Add per-request CSP nonces (drop script unsafe-inline), post-deploy /api/health gate, bump next-auth to beta.32, and remove unused motion/cache/permission helpers. Co-authored-by: Cursor <[email protected]>
78 lines
3.3 KiB
TypeScript
78 lines
3.3 KiB
TypeScript
import { readFileSync } from "node:fs";
|
|
import { resolve } from "node:path";
|
|
import { describe, expect, it } from "vitest";
|
|
|
|
describe("production deploy workflow", () => {
|
|
const workflow = readFileSync(
|
|
resolve(process.cwd(), ".gitea/workflows/deploy.yaml"),
|
|
"utf8",
|
|
);
|
|
|
|
it("preserves the Next.js incremental build cache", () => {
|
|
// May clear .next/types or .next/dev, but must not wipe the whole .next tree.
|
|
expect(workflow).not.toMatch(/rm\s+-rf\s+\.next(?:\s|$)/);
|
|
expect(workflow).toContain("rm -rf .output dist .next/types .next/dev");
|
|
expect(workflow).toContain("pnpm install --frozen-lockfile");
|
|
// Production builds must validate env (AUTH_SECRET, DATABASE_URL, …).
|
|
expect(workflow).not.toContain("SKIP_ENV_VALIDATION=1");
|
|
});
|
|
|
|
it("reclaims ownership before git reset so www-data files can be overwritten", () => {
|
|
expect(workflow).toContain('sudo chown -R "$' + "{DEPLOY_USER}:" + '$' + '{DEPLOY_GROUP}"');
|
|
const reclaimAt = workflow.indexOf(
|
|
'sudo chown -R "$' + "{DEPLOY_USER}:" + '$' + '{DEPLOY_GROUP}"',
|
|
);
|
|
const resetAt = workflow.indexOf("git reset --hard origin/main");
|
|
expect(reclaimAt).toBeGreaterThan(-1);
|
|
expect(resetAt).toBeGreaterThan(reclaimAt);
|
|
});
|
|
|
|
it("nuclear-replaces src/ and clears sticky bits without scanning every path", () => {
|
|
expect(workflow).toContain("rm -rf src");
|
|
expect(workflow).toContain("git checkout -f HEAD -- src");
|
|
expect(workflow).toContain("no-skip-worktree");
|
|
expect(workflow).toContain("no-assume-unchanged");
|
|
expect(workflow).toContain("Verified src/ matches HEAD");
|
|
expect(workflow).toContain("git ls-files -v");
|
|
expect(workflow).not.toContain("git ls-files -z");
|
|
expect(workflow).toContain("pnpm typecheck");
|
|
});
|
|
|
|
it("does not override onlyBuiltDependencies (uses pnpm-workspace.yaml)", () => {
|
|
expect(workflow).not.toContain("PNPM_CONFIG_ONLY_BUILT_DEPENDENCIES");
|
|
});
|
|
|
|
it("runs typecheck and tests before build", () => {
|
|
expect(workflow).toContain("pnpm typecheck");
|
|
expect(workflow).toContain("pnpm test");
|
|
// Scope to the deploy job: the release job's documentation body also
|
|
// mentions these commands, which must not affect this contract.
|
|
const deployJob = workflow.slice(workflow.indexOf("\n deploy:"));
|
|
const typecheckAt = deployJob.indexOf("pnpm typecheck");
|
|
const testAt = deployJob.indexOf("pnpm test");
|
|
const buildAt = deployJob.indexOf("pnpm build");
|
|
expect(typecheckAt).toBeGreaterThan(-1);
|
|
expect(testAt).toBeGreaterThan(typecheckAt);
|
|
expect(buildAt).toBeGreaterThan(testAt);
|
|
});
|
|
|
|
it("exports APP_VERSION from git for Sentry releases", () => {
|
|
expect(workflow).toContain('export APP_VERSION="$(git rev-parse --short HEAD)"');
|
|
expect(workflow).toContain(
|
|
'export NEXT_PUBLIC_APP_VERSION="$' + "{APP_VERSION}\"",
|
|
);
|
|
});
|
|
|
|
it("runs an HTTP health check before declaring deploy success", () => {
|
|
expect(workflow).toContain("/api/health");
|
|
expect(workflow).toContain('"database":true');
|
|
const deployJob = workflow.slice(workflow.indexOf("\n deploy:"));
|
|
const startAt = deployJob.indexOf("systemctl start atom-nexst.service");
|
|
const healthAt = deployJob.indexOf("/api/health");
|
|
const successAt = deployJob.indexOf("--- Deployed successfully ---");
|
|
expect(startAt).toBeGreaterThan(-1);
|
|
expect(healthAt).toBeGreaterThan(startAt);
|
|
expect(successAt).toBeGreaterThan(healthAt);
|
|
});
|
|
});
|