Files
silo-server/internal/audiobooks/abs/collections_handler_test.go
eb6024573e feat(audiobooks): make audiobook libraries first-class catalog items (#73)
* docs(audiobooks): design spec for plugin absorption

Plan to absorb silo-plugin-audiobooks into silo-server as a first-party
feature. Audiobooks land in silo's existing SPA; ABS clients connect
directly. Hard constraints: reuse existing tables (media_items,
media_files, user_watch_progress, user_playback_sessions, people,
item_people, library_collections); only two new tables (abs_sessions,
podcast_feeds) and at most one column add (media_libraries.kind);
silo's main :8080 listener handles ABS Socket.io natively. Out of
scope: audiobook requests flow, smart collections, share links,
external recommender, custom metadata providers, separate audiobook
SPA.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audiobooks): implementation plan sub-plan 1 (discovery + schema)

First of six sub-plans for the absorption. Six tasks: a discovery
audit that resolves the spec's Risk questions, four idempotent SQL
migrations (abs_sessions, podcast_feeds, media_libraries.kind,
audiobooks.enabled feature flag), and an empty-but-compiling
internal/audiobooks package scaffolded into cmd/silo. Lands as a
strict no-op for users (feature flag defaults to false).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audiobooks): discovery findings for absorption sub-plan 1

Locks schema/code decisions for migrations 139-142 and downstream
sub-plans. Resolves open Risk questions from the absorption design spec.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(audiobooks): migration 139 add abs_sessions table

Parallel of jellycompat_sessions for Audiobookshelf-compatible clients.
Lets ABS mobile/desktop apps maintain a device-bound session that
silo's audiobooks/abs handlers will validate.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* style(audiobooks): match codebase conventions in migration 139

Lowercases type keywords in the abs_sessions CREATE TABLE body to
match neighboring migrations, fixes the client_version column
alignment, and replaces the misleading "parallel to
jellycompat_sessions" header comment with a more accurate
description of the table's role.

Cosmetic only — the running schema is unchanged.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(audiobooks): migration 140 add podcast_feeds table

Side table on media_items for RSS-subscribed podcasts. Holds feed URL,
ETag/Last-Modified for conditional fetches, last-refresh timestamp, and
the per-feed refresh interval consumed by the upcoming
podcastfeed.Refresher scheduled task.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* style(audiobooks): uppercase PRIMARY KEY in migration 140

Aligns with the codebase convention (type keywords lowercase,
constraint keywords uppercase) established in migration 139's
post-style-fix form. Cosmetic only — running schema is unchanged.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* chore(audiobooks): migration 141 no-op for media_folders.type

Sub-plan 1 originally reserved migration 141 to add a 'kind' column to
media_libraries discriminating audiobook/podcast libraries. Discovery
audit (sub-plan 1 Task 1) found that the actual table is media_folders
and it already has a type text NOT NULL column with no CHECK constraint
or enum, so 'audiobooks' and 'podcasts' can be added as future values
without DDL.

Landing this migration as a documented no-op preserves the version
numbering audit trail and pins the decision in git history. The
matching down migration is also a no-op.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(audiobooks): migration 142 add audiobooks.enabled flag

Server-settings row that gates the absorbed audiobooks feature.
Defaults to 'false' so sub-plan 1 lands as a strict no-op; subsequent
sub-plans branch on this flag and operators flip it to 'true' at
cutover.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(audiobooks): scaffold internal/audiobooks package

Empty-but-compiling Service that reads the audiobooks.enabled feature
flag from server_settings. Wired into cmd/silo so the package is
referenced from the binary; no routes mounted, no scheduled tasks
registered, no DB writes. Subsequent sub-plans hang scanner branches,
ABS handlers, Socket.io, podcast refresher, and SPA pages off this
Service.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* style(audiobooks): cosmetic cleanups in scaffolded package

Two pre-emptive cleanups flagged by code review before sub-plan 2
copies the patterns:

  1. Sort the internal/audiobooks import after internal/adminjob in
     cmd/silo/main.go (alphabetical).
  2. Drop the redundant "audiobooks: " prefix from the Enabled() error
     wrap; matches how every other top-level service package
     (watchstate, scanqueue, metadata, etc.) formats errors.

No behavior change.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audiobooks): implementation plan sub-plan 2 (scanner)

Second of six sub-plans. 10 tasks: PersonKind constants for Author and
Narrator, audio-extension recognizer, library-type helpers, a
walkLogicalTree refactor (movieLibrary bool -> typed walkMode), chapter
extraction via ffprobe, single-file and multi-file audiobook parsers,
scanner write path producing media_items.type='audiobook', and a
filesystem podcast parser (RSS deferred to sub-plan 5).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(audiobooks): add Author and Narrator PersonKind constants

Discovery audit confirmed item_people.kind is unconstrained smallint
with values 1-6 in use. Reserve 7 = Author, 8 = Narrator for audiobook
people-links written by the upcoming scanner branches.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(audiobooks): add audio-extension recognizer for scanner

Mirrors the existing videoExtensions/SupportsVideoFile pair. Used by
upcoming audiobook and podcast scanner branches to filter directory
walks.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(audiobooks): library-type recognizers for scanner dispatch

isAudiobookLibraryType and isPodcastLibraryType match singular and
plural forms case-insensitively, mirroring isMovieLibraryType. Used by
upcoming scanner walk branches (Task 4) that filter audio files into
audiobook and podcast libraries.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* refactor(scanner): replace movieLibrary bool with typed walkMode

Lets walkLogicalTree dispatch on multiple library shapes (video, movie,
audiobook, podcast) without proliferating boolean flags. Behavior for
existing video and movie libraries is unchanged; audiobook and podcast
modes will be consumed by the upcoming audiobook.go and podcast.go
parsers in later tasks of this sub-plan.

walkModeFor() derives the mode from a media_folders.type string;
unknown types default to walkModeVideo to preserve prior behavior for
any caller still passing a raw type.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(audiobooks): expose ffprobe format tags on ProbeData

The audiobook scanner needs format-level tags (title, artist, album,
date) for media_items metadata; ffprobe already parses them in
ffprobeFormat.Tags but ProbeData previously discarded them. Add
FormatTags map[string]string to ProbeData, populate it in
convertProbeData via a new normalizeFormatTags helper that lowercases
keys and trims values.

Adds a fixture audiobook .m4b with embedded chapters (Intro/Outro) and
format tags, and a test that verifies ProbeFile() returns both
correctly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(audiobooks): parser for single-file audiobook folders

parseAudiobookFolder reads tags + chapters via the existing ProbeFile
(now that Task 5 exposes FormatTags on ProbeData) and produces a
parsedAudiobook struct. Title falls back from "title" tag to "album";
author from "artist" -> "album_artist" -> "composer"; series from
"album" -> "series" -> "mvnm" (Movement Name, used by some MP4 tools).
Year parsed from "date" or "year" tags, tolerating ISO dates and
parenthesized forms.

Single-file case only; multi-file folders (one audio file per chapter)
return a placeholder error and arrive in Task 7.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(audiobooks): multi-file audiobook folder support

Folders containing N audio files (one per chapter/part) get one
parsedAudiobookFile per file; each file's chapter list is synthesized
as a single chapter with title = filename stem. Title/author/series/
year come from the first file's tags.

Also drops the duplicate pickFirstNonEmpty helper added in Task 6 in
favor of the existing firstNonEmpty already in probe.go.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(audiobooks): scanner write path produces audiobook media_items

ScanAudiobookFolder walks an audiobooks-typed media folder and treats
each immediate subdirectory as one audiobook. For each parsed audiobook
it upserts:
  - one media_items row with type='audiobook'
  - one media_files row per audio file (with chapters JSONB)
  - author/narrator links in item_people (kind=7, kind=8)

Adds itemRepo and personRepo to the Scanner struct, wired from
fileRepo.Pool() in NewScanner — no constructor signature change needed.

ScanFolder dispatches to this path when folder.Type='audiobooks',
bypassing the per-file movie/TV pipeline because audiobooks are
folder-scoped entities.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(audiobooks): filesystem podcast scanner

ScanPodcastFolder walks a podcasts-typed media folder, treating each
subdirectory as a podcast show and each audio file inside as an
episode. Writes media_items.type='podcast' + episodes rows + media_files
rows. RSS-subscribed feeds (podcast_feeds table) arrive in sub-plan 5;
this task covers filesystem-only ingestion.

ScanFolder dispatches to this path when folder.Type='podcasts'.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audiobooks): implementation plan sub-plan 5 (podcasts)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(audiobooks): expose audiobooks/podcasts library types in admin UI

Adds 'Audiobooks' and 'Podcasts' options to the library-type dropdown
in the admin libraries page so operators can flag a folder as an
audiobook or podcast library. Extends contentLevelsForType() so the
admin UI's downstream filtering treats those types correctly
(audiobook -> ['audiobook'], podcasts -> ['podcast',
'podcast_episode']).

Backend scanner branches for these types were already wired in
sub-plan 2.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* chore(migrations): renumber 139_abs_sessions to 147 for origin/main merge

origin/main adds 139_media_requests at the same number our local
audiobook branch had used for abs_sessions. Renumber ours to 147 to
free up 139 for the upstream migration. The schema_versions row is
updated in lockstep on the running database so the migrator sees the
abs_sessions migration as already applied at its new version.

Migrations 140-146 (podcast feeds, media_folders kind noop, audiobook
feature flag, abs playback sessions, podcast episode guid, audiobook
series, audiobook title cleanup) stay where they are — they don't
collide with anything on origin/main.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* chore(migrations): renumber 140_podcast_feeds to 157 for origin/main merge

origin/main added 140_user_permissions at the same version this branch
had used for podcast_feeds. Renumber ours to 157 (next free above the
collections-unify migration at 156) so 140 is free for the upstream
migration. schema_versions on the running database is updated in lockstep
so the migrator sees podcast_feeds as already applied at its new version.

Same pattern as d59c1cb (renumber 139_abs_sessions to 147 for the prior
main merge). Pending migrations after this rename: 132 (downloaded
subtitles admin index, main), 140 (user_permissions, main), and 156
(unify_user_collections, this branch).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* chore(migrations): renumber 141_media_folders_kind_noop to 159 for origin/main merge

Same shape as eb8f67d (the 140→157 renumber from the previous main
merge). origin/main added 141_episode_title_sort_index at the same
version this branch had used for media_folders_kind_noop. Renumber
ours to 159 (next free above the audiobook_series truncate at 158) so
141 is open for the upstream migration. schema_versions on the
running database is updated in lockstep so the migrator sees
media_folders_kind_noop as already applied at its new version.

Pending migrations on silo-prod after this rename: 141
(episode_title_sort_index, main) and any other newer ones from main
that the branch hasn't picked up yet.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* chore(migrations): renumber 142_audiobooks_feature_flag to 160 for origin/main merge

Companion to 3c6f062's 141 renumber — origin/main also added
142_episode_catalog_entries (alongside 141_episode_title_sort_index)
at a version this branch had used for the audiobooks feature flag.
Renumber ours to 160 so 142 is open for the upstream migration;
schema_versions on silo-prod is updated in lockstep so the migrator
sees audiobooks_feature_flag as already applied at its new version.

This was the only remaining collision (verified by checking for
duplicate version prefixes across migrations/).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(audiobooks): address foundation review comments

* fix(audiobooks): tighten scanner identity handling

* fix(audiobooks): propagate scanner cancellation

* chore(audiobooks): adopt goose migration layout

* docs(audiobooks): implementation plan sub-plan 3 (API + frontend MVP)

Third of six sub-plans. 9 tasks: three REST endpoints (list/detail/
progress), TanStack Query hooks + types, three React pages
(Library/Detail/Player), and navigation integration. Scoped to MVP —
author/series indices, smart collections, share links, and other
nice-to-haves from the spec are deferred. Streaming reuses silo's
existing /api/v1/stream/{session_id}; no new transcode code.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(audiobooks): list endpoint at GET /api/v1/audiobooks

Paginated list of media_items with type='audiobook' scoped to the
caller's accessible libraries via the existing access filter.
Mirrors silo's existing list-style handlers for movies and series.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(audiobooks): detail endpoint at GET /api/v1/audiobooks/{id}

Returns the media_items row, its media_files (with chapters JSONB),
author/narrator extracted from item_people (kinds 7/8), and the
caller's per-profile listening progress from user_watch_progress.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(audiobooks): progress endpoint at POST /api/v1/audiobooks/{id}/progress

UPSERTs user_watch_progress for the caller's (user_id, profile_id,
content_id). Body carries position_seconds; clients are expected to
post every 5-10s during playback plus on pause/seek (matching silo's
existing video progress cadence).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(audiobooks): frontend types and TanStack Query hooks

TypeScript types match the JSON shapes from the new
/api/v1/audiobooks endpoints (list, detail, progress). Three hooks:
useAudiobookLibrary (list), useAudiobook (detail), and
useReportAudiobookProgress (mutation that invalidates the detail
query on success so progress updates reflect immediately).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(audiobooks): library grid page at /audiobooks

Renders a paginated grid of audiobook cards using the
useAudiobookLibrary hook. Each card links to /audiobooks/book/{id}.
Cards show poster, title, and year; falls back to a "No cover"
placeholder when the audiobook has no poster_url. Empty state hints
to operators that they need to set a library's type to 'audiobooks'.

Routes themselves are wired in Task 8 (navigation integration).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(audiobooks): detail page with chapter list

Renders cover, title, author, narrator, year, and overview alongside a
chapter list. Clicking a chapter opens an inline sticky
AudiobookPlayer at that chapter's start. A "Resume" button restarts
playback at the saved progress position if present.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(audiobooks): HTML5 audio player with chapter navigation

Single-file audiobook playback for MVP. Multi-file queuing arrives in
a follow-up. Streams via the existing /api/v1/direct-download GET
endpoint. Position is reported to /api/v1/audiobooks/{id}/progress
every 10s while playing plus on pause/seek/end. Skip-30s, playback
rate select, chapter list panel.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(audiobooks): wire navigation and routes

Adds an Audiobooks entry to the sidebar and registers the two new
routes (/audiobooks for the library grid, /audiobooks/book/:id for
detail). The player renders inline inside the detail page; no
dedicated player route is required for MVP.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(audiobooks): address native API review comments

* feat(audiobooks): add ABS compatibility and polish

* fix(audiobooks): stabilize ABS playback progress reporting

* fix(audiobooks): clean up ABS branch review fixes

* chore(audiobooks): adopt goose layout for ABS migrations

* fix(audiobooks): align player seek bar props

* feat(audiobooks): make libraries first-class catalog items

* feat(admin): add server restart endpoint

* fix(audiobooks): address review comment findings

---------

Co-authored-by: RXWatcher <14085001+RXWatcher@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-06-07 15:57:05 -04:00

589 lines
21 KiB
Go

package abs
import (
"bytes"
"context"
"encoding/json"
"net/http"
"net/http/httptest"
"sort"
"sync"
"testing"
"time"
"github.com/go-chi/chi/v5"
"github.com/Silo-Server/silo-server/internal/models"
)
// ---------------------------------------------------------------------------
// In-memory fakes
// ---------------------------------------------------------------------------
// memCollectionStore is an in-memory CollectionStore for handler tests.
// Owner identity is tracked alongside the row (production stores user_id
// and profile_id; we mirror that so List can filter correctly).
type memCollectionStore struct {
mu sync.Mutex
rows map[string]Collection // id -> row
items map[string][]CollectionItem // collection_id -> items
}
func newMemCollectionStore() *memCollectionStore {
return &memCollectionStore{
rows: map[string]Collection{},
items: map[string][]CollectionItem{},
}
}
func (m *memCollectionStore) ListUserCollections(_ context.Context, userID, profileID string) ([]Collection, error) {
m.mu.Lock()
defer m.mu.Unlock()
out := make([]Collection, 0)
for _, c := range m.rows {
if c.UserID == userID && c.ProfileID == profileID {
out = append(out, c)
}
}
sort.Slice(out, func(i, j int) bool { return out[i].CreatedAt.After(out[j].CreatedAt) })
return out, nil
}
func (m *memCollectionStore) GetCollection(_ context.Context, id string) (Collection, error) {
m.mu.Lock()
defer m.mu.Unlock()
c, ok := m.rows[id]
if !ok {
return Collection{}, ErrNotFound
}
return c, nil
}
func (m *memCollectionStore) CreateCollection(_ context.Context, c Collection) error {
m.mu.Lock()
defer m.mu.Unlock()
m.rows[c.ID] = c
return nil
}
func (m *memCollectionStore) UpdateCollection(_ context.Context, c Collection) error {
m.mu.Lock()
defer m.mu.Unlock()
existing, ok := m.rows[c.ID]
if !ok {
return ErrNotFound
}
existing.Name = c.Name
existing.Description = c.Description
existing.IsPublic = c.IsPublic
existing.UpdatedAt = time.Now()
m.rows[c.ID] = existing
return nil
}
func (m *memCollectionStore) DeleteCollection(_ context.Context, id string) error {
m.mu.Lock()
defer m.mu.Unlock()
delete(m.rows, id)
delete(m.items, id) // cascade
return nil
}
func (m *memCollectionStore) ListCollectionItems(_ context.Context, collectionID string) ([]CollectionItem, error) {
m.mu.Lock()
defer m.mu.Unlock()
items := m.items[collectionID]
out := make([]CollectionItem, len(items))
copy(out, items)
sort.Slice(out, func(i, j int) bool { return out[i].AddedAt.Before(out[j].AddedAt) })
return out, nil
}
func (m *memCollectionStore) AddCollectionItem(_ context.Context, collectionID, libraryItemID string) error {
m.mu.Lock()
defer m.mu.Unlock()
for _, it := range m.items[collectionID] {
if it.LibraryItemID == libraryItemID {
return nil // ON CONFLICT DO NOTHING
}
}
m.items[collectionID] = append(m.items[collectionID], CollectionItem{
CollectionID: collectionID,
LibraryItemID: libraryItemID,
AddedAt: time.Now(),
})
if c, ok := m.rows[collectionID]; ok {
c.UpdatedAt = time.Now()
m.rows[collectionID] = c
}
return nil
}
func (m *memCollectionStore) RemoveCollectionItem(_ context.Context, collectionID, libraryItemID string) error {
m.mu.Lock()
defer m.mu.Unlock()
items := m.items[collectionID]
out := items[:0]
for _, it := range items {
if it.LibraryItemID != libraryItemID {
out = append(out, it)
}
}
m.items[collectionID] = out
if c, ok := m.rows[collectionID]; ok {
c.UpdatedAt = time.Now()
m.rows[collectionID] = c
}
return nil
}
// ---------------------------------------------------------------------------
// Test harness
// ---------------------------------------------------------------------------
type collectionsHarness struct {
H *Handler
Coll *memCollectionStore
Pub *recordingPublisher
}
func newCollectionsHarness(t *testing.T, knownItems ...string) *collectionsHarness {
t.Helper()
known := map[string]*models.MediaItem{}
for _, id := range knownItems {
known[id] = nil
}
pub := &recordingPublisher{}
store := newMemCollectionStore()
h := New(Dependencies{
MediaStore: &stubMediaStore{known: known},
CollectionStore: store,
Publisher: pub,
})
return &collectionsHarness{H: h, Coll: store, Pub: pub}
}
// dispatchABSWithParams drives a handler directly with arbitrary URL
// params + injected ctxAuth, bypassing the bearerAuth middleware.
// Generalised version of dispatchBookmark for surfaces with different
// URL-param shapes (collections use {id}, {bookId}; playlists use
// {id}, {libraryItemId}, {episodeId}).
func dispatchABSWithParams(method, path string, params map[string]string, body []byte, userID, profileID string, fn http.HandlerFunc) *httptest.ResponseRecorder {
var req *http.Request
if body != nil {
req = httptest.NewRequest(method, path, bytes.NewReader(body))
req.Header.Set("Content-Type", "application/json")
} else {
req = httptest.NewRequest(method, path, nil)
}
rctx := chi.NewRouteContext()
for k, v := range params {
rctx.URLParams.Add(k, v)
}
ctx := context.WithValue(req.Context(), chi.RouteCtxKey, rctx)
ctx = context.WithValue(ctx, ctxKey{}, ctxAuth{UserID: userID, ProfileID: profileID})
req = req.WithContext(ctx)
rec := httptest.NewRecorder()
fn(rec, req)
return rec
}
// ---------------------------------------------------------------------------
// Tests
// ---------------------------------------------------------------------------
func TestCollection_Create_ReturnsFullShape(t *testing.T) {
hb := newCollectionsHarness(t)
body := []byte(`{"name":"Favorites","description":"My top picks"}`)
rec := dispatchABSWithParams(http.MethodPost, "/api/collections", nil, body, "1", "", hb.H.handleCreateCollection)
if rec.Code != http.StatusOK {
t.Fatalf("status = %d, want 200; body=%s", rec.Code, rec.Body.String())
}
var got map[string]any
if err := json.Unmarshal(rec.Body.Bytes(), &got); err != nil {
t.Fatalf("decode: %v; body=%s", err, rec.Body.String())
}
if got["name"] != "Favorites" {
t.Errorf("name = %v, want Favorites", got["name"])
}
if got["description"] != "My top picks" {
t.Errorf("description = %v, want 'My top picks'", got["description"])
}
if got["userId"] != "1" {
t.Errorf("userId = %v, want 1", got["userId"])
}
if got["isPublic"] != false {
t.Errorf("isPublic = %v, want false", got["isPublic"])
}
for _, k := range []string{"id", "lastUpdate", "createdAt"} {
if _, ok := got[k]; !ok {
t.Errorf("response missing %q", k)
}
}
books, ok := got["books"].([]any)
if !ok || len(books) != 0 {
t.Errorf("books = %v (type %T), want empty array", got["books"], got["books"])
}
}
func TestCollection_Create_NameRequired_400(t *testing.T) {
hb := newCollectionsHarness(t)
body := []byte(`{"description":"only"}`)
rec := dispatchABSWithParams(http.MethodPost, "/api/collections", nil, body, "1", "", hb.H.handleCreateCollection)
if rec.Code != http.StatusBadRequest {
t.Errorf("status = %d, want 400; body=%s", rec.Code, rec.Body.String())
}
}
func TestCollection_Create_InvalidBody_400(t *testing.T) {
hb := newCollectionsHarness(t)
rec := dispatchABSWithParams(http.MethodPost, "/api/collections", nil, []byte(`{not json`), "1", "", hb.H.handleCreateCollection)
if rec.Code != http.StatusBadRequest {
t.Errorf("status = %d, want 400; body=%s", rec.Code, rec.Body.String())
}
}
func TestCollection_List_ReturnsWrappedEnvelope(t *testing.T) {
hb := newCollectionsHarness(t)
// Seed two collections.
_ = dispatchABSWithParams(http.MethodPost, "/api/collections", nil, []byte(`{"name":"A"}`), "1", "", hb.H.handleCreateCollection)
_ = dispatchABSWithParams(http.MethodPost, "/api/collections", nil, []byte(`{"name":"B"}`), "1", "", hb.H.handleCreateCollection)
rec := dispatchABSWithParams(http.MethodGet, "/api/collections", nil, nil, "1", "", hb.H.handleListCollections)
if rec.Code != http.StatusOK {
t.Fatalf("status = %d, want 200; body=%s", rec.Code, rec.Body.String())
}
var env map[string]any
if err := json.Unmarshal(rec.Body.Bytes(), &env); err != nil {
t.Fatalf("decode: %v; body=%s", err, rec.Body.String())
}
list, ok := env["collections"].([]any)
if !ok {
t.Fatalf("response missing 'collections' key; body=%s", rec.Body.String())
}
if len(list) != 2 {
t.Errorf("list len = %d, want 2", len(list))
}
// List-shape must omit books.
for _, c := range list {
entry := c.(map[string]any)
if _, has := entry["books"]; has {
t.Errorf("list entry has books key (should be detail-only): %v", entry)
}
}
}
func TestCollection_List_DoesNotLeakOtherUsers(t *testing.T) {
hb := newCollectionsHarness(t)
// User 1 creates.
_ = dispatchABSWithParams(http.MethodPost, "/api/collections", nil, []byte(`{"name":"mine"}`), "1", "", hb.H.handleCreateCollection)
// User 2 lists.
rec := dispatchABSWithParams(http.MethodGet, "/api/collections", nil, nil, "2", "", hb.H.handleListCollections)
var env map[string]any
if rec.Code != http.StatusOK {
t.Fatalf("status = %d, want 200; body=%s", rec.Code, rec.Body.String())
}
if err := json.Unmarshal(rec.Body.Bytes(), &env); err != nil {
t.Fatalf("decode: %v; body=%s", err, rec.Body.String())
}
list, ok := env["collections"].([]any)
if !ok {
t.Fatalf("response missing 'collections' key; body=%s", rec.Body.String())
}
if len(list) != 0 {
t.Errorf("user 2 sees %d collections, want 0", len(list))
}
}
func TestCollection_List_ProfileIsolation(t *testing.T) {
hb := newCollectionsHarness(t)
pA := "00000000-0000-0000-0000-0000000000aa"
pB := "00000000-0000-0000-0000-0000000000bb"
_ = dispatchABSWithParams(http.MethodPost, "/api/collections", nil, []byte(`{"name":"A"}`), "1", pA, hb.H.handleCreateCollection)
rec := dispatchABSWithParams(http.MethodGet, "/api/collections", nil, nil, "1", pB, hb.H.handleListCollections)
var env map[string]any
if rec.Code != http.StatusOK {
t.Fatalf("status = %d, want 200; body=%s", rec.Code, rec.Body.String())
}
if err := json.Unmarshal(rec.Body.Bytes(), &env); err != nil {
t.Fatalf("decode: %v; body=%s", err, rec.Body.String())
}
list, ok := env["collections"].([]any)
if !ok {
t.Fatalf("response missing 'collections' key; body=%s", rec.Body.String())
}
if len(list) != 0 {
t.Errorf("profile B sees %d collections, want 0", len(list))
}
}
// createCollectionForUser is a tiny helper that POSTs a collection and
// returns its id. Used by tests that need to seed a row.
func createCollectionForUser(t *testing.T, hb *collectionsHarness, userID, profileID, body string) string {
t.Helper()
rec := dispatchABSWithParams(http.MethodPost, "/api/collections", nil, []byte(body), userID, profileID, hb.H.handleCreateCollection)
if rec.Code != http.StatusOK {
t.Fatalf("seed POST status = %d; body=%s", rec.Code, rec.Body.String())
}
var got map[string]any
_ = json.Unmarshal(rec.Body.Bytes(), &got)
id, _ := got["id"].(string)
if id == "" {
t.Fatalf("seed POST returned no id; body=%s", rec.Body.String())
}
return id
}
func TestCollection_Get_Owner_ReturnsFullShape(t *testing.T) {
hb := newCollectionsHarness(t)
id := createCollectionForUser(t, hb, "1", "", `{"name":"mine"}`)
rec := dispatchABSWithParams(http.MethodGet, "/api/collections/"+id, map[string]string{"id": id}, nil, "1", "", hb.H.handleGetCollection)
if rec.Code != http.StatusOK {
t.Fatalf("status = %d, want 200; body=%s", rec.Code, rec.Body.String())
}
var got map[string]any
_ = json.Unmarshal(rec.Body.Bytes(), &got)
if got["name"] != "mine" {
t.Errorf("name = %v, want 'mine'", got["name"])
}
books, ok := got["books"].([]any)
if !ok {
t.Errorf("books missing on full-shape response: %v", got)
}
if len(books) != 0 {
t.Errorf("books len = %d, want 0 for freshly created", len(books))
}
}
func TestCollection_Get_NonOwner_Private_404(t *testing.T) {
hb := newCollectionsHarness(t)
id := createCollectionForUser(t, hb, "1", "", `{"name":"private"}`)
rec := dispatchABSWithParams(http.MethodGet, "/api/collections/"+id, map[string]string{"id": id}, nil, "2", "", hb.H.handleGetCollection)
if rec.Code != http.StatusNotFound {
t.Errorf("non-owner private GET status = %d, want 404 (anti-enumeration); body=%s", rec.Code, rec.Body.String())
}
}
func TestCollection_Get_NonOwner_Public_OK(t *testing.T) {
hb := newCollectionsHarness(t)
id := createCollectionForUser(t, hb, "1", "", `{"name":"public","isPublic":true}`)
rec := dispatchABSWithParams(http.MethodGet, "/api/collections/"+id, map[string]string{"id": id}, nil, "2", "", hb.H.handleGetCollection)
if rec.Code != http.StatusOK {
t.Fatalf("non-owner public GET status = %d, want 200; body=%s", rec.Code, rec.Body.String())
}
var got map[string]any
_ = json.Unmarshal(rec.Body.Bytes(), &got)
if got["name"] != "public" {
t.Errorf("name = %v, want 'public'", got["name"])
}
}
func TestCollection_Get_Unknown_404(t *testing.T) {
hb := newCollectionsHarness(t)
rec := dispatchABSWithParams(http.MethodGet, "/api/collections/01HZZZ", map[string]string{"id": "01HZZZ"}, nil, "1", "", hb.H.handleGetCollection)
if rec.Code != http.StatusNotFound {
t.Errorf("status = %d, want 404; body=%s", rec.Code, rec.Body.String())
}
}
func TestCollection_Patch_OwnerUpdatesNameAndDescription(t *testing.T) {
hb := newCollectionsHarness(t)
id := createCollectionForUser(t, hb, "1", "", `{"name":"old","description":"d1"}`)
body := []byte(`{"name":"new","description":"d2","isPublic":true}`)
rec := dispatchABSWithParams(http.MethodPatch, "/api/collections/"+id, map[string]string{"id": id}, body, "1", "", hb.H.handleUpdateCollection)
if rec.Code != http.StatusOK {
t.Fatalf("status = %d, want 200; body=%s", rec.Code, rec.Body.String())
}
var got map[string]any
_ = json.Unmarshal(rec.Body.Bytes(), &got)
if got["name"] != "new" {
t.Errorf("name = %v, want 'new'", got["name"])
}
if got["description"] != "d2" {
t.Errorf("description = %v, want 'd2'", got["description"])
}
if got["isPublic"] != true {
t.Errorf("isPublic = %v, want true", got["isPublic"])
}
}
func TestCollection_Patch_PartialOnlyChangesPresentFields(t *testing.T) {
hb := newCollectionsHarness(t)
id := createCollectionForUser(t, hb, "1", "", `{"name":"keep","description":"d1"}`)
// PATCH only name; description and isPublic must stay.
body := []byte(`{"name":"renamed"}`)
rec := dispatchABSWithParams(http.MethodPatch, "/api/collections/"+id, map[string]string{"id": id}, body, "1", "", hb.H.handleUpdateCollection)
if rec.Code != http.StatusOK {
t.Fatalf("status = %d", rec.Code)
}
var got map[string]any
_ = json.Unmarshal(rec.Body.Bytes(), &got)
if got["name"] != "renamed" {
t.Errorf("name = %v, want 'renamed'", got["name"])
}
if got["description"] != "d1" {
t.Errorf("description = %v, want 'd1' (unchanged)", got["description"])
}
}
func TestCollection_Patch_NonOwner_404(t *testing.T) {
hb := newCollectionsHarness(t)
id := createCollectionForUser(t, hb, "1", "", `{"name":"mine"}`)
body := []byte(`{"name":"hijack"}`)
rec := dispatchABSWithParams(http.MethodPatch, "/api/collections/"+id, map[string]string{"id": id}, body, "2", "", hb.H.handleUpdateCollection)
if rec.Code != http.StatusNotFound {
t.Errorf("status = %d, want 404 (no leak); body=%s", rec.Code, rec.Body.String())
}
// User 1's collection must be untouched.
c, _ := hb.Coll.GetCollection(context.Background(), id)
if c.Name != "mine" {
t.Errorf("collection name = %q, want 'mine'; non-owner mutation leaked", c.Name)
}
}
func TestCollection_Delete_Owner_204(t *testing.T) {
hb := newCollectionsHarness(t, "book-1")
id := createCollectionForUser(t, hb, "1", "", `{"name":"x"}`)
// Seed an item so the cascade-delete is exercised.
_ = dispatchABSWithParams(http.MethodPost, "/api/collections/"+id+"/book/book-1",
map[string]string{"id": id, "bookId": "book-1"}, nil, "1", "", hb.H.handleAddCollectionBook)
rec := dispatchABSWithParams(http.MethodDelete, "/api/collections/"+id, map[string]string{"id": id}, nil, "1", "", hb.H.handleDeleteCollection)
if rec.Code != http.StatusNoContent {
t.Fatalf("status = %d, want 204; body=%s", rec.Code, rec.Body.String())
}
// Subsequent GET must 404.
rec2 := dispatchABSWithParams(http.MethodGet, "/api/collections/"+id, map[string]string{"id": id}, nil, "1", "", hb.H.handleGetCollection)
if rec2.Code != http.StatusNotFound {
t.Errorf("post-delete GET status = %d, want 404", rec2.Code)
}
// Cascade: items table must be empty for the deleted collection.
items, _ := hb.Coll.ListCollectionItems(context.Background(), id)
if len(items) != 0 {
t.Errorf("items len = %d, want 0 (cascade did not drop child rows)", len(items))
}
}
func TestCollection_Delete_NonOwner_404(t *testing.T) {
hb := newCollectionsHarness(t)
id := createCollectionForUser(t, hb, "1", "", `{"name":"mine"}`)
rec := dispatchABSWithParams(http.MethodDelete, "/api/collections/"+id, map[string]string{"id": id}, nil, "2", "", hb.H.handleDeleteCollection)
if rec.Code != http.StatusNotFound {
t.Errorf("status = %d, want 404; body=%s", rec.Code, rec.Body.String())
}
// User 1's collection still exists.
if _, err := hb.Coll.GetCollection(context.Background(), id); err != nil {
t.Errorf("collection wrongly deleted: %v", err)
}
}
func TestCollection_AddBook_Owner_HydratesInResponse(t *testing.T) {
hb := newCollectionsHarness(t, "book-1")
id := createCollectionForUser(t, hb, "1", "", `{"name":"x"}`)
rec := dispatchABSWithParams(http.MethodPost, "/api/collections/"+id+"/book/book-1",
map[string]string{"id": id, "bookId": "book-1"}, nil, "1", "", hb.H.handleAddCollectionBook)
if rec.Code != http.StatusOK {
t.Fatalf("status = %d, want 200; body=%s", rec.Code, rec.Body.String())
}
var got map[string]any
_ = json.Unmarshal(rec.Body.Bytes(), &got)
books, _ := got["books"].([]any)
if len(books) != 1 {
t.Fatalf("books len = %d, want 1", len(books))
}
entry := books[0].(map[string]any)
if entry["id"] != "book-1" {
t.Errorf("book entry id = %v, want book-1", entry["id"])
}
if _, has := entry["media"]; !has {
t.Errorf("book entry missing media hydration: %v", entry)
}
}
func TestCollection_AddBook_Idempotent(t *testing.T) {
hb := newCollectionsHarness(t, "book-1")
id := createCollectionForUser(t, hb, "1", "", `{"name":"x"}`)
_ = dispatchABSWithParams(http.MethodPost, "/api/collections/"+id+"/book/book-1",
map[string]string{"id": id, "bookId": "book-1"}, nil, "1", "", hb.H.handleAddCollectionBook)
rec := dispatchABSWithParams(http.MethodPost, "/api/collections/"+id+"/book/book-1",
map[string]string{"id": id, "bookId": "book-1"}, nil, "1", "", hb.H.handleAddCollectionBook)
if rec.Code != http.StatusOK {
t.Fatalf("second add status = %d, want 200 (idempotent); body=%s", rec.Code, rec.Body.String())
}
var got map[string]any
_ = json.Unmarshal(rec.Body.Bytes(), &got)
books, _ := got["books"].([]any)
if len(books) != 1 {
t.Errorf("books len after double-add = %d, want 1", len(books))
}
}
func TestCollection_AddBook_UnknownItem_404(t *testing.T) {
hb := newCollectionsHarness(t /* no known items */)
id := createCollectionForUser(t, hb, "1", "", `{"name":"x"}`)
rec := dispatchABSWithParams(http.MethodPost, "/api/collections/"+id+"/book/ghost",
map[string]string{"id": id, "bookId": "ghost"}, nil, "1", "", hb.H.handleAddCollectionBook)
if rec.Code != http.StatusNotFound {
t.Errorf("status = %d, want 404 (item not found); body=%s", rec.Code, rec.Body.String())
}
}
func TestCollection_AddBook_NonOwner_404(t *testing.T) {
hb := newCollectionsHarness(t, "book-1")
id := createCollectionForUser(t, hb, "1", "", `{"name":"mine"}`)
rec := dispatchABSWithParams(http.MethodPost, "/api/collections/"+id+"/book/book-1",
map[string]string{"id": id, "bookId": "book-1"}, nil, "2", "", hb.H.handleAddCollectionBook)
if rec.Code != http.StatusNotFound {
t.Errorf("status = %d, want 404 (no leak); body=%s", rec.Code, rec.Body.String())
}
}
func TestCollection_RemoveBook_Idempotent(t *testing.T) {
hb := newCollectionsHarness(t, "book-1")
id := createCollectionForUser(t, hb, "1", "", `{"name":"x"}`)
// Remove book that was never added — should be 200 with empty books.
rec := dispatchABSWithParams(http.MethodDelete, "/api/collections/"+id+"/book/book-1",
map[string]string{"id": id, "bookId": "book-1"}, nil, "1", "", hb.H.handleRemoveCollectionBook)
if rec.Code != http.StatusOK {
t.Fatalf("status = %d, want 200; body=%s", rec.Code, rec.Body.String())
}
var got map[string]any
_ = json.Unmarshal(rec.Body.Bytes(), &got)
books, _ := got["books"].([]any)
if len(books) != 0 {
t.Errorf("books len = %d, want 0", len(books))
}
}
func TestCollection_RemoveBook_NonOwner_404(t *testing.T) {
hb := newCollectionsHarness(t, "book-1")
id := createCollectionForUser(t, hb, "1", "", `{"name":"mine"}`)
_ = dispatchABSWithParams(http.MethodPost, "/api/collections/"+id+"/book/book-1",
map[string]string{"id": id, "bookId": "book-1"}, nil, "1", "", hb.H.handleAddCollectionBook)
rec := dispatchABSWithParams(http.MethodDelete, "/api/collections/"+id+"/book/book-1",
map[string]string{"id": id, "bookId": "book-1"}, nil, "2", "", hb.H.handleRemoveCollectionBook)
if rec.Code != http.StatusNotFound {
t.Errorf("status = %d, want 404; body=%s", rec.Code, rec.Body.String())
}
// User 1's items must be intact.
items, _ := hb.Coll.ListCollectionItems(context.Background(), id)
if len(items) != 1 {
t.Errorf("items len = %d, want 1 (non-owner remove leaked)", len(items))
}
}