using Microsoft.Extensions.Logging.Abstractions; using ZB.MOM.WW.ScadaBridge.SiteRuntime.Persistence; using ZB.MOM.WW.ScadaBridge.TestSupport; namespace ZB.MOM.WW.ScadaBridge.SiteRuntime.Tests.Persistence; /// /// WP-33: Local Artifact Storage tests — shared scripts, external systems, /// database connections, notification lists. /// /// /// Backed by a real temp-file LocalDb: takes an /// ILocalDb rather than a connection string, and LocalDb has no in-memory mode. /// public class ArtifactStorageTests : IAsyncLifetime, IDisposable { private readonly TestLocalDb _localDb; private SiteStorageService _storage = null!; public ArtifactStorageTests() { _localDb = TestLocalDb.CreateTemp("artifact-test"); } public async Task InitializeAsync() { _storage = new SiteStorageService( _localDb.Db, NullLogger.Instance); await _storage.InitializeAsync(); } public Task DisposeAsync() => Task.CompletedTask; public void Dispose() { // Dispose first — the master connection anchors the WAL, so the sidecars // cannot be removed while it is open. var path = _localDb.Path; _localDb.Dispose(); TestLocalDb.DeleteFiles(path); } // ── Shared Script Storage ── [Fact] public async Task StoreSharedScript_RoundTrips() { await _storage.StoreSharedScriptAsync("CalcAvg", "return 42;", "{}", "int"); var scripts = await _storage.GetAllSharedScriptsAsync(); Assert.Single(scripts); Assert.Equal("CalcAvg", scripts[0].Name); Assert.Equal("return 42;", scripts[0].Code); Assert.Equal("{}", scripts[0].ParameterDefinitions); Assert.Equal("int", scripts[0].ReturnDefinition); } [Fact] public async Task StoreSharedScript_Upserts_OnConflict() { await _storage.StoreSharedScriptAsync("CalcAvg", "return 1;", null, null); await _storage.StoreSharedScriptAsync("CalcAvg", "return 2;", "{\"x\":\"int\"}", "int"); var scripts = await _storage.GetAllSharedScriptsAsync(); Assert.Single(scripts); Assert.Equal("return 2;", scripts[0].Code); Assert.Equal("{\"x\":\"int\"}", scripts[0].ParameterDefinitions); } [Fact] public async Task StoreSharedScript_MultipleScripts() { await _storage.StoreSharedScriptAsync("Script1", "1", null, null); await _storage.StoreSharedScriptAsync("Script2", "2", null, null); await _storage.StoreSharedScriptAsync("Script3", "3", null, null); var scripts = await _storage.GetAllSharedScriptsAsync(); Assert.Equal(3, scripts.Count); } [Fact] public async Task StoreSharedScript_NullableFields() { await _storage.StoreSharedScriptAsync("Simple", "42", null, null); var scripts = await _storage.GetAllSharedScriptsAsync(); Assert.Single(scripts); Assert.Null(scripts[0].ParameterDefinitions); Assert.Null(scripts[0].ReturnDefinition); } // ── External System Storage ── [Fact] public async Task StoreExternalSystem_DoesNotThrow() { await _storage.StoreExternalSystemAsync( "WeatherAPI", "https://api.weather.com", "ApiKey", "{\"key\":\"abc\"}", "{\"getForecast\":{}}"); // No exception = success. Query verification would need a Get method. } [Fact] public async Task StoreExternalSystem_Upserts() { await _storage.StoreExternalSystemAsync("API1", "https://v1", "Basic", null, null); await _storage.StoreExternalSystemAsync("API1", "https://v2", "ApiKey", "{}", null); // Upsert should not throw } // ── Database Connection Storage ── [Fact] public async Task StoreDatabaseConnection_DoesNotThrow() { await _storage.StoreDatabaseConnectionAsync( "MainDB", "Server=localhost;Database=main", 3, TimeSpan.FromSeconds(1)); } [Fact] public async Task StoreDatabaseConnection_Upserts() { await _storage.StoreDatabaseConnectionAsync( "DB1", "Server=old", 3, TimeSpan.FromSeconds(1)); await _storage.StoreDatabaseConnectionAsync( "DB1", "Server=new", 5, TimeSpan.FromSeconds(2)); // Upsert should not throw } // ── Artifact set reconciliation ── // // Central always ships the COMPLETE system-wide set of each artifact class, so a // stored row absent from the incoming set was deleted centrally. The store methods // are upsert-only; without these deletes a centrally-deleted external system (or // shared script / DB connection / data connection) stayed orphaned on the site // forever and remained callable from site scripts. [Fact] public async Task DeleteSharedScriptsExcept_RemovesOrphans_KeepsPresent() { await _storage.StoreSharedScriptAsync("Keep1", "1", null, null); await _storage.StoreSharedScriptAsync("Keep2", "2", null, null); await _storage.StoreSharedScriptAsync("Orphan", "3", null, null); var removed = await _storage.DeleteSharedScriptsExceptAsync(["Keep1", "Keep2"]); Assert.Equal(["Orphan"], removed); var names = (await _storage.GetAllSharedScriptsAsync()).Select(s => s.Name).Order().ToList(); Assert.Equal(["Keep1", "Keep2"], names); } [Fact] public async Task DeleteExternalSystemsExcept_RemovesOrphans_KeepsPresent() { await _storage.StoreExternalSystemAsync("MES", "https://mes", "ApiKey", null, null); await _storage.StoreExternalSystemAsync("Deleted", "https://old", "Basic", null, null); var removed = await _storage.DeleteExternalSystemsExceptAsync(["MES"]); Assert.Equal(["Deleted"], removed); Assert.Equal(["MES"], await TableNamesAsync("external_systems")); } [Fact] public async Task DeleteDatabaseConnectionsExcept_EmptyKeepSet_DeletesAll() { await _storage.StoreDatabaseConnectionAsync("DB1", "Server=a", 3, TimeSpan.FromSeconds(1)); await _storage.StoreDatabaseConnectionAsync("DB2", "Server=b", 3, TimeSpan.FromSeconds(1)); // An empty full set is legitimate: central saying no DB connections exist anymore. var removed = await _storage.DeleteDatabaseConnectionsExceptAsync([]); Assert.Equal(["DB1", "DB2"], removed.Order().ToList()); Assert.Empty(await TableNamesAsync("database_connections")); } [Fact] public async Task DeleteDataConnectionDefinitionsExcept_RemovesOrphans_KeepsPresent() { await _storage.StoreDataConnectionDefinitionAsync("PlcA", "OpcUa", "{}"); await _storage.StoreDataConnectionDefinitionAsync("Gone", "OpcUa", "{}"); var removed = await _storage.DeleteDataConnectionDefinitionsExceptAsync(["PlcA"]); Assert.Equal(["Gone"], removed); var names = (await _storage.GetAllDataConnectionDefinitionsAsync()).Select(d => d.Name).ToList(); Assert.Equal(["PlcA"], names); } [Fact] public async Task DeleteRowsExcept_NoOrphans_ReturnsEmpty_AndIsIdempotent() { await _storage.StoreExternalSystemAsync("MES", "https://mes", "ApiKey", null, null); Assert.Empty(await _storage.DeleteExternalSystemsExceptAsync(["MES"])); Assert.Empty(await _storage.DeleteExternalSystemsExceptAsync(["MES"])); Assert.Equal(["MES"], await TableNamesAsync("external_systems")); } private async Task> TableNamesAsync(string table) { await using var connection = _storage.CreateConnection(); await using var command = connection.CreateCommand(); command.CommandText = $"SELECT name FROM {table} ORDER BY name"; var names = new List(); await using var reader = await command.ExecuteReaderAsync(); while (await reader.ReadAsync()) names.Add(reader.GetString(0)); return names; } // ── DeploymentManager-025 / SiteRuntime-031: central-only notif/SMTP purge ── // // Notification config is central-only. The site-side write paths and // SiteNotificationRepository were removed 2026-07-10 (arch-review 08 §1.3/#23); // PurgeCentralOnlyNotificationConfigAsync is retained as the security cleanup for // DBs written by older builds. These tests seed the (still-present) tables via raw // SQL — the only way rows can now exist — and assert the purge empties them. private async Task SeedNotificationRowAsync(string name, string emailsJson) { // Seeded through the service's own (already-open) LocalDb connection — a raw // SqliteConnection would lack the pragmas and the zb_hlc_next() UDF the site // tables' capture triggers call. await using var connection = _storage.CreateConnection(); await using var command = connection.CreateCommand(); command.CommandText = "INSERT INTO notification_lists (name, recipient_emails, updated_at) VALUES (@n, @e, @u)"; command.Parameters.AddWithValue("@n", name); command.Parameters.AddWithValue("@e", emailsJson); command.Parameters.AddWithValue("@u", DateTimeOffset.UtcNow.ToString("O")); await command.ExecuteNonQueryAsync(); } private async Task SeedSmtpRowAsync(string name, string password) { await using var connection = _storage.CreateConnection(); await using var command = connection.CreateCommand(); command.CommandText = @"INSERT INTO smtp_configurations (name, server, port, auth_mode, from_address, username, password, oauth_config, updated_at) VALUES (@n, 'smtp.example.com', 587, 'BasicAuth', 'noreply@example.com', 'smtpuser', @p, NULL, @u)"; command.Parameters.AddWithValue("@n", name); command.Parameters.AddWithValue("@p", password); command.Parameters.AddWithValue("@u", DateTimeOffset.UtcNow.ToString("O")); await command.ExecuteNonQueryAsync(); } private async Task RowCountAsync(string table) { await using var connection = _storage.CreateConnection(); await using var command = connection.CreateCommand(); command.CommandText = $"SELECT COUNT(*) FROM {table}"; return (long)(await command.ExecuteScalarAsync())!; } [Fact] public async Task PurgeCentralOnlyNotificationConfig_RemovesPersistedNotificationListsAndSmtpRows() { // Simulate a pre-fix build that already shipped a notification list and an // SMTP config (with a plaintext password) to the site. await SeedNotificationRowAsync("Ops Team", "[\"ops@example.com\"]"); await SeedSmtpRowAsync("smtp.example.com:587", "PLAINTEXT-SECRET"); Assert.Equal(1, await RowCountAsync("notification_lists")); Assert.Equal(1, await RowCountAsync("smtp_configurations")); // The fix: every artifact apply/deploy purges these central-only rows. await _storage.PurgeCentralOnlyNotificationConfigAsync(); // Both tables are now empty — the plaintext SMTP credential is gone. Assert.Equal(0, await RowCountAsync("notification_lists")); Assert.Equal(0, await RowCountAsync("smtp_configurations")); } [Fact] public async Task PurgeCentralOnlyNotificationConfig_IsIdempotent_OnEmptyTables() { // No rows present — purge must not throw and must leave the tables empty. await _storage.PurgeCentralOnlyNotificationConfigAsync(); await _storage.PurgeCentralOnlyNotificationConfigAsync(); Assert.Equal(0, await RowCountAsync("notification_lists")); Assert.Equal(0, await RowCountAsync("smtp_configurations")); } // ── Schema includes all WP-33 tables ── [Fact] public async Task Initialize_CreatesAllArtifactTables() { // The initialize already ran. Verify by storing to each table. await _storage.StoreSharedScriptAsync("s", "code", null, null); await _storage.StoreExternalSystemAsync("e", "url", "None", null, null); await _storage.StoreDatabaseConnectionAsync("d", "connstr", 1, TimeSpan.Zero); // notification_lists / smtp_configurations remain in the schema (kept for the // security purge) — their presence is exercised by the purge tests above. // All succeeded without exceptions = tables exist } }