Files
EpicNext-Cms/src/lib/deploy-workflow-contract.test.ts
T
SimoandCursor 9b47668fe9 chore: CSP script nonces, deploy health check, dead-code cleanup
Add per-request CSP nonces (drop script unsafe-inline), post-deploy /api/health gate, bump next-auth to beta.32, and remove unused motion/cache/permission helpers.

Co-authored-by: Cursor <[email protected]>
2026-07-21 20:27:08 +02:00

78 lines
3.3 KiB
TypeScript

import { readFileSync } from "node:fs";
import { resolve } from "node:path";
import { describe, expect, it } from "vitest";
describe("production deploy workflow", () => {
const workflow = readFileSync(
resolve(process.cwd(), ".gitea/workflows/deploy.yaml"),
"utf8",
);
it("preserves the Next.js incremental build cache", () => {
// May clear .next/types or .next/dev, but must not wipe the whole .next tree.
expect(workflow).not.toMatch(/rm\s+-rf\s+\.next(?:\s|$)/);
expect(workflow).toContain("rm -rf .output dist .next/types .next/dev");
expect(workflow).toContain("pnpm install --frozen-lockfile");
// Production builds must validate env (AUTH_SECRET, DATABASE_URL, …).
expect(workflow).not.toContain("SKIP_ENV_VALIDATION=1");
});
it("reclaims ownership before git reset so www-data files can be overwritten", () => {
expect(workflow).toContain('sudo chown -R "$' + "{DEPLOY_USER}:" + '$' + '{DEPLOY_GROUP}"');
const reclaimAt = workflow.indexOf(
'sudo chown -R "$' + "{DEPLOY_USER}:" + '$' + '{DEPLOY_GROUP}"',
);
const resetAt = workflow.indexOf("git reset --hard origin/main");
expect(reclaimAt).toBeGreaterThan(-1);
expect(resetAt).toBeGreaterThan(reclaimAt);
});
it("nuclear-replaces src/ and clears sticky bits without scanning every path", () => {
expect(workflow).toContain("rm -rf src");
expect(workflow).toContain("git checkout -f HEAD -- src");
expect(workflow).toContain("no-skip-worktree");
expect(workflow).toContain("no-assume-unchanged");
expect(workflow).toContain("Verified src/ matches HEAD");
expect(workflow).toContain("git ls-files -v");
expect(workflow).not.toContain("git ls-files -z");
expect(workflow).toContain("pnpm typecheck");
});
it("does not override onlyBuiltDependencies (uses pnpm-workspace.yaml)", () => {
expect(workflow).not.toContain("PNPM_CONFIG_ONLY_BUILT_DEPENDENCIES");
});
it("runs typecheck and tests before build", () => {
expect(workflow).toContain("pnpm typecheck");
expect(workflow).toContain("pnpm test");
// Scope to the deploy job: the release job's documentation body also
// mentions these commands, which must not affect this contract.
const deployJob = workflow.slice(workflow.indexOf("\n deploy:"));
const typecheckAt = deployJob.indexOf("pnpm typecheck");
const testAt = deployJob.indexOf("pnpm test");
const buildAt = deployJob.indexOf("pnpm build");
expect(typecheckAt).toBeGreaterThan(-1);
expect(testAt).toBeGreaterThan(typecheckAt);
expect(buildAt).toBeGreaterThan(testAt);
});
it("exports APP_VERSION from git for Sentry releases", () => {
expect(workflow).toContain('export APP_VERSION="$(git rev-parse --short HEAD)"');
expect(workflow).toContain(
'export NEXT_PUBLIC_APP_VERSION="$' + "{APP_VERSION}\"",
);
});
it("runs an HTTP health check before declaring deploy success", () => {
expect(workflow).toContain("/api/health");
expect(workflow).toContain('"database":true');
const deployJob = workflow.slice(workflow.indexOf("\n deploy:"));
const startAt = deployJob.indexOf("systemctl start atom-nexst.service");
const healthAt = deployJob.indexOf("/api/health");
const successAt = deployJob.indexOf("--- Deployed successfully ---");
expect(startAt).toBeGreaterThan(-1);
expect(healthAt).toBeGreaterThan(startAt);
expect(successAt).toBeGreaterThan(healthAt);
});
});