Coolify API tokens are team-scoped, and a wrong-team token does not error: the API resolves what it cannot see to `null` (getResourceByUuid walks resource → environment → project → team_id and returns null on a mismatch). To cast, `null` is indistinguishable from "this resource does not exist yet" — an invitation to create it. So an apply with a token minted under the wrong team would not fail loudly; it would provision a duplicate set of resources into the wrong team, against whatever server that team owns. Silent, mutating, discovered late. That makes this a correctness bug, not hardening. - environments.yaml carries a required `team:` per environment (id, name, or both). Required is the point: an environment with no declared team is one cast cannot verify it is pointed at. - Every command that reaches a live Coolify (apply, diff, server add, smoke) resolves GET /teams/current — the only endpoint that answers "what team does this token act as?" — and aborts on mismatch before its first READ, not merely its first write: a wrong-team diff reports "everything is absent", which is the very lie an apply would then act on. - server add and smoke take --env for this reason. A server belongs to exactly one team forever (no pivot, no is_system_wide escape hatch), and smoke writes env vars onto a live app. - New read-only `cast team` prints the token's team, so the binding can be filled in without a chicken-and-egg. With --env it also checks the binding: the dry run for "would apply refuse?". Team id 0 is a first-class value, not a falsy absent — it is the Root Team that a single-admin instance keeps everything in (app/Models/User.php). Also records the #4 investigation in docs/semantics.md: GithubApp `is_system_wide` IS the supported way to serve every team — list_github_apps scopes to `team_id = token's team OR is_system_wide`, and POST /github-apps accepts the flag — so per-team App duplication is unnecessary. Corollary: resolving a GitHub App by name is NOT a proxy for being in the right team, which is the second reason the assert has to be explicit. Closes #9 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
63 lines
2.3 KiB
TypeScript
63 lines
2.3 KiB
TypeScript
import { describe, expect, it, vi } from "vitest";
|
|
import { CoolifyClient } from "../src/coolify.js";
|
|
|
|
function mockFetch(routes: Record<string, unknown>) {
|
|
return vi.fn(async (url: string | URL, init?: RequestInit) => {
|
|
const key = `${init?.method ?? "GET"} ${new URL(String(url)).pathname}`;
|
|
if (!(key in routes)) return new Response("not found", { status: 404 });
|
|
return new Response(JSON.stringify(routes[key]), { status: 200 });
|
|
}) as unknown as typeof fetch;
|
|
}
|
|
|
|
describe("CoolifyClient", () => {
|
|
it("sends bearer auth and resolves servers by name", async () => {
|
|
const fetchImpl = mockFetch({
|
|
"GET /api/v1/servers": [{ uuid: "srv-1", name: "prod-box" }],
|
|
});
|
|
const c = new CoolifyClient("https://coolify.test", "tok", fetchImpl);
|
|
expect(await c.serverUuid("prod-box")).toBe("srv-1");
|
|
const call = (fetchImpl as unknown as ReturnType<typeof vi.fn>).mock
|
|
.calls[0];
|
|
expect((call[1].headers as Record<string, string>).Authorization).toBe(
|
|
"Bearer tok",
|
|
);
|
|
});
|
|
it("throws a named error when a resolver misses", async () => {
|
|
const c = new CoolifyClient(
|
|
"https://coolify.test",
|
|
"tok",
|
|
mockFetch({ "GET /api/v1/servers": [] }),
|
|
);
|
|
await expect(c.serverUuid("nope")).rejects.toThrow(
|
|
/not found in Coolify: server nope/,
|
|
);
|
|
});
|
|
it("surfaces API errors with method, path and status", async () => {
|
|
const c = new CoolifyClient("https://coolify.test", "tok", mockFetch({}));
|
|
await expect(c.get("/projects")).rejects.toThrow(/GET \/projects → 404/);
|
|
});
|
|
it("reads the token's team from /teams/current", async () => {
|
|
const c = new CoolifyClient(
|
|
"https://coolify.test",
|
|
"tok",
|
|
mockFetch({
|
|
"GET /api/v1/teams/current": {
|
|
id: 1,
|
|
name: "heavy-duty",
|
|
personal_team: false,
|
|
},
|
|
}),
|
|
);
|
|
await expect(c.currentTeam()).resolves.toEqual({
|
|
id: 1,
|
|
name: "heavy-duty",
|
|
});
|
|
});
|
|
it("reads version as plain text, not JSON", async () => {
|
|
const fetchImpl = vi.fn(
|
|
async () => new Response("4.1.2", { status: 200 }),
|
|
) as unknown as typeof fetch;
|
|
const c = new CoolifyClient("https://coolify.test", "tok", fetchImpl);
|
|
await expect(c.version()).resolves.toBe("4.1.2");
|
|
});
|
|
});
|