
t.Fatalf("break-glass must not enter the connection chooser")
}
if cmd == nil {
t.Fatalf("break-glass owner completion should return a command (tea.Quit)")
}
if msg := cmd(); !isQuit(msg) {
t.Fatalf("break-glass owner completion command = %T, want tea.Quit", msg)
}
if !rm.result.provisioned || rm.result.username != "owner" {
t.Fatalf("break-glass owner result not recorded: %+v", rm.result)
}
}
func key(t tea.KeyType) tea.KeyMsg { return tea.KeyMsg{Type: t} }
// TestRootRailReviewNavigation locks the ←/→ rail-walk added for ergonomics:
// from a yielding screen ← steps back through completed stages read-only,
// → / esc return to the live screen, and ← is ignored on text-input screens
// (which need the arrow for their cursor). A screenshot can't verify this — the
// keys only matter live — so the contract lives here.
func TestRootRailReviewNavigation(t *testing.T) {
m := newTestRoot(false, consoleModeSetup, "")
m = drive(t, m, preflightDoneMsg{})
// On the Owner screen (text inputs) ← must NOT hijack the arrow: it stays
// with the field, so we remain on the live screen.
m = drive(t, m, key(tea.KeyLeft))
if m.reviewing != -1 {
t.Fatalf("← on the owner (text-input) screen entered review (%d); arrows belong to the field", m.reviewing)
}
// Advance to the Connection chooser (a select — it yields ←/→).
m = drive(t, m, ownerResultMsg{username: "owner", displayPassword: "hunter2"})
if m.reviewing != -1 {
t.Fatalf("fresh chooser should start live, reviewing = %d", m.reviewing)
}
// ← walks back to Owner (read-only recap), then Preflight, then clamps.
m = drive(t, m, key(tea.KeyLeft))
if m.reviewing != int(stageOwner) {
t.Fatalf("first ← = stage %d, want stageOwner %d", m.reviewing, stageOwner)
}
if v := m.View(); !strings.Contains(v, "Owner account") || !strings.Contains(v, "username") {
t.Fatalf("owner review body missing recap, got:\n%s", v)
}
m = drive(t, m, key(tea.KeyLeft))
if m.reviewing != int(stagePreflight) {
t.Fatalf("second ← = stage %d, want stagePreflight %d", m.reviewing, stagePreflight)
}
m = drive(t, m, key(tea.KeyLeft))
if m.reviewing != int(stagePreflight) {
t.Fatalf("← past the first step should clamp, got %d", m.reviewing)
}
// → walks forward; stepping past the last completed step returns to live.
m = drive(t, m, key(tea.KeyRight))
if m.reviewing != int(stageOwner) {
t.Fatalf("→ = stage %d, want stageOwner %d", m.reviewing, stageOwner)
}
m = drive(t, m, key(tea.KeyRight))
if m.reviewing != -1 {
t.Fatalf("→ past the last completed step should return live, reviewing = %d", m.reviewing)
}
if v := m.View(); !strings.Contains(v, "reach the panel") {
t.Fatalf("returning live should show the chooser, got:\n%s", v)
}
// esc is an immediate escape hatch back to the live screen.
m = drive(t, m, key(tea.KeyLeft))
if m.reviewing < 0 {
t.Fatalf("← should re-enter review")
}
m = drive(t, m, key(tea.KeyEsc))
if m.reviewing != -1 {
t.Fatalf("esc should return to the live screen, reviewing = %d", m.reviewing)
}
}
// TestSetupRailSpansBootstrap locks the cross-program progress rail: the
// host-bootstrap screen shows Bootstrap as the live step 1, and once the wizard
// takes over Bootstrap is carried as a completed (✓) step ahead of the live one.
// This is what makes the rail read as one continuous bar across the two separate
// bubbletea programs instead of restarting when the wizard launches.
func TestSetupRailSpansBootstrap(t *testing.T) {
boot := newHostBootstrapModel(context.Background())
if v := boot.View(); !strings.Contains(v, "1. Bootstrap") || !strings.Contains(v, "Preflight") {
t.Fatalf("bootstrap screen should show the shared rail with Bootstrap as step 1, got:\n%s", v)
}
m := newTestRoot(false, consoleModeSetup, "")
m = drive(t, m, tea.WindowSizeMsg{Width: 90, Height: 30})
m = drive(t, m, preflightDoneMsg{})
if _, ok := m.screen.(*ownerModel); !ok {
t.Fatalf("expected owner screen after preflight, got %T", m.screen)
}
if v := m.View(); !strings.Contains(v, "✓ Bootstrap") {
t.Fatalf("wizard rail should carry Bootstrap as a completed step, got:\n%s", v)
}
}
// isQuit reports whether a command's message is tea.Quit's sentinel. tea.Quit
// returns an unexported tea.quitMsg, so compare against the documented value
// produced by calling tea.Quit itself.
func isQuit(msg tea.Msg) bool {
_, ok := msg.(tea.QuitMsg)
return ok
}