import { beforeEach, describe, expect, it, vi } from "vitest"; const publishDeploymentStatus = vi.fn(); vi.mock("@/lib/deployment/repository", () => ({ publishDeploymentStatus })); const { POST } = await import("./route"); const deploymentId = "a".repeat(40); function request(body: unknown, authorization?: string) { return new Request("https://guide.sudloh.com/api/deployments/status", { method: "POST", headers: { "Content-Type": "application/json", ...(authorization ? { Authorization: authorization } : {}), }, body: JSON.stringify(body), }); } describe("deployment status webhook", () => { beforeEach(() => { process.env.DEPLOYMENT_WEBHOOK_SECRET = "test-deployment-secret"; publishDeploymentStatus.mockReset(); publishDeploymentStatus.mockResolvedValue({ accepted: true, event: { deploymentId, status: "deploying", updatedAt: "2026-09-26T12:00:00.000Z", }, }); }); it("rejects missing or incorrect credentials", async () => { expect((await POST(request({ deploymentId, status: "deploying" }))).status).toBe(401); expect((await POST(request( { deploymentId, status: "deploying" }, "Bearer incorrect", ))).status).toBe(401); expect(publishDeploymentStatus).not.toHaveBeenCalled(); }); it("rejects invalid lifecycle payloads", async () => { const response = await POST(request( { deploymentId: "short", status: "unknown" }, "Bearer test-deployment-secret", )); expect(response.status).toBe(400); expect(publishDeploymentStatus).not.toHaveBeenCalled(); }); it("publishes an authenticated lifecycle update", async () => { const response = await POST(request( { deploymentId, status: "deploying" }, "Bearer test-deployment-secret", )); expect(response.status).toBe(202); expect(publishDeploymentStatus).toHaveBeenCalledWith(deploymentId, "deploying"); }); });