import { env, exports } from "cloudflare:workers"; import { eq, sql } from "drizzle-orm"; import { beforeAll, beforeEach, describe, expect, it } from "vitest"; const SELF = exports.default; import { makeAuth } from "@/worker/auth"; import { makeDb } from "@/worker/db"; import { invites, users } from "@/worker/db/schema"; import { ISSUER, signInForCookie, testHeaders } from "./helpers"; // Admin invite creation refuses minting when (a) a `users` row already // exists for the email — tessera is invite-only, an existing user means // the address signed up via another channel, so a new invite would // generate a doomed URL — and (b) an invite for that email already // exists, consumed or not. The DB-level UNIQUE(email) on the invites // table is the authoritative race guard; these specs cover the // pre-flight 409 paths. describe("/api/admin/invites POST — pre-flight rejections", () => { const adminCred = { email: "invite-create-admin@example.com", password: "correct-horse-battery-staple", name: "Invite Create Admin", }; let cookie: string; beforeAll(async () => { const auth = makeAuth(env, { baseURL: ISSUER, issuer: ISSUER }); await auth.api.signUpEmail({ body: adminCred, asResponse: false }); await env.DB.prepare("UPDATE users SET role = ? WHERE email = ?").bind("admin", adminCred.email).run(); cookie = await signInForCookie(adminCred.email, adminCred.password, "10.74.1.1"); }); beforeEach(async () => { const db = makeDb(env); await db.delete(invites).where(sql`email LIKE 'create-test-%@example.com'`); await db.delete(users).where(sql`email LIKE 'create-test-%@example.com'`); }); const mint = (email: string): Promise => SELF.fetch(`${ISSUER}/api/admin/invites`, { method: "POST", headers: testHeaders({ cookie }), body: JSON.stringify({ email }), }); it("first mint for a fresh email succeeds (200)", async () => { const res = await mint("create-test-fresh@example.com"); expect(res.status).toBe(200); const body = (await res.json()) as { email: string; inviteUrl: string }; expect(body.email).toBe("create-test-fresh@example.com"); expect(body.inviteUrl).toBeTruthy(); }); it("second mint for the same email returns 409 invite_exists", async () => { const first = await mint("create-test-dup@example.com"); expect(first.status).toBe(200); const second = await mint("create-test-dup@example.com"); expect(second.status).toBe(409); const body = (await second.json()) as { error: string }; expect(body.error).toBe("invite_exists"); // Only one row should exist. const db = makeDb(env); const rows = await db.select().from(invites).where(eq(invites.email, "create-test-dup@example.com")); expect(rows).toHaveLength(1); }); it("mint for an email already attached to a users row returns 409 user_exists", async () => { const db = makeDb(env); await db.insert(users).values({ id: "usr-create-test-existing", name: "Existing", email: "create-test-occupied@example.com", emailVerified: true, }); const res = await mint("create-test-occupied@example.com"); expect(res.status).toBe(409); const body = (await res.json()) as { error: string }; expect(body.error).toBe("user_exists"); // No invite row should have been written. const rows = await db.select().from(invites).where(eq(invites.email, "create-test-occupied@example.com")); expect(rows).toHaveLength(0); }); it("mint normalizes email to lowercase before pre-flight + insert", async () => { const first = await mint("Create-Test-Case@Example.com"); expect(first.status).toBe(200); // Same address differing only in case must be rejected by the // invite_exists path because both checks compare against the // already-lowercased stored value. const second = await mint("create-test-case@example.com"); expect(second.status).toBe(409); const body = (await second.json()) as { error: string }; expect(body.error).toBe("invite_exists"); }); });