|
| 1 | +/** @vitest-environment node */ |
| 2 | +import { describe, expect, it, vi } from 'vitest' |
| 3 | +import { v2ExecuteWorkflowBodySchema } from '@/lib/api/contracts/v2/workflows' |
| 4 | +import { workflowApiCommand } from '@/lib/mothership/agent-cli/engines/workflow-api' |
| 5 | +import type { AgentCliRuntime } from '@/lib/mothership/agent-cli/types' |
| 6 | + |
| 7 | +vi.mock('@/lib/core/utils/urls', () => ({ getBaseUrl: () => 'https://self-hosted.example' })) |
| 8 | + |
| 9 | +function fixture( |
| 10 | + options: { public?: boolean; deployed?: boolean; changed?: boolean; api?: boolean } = {} |
| 11 | +) { |
| 12 | + const deployed = options.deployed !== false |
| 13 | + const requests: string[] = [] |
| 14 | + const deployment = { |
| 15 | + id: 'wf-1', |
| 16 | + isDeployed: deployed, |
| 17 | + deployedAt: '2026-09-08T00:00:00Z', |
| 18 | + warnings: [], |
| 19 | + activeDeployment: deployed |
| 20 | + ? { deploymentVersionId: 'version-2', version: 2, deployedAt: '2026-09-08T00:00:00Z' } |
| 21 | + : null, |
| 22 | + latestDeploymentAttempt: null, |
| 23 | + needsRedeployment: true, |
| 24 | + isPublicApi: options.public === true, |
| 25 | + webhooks: [], |
| 26 | + } |
| 27 | + const version = { |
| 28 | + id: 'version-2', |
| 29 | + version: 2, |
| 30 | + name: null, |
| 31 | + description: null, |
| 32 | + isActive: !options.changed, |
| 33 | + createdAt: '2026-09-08T00:00:00Z', |
| 34 | + state: { |
| 35 | + blocks: { |
| 36 | + start: { |
| 37 | + id: 'start', |
| 38 | + type: options.api === false ? 'schedule' : 'start_trigger', |
| 39 | + name: 'Start', |
| 40 | + enabled: true, |
| 41 | + subBlocks: { |
| 42 | + inputFormat: { |
| 43 | + value: [ |
| 44 | + { |
| 45 | + name: 'query', |
| 46 | + type: 'string', |
| 47 | + value: "today's news", |
| 48 | + description: 'Search query', |
| 49 | + }, |
| 50 | + { name: 'limit', type: 'number', value: '5' }, |
| 51 | + ], |
| 52 | + }, |
| 53 | + }, |
| 54 | + }, |
| 55 | + }, |
| 56 | + }, |
| 57 | + } |
| 58 | + const runtime: AgentCliRuntime = { |
| 59 | + workspaceId: 'ws-1', |
| 60 | + userId: 'user-1', |
| 61 | + client: { |
| 62 | + request: async <T>(path: string): Promise<T> => { |
| 63 | + requests.push(path) |
| 64 | + if (path === '/api/v2/workflows/wf-1/deployment') return { data: deployment } as T |
| 65 | + if (path === '/api/v2/workflows/wf-1/versions/2') return { data: version } as T |
| 66 | + throw new Error(`Unexpected request: ${path}`) |
| 67 | + }, |
| 68 | + }, |
| 69 | + } |
| 70 | + return { runtime, requests } |
| 71 | +} |
| 72 | + |
| 73 | +describe('Mothership workflow API details', () => { |
| 74 | + it('reads the pinned live schema, not the changed draft, and describes the configured external API', async () => { |
| 75 | + const { runtime, requests } = fixture() |
| 76 | + const result = await workflowApiCommand.execute(['wf-1'], runtime, {}) |
| 77 | + expect(result.exitCode).toBe(0) |
| 78 | + const api = JSON.parse(result.stdout) |
| 79 | + expect(requests).toEqual([ |
| 80 | + '/api/v2/workflows/wf-1/deployment', |
| 81 | + '/api/v2/workflows/wf-1/versions/2', |
| 82 | + ]) |
| 83 | + expect(api).toMatchObject({ |
| 84 | + activeVersion: 2, |
| 85 | + needsRedeployment: true, |
| 86 | + method: 'POST', |
| 87 | + endpoint: 'https://self-hosted.example/api/v2/workflows/wf-1/execute', |
| 88 | + }) |
| 89 | + expect(api.input.fields).toEqual([ |
| 90 | + { name: 'query', type: 'string', default: "today's news", description: 'Search query' }, |
| 91 | + { name: 'limit', type: 'number', default: '5' }, |
| 92 | + ]) |
| 93 | + expect(api.responses.errors).toContain('HTTP 200 can contain data.status=failed') |
| 94 | + expect(api.examples.poll).toContain('/runs/<runId>?includeOutput=true') |
| 95 | + expect(result.stdout.length).toBeLessThan(7000) |
| 96 | + // The example must survive shell quoting, including apostrophes in saved inputs, |
| 97 | + // and parse as the actual public execute contract rather than a native tool body. |
| 98 | + for (const [mode, command] of Object.entries<string>(api.examples)) { |
| 99 | + if (mode === 'poll') continue |
| 100 | + const quoted = command.split(' --data ')[1] |
| 101 | + expect(quoted.startsWith("'") && quoted.endsWith("'")).toBe(true) |
| 102 | + const body = JSON.parse(quoted.slice(1, -1).replaceAll("'\\''", "'")) |
| 103 | + expect(v2ExecuteWorkflowBodySchema.safeParse(body).success).toBe(true) |
| 104 | + expect(body.input).toEqual({ query: "today's news", limit: 5 }) |
| 105 | + expect(body.async === true).toBe(mode === 'async') |
| 106 | + expect(body.stream === true).toBe(mode === 'stream') |
| 107 | + } |
| 108 | + }) |
| 109 | + |
| 110 | + it('keeps API-key auth on queued execution and polling even for a public workflow', async () => { |
| 111 | + const { runtime } = fixture({ public: true }) |
| 112 | + const api = JSON.parse((await workflowApiCommand.execute(['wf-1'], runtime, {})).stdout) |
| 113 | + expect(api.authentication.type).toBe('public') |
| 114 | + expect(api.examples.sync).not.toContain('X-API-Key') |
| 115 | + expect(api.examples.stream).not.toContain('X-API-Key') |
| 116 | + expect(api.examples.async).toContain('X-API-Key') |
| 117 | + expect(api.examples.poll).toContain('X-API-Key') |
| 118 | + }) |
| 119 | + |
| 120 | + it('does not advertise a live endpoint when undeployed or lacking an API entry block', async () => { |
| 121 | + const { runtime, requests } = fixture({ deployed: false }) |
| 122 | + const undeployed = JSON.parse((await workflowApiCommand.execute(['wf-1'], runtime, {})).stdout) |
| 123 | + expect(undeployed.isDeployed).toBe(false) |
| 124 | + expect(undeployed.endpoint).toBeUndefined() |
| 125 | + expect(requests).toHaveLength(1) |
| 126 | + const noApi = JSON.parse( |
| 127 | + (await workflowApiCommand.execute(['wf-1'], fixture({ api: false }).runtime, {})).stdout |
| 128 | + ) |
| 129 | + expect(noApi.apiRunnable).toBe(false) |
| 130 | + expect(noApi.endpoint).toBeUndefined() |
| 131 | + }) |
| 132 | + |
| 133 | + it('refuses mismatched active-version observations and propagates authorization failures', async () => { |
| 134 | + const changed = await workflowApiCommand.execute( |
| 135 | + ['wf-1'], |
| 136 | + fixture({ changed: true }).runtime, |
| 137 | + {} |
| 138 | + ) |
| 139 | + expect(changed.exitCode).toBe(1) |
| 140 | + expect(changed.stderr).toContain('active deployment changed') |
| 141 | + const { runtime } = fixture() |
| 142 | + runtime.client.request = vi.fn().mockRejectedValue(new Error('Forbidden')) |
| 143 | + await expect(workflowApiCommand.execute(['wf-1'], runtime, {})).rejects.toThrow('Forbidden') |
| 144 | + expect(runtime.client.request).toHaveBeenCalledTimes(1) |
| 145 | + }) |
| 146 | +}) |
0 commit comments