// Copyright (c) 2026 Petr Balvín (https://petrbalvin.org) // SPDX-License-Identifier: PolyForm-Noncommercial-1.0.0 package admin import ( "net/http" "net/http/httptest" "net/url" "strings" "testing" "sourcedock.dev/petrbalvin/volumen/internal/i18n" "sourcedock.dev/petrbalvin/volumen/internal/web" ) // A stale anonymous preview cookie (a leftover of an abandoned or reset // setup) must not greet the operator on the wizard: the first run opens // on the clean defaults. func TestSetupFormIgnoresPreviewCookies(t *testing.T) { f := newFixtureSeeded(t, false) req := httptest.NewRequest(http.MethodGet, "/admin/setup", nil) req.AddCookie(&http.Cookie{Name: i18n.Cookie, Value: "cs"}) req.AddCookie(&http.Cookie{Name: web.ThemeCookie, Value: "magma"}) rec := f.do(t, req) if rec.Code != http.StatusOK { t.Fatalf("code = %d", rec.Code) } body := rec.Body.String() if !strings.Contains(body, ``) { t.Fatalf("wizard did not open on the clean defaults:\n%s", body[:min(len(body), 400)]) } // The response expires both preview cookies so later screens are clean too. var sawLang, sawTheme bool for _, c := range rec.Result().Cookies() { if c.Name == i18n.Cookie && c.MaxAge < 0 { sawLang = true } if c.Name == web.ThemeCookie && c.MaxAge < 0 { sawTheme = true } } if !sawLang || !sawTheme { t.Fatalf("preview cookies not expired on the wizard response: %v", rec.Result().Cookies()) } } // A deployment with no accounts shows the wizard in place of the login // screen; the login URL itself redirects, so an old bookmark lands in // the right place too. func TestLoginFormRedirectsToWizard(t *testing.T) { f := newFixtureSeeded(t, false) rec := f.do(t, httptest.NewRequest(http.MethodGet, "/admin/login", nil)) if rec.Code != http.StatusSeeOther || rec.Header().Get("Location") != "/admin/setup" { t.Fatalf("code=%d location=%q", rec.Code, rec.Header().Get("Location")) } } func TestSetupFormServesWhileNoAccounts(t *testing.T) { f := newFixtureSeeded(t, false) rec := f.do(t, httptest.NewRequest(http.MethodGet, "/admin/setup", nil)) if rec.Code != http.StatusOK { t.Fatalf("code = %d", rec.Code) } body := rec.Body.String() for _, want := range []string{"Welcome to Volumen", "name=\"password\"", `name="theme"`, `name="language"`} { if !strings.Contains(body, want) { t.Fatalf("missing %q", want) } } } // The chips are real links, so the language is a server-side choice // too: ?lang renders the whole page in it and the hidden field carries // it into the account. func TestSetupFormHonoursLangQuery(t *testing.T) { f := newFixtureSeeded(t, false) rec := f.do(t, httptest.NewRequest(http.MethodGet, "/admin/setup?lang=cs", nil)) if rec.Code != http.StatusOK { t.Fatalf("code = %d", rec.Code) } body := rec.Body.String() for _, want := range []string{`