Files
synapbus/internal/agents/middleware_test.go
T
Algis DumbrisandClaude Opus 4.6 2f55ce87c3 feat: implement core foundation (storage, messaging, agents, MCP server)
Implements the foundational layer that all SynapBus features depend on:

- internal/storage: SQLite connection manager (WAL mode, busy_timeout,
  foreign_keys) and embedded migration runner using modernc.org/sqlite
- internal/messaging: MessagingService with send, read inbox, claim,
  mark done/failed, and FTS5 search. SQLite-backed MessageStore with
  conversation auto-creation and read/unread tracking via inbox_state.
- internal/agents: AgentService with register, authenticate (bcrypt),
  update, deregister, discover by capability. HTTP auth middleware.
- internal/mcp: MCP server using mark3labs/mcp-go with 9 registered
  tools (send_message, read_inbox, claim_messages, mark_done,
  search_messages, register_agent, discover_agents, update_agent,
  deregister_agent). SSE transport, health endpoint, connection manager.
- internal/trace: Async trace recorder with buffered channel for
  recording agent actions to SQLite traces table.
- cmd/synapbus: Updated main.go wiring storage, migrations, services,
  MCP server, chi router, and graceful shutdown.

All code compiles with CGO_ENABLED=0. Full test suite passes.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 11:45:22 +02:00

90 lines
1.9 KiB
Go

package agents
import (
"encoding/json"
"net/http"
"net/http/httptest"
"testing"
_ "modernc.org/sqlite"
"github.com/smart-mcp-proxy/synapbus/internal/trace"
)
func TestAuthMiddleware(t *testing.T) {
db := newTestDB(t)
store := NewSQLiteAgentStore(db)
tracer := trace.NewTracer(db)
t.Cleanup(func() { tracer.Close() })
svc := NewAgentService(store, tracer)
// Register an agent to get a valid API key
_, apiKey, err := svc.Register(t.Context(), "mw-bot", "Middleware Bot", "ai", json.RawMessage("{}"), 1)
if err != nil {
t.Fatalf("Register: %v", err)
}
middleware := AuthMiddleware(svc)
// Protected handler
handler := middleware(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
agent, ok := AgentFromContext(r.Context())
if !ok {
t.Error("expected agent in context")
http.Error(w, "no agent", http.StatusInternalServerError)
return
}
w.WriteHeader(http.StatusOK)
w.Write([]byte(agent.Name))
}))
tests := []struct {
name string
authHeader string
wantStatus int
}{
{
name: "valid API key",
authHeader: "Bearer " + apiKey,
wantStatus: http.StatusOK,
},
{
name: "missing header",
authHeader: "",
wantStatus: http.StatusUnauthorized,
},
{
name: "invalid key",
authHeader: "Bearer invalid-key",
wantStatus: http.StatusUnauthorized,
},
{
name: "malformed header",
authHeader: "NotBearer " + apiKey,
wantStatus: http.StatusUnauthorized,
},
{
name: "bearer only no key",
authHeader: "Bearer",
wantStatus: http.StatusUnauthorized,
},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
req := httptest.NewRequest("GET", "/test", nil)
if tt.authHeader != "" {
req.Header.Set("Authorization", tt.authHeader)
}
rr := httptest.NewRecorder()
handler.ServeHTTP(rr, req)
if rr.Code != tt.wantStatus {
t.Errorf("status = %d, want %d", rr.Code, tt.wantStatus)
}
})
}
}