import { describe, expect, it } from "vitest"; import { createRedirectLoopGuard, decideRouteAccess, } from "../../src/presentation/routes/navigation-policy.js"; import { ROUTE_REGISTRY } from "../../src/contracts/routes.js"; describe("route registry", () => { it("matches the stable registry snapshot", () => { expect(ROUTE_REGISTRY).toMatchInlineSnapshot(` { "APP_HOME": { "access": "public", "chunkId": "route-home", "errorSurface": "route-boundary", "loadingSurface": "app-shell", "paramsSchema": null, "path": "/", "routeId": "APP_HOME", "searchSchema": null, }, "NOT_FOUND": { "access": "public", "chunkId": "route-not-found", "errorSurface": "not-found", "loadingSurface": "none", "paramsSchema": null, "path": "*", "routeId": "NOT_FOUND", "searchSchema": null, }, "SAMPLE_RESOURCE_LIST": { "access": "integration-defined", "chunkId": "route-sample-resources", "errorSurface": "feature-boundary", "loadingSurface": "sample-resource-list", "paramsSchema": null, "path": "/sample/resources", "routeId": "SAMPLE_RESOURCE_LIST", "searchSchema": "SampleResourceListQuery", }, } `); }); it("treats client access as a UX hint, not authorization", () => { expect(decideRouteAccess("APP_HOME", "unauthenticated")).toEqual({ allowed: true, action: "none", }); expect(decideRouteAccess("SAMPLE_RESOURCE_LIST", "unauthenticated")).toEqual({ allowed: false, action: "show-sign-in", }); expect(decideRouteAccess("SAMPLE_RESOURCE_LIST", "authenticated")).toEqual({ allowed: true, action: "none", }); }); it("allows at most one automatic redirect per source-target pair", () => { const guard = createRedirectLoopGuard(); expect(guard.allow("/private", "/signin")).toBe(true); expect(guard.allow("/private", "/signin")).toBe(false); expect(guard.allow("/signin", "/signin")).toBe(false); }); });