import { describe, expect, test } from "bun:test"; import { parseConfig, SAFE_DEFAULT_TOOLS } from "./auth"; import { sanitizeLogOutput } from "./helpers"; import { getToolRisk } from "./tools"; describe("secure tool configuration", () => { test("new and incomplete configs use the read-only baseline", () => { const cfg = parseConfig("MUA_API_KEY=test\n"); expect(cfg.allToolsEnabled).toBe(false); expect(cfg.enabledTools).toEqual(SAFE_DEFAULT_TOOLS); expect(cfg.enabledTools).not.toContain("unraid_system_shell"); }); test("none means no tools instead of all tools", () => { const cfg = parseConfig("MUA_API_KEY=test\nMUA_ENABLED_TOOLS=none\n"); expect(cfg.allToolsEnabled).toBe(false); expect(cfg.enabledTools).toEqual([]); }); test("legacy all remains backwards compatible and explicit", () => { const cfg = parseConfig("MUA_API_KEY=test\nMUA_ENABLED_TOOLS=all\n"); expect(cfg.allToolsEnabled).toBe(true); expect(cfg.enabledTools).toEqual([]); }); }); describe("secret handling", () => { test("redacts common key-value and JSON secrets", () => { const output = sanitizeLogOutput( 'API_KEY=very-secret password:also-secret {"token":"third-secret"}', ); expect(output).not.toContain("very-secret"); expect(output).not.toContain("also-secret"); expect(output).not.toContain("third-secret"); expect(output).toContain("[REDACTED]"); }); }); describe("risk classification", () => { test("classifies root shell and container changes as critical", () => { expect(getToolRisk("unraid_system_shell")).toBe("critical"); expect(getToolRisk("unraid_docker_modify")).toBe("critical"); expect(getToolRisk("unraid_docker_restart")).toBe("write"); expect(getToolRisk("unraid_network_lan_probe")).toBe("active"); expect(getToolRisk("unraid_docker_list")).toBe("read"); }); });