Files
doormile_backend/db/nats_guard_test.go

51 lines
1.6 KiB
Go

package db
import (
"testing"
"doormile/config"
)
// DM-06: NATS_URL used to default to the production cluster, so a backend run
// locally with no NATS configuration silently joined the live stream and
// competed with the production workers for the same durable pull consumer.
// That happened for real on 2026-09-11.
//
// The default is now empty, and empty must mean "do not connect" rather than
// "connect to whatever nats.Connect does with an empty string" — which would
// be localhost:4222, i.e. still a connection attempt.
func TestInitNATSSkipsWhenNoURLIsConfigured(t *testing.T) {
previousNc, previousJs := Nc, Js
t.Cleanup(func() { Nc, Js = previousNc, previousJs })
Nc, Js = nil, nil
for _, url := range []string{"", " "} {
Nc, Js = nil, nil
InitNATS(&config.Config{NatsURL: url})
if Nc != nil {
t.Errorf("NatsURL=%q opened a connection; empty must mean no NATS", url)
Nc.Close()
Nc = nil
}
if Js != nil {
t.Errorf("NatsURL=%q initialised JetStream; empty must mean no NATS", url)
}
}
}
// The config side of the same guarantee: no NATS setting may carry a real
// default, or the guard above is bypassed before it is ever reached.
func TestNATSConfigHasNoProductionDefaults(t *testing.T) {
for _, key := range []string{"NATS_URL", "NATS_USER", "NATS_PASSWORD"} {
t.Setenv(key, "")
}
t.Setenv("JWT_SECRET_KEY", "test")
t.Setenv("ENV", "development")
cfg := config.Load()
if cfg.NatsURL != "" || cfg.NatsUser != "" || cfg.NatsPassword != "" {
t.Errorf("NATS settings defaulted to %q / %q / %q — all must be empty",
cfg.NatsURL, cfg.NatsUser, cfg.NatsPassword)
}
}