import { NextResponse } from "next/server"; import { afterEach, beforeEach, describe, expect, it, vi } from "vitest"; const createMiddlewareMock = vi.fn(); const intlHandlerMock = vi.fn(() => NextResponse.next()); vi.mock("next-intl/middleware", () => ({ default: createMiddlewareMock, })); vi.mock("../lib/admin-routing", () => ({ fromDevelopmentAdminPath: (pathname: string) => pathname, getAdminBaseUrl: () => "https://admin.example.com", getRequestHostname: (_forwardedHost: string | null, host: string | null, hostname: string) => host ?? hostname, isDevelopmentAdminPath: () => false, isAdminHost: () => false, hasDedicatedAdminHost: () => false, isInternalAdminPath: () => false, isLegacyAdminPath: () => false, toInternalAdminPath: (pathname: string) => pathname, })); function createMockRequest(url: string, cookieValue?: string) { const nextUrl = new URL(url) as URL & { clone: () => URL }; nextUrl.clone = () => new URL(nextUrl.toString()); return { url, nextUrl, headers: new Headers({ host: nextUrl.host, }), cookies: { has: vi.fn(() => cookieValue !== undefined), get: vi.fn(() => (cookieValue !== undefined ? { name: "moh_admin_session", value: cookieValue } : undefined)), }, }; } function stubMaintenanceRuntime() { vi.stubGlobal( "fetch", vi.fn(async () => ({ ok: true, json: async () => ({ defaultLocale: "de", maintenanceEnabled: true, }), })), ); } describe("middleware locale runtime config", () => { beforeEach(() => { vi.resetModules(); vi.stubEnv("NODE_ENV", "production"); delete process.env.SITE_RUNTIME_ORIGIN; createMiddlewareMock.mockReset(); intlHandlerMock.mockReset(); intlHandlerMock.mockReturnValue(NextResponse.next()); createMiddlewareMock.mockReturnValue(intlHandlerMock); }); afterEach(() => { vi.unstubAllGlobals(); vi.unstubAllEnvs(); }); it("passes the runtime default locale into next-intl middleware", async () => { vi.stubGlobal( "fetch", vi.fn(async () => ({ ok: true, json: async () => ({ defaultLocale: "ar", maintenanceEnabled: false, }), })), ); const { default: middleware } = await import("../proxy"); const request = createMockRequest("https://example.com/"); await middleware(request as never); expect(fetch).toHaveBeenCalledWith( new URL("http://127.0.0.1:3000/api/site/default-locale"), expect.any(Object), ); expect(createMiddlewareMock).toHaveBeenCalledTimes(1); expect(createMiddlewareMock).toHaveBeenCalledWith( expect.objectContaining({ defaultLocale: "ar", }), ); expect(intlHandlerMock).toHaveBeenCalledTimes(1); }); it("falls back safely when the runtime locale lookup fails", async () => { vi.stubGlobal( "fetch", vi.fn(async () => { throw new Error("network failed"); }), ); const { default: middleware } = await import("../proxy"); const request = createMockRequest("https://example.com/"); await middleware(request as never); expect(createMiddlewareMock).toHaveBeenCalledWith( expect.objectContaining({ defaultLocale: "de", }), ); }); it("redirects maintenance traffic using the runtime default locale", async () => { vi.stubGlobal( "fetch", vi.fn(async () => ({ ok: true, json: async () => ({ defaultLocale: "ar", maintenanceEnabled: true, }), })), ); const { default: middleware } = await import("../proxy"); const request = createMockRequest("https://example.com/"); const response = await middleware(request as never); expect(response.headers.get("location")).toBe("https://example.com/coming-soon"); expect(intlHandlerMock).not.toHaveBeenCalled(); }); it("does not let a forged admin cookie bypass maintenance mode", async () => { vi.stubEnv("ADMIN_AUTH_SECRET", "test-secret"); stubMaintenanceRuntime(); const { default: middleware } = await import("../proxy"); const response = await middleware(createMockRequest("https://example.com/about", "superadmin.forged") as never); expect(response.headers.get("location")).toBe("https://example.com/coming-soon"); expect(intlHandlerMock).not.toHaveBeenCalled(); }); it("lets a correctly signed admin cookie through maintenance mode", async () => { vi.stubEnv("ADMIN_AUTH_SECRET", "test-secret"); stubMaintenanceRuntime(); const { buildAdminSessionToken } = await import("../lib/admin-session-token"); const { default: middleware } = await import("../proxy"); await middleware(createMockRequest("https://example.com/about", buildAdminSessionToken()) as never); expect(intlHandlerMock).toHaveBeenCalledTimes(1); }); it("prefers the configured internal runtime origin when provided", async () => { process.env.SITE_RUNTIME_ORIGIN = "http://app:3000"; vi.stubGlobal( "fetch", vi.fn(async () => ({ ok: true, json: async () => ({ defaultLocale: "en", maintenanceEnabled: false, }), })), ); const { default: middleware } = await import("../proxy"); const request = createMockRequest("https://example.com/"); await middleware(request as never); expect(fetch).toHaveBeenCalledWith( new URL("http://app:3000/api/site/default-locale"), expect.any(Object), ); }); });