import {createHash} from "node:crypto" import type {BrowserContext} from "@playwright/test" import {HOUR, int, now, omit} from "@welshman/lib" import type {Handle} from "@welshman/util" import type {ZapperValues} from "@welshman/domain" import {tenantByUrl} from "../zooid/config" import {requestZooid} from "../zooid/transport" // Mirrors the service urls in src/app/env.ts and .env, which this process can't import: env.ts // reads import.meta.env and pulls in Capacitor. Nothing here is ever fetched — these are route // patterns, and every handler answers from memory. const DUFFLEPUD_ORIGIN = "https://dufflepud.coracle.social" const PUSH_SERVER_ORIGIN = "https://nps.flotilla.social" const HOSTING_ORIGIN = "https://api.hosting.coracle.social" // Hard-coded in src/app.html, so every navigation asks for it whatever the scenario is doing. const PLAUSIBLE_ORIGIN = "https://plausible.coracle.social" // Where the hosting api sends a browser to pay. Nothing serves it — `.test` resolves nowhere and // the block-all aborts the navigation — so a spec sees the redirect without one leaving. const CHECKOUT_ORIGIN = "https://checkout.test" // Relay-hosted livekit lives under a well-known path rather than an origin of its own. const LIVEKIT_PATH = "/.well-known/nip29/livekit" // A 1x1 transparent png, small enough to inline and real enough for an to decode. const PNG = Buffer.from( "iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAC0lEQVR42mNgAAIAAAUAAen63NgAAAAASUVORK5CYII=", "base64", ) // The dev server from vite.config.ts. Traffic to it is the app loading itself rather than egress, // so it is the one host both layers here let past, websockets included — Vite's hmr socket has to // keep working. export const isDevServerUrl = (url: URL) => url.port === "1847" && ["localhost", "127.0.0.1", "[::1]"].includes(url.hostname) // A relay is reached over wss and its own http origin is where nip-11 and nip-86 live. const relayOrigin = (url: string) => new URL(url.replace(/^ws/, "http")).origin const hostByOrigin = new Map( Array.from(tenantByUrl, ([url, host]): [string, string] => [relayOrigin(url), host]), ) export type BlockedRequest = { method: string url: string } const blockedByContext = new WeakMap() export const getBlockedRequests = (context: BrowserContext) => { const blocked = blockedByContext.get(context) if (blocked) { return blocked } throw new Error("installHttpRoutes was never called for this browser context") } /** * Blocks every http request the app makes, except to the dev server and to a relay's own origin, * which is forwarded to the container so that the nip-11 document and the nip-86 management api the * app reads are the real relay's. Install this first: the per-service mocks below are registered * later and therefore take priority, so a request that still reaches this handler is one nothing * has mocked. */ export const installHttpRoutes = (context: BrowserContext) => { const blocked: BlockedRequest[] = [] blockedByContext.set(context, blocked) // The dev server is left unrouted rather than matched and continued: a sveltekit page in dev is // hundreds of module requests, and none of them is egress. return context.route( url => !isDevServerUrl(url), async route => { const request = route.request() const {origin, pathname, search} = new URL(request.url()) const host = hostByOrigin.get(origin) if (host) { return route.fulfill( await requestZooid( host, request.method(), pathname + search, request.headers(), request.postDataBuffer() ?? undefined, ), ) } blocked.push({method: request.method(), url: request.url()}) return route.abort() }, ) } /** * Opt-in, for a spec that wants every request the app made to have been answered by something the * scenario stood up. Some of what a page asks for is meant to be refused — the blossom probe * against a relay with blossom off, for one — so call this from a spec that has mocked what it * exercises rather than from teardown. */ export const assertNoBlockedRequests = (context: BrowserContext) => { const blocked = getBlockedRequests(context) if (blocked.length > 0) { throw new Error( [ `The app made ${blocked.length} http request(s) nothing served:`, ...blocked.map(({method, url}) => ` ${method} ${url}`), ].join("\n"), ) } } // Fields to merge over a relay's own nip-11 document, keyed by its url. export type RelayInfoOverrides = Record /** * A relay's real document with a few fields replaced: a `redirect_to`, a `limitation`, a NIP the * relay does not implement. Merged rather than fabricated, because `self`, `pubkey`, `name` and * `supported_nips` are what room state is trusted from — a hand-written document breaks every * room on the page. * * Install it before the page navigates: the document is read at startup and cached from then on. */ export const mockRelayInfo = (context: BrowserContext, overrides: RelayInfoOverrides) => { const overrideByOrigin = new Map( Object.entries(overrides).map(([url, override]): [string, object] => [ relayOrigin(url), override, ]), ) return context.route( url => url.pathname === "/" && overrideByOrigin.has(url.origin), async route => { const request = route.request() const {origin} = new URL(request.url()) const host = hostByOrigin.get(origin) const override = overrideByOrigin.get(origin) // The nip-86 management api posts to this same path, and what it answers decides what the // admin ui offers, so only the document request is touched. if (request.method() === "GET" && host && override) { const {status, headers, body} = await requestZooid(host, "GET", "/", { ...request.headers(), // The merge has to read the document, and khatru will compress it if invited to. "accept-encoding": "identity", }) return route.fulfill({ status, // khatru's Access-Control-Allow-Origin is what makes the fetch legal, so the relay's own // headers are kept — all but the length of a body that is about to change. headers: omit(["content-length"], headers), body: JSON.stringify({...JSON.parse(body.toString()), ...override}), }) } return route.fallback() }, ) } /** * The analytics script src/app.html loads on every page. Answering with an empty body leaves * `window.plausible` as the queueing shim src/app/analytics.ts installs, so pageviews accumulate * in memory and nothing is ever sent — and `assertNoBlockedRequests` stays a statement about the * scenario rather than about the page shell. */ export const mockAnalytics = (context: BrowserContext) => context.route(`${PLAUSIBLE_ORIGIN}/**`, route => route.fulfill({contentType: "application/javascript", body: ""}), ) export type DufflepudFixtures = { // The remote half of the read-state sync in src/app/notifications.ts, keyed by path. checked?: Record // A link preview is only rendered when it carries a title or an image. preview?: {title?: string; description?: string; image?: string} handles?: {handle: string; info?: Handle}[] // `lnurl` is hex here, not bech32 — that's the encoding dufflepud speaks. zappers?: {lnurl: string; info?: Omit}[] } /** * Dufflepud, whose origin is the one service url the app hard-codes rather than reading from a * `VITE_` value. `as()` installs it with no fixtures, so a spec that needs one — a zapper for a zap * receipt, a link preview — calls this again with its own: playwright matches the most recently * registered route first, so the spec's answers win over the empty defaults. */ export const mockDufflepud = (context: BrowserContext, fixtures: DufflepudFixtures = {}) => context.route(`${DUFFLEPUD_ORIGIN}/**`, route => { const {pathname} = new URL(route.request().url()) if (pathname === "/link/preview") { return route.fulfill({json: fixtures.preview ?? {}}) } if (pathname === "/handle/info") { return route.fulfill({json: {data: fixtures.handles ?? []}}) } if (pathname === "/zapper/info") { return route.fulfill({json: {data: fixtures.zappers ?? []}}) } if (pathname === "/kv/checked") { return route.fulfill({ json: route.request().method() === "GET" ? (fixtures.checked ?? {}) : {}, }) } return route.fallback() }) export type BlossomOptions = { // The blossom server the scenario expects an upload to land on, e.g. a space's own url. server: string } /** * A blossom server that keeps what it was given: an upload is hashed exactly as the real thing * would be, so the descriptor it answers with points at a blob this mock can then serve back. */ export const mockBlossom = (context: BrowserContext, {server}: BlossomOptions) => { const {origin} = new URL(server) const blobs = new Map() return context.route(`${origin}/**`, route => { const request = route.request() const method = request.method() const {pathname} = new URL(request.url()) if (pathname === "/upload") { if (method === "HEAD") { return route.fulfill({status: 200, body: ""}) } if (method === "PUT") { const body = request.postDataBuffer() ?? Buffer.alloc(0) const type = request.headers()["content-type"] ?? "application/octet-stream" const sha256 = createHash("sha256").update(body).digest("hex") blobs.set(sha256, {body, type}) return route.fulfill({ json: {sha256, type, url: `${origin}/${sha256}`, size: body.length, uploaded: now()}, }) } } const blob = blobs.get(pathname.slice(1).split(".")[0]) if (blob) { return route.fulfill({ contentType: blob.type, body: method === "HEAD" ? "" : blob.body, }) } return route.fallback() }) } /** * The push server from src/app/push/adapters/capacitor.ts. Only the native adapters talk to it, * so a browser run reaches this only if the platform detection regresses. */ export const mockPushServer = (context: BrowserContext) => context.route(`${PUSH_SERVER_ORIGIN}/**`, route => { const [resource] = new URL(route.request().url()).pathname.split("/").filter(Boolean) if (resource === "subscription") { if (route.request().method() === "DELETE") { return route.fulfill({json: {}}) } // Registration is only usable if it comes back with both, and the relay is told to post // notifications to the callback rather than the client ever fetching it. const key = "test-push-subscription" return route.fulfill({json: {key, callback: `${PUSH_SERVER_ORIGIN}/callback/${key}`}}) } return route.fallback() }) // One record straight off the hosting api, whose shapes live in src/app/hosting.ts. They're left // as loose objects here so that mocking a payment flow doesn't pull the app's module graph — and // with it import.meta.env — into the node process. A relay record may also carry `members` and // `activity`, and an invoice `items` and `bolt11`, which is where those endpoints answer from. export type HostingRecord = Record // The backend's state when the page opens. Everything after that is what the app wrote, plus // whatever the handle below changed. export type HostingFixtures = { plans?: HostingRecord[] // Provisioning runs on every login and ignores what it gets back, so the empty default carries // any spec that isn't actually exercising the hosting ui. tenant?: HostingRecord relays?: HostingRecord[] invoices?: HostingRecord[] draftInvoice?: HostingRecord } // The backend changing its mind between two of the user's clicks — a custom domain that verifies, // an invoice that gets paid — which is the half of those flows no click can reach. export type HostingHandle = { setTenant(patch: HostingRecord): void setRelay(id: string, patch: HostingRecord): void setInvoice(id: string, patch: HostingRecord): void } const hostingByContext = new WeakMap() export const getHosting = (context: BrowserContext) => { const handle = hostingByContext.get(context) if (handle) { return handle } throw new Error("mockHosting was never called for this browser context") } /** * The hosting api as a small stateful fake: a write mutates the record it names and the next read * sees it, which is what makes editing a space's details, deactivating it, changing its plan or * saving a custom domain observable at all. Each browser context gets its own store, so one user's * spaces are not another's. */ export const mockHosting = async (context: BrowserContext, fixtures: HostingFixtures = {}) => { const plans = fixtures.plans ?? [] const relays = new Map((fixtures.relays ?? []).map(relay => [String(relay.id), relay])) const invoices = new Map((fixtures.invoices ?? []).map(invoice => [String(invoice.id), invoice])) let tenant: HostingRecord = { pubkey: "", return_url: "", nwc_is_set: false, stripe_customer_id: "", created_at: now(), ...fixtures.tenant, } const handle: HostingHandle = { setTenant: patch => { tenant = {...tenant, ...patch} }, setRelay: (id, patch) => { relays.set(id, {...relays.get(id), ...patch}) }, setInvoice: (id, patch) => { invoices.set(id, {...invoices.get(id), ...patch}) }, } hostingByContext.set(context, handle) await context.route(`${HOSTING_ORIGIN}/**`, route => { const request = route.request() const method = request.method() const body: HostingRecord = request.postDataJSON() ?? {} const [resource, id, sub, detail] = new URL(request.url()).pathname.split("/").filter(Boolean) const missing = (what: string) => route.fulfill({status: 404, json: {error: `No such ${what}`}}) if (resource === "plans") { return route.fulfill({json: {data: plans}}) } if (resource === "tenants") { // Provisioning is the one tenant route with no pubkey in the path. if (id) { tenant = {...tenant, pubkey: id} } else { tenant = {...tenant, ...body} return route.fulfill({json: {data: tenant}}) } if (sub === "relays") { return route.fulfill({json: {data: Array.from(relays.values())}}) } if (sub === "invoices") { const data = detail === "draft" ? fixtures.draftInvoice : Array.from(invoices.values()) return route.fulfill({json: {data}}) } if (sub === "stripe") { return route.fulfill({json: {data: {url: `${CHECKOUT_ORIGIN}/portal/${id}`}}}) } // A wallet is the only thing the app updates a tenant with, so saving one is what sets it. if (method === "PUT") { tenant = {...tenant, ...body, nwc_is_set: Boolean(body.nwc_url)} } // GET and reconcile both answer with the tenant as it now stands. return route.fulfill({json: {data: tenant}}) } if (resource === "relays") { if (!id) { const relay = { id: `relay-${relays.size + 1}`, status: "active", sync_error: "", synced: now(), custom_domain: "", custom_domain_verified: 0, ...body, // A created space is opened straight away, so its url has to be one the container // serves. The client names the domain from VITE_HOSTING_RELAY_DOMAIN. zooid_domain: body.zooid_domain || "test", } relays.set(String(relay.id), relay) return route.fulfill({json: {data: relay}}) } const relay = relays.get(id) if (!relay) { return missing(`relay ${id}`) } if (sub === "members") { return route.fulfill({json: {data: {members: relay.members ?? []}}}) } if (sub === "activity") { return route.fulfill({json: {data: {activity: relay.activity ?? []}}}) } const updated = {...relay, ...(method === "PUT" ? body : {})} if (sub === "deactivate") { updated.status = "inactive" } if (sub === "reactivate") { updated.status = "active" } relays.set(id, updated) return route.fulfill({json: {data: updated}}) } if (resource === "invoices") { const invoice = invoices.get(id) if (!invoice) { return missing(`invoice ${id}`) } if (sub === "items") { return route.fulfill({json: {data: invoice.items ?? []}}) } if (sub === "bolt11") { const bolt11 = invoice.bolt11 ?? { id: `bolt11-${id}`, invoice_id: id, lnbc: `lnbc${id}`, msats: 0, created_at: now(), expires_at: now() + int(1, HOUR), } return route.fulfill({json: {data: bolt11}}) } if (sub === "checkout") { return route.fulfill({json: {data: {url: `${CHECKOUT_ORIGIN}/invoices/${id}`}}}) } // GET and reconcile both answer with the invoice as it now stands, which is how a spec // marks one paid: flip `paid_at` with the handle and let the dialog's next poll find it. return route.fulfill({json: {data: invoice}}) } return route.fallback() }) return handle } export type LivekitOptions = { // Where the client is told to connect. Point it at something the test owns — the token this // hands out is accepted by nothing else. serverUrl: string token?: string } export const mockLivekit = (context: BrowserContext, {serverUrl, token}: LivekitOptions) => context.route( url => url.pathname.startsWith(LIVEKIT_PATH), route => { const roomId = new URL(route.request().url()).pathname.slice(LIVEKIT_PATH.length + 1) if (roomId) { return route.fulfill({ json: {server_url: serverUrl, participant_token: token ?? "test-participant-token"}, }) } // The support probe in src/lib/livekit.ts reads support off the status alone. return route.fulfill({status: 204, body: ""}) }, ) /** * Serves a png for anything the browser is loading as an image — avatars, banners, blossom blobs, * video posters — so a scenario's fixtures can reference urls without any of them being fetched. */ export const mockImages = (context: BrowserContext) => context.route( url => !isDevServerUrl(url), route => { if (route.request().resourceType() === "image") { return route.fulfill({contentType: "image/png", body: PNG}) } return route.fallback() }, )