This commit is contained in:
2026-09-25 09:53:16 +05:30
parent 00317a00d8
commit db84a9a752
6 changed files with 317 additions and 1 deletions

View File

@@ -40,4 +40,12 @@ func RegisterRoutes(app *fiber.App, f *facade.Facade) {
RegisterUploadRoutes(api, f)
RegisterScanRoutes(api, f)
RegisterAssistantRoutes(api, f)
// What is running here.
//
// Registered on `api` and NOT under `/v1/web`, so it answers without a
// session — which is the whole point. The question it exists for is "why
// does nothing work", and a health check that needs a working credential
// cannot answer that. It returns booleans and a build id, never values.
api.Get("/v1/health", f.HealthController.Health)
}

View File

@@ -90,6 +90,26 @@ func TestEveryAssistantRouteIsReachable(t *testing.T) {
}
}
func TestHealthAnswersThroughTheRealRouteTableWithoutASession(t *testing.T) {
// Registered on `api` rather than under `/v1/web`, which is what keeps it
// outside the session guard. Asserted here rather than trusted, because the
// difference is one path segment and getting it wrong makes the endpoint
// useless for the only situation it exists for: nothing else works.
//
// It also has to survive a facade built with no database, no model and no
// embedder — the state somebody is most likely to be asking from.
app := fiber.New()
RegisterRoutes(app, testFacade(t))
resp, err := app.Test(httptest.NewRequest("GET", "/live/api/v1/health", nil), -1)
if err != nil {
t.Fatalf("calling health: %v", err)
}
if resp.StatusCode != fiber.StatusOK {
t.Fatalf("health needs a session or is unregistered: HTTP %d", resp.StatusCode)
}
}
func TestTheAssistantSurfaceSitsBehindTheSessionGuard(t *testing.T) {
// The assistant reads the same data the console does and must read it as
// the same person. Being under `/v1/web` is what puts it behind WebAuth —