package slack_test import ( "context" "errors" "io" "net/http" "net/http/httptest" "testing" "atlas9.dev/c/core/assert" "atlas9.dev/c/core/iam" "atlas9.dev/c/demo/lib/access" "atlas9.dev/c/demo/lib/slack" ) func TestSender_Deliver_PostsBody(t *testing.T) { var gotBody []byte var gotContentType string srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { gotContentType = r.Header.Get("Content-Type") gotBody, _ = io.ReadAll(r.Body) w.WriteHeader(http.StatusOK) })) defer srv.Close() sender := &slack.Sender{Client: srv.Client(), Guard: access.ContextGuard{}} ctx := access.PutSystem(context.Background(), slack.Cap_Slack_Send) body := []byte(`{"text":"hello"}`) status, err := sender.Deliver(ctx, srv.URL, body) assert.Ok(t, err) assert.Eq(t, status, 200) assert.Eq(t, string(gotBody), `{"text":"hello"}`) assert.Eq(t, gotContentType, "application/json") } // The egress cap is a chokepoint: without it, nothing is sent. Slack messages // are unsigned, so the cap is the only guard on outbound posts. func TestSender_Deliver_DeniedWithoutCap(t *testing.T) { hit := false srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { hit = true })) defer srv.Close() sender := &slack.Sender{Client: srv.Client(), Guard: access.ContextGuard{}} _, err := sender.Deliver(context.Background(), srv.URL, []byte(`{"text":"x"}`)) assert.Eq(t, errors.Is(err, iam.ErrForbidden), true) assert.Eq(t, hit, false) }