//! §11 tail M1 integration test: GROUP-level template suppression. //! A child group declares a suppression for a template it inherits from its //! parent group → EVERY app in the child's subtree declines it (trigger //! anti-join joins the chain; route rebuild expands the group suppression //! across descendants), while an app under the parent but NOT under the child //! still inherits. A `sealed` parent template ignores the child's suppression. //! //! Deterministic: drives `list_matching_kv` + `list_effective` / //! `compile_effective_routes` directly. Skips when `DATABASE_URL` is unset. #![allow( clippy::needless_pass_by_value, clippy::many_single_char_names, clippy::too_many_lines )] use picloud_manager_core::route_admin::compile_effective_routes; use picloud_manager_core::route_repo::{PostgresRouteRepository, RouteRepository}; use picloud_manager_core::trigger_repo::{PostgresTriggerRepo, TriggerRepo}; use picloud_shared::{AppId, KvEventOp}; use sqlx::postgres::PgPoolOptions; use sqlx::PgPool; use uuid::Uuid; async fn pool_or_skip() -> Option { let Ok(url) = std::env::var("DATABASE_URL") else { picloud_test_support::abort_if_db_required("group_suppression"); eprintln!("group_suppression: DATABASE_URL unset — skipping"); return None; }; let pool = PgPoolOptions::new() .max_connections(2) .connect(&url) .await .expect("connect to DATABASE_URL"); sqlx::migrate!("./migrations") .run(&pool) .await .expect("apply migrations"); Some(pool) } async fn id1(pool: &PgPool, sql: &str, bind: &str) -> Uuid { let row: (Uuid,) = sqlx::query_as(sql) .bind(bind) .fetch_one(pool) .await .expect("insert returning id"); row.0 } /// A group with an explicit parent. async fn group_under(pool: &PgPool, slug: &str, parent: Option) -> Uuid { let row: (Uuid,) = sqlx::query_as( "INSERT INTO groups (slug, name, parent_id) VALUES ($1, $1, $2) RETURNING id", ) .bind(slug) .bind(parent) .fetch_one(pool) .await .expect("group insert"); row.0 } async fn app_under(pool: &PgPool, slug: &str, group: Uuid) -> Uuid { let row: (Uuid,) = sqlx::query_as("INSERT INTO apps (slug, name, group_id) VALUES ($1, $1, $2) RETURNING id") .bind(slug) .bind(group) .fetch_one(pool) .await .expect("app insert"); row.0 } /// Whether `app`'s compiled route slice serves `/hello`. async fn serves_hello(repo: &PostgresRouteRepository, app: Uuid) -> bool { let effective = repo.list_effective().await.expect("list_effective"); let mut suppressed: std::collections::HashMap<(AppId, String), i32> = std::collections::HashMap::new(); for (a, p, d) in repo .list_route_suppressions() .await .expect("list_route_suppressions") { suppressed .entry((a, p)) .and_modify(|x| *x = (*x).min(d)) .or_insert(d); } compile_effective_routes(&effective, &suppressed) .into_iter() .any(|c| c.app_id == AppId::from(app) && format!("{:?}", c.path).contains("/hello")) } #[tokio::test(flavor = "multi_thread", worker_threads = 2)] async fn group_suppression_declines_for_whole_subtree_only() { let Some(pool) = pool_or_skip().await else { return; }; let sfx = Uuid::new_v4().simple().to_string(); let admin = id1( &pool, "INSERT INTO admin_users (username, password_hash) VALUES ($1, 'x') RETURNING id", &format!("gs-{sfx}"), ) .await; // Parent group P owns a handler `audit` + a kv trigger template + a /hello // route template. Child group C is under P. A sealed route template too. let p = group_under(&pool, &format!("gs-p-{sfx}"), None).await; let c = group_under(&pool, &format!("gs-c-{sfx}"), Some(p)).await; let handler_name = format!("audit-{sfx}"); let handler: (Uuid,) = sqlx::query_as( "INSERT INTO scripts (name, source, group_id) VALUES ($1, 'x', $2) RETURNING id", ) .bind(&handler_name) .bind(p) .fetch_one(&pool) .await .expect("group handler"); let tmpl: (Uuid,) = sqlx::query_as( "INSERT INTO triggers \ (group_id, script_id, kind, enabled, dispatch_mode, \ retry_max_attempts, retry_backoff, retry_base_ms, \ registered_by_principal, name) \ VALUES ($1, $2, 'kv', TRUE, 'async', 3, 'exponential', 1000, $3, $4) RETURNING id", ) .bind(p) .bind(handler.0) .bind(admin) .bind(format!("tmpl-{sfx}")) .fetch_one(&pool) .await .expect("kv template"); sqlx::query( "INSERT INTO kv_trigger_details (trigger_id, collection_glob, ops) \ VALUES ($1, '*', ARRAY['insert'])", ) .bind(tmpl.0) .execute(&pool) .await .expect("kv details"); sqlx::query( "INSERT INTO routes (group_id, script_id, host_kind, host, path_kind, path, method) \ VALUES ($1, $2, 'any', '', 'exact', '/hello', NULL)", ) .bind(p) .bind(handler.0) .execute(&pool) .await .expect("route template"); // App A under child C (will inherit C's suppression); app D under parent P // but NOT under C (control — must still inherit). let a = app_under(&pool, &format!("gs-a-{sfx}"), c).await; let d = app_under(&pool, &format!("gs-d-{sfx}"), p).await; // Child group C suppresses BOTH the trigger (by handler name) and the route. sqlx::query( "INSERT INTO template_suppressions (group_id, target_kind, reference) \ VALUES ($1, 'trigger', $2), ($1, 'route', '/hello')", ) .bind(c) .bind(&handler_name) .execute(&pool) .await .expect("group suppressions for C"); let trig = PostgresTriggerRepo::new(pool.clone()); let routes = PostgresRouteRepository::new(pool.clone()); // App A (under C) → both declined by C's group-level suppression. let a_trig = trig .list_matching_kv(AppId::from(a), "users", KvEventOp::Insert) .await .expect("match A"); assert!( !a_trig.iter().any(|m| m.trigger_id == tmpl.0.into()), "an app under the suppressing group must NOT match the inherited trigger" ); assert!( !serves_hello(&routes, a).await, "an app under the suppressing group must NOT serve the inherited route" ); // App D (under P only) → still inherits both (isolation: C's suppression // does not reach a sibling subtree). let d_trig = trig .list_matching_kv(AppId::from(d), "users", KvEventOp::Insert) .await .expect("match D"); assert!( d_trig.iter().any(|m| m.trigger_id == tmpl.0.into()), "an app outside the suppressing group's subtree still inherits the trigger" ); assert!( serves_hello(&routes, d).await, "an app outside the suppressing group's subtree still serves the route" ); // A SEALED parent route template ignores the child group's suppression. sqlx::query( "INSERT INTO routes \ (group_id, script_id, host_kind, host, path_kind, path, method, sealed) \ VALUES ($1, $2, 'any', '', 'exact', '/sealed', NULL, TRUE)", ) .bind(p) .bind(handler.0) .execute(&pool) .await .expect("sealed route template"); sqlx::query( "INSERT INTO template_suppressions (group_id, target_kind, reference) \ VALUES ($1, 'route', '/sealed')", ) .bind(c) .execute(&pool) .await .expect("suppress sealed"); let effective = routes.list_effective().await.expect("list_effective"); let mut suppressed: std::collections::HashMap<(AppId, String), i32> = std::collections::HashMap::new(); for (app, path, depth) in routes .list_route_suppressions() .await .expect("suppressions") { suppressed .entry((app, path)) .and_modify(|x| *x = (*x).min(depth)) .or_insert(depth); } let a_serves_sealed = compile_effective_routes(&effective, &suppressed) .into_iter() .any(|cr| cr.app_id == AppId::from(a) && format!("{:?}", cr.path).contains("/sealed")); assert!( a_serves_sealed, "a sealed parent template is non-suppressible even by a group" ); // Cleanup (FK order). let _ = sqlx::query("DELETE FROM triggers WHERE id = $1") .bind(tmpl.0) .execute(&pool) .await; let _ = sqlx::query("DELETE FROM routes WHERE group_id = $1") .bind(p) .execute(&pool) .await; let _ = sqlx::query("DELETE FROM template_suppressions WHERE group_id = $1") .bind(c) .execute(&pool) .await; let _ = sqlx::query("DELETE FROM apps WHERE id = ANY($1)") .bind(vec![a, d]) .execute(&pool) .await; let _ = sqlx::query("DELETE FROM scripts WHERE id = $1") .bind(handler.0) .execute(&pool) .await; let _ = sqlx::query("DELETE FROM groups WHERE id = ANY($1)") .bind(vec![c, p]) .execute(&pool) .await; let _ = sqlx::query("DELETE FROM admin_users WHERE id = $1") .bind(admin) .execute(&pool) .await; } /// Audit fix #3 (trigger side): a mid-tree group's suppression of an ancestor /// template's handler name must NOT over-decline a NEARER descendant group's /// OWN trigger that binds a same-named handler. `sc.depth < c.depth` in the /// anti-join is the guard. #[tokio::test(flavor = "multi_thread", worker_threads = 2)] async fn ancestor_suppression_does_not_over_decline_a_descendants_own_trigger() { let Some(pool) = pool_or_skip().await else { return; }; let sfx = Uuid::new_v4().simple().to_string(); let admin = id1( &pool, "INSERT INTO admin_users (username, password_hash) VALUES ($1, 'x') RETURNING id", &format!("od-{sfx}"), ) .await; // Chain: gg (root) → g → h → app a. gg AND h each own a handler of the SAME // NAME plus a kv trigger bound to it. g suppresses that handler name. let gg = group_under(&pool, &format!("od-gg-{sfx}"), None).await; let g = group_under(&pool, &format!("od-g-{sfx}"), Some(gg)).await; let h = group_under(&pool, &format!("od-h-{sfx}"), Some(g)).await; let a = app_under(&pool, &format!("od-a-{sfx}"), h).await; let name = format!("audit-{sfx}"); let mk_trigger = |owner: Uuid, name: String| { let pool = pool.clone(); async move { let handler: (Uuid,) = sqlx::query_as( "INSERT INTO scripts (name, source, group_id) VALUES ($1, 'x', $2) RETURNING id", ) .bind(&name) .bind(owner) .fetch_one(&pool) .await .expect("handler"); let t: (Uuid,) = sqlx::query_as( "INSERT INTO triggers \ (group_id, script_id, kind, enabled, dispatch_mode, \ retry_max_attempts, retry_backoff, retry_base_ms, \ registered_by_principal, name) \ VALUES ($1, $2, 'kv', TRUE, 'async', 3, 'exponential', 1000, $3, $4) \ RETURNING id", ) .bind(owner) .bind(handler.0) .bind(admin) .bind(format!("t-{}", Uuid::new_v4().simple())) .fetch_one(&pool) .await .expect("trigger"); sqlx::query( "INSERT INTO kv_trigger_details (trigger_id, collection_glob, ops) \ VALUES ($1, '*', ARRAY['insert'])", ) .bind(t.0) .execute(&pool) .await .expect("kv details"); (handler.0, t.0) } }; let (gg_handler, gg_trig) = mk_trigger(gg, name.clone()).await; let (h_handler, h_trig) = mk_trigger(h, name.clone()).await; // g suppresses the handler name for its whole subtree. sqlx::query( "INSERT INTO template_suppressions (group_id, target_kind, reference) VALUES ($1, 'trigger', $2)", ) .bind(g) .bind(&name) .execute(&pool) .await .expect("suppression"); let trig = PostgresTriggerRepo::new(pool.clone()); let m = trig .list_matching_kv(AppId::from(a), "users", KvEventOp::Insert) .await .expect("match"); let ids: Vec<_> = m.iter().map(|x| x.trigger_id).collect(); assert!( !ids.contains(&gg_trig.into()), "the far-ancestor template (above the suppressor) must be declined" ); assert!( ids.contains(&h_trig.into()), "the nearer descendant group's OWN trigger (below the suppressor) must survive" ); // Cleanup (FK order). let _ = sqlx::query("DELETE FROM triggers WHERE id = ANY($1)") .bind(vec![gg_trig, h_trig]) .execute(&pool) .await; let _ = sqlx::query("DELETE FROM apps WHERE id = $1") .bind(a) .execute(&pool) .await; let _ = sqlx::query("DELETE FROM scripts WHERE id = ANY($1)") .bind(vec![gg_handler, h_handler]) .execute(&pool) .await; let _ = sqlx::query("DELETE FROM groups WHERE id = ANY($1)") .bind(vec![h, g, gg]) .execute(&pool) .await; let _ = sqlx::query("DELETE FROM admin_users WHERE id = $1") .bind(admin) .execute(&pool) .await; }