package api import ( "strings" "testing" "gitea.dooplex.hu/admin/felhom-hub/internal/notify" ) // R-539 — controller_slow_crashloop joins its fast sibling: allowlisted AND operator-only. // RED-PROOF: remove it from operatorOnlyEvents → "must be operator-only". func TestControllerSlowCrashloopIsAllowlistedAndOperatorOnly(t *testing.T) { et := "controller_slow_crashloop" if !allowedEventTypes[et] { t.Fatalf("%s must be in allowedEventTypes (R-77)", et) } if !notify.IsOperatorOnly(et) { t.Fatalf("%s must be operator-only — host ids and vmids are not a household's business", et) } } // R-550 — restore_interrupted is pushed by controller v0.246.0 and IS for the household: they started // the restore and can run it again. So it must be allowlisted (or POST /event 400s — R-77), must NOT be // operator-only, and must carry a Hungarian customer message (a missing entry falls back to the raw // English message — the v0.78.0 defect). // RED-PROOF: drop the customerMessages entry → the subject/body carry the raw message. func TestRestoreInterruptedReachesTheHouseholdInHungarian(t *testing.T) { et := "restore_interrupted" if !allowedEventTypes[et] { t.Fatalf("%s must be in allowedEventTypes — the controller's push would 400", et) } if notify.IsOperatorOnly(et) { t.Fatalf("%s must reach the household, not only the operator", et) } const raw = "RAW-ENGLISH-SENTINEL restore interrupted" // The SUBJECT is built from the Hungarian message alone; the body legitimately repeats the raw // message as a detail line ("Üzenet: …"), so the body cannot be the witness — the subject is. subject, body := notify.FormatCustomerEmail("hu", "c1", et, "warning", raw, "", "{}") if strings.Contains(subject, "RAW-ENGLISH-SENTINEL") { t.Fatalf("customer mail subject for %s is the raw message — customerMessages entry missing: %q", et, subject) } // ASCII fragment of the Hungarian text („megszakadt"), with a negative control. if !strings.Contains(body, "megszakadt") { t.Fatalf("customer mail for %s lacks the Hungarian sentence (fragment \"megszakadt\")", et) } if strings.Contains(body, "zzzz-not-present") { t.Fatalf("negative control matched — the fragment search is broken") } } // v0.120.0 — the two update outcomes reach the household, in its language, never as raw English. // RED-PROOF (REPORT.md): drop app_update_undone from allowedEventTypes → "must be in allowedEventTypes". func TestAppUpdateOutcomesReachTheHousehold(t *testing.T) { for _, et := range []string{"app_update_undone", "app_update_held"} { if !allowedEventTypes[et] { t.Fatalf("%s must be in allowedEventTypes — the controller's push would 400", et) } if notify.IsOperatorOnly(et) { t.Fatalf("%s must reach the household", et) } const raw = "RAW-ENGLISH-SENTINEL" for _, lang := range []string{"hu", "en"} { subject, _ := notify.FormatCustomerEmail(lang, "c1", et, "warning", raw, "", `{"stack_name":"docmost"}`) if strings.Contains(subject, raw) || !strings.Contains(subject, "docmost:") { t.Fatalf("%s/%s subject must be the entry naming the app, got %q", et, lang, subject) } } } } // R-636 (v0.121.0) — app_oom_storm is allow-listed AND operator-only, pinned together (allow-listed // but not operator-only is the v0.78.0 defect: raw English to a household). // RED-PROOF (REPORT.md): drop it from operatorOnlyEvents → "must be operator-only". func TestAppOOMStormIsAllowlistedAndOperatorOnly(t *testing.T) { et := "app_oom_storm" if !allowedEventTypes[et] { t.Fatalf("%s must be in allowedEventTypes — the controller's push would 400", et) } if !notify.IsOperatorOnly(et) { t.Fatalf("%s must be operator-only — container names and memory figures are not a household's business", et) } } // R-659 (v0.122.0) — app_hold_no_whole_copy is allow-listed AND operator-only, pinned together. // RED-PROOF (REPORT.md): drop it from operatorOnlyEvents → "must be operator-only". func TestAppHoldNoWholeCopyIsAllowlistedAndOperatorOnly(t *testing.T) { et := "app_hold_no_whole_copy" if !allowedEventTypes[et] { t.Fatalf("%s must be in allowedEventTypes — the controller's push would 400", et) } if !notify.IsOperatorOnly(et) { t.Fatalf("%s must be operator-only — the household is told by app_update_held; this carries support's detail", et) } } // Decision 28 (hub v0.123.0) — app_stopped_unhealthy is a HOUSEHOLD event: allow-listed, NOT operator-only, // and it has a Hungarian AND English mail entry (never the raw-English fallback). // RED-PROOF (REPORT.md): drop it from allowedEventTypes → "the controller's push would 400". func TestAppStoppedUnhealthyIsAHouseholdEvent(t *testing.T) { et := "app_stopped_unhealthy" if !allowedEventTypes[et] { t.Fatalf("%s must be in allowedEventTypes — the controller's push would 400", et) } if notify.IsOperatorOnly(et) { t.Fatalf("%s must reach the household", et) } for _, lang := range []string{"hu", "en"} { subject, _ := notify.FormatCustomerEmail(lang, "c1", et, "warning", "RAW-ENGLISH-SENTINEL", "", `{"stack_name":"gokapi"}`) if strings.Contains(subject, "RAW-ENGLISH-SENTINEL") || !strings.Contains(subject, "gokapi:") { t.Fatalf("%s/%s subject must be the mail entry naming the app, got %q", et, lang, subject) } } }