trails/e2e/integration.test.ts
Ullrich Schäfer ed7f6ce153
Session-bind /api/route and /api/overpass
Today both proxies are effectively open to anyone who can set an
Origin header for trails.cool — a third party can use us as a free
BRouter/Overpass relay. Require a live planner session on every call
so abuse traffic costs the scraper a session row (observable,
revocable) before they can issue a single query.

Server:
- New `requireSession(id)` helper — returns the session row or a 401
  Response. Reused by both route handlers.
- `/api/route`: `sessionId` in body is now required and verified;
  rate-limit key always falls back to the session id.
- `/api/overpass`: new `X-Trails-Session` header, verified. Header
  keeps the session out of the request body so the body-keyed cache
  is unaffected.

Client plumbing:
- `useRouting(yjs, sessionId)` — sessionId goes into the /api/route
  body.
- `usePois(sessionId)` → `queryPois(..., sessionId)` → `X-Trails-Session`
  on the proxy call.
- `PlannerMap` + `YjsDebugPanel` gain a `sessionId` prop from
  `SessionView`.

Journal server-to-server:
- Demo-bot and `/api/v1/routes/compute` now POST `/api/sessions` to
  mint a throwaway planner session, then cite it on the forwarded
  `/api/route` call. Planner's `expire-sessions` cron cleans these up
  (7d window) so nothing needs explicit teardown.

Tests:
- 5 unit tests for `requireSession` covering missing / empty /
  non-string / unknown-session / valid-session cases.
- Two integration E2E tests document the 401 for missing session on
  each proxy.
- Pre-existing `/api/route` integration tests updated to mint a
  session first.

Caveat: existing browser tabs lose their /api/route ability until
reload (the old JS doesn't know to send sessionId). Acceptable for
an anonymous planner.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-21 22:18:45 +02:00

219 lines
7.6 KiB
TypeScript

import { test, expect } from "./fixtures/test";
/**
* Integration tests that require the full dev stack:
* - PostgreSQL (for sessions)
* - BRouter (for route computation)
*
* In CI, these services are started by the workflow.
* Locally, run `pnpm dev:full` first.
*/
const PLANNER = "http://localhost:3001";
test.describe("Integration: Journal ↔ Planner handoff", () => {
test("GPX import → view route → export GPX", async ({ request }) => {
const gpx = `<?xml version="1.0" encoding="UTF-8"?>
<gpx version="1.1" creator="test" xmlns="http://www.topografix.com/GPX/1/1">
<wpt lat="52.52" lon="13.405"><name>Berlin</name></wpt>
<wpt lat="52.50" lon="13.35"><name>Tiergarten</name></wpt>
<trk><trkseg>
<trkpt lat="52.52" lon="13.405"><ele>34</ele></trkpt>
<trkpt lat="52.51" lon="13.38"><ele>40</ele></trkpt>
<trkpt lat="52.50" lon="13.35"><ele>35</ele></trkpt>
</trkseg></trk>
</gpx>`;
const sessionResp = await request.post(`${PLANNER}/api/sessions`, {
data: { gpx },
});
expect(sessionResp.ok()).toBeTruthy();
const session = await sessionResp.json();
expect(session.initialWaypoints).toHaveLength(2);
expect(session.initialWaypoints[0].name).toBe("Berlin");
});
test("GPX import with overnight waypoints preserves isDayBreak", async ({ request }) => {
const gpx = `<?xml version="1.0" encoding="UTF-8"?>
<gpx version="1.1" creator="test" xmlns="http://www.topografix.com/GPX/1/1">
<wpt lat="52.52" lon="13.405"><name>Berlin</name></wpt>
<wpt lat="51.84" lon="12.243"><name>Dessau</name><type>overnight</type></wpt>
<wpt lat="50.98" lon="11.028"><name>Erfurt</name></wpt>
<trk><trkseg>
<trkpt lat="52.52" lon="13.405"><ele>34</ele></trkpt>
<trkpt lat="51.84" lon="12.243"><ele>80</ele></trkpt>
<trkpt lat="50.98" lon="11.028"><ele>195</ele></trkpt>
</trkseg></trk>
</gpx>`;
const sessionResp = await request.post(`${PLANNER}/api/sessions`, {
data: { gpx },
});
expect(sessionResp.ok()).toBeTruthy();
const session = await sessionResp.json();
expect(session.initialWaypoints).toHaveLength(3);
expect(session.initialWaypoints[1].name).toBe("Dessau");
// isDayBreak should be preserved through GPX parsing
expect(session.initialWaypoints[1].isDayBreak).toBe(true);
});
});
test.describe("Integration: BRouter routing", () => {
// Helper: mint a planner session so our /api/route calls satisfy
// the session-bound gate introduced alongside this test file.
async function createSessionId(
request: import("@playwright/test").APIRequestContext,
): Promise<string> {
const resp = await request.post(`${PLANNER}/api/sessions`, { data: {} });
const payload = (await resp.json()) as { sessionId: string };
return payload.sessionId;
}
test("computes route between Berlin waypoints", async ({ request }) => {
const sessionId = await createSessionId(request);
const response = await request.post(`${PLANNER}/api/route`, {
data: {
waypoints: [
{ lat: 52.516, lon: 13.377 },
{ lat: 52.515, lon: 13.351 },
],
profile: "trekking",
sessionId,
},
});
expect(response.ok()).toBeTruthy();
const enriched = await response.json();
expect(enriched.geojson.features).toHaveLength(1);
expect(enriched.geojson.features[0].geometry.type).toBe("LineString");
expect(enriched.coordinates.length).toBeGreaterThan(10);
});
test("routes through all waypoints (segment by segment)", async ({ request }) => {
const sessionId = await createSessionId(request);
const response = await request.post(`${PLANNER}/api/route`, {
data: {
waypoints: [
{ lat: 52.520, lon: 13.405 },
{ lat: 52.516, lon: 13.377 },
{ lat: 52.510, lon: 13.390 },
],
profile: "trekking",
sessionId,
},
});
expect(response.ok()).toBeTruthy();
const enriched = await response.json();
const coords = enriched.coordinates;
const nearMiddle = coords.some(
(c: number[]) =>
Math.abs(c[1] - 52.516) < 0.005 && Math.abs(c[0] - 13.377) < 0.005,
);
expect(nearMiddle).toBeTruthy();
});
test("returns rate limit headers", async ({ request }) => {
const sessionId = await createSessionId(request);
const response = await request.post(`${PLANNER}/api/route`, {
data: {
waypoints: [
{ lat: 52.516, lon: 13.377 },
{ lat: 52.515, lon: 13.351 },
],
sessionId,
},
});
expect(response.headers()["x-ratelimit-remaining"]).toBeDefined();
});
test("rejects with fewer than 2 waypoints", async ({ request }) => {
const sessionId = await createSessionId(request);
const response = await request.post(`${PLANNER}/api/route`, {
data: {
waypoints: [{ lat: 52.516, lon: 13.377 }],
sessionId,
},
});
expect(response.status()).toBe(400);
});
test("returns enriched route with segment boundaries", async ({ request }) => {
const sessionId = await createSessionId(request);
const response = await request.post(`${PLANNER}/api/route`, {
data: {
waypoints: [
{ lat: 52.520, lon: 13.405 },
{ lat: 52.516, lon: 13.377 },
{ lat: 52.510, lon: 13.390 },
],
profile: "trekking",
sessionId,
},
});
expect(response.ok()).toBeTruthy();
const enriched = await response.json();
// EnrichedRoute fields
expect(enriched.coordinates).toBeDefined();
expect(enriched.coordinates.length).toBeGreaterThan(10);
expect(enriched.coordinates[0]).toHaveLength(3); // [lon, lat, ele]
expect(enriched.segmentBoundaries).toBeDefined();
expect(enriched.segmentBoundaries).toHaveLength(2); // 3 waypoints = 2 segments
expect(enriched.segmentBoundaries[0]).toBe(0);
expect(enriched.totalLength).toBeGreaterThan(0);
expect(enriched.geojson).toBeDefined();
expect(enriched.geojson.features[0].geometry.type).toBe("LineString");
});
test("accepts no-go areas parameter", async ({ request }) => {
const sessionId = await createSessionId(request);
const response = await request.post(`${PLANNER}/api/route`, {
data: {
waypoints: [
{ lat: 52.516, lon: 13.377 },
{ lat: 52.515, lon: 13.351 },
],
profile: "trekking",
sessionId,
noGoAreas: [
{
points: [
{ lat: 52.516, lon: 13.365 },
{ lat: 52.514, lon: 13.365 },
{ lat: 52.514, lon: 13.370 },
{ lat: 52.516, lon: 13.370 },
],
},
],
},
});
expect(response.ok()).toBeTruthy();
const enriched = await response.json();
expect(enriched.geojson.features).toHaveLength(1);
expect(enriched.geojson.features[0].geometry.type).toBe("LineString");
});
test("rejects /api/route without a sessionId (session-bound)", async ({ request }) => {
const response = await request.post(`${PLANNER}/api/route`, {
data: {
waypoints: [
{ lat: 52.516, lon: 13.377 },
{ lat: 52.515, lon: 13.351 },
],
profile: "trekking",
},
});
expect(response.status()).toBe(401);
});
test("rejects /api/overpass without an X-Trails-Session header", async ({ request }) => {
const response = await request.post(`${PLANNER}/api/overpass`, {
data: "data=[out:json];node[amenity=drinking_water](52.52,13.4,52.53,13.41);out;",
headers: {
"Content-Type": "application/x-www-form-urlencoded",
Origin: PLANNER,
},
});
expect(response.status()).toBe(401);
});
});