import { afterEach, describe, expect, it } from 'vitest'; import { checkTransport } from './transport'; const original = process.env.DEVICE_ALLOW_HTTP; afterEach(() => { process.env.DEVICE_ALLOW_HTTP = original; }); function request(headers: Record, url = 'https://horaires.test/api/display') { return new Request(url, { headers }); } describe('checkTransport', () => { it('accepts a request the proxy says came over TLS', () => { process.env.DEVICE_ALLOW_HTTP = 'false'; expect(checkTransport(request({ 'x-forwarded-proto': 'https' })).ok).toBe(true); }); it('refuses a plain request when plain is not allowed', () => { process.env.DEVICE_ALLOW_HTTP = 'false'; const result = checkTransport(request({ 'x-forwarded-proto': 'http' })); expect(result.ok).toBe(false); if (!result.ok) { expect(result.response.status).toBe(403); } }); it('accepts a plain request once it has been allowed deliberately', () => { // The panel's certificate bundle is fixed at build time; when it cannot // trust the chain, this is the recorded decision to let it through. process.env.DEVICE_ALLOW_HTTP = 'true'; expect(checkTransport(request({ 'x-forwarded-proto': 'http' })).ok).toBe(true); }); it('falls back to the request URL when no proxy header is present', () => { process.env.DEVICE_ALLOW_HTTP = 'false'; expect(checkTransport(request({})).ok).toBe(true); expect(checkTransport(request({}, 'http://horaires.test/api/display')).ok).toBe(false); }); it('treats any value other than "true" as a refusal', () => { // A half-set variable must not quietly open the door. for (const value of ['', 'yes', '1', 'TRUE', 'oui']) { process.env.DEVICE_ALLOW_HTTP = value; expect(checkTransport(request({ 'x-forwarded-proto': 'http' })).ok).toBe(false); } }); });