Files
Aether/apps/aether-gateway/tests/architecture/admin_users.rs
T
AAEE86 3394a51278 ci(gateway): slim Test (Gateway) batch 1 — split architecture guards, pin build fingerprint
第一批减负(对应 docs/operations/gateway-ci-timeout-reduction-plan.md):

A1 架构守卫迁出
- 将 src/tests/architecture/**(208 项 / 约 1.5 万行字符串断言)迁至
  tests/architecture/,入口 tests/architecture_guard.rs
- 从 lib cfg(test) 巨型编译单元移除,压低 rustc 峰值与 OOM 风险
- 断言逻辑不变;helper 可见性改为 pub(crate)

A2 构建指纹统一
- test_gateway 的 mold RUSTFLAGS / RUST_MIN_STACK / sccache 上移至 job 级 env
- rust-ci.yml 全部 toolchain 钉住 1.95.0(与 rust-toolchain.toml、fmt/clippy 一致)
- Gateway 独立 cache key,避免 mold 指纹与无 mold job 互相污染

A4 补安全集成测试
- 新增 Test integration targets:cargo nextest run -p aether-gateway --tests
- 覆盖 architecture_guard + 此前未执行的 admin_unsigned_identity_headers

验证:architecture_guard + admin_unsigned 209 passed;
cargo check -p aether-gateway --lib --tests 通过;cargo fmt --check 通过。

不创建 PR,仅本地分支提交。
2026-09-23 17:51:45 +08:00

59 lines
1.8 KiB
Rust

use super::{read_workspace_file, workspace_file_exists};
#[test]
fn admin_users_lifecycle_mod_stays_thin() {
let lifecycle_mod =
read_workspace_file("apps/aether-gateway/src/handlers/admin/users/lifecycle/mod.rs");
for pattern in [
"mod create;",
"mod delete;",
"mod reads;",
"mod support;",
"mod update;",
] {
assert!(
lifecycle_mod.contains(pattern),
"users/lifecycle/mod.rs should keep explicit owner seam {pattern}"
);
}
assert!(
!workspace_file_exists("apps/aether-gateway/src/handlers/admin/users/lifecycle/core.rs"),
"users/lifecycle/core.rs should be removed once lifecycle is split into explicit owners"
);
}
#[test]
fn admin_users_api_key_responses_mod_stays_wrapped() {
let responses_mod = read_workspace_file(
"apps/aether-gateway/src/handlers/admin/users/api_keys/responses/mod.rs",
);
for pattern in [
"mod create;",
"mod delete;",
"mod list;",
"mod reveal;",
"mod toggle_lock;",
"mod update;",
"pub(in super::super::super) use create::build_admin_create_user_api_key_response;",
"pub(in super::super::super) use update::build_admin_update_user_api_key_response;",
] {
assert!(
responses_mod.contains(pattern),
"users/api_keys/responses/mod.rs should keep wrapped response seam {pattern}"
);
}
for forbidden in [
"pub mod create;",
"pub mod delete;",
"pub mod list;",
"pub mod reveal;",
"pub mod toggle_lock;",
"pub mod update;",
] {
assert!(
!responses_mod.contains(forbidden),
"users/api_keys/responses/mod.rs should not expose raw public response module seam {forbidden}"
);
}
}