Files
fleetd/bridged/src/test/java/dev/ltms/bridged/guard/SubscriptionGuardTest.java
T
Dai Ha 93cfdb640f Stage-1 walking skeleton: bridged Java daemon (herdr client + REST + guard)
Maven/Java 25 module under bridged/. End-to-end verified against live
herdr 0.7.0 (protocol 14): GET /healthz and GET /sessions serve real
workspace data through the socket client.

- herdr client (CB-101): Unix-socket JSON-RPC via UnixDomainSocketAddress.
  Two contract facts pinned by tests against the real daemon:
  ids MUST be strings, and herdr is one-shot per connection
  (connection-per-call, which also makes the client lock-free).
- subscription guard: worker base_url must be on the off-subscription
  allowlist (gx00.gw, ollama.ltms.dev); primary env must carry no base_url.
- config (CB-106): Jackson YAML + Logback; example grounded in ltms-local.
- REST app (CB-104 start): injectable HerdrClient so acceptance tests run
  on an ephemeral port with a fake herdr, no daemon/Claude in the loop.
- tests: 17 unit/acceptance (mvn test) + 3 contract (mvn test -Pcontract).
2026-07-12 20:00:02 +02:00

53 lines
1.7 KiB
Java

package dev.ltms.bridged.guard;
import org.junit.jupiter.api.Test;
import java.util.Map;
import java.util.Set;
import static org.junit.jupiter.api.Assertions.*;
/** The subscription boundary is the system's core invariant — test it hard. */
class SubscriptionGuardTest {
private final SubscriptionGuard guard =
new SubscriptionGuard(Set.of("gx00.gw", "ollama.ltms.dev"));
@Test
void acceptsAllowlistedWorkerHosts() {
assertDoesNotThrow(() -> guard.assertWorker("http://gx00.gw:8000"));
assertDoesNotThrow(() -> guard.assertWorker("https://ollama.ltms.dev"));
}
@Test
void rejectsHostNotOnAllowlist() {
GuardException ex = assertThrows(GuardException.class,
() -> guard.assertWorker("https://api.anthropic.com"));
assertTrue(ex.getMessage().contains("api.anthropic.com"));
}
@Test
void rejectsMissingWorkerBaseUrl() {
assertThrows(GuardException.class, () -> guard.assertWorker(null));
assertThrows(GuardException.class, () -> guard.assertWorker(" "));
}
@Test
void rejectsMalformedWorkerBaseUrl() {
assertThrows(GuardException.class, () -> guard.assertWorker("not a url"));
}
@Test
void primaryWithBaseUrlIsTainted() {
GuardException ex = assertThrows(GuardException.class,
() -> guard.assertPrimaryClean(Map.of("ANTHROPIC_BASE_URL", "http://gx00.gw:8000")));
assertTrue(ex.getMessage().contains("tainted"));
}
@Test
void cleanPrimaryPasses() {
assertDoesNotThrow(() -> guard.assertPrimaryClean(Map.of("PATH", "/usr/bin")));
assertDoesNotThrow(() -> guard.assertPrimaryClean(Map.of("ANTHROPIC_BASE_URL", "")));
}
}