3738dfc548
gates / gates (push) Successful in 19s
Off-site is ON by default for a new customer — shared, 100 GB soft quota prefilled, the checkbox kept so an operator can opt a customer out. The reason is this repo's own [FACT]: the whole-guest tiers do not carry the data drive and a Tier-1 unit has no file leg, so with this unticked a one-drive box keeps NO copy of the household's own files. Measured on a fresh box the same day. The quota is prefilled because the fill warning only fires when quota_gb > 0. Also registers controller v0.244.0's app_deploy_started / app_deploy_failed in both allowedEventTypes and customerMessages, per the rule that the two move together. Red-proofed: dropping the default fails the new render test. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
60 lines
2.2 KiB
Go
60 lines
2.2 KiB
Go
package web
|
|
|
|
import (
|
|
"net/http/httptest"
|
|
"strings"
|
|
"testing"
|
|
)
|
|
|
|
// Off-site-by-default (operator ruling 2026-09-16) — the same shape as DR-tier-by-default, and for a
|
|
// sharper reason: with the box's off-site copy unticked, a one-drive box keeps NO copy of the
|
|
// household's own files. The whole-guest tiers do not carry the data drive (07-backup-architecture
|
|
// §6) and a Tier-1 unit holds no file leg, so the files are covered by Tier 2 or Tier 3 and by
|
|
// nothing else. On 2026-09-16 that was measured, not argued: five photos deleted on a fresh box,
|
|
// restored from the box's own backup, and none of them opened.
|
|
//
|
|
// Red-proof partner: drop the overrides from handleConfigNewForm → this test fails at the checkbox.
|
|
func TestOffsite_NewCustomerFormDefaultsOn(t *testing.T) {
|
|
s, _ := newTestServer(t)
|
|
req := httptest.NewRequest("GET", "/configs/new", nil)
|
|
rr := httptest.NewRecorder()
|
|
s.handleConfigNewForm(rr, req)
|
|
|
|
// The render itself is half the assertion: the form compares `box_type` with `eq`, and a default
|
|
// that supplies some keys but not that one makes `eq` fail and takes the whole page with it.
|
|
if rr.Code != 200 || rr.Body.Len() == 0 {
|
|
t.Fatalf("the new-customer form did not render: code=%d len=%d", rr.Code, rr.Body.Len())
|
|
}
|
|
out := rr.Body.String()
|
|
if strings.Contains(out, "incompatible types") || strings.Contains(out, "executing \"config_form") {
|
|
t.Fatalf("the form rendered a template error:\n%s", out[max0(len(out)-400):])
|
|
}
|
|
|
|
i := strings.Index(out, `name="offsite_enabled"`)
|
|
if i < 0 {
|
|
t.Fatal("the new-customer form has no off-site checkbox at all")
|
|
}
|
|
if !strings.Contains(out[i:min0(i+200, len(out))], "checked") {
|
|
t.Fatal("the new-customer form does not default the off-site copy ON — a fresh one-drive box would keep no copy of the customer's files")
|
|
}
|
|
// The quota is prefilled on purpose: the fill warning in monitor/offsite.go only fires when
|
|
// quota_gb > 0, so an empty field means the operator is never told the store is filling up.
|
|
if !strings.Contains(out, `value="100"`) {
|
|
t.Fatal("the off-site soft quota must be prefilled (100 GB) — an empty quota silences the fill warning")
|
|
}
|
|
}
|
|
|
|
func max0(n int) int {
|
|
if n < 0 {
|
|
return 0
|
|
}
|
|
return n
|
|
}
|
|
|
|
func min0(a, b int) int {
|
|
if a < b {
|
|
return a
|
|
}
|
|
return b
|
|
}
|