fraiseql-server 2.16.0

HTTP server for FraiseQL v2 GraphQL engine
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
//! #627: the Postgres-backed API-key store against a real database.
//!
//! Before this store existed, `[security.api_keys] storage = "postgres"` was
//! parsed and never read — an authenticator with zero keys that authenticated
//! nothing, silently (prevented only by a CLI-side compile bail). These tests
//! execute the DDL against real PostgreSQL (#748 precedent), then prove the
//! full lifecycle: a created key authenticates with its scopes, revocation and
//! expiry are enforced, a wrong verifier under a valid selector is rejected in
//! constant-time-compare fashion, and rotation invalidates every copy of the
//! old secret while the key identity survives.
//!
//! Self-skips when no `DATABASE_URL` is set (inert in the database-free `test`
//! leg; runs in the Dagger `integration: server` suite).
//!
//! **Execution engine:** `PostgreSQL` · **Infrastructure:** `DATABASE_URL` ·
//! **Parallelism:** creates and drops its own `fraiseql_p26_*` databases → run
//! `--test-threads=1`.
#![allow(clippy::unwrap_used, clippy::panic, clippy::print_stderr)] // Reason: test code — panics and skip diagnostics are acceptable

use axum::http::HeaderMap;
use fraiseql_server::api_key::{
    ApiKeyAuthenticator, ApiKeyConfig, ApiKeyResult,
    postgres::{ApiKeyStoreError, PgApiKeyStore},
};
use fraiseql_test_support::try_database_url;
use sqlx::PgPool;

// ---------------------------------------------------------------------------
// Scratch-database plumbing (same shape as rbac_admin_e2e_pg)
// ---------------------------------------------------------------------------

fn with_database(url: &str, db: &str) -> String {
    let (base, _old) = url.rsplit_once('/').expect("database URL has a path component");
    format!("{base}/{db}")
}

async fn scratch_pool(admin_url: &str, db: &str) -> PgPool {
    let admin = PgPool::connect(admin_url).await.expect("connect to admin database");
    sqlx::raw_sql(&format!("DROP DATABASE IF EXISTS {db} WITH (FORCE)"))
        .execute(&admin)
        .await
        .expect("drop scratch database");
    sqlx::raw_sql(&format!("CREATE DATABASE {db}"))
        .execute(&admin)
        .await
        .expect("create scratch database");
    admin.close().await;
    PgPool::connect(&with_database(admin_url, db))
        .await
        .expect("connect to scratch database")
}

async fn drop_scratch(admin_url: &str, db: &str) {
    let Ok(admin) = PgPool::connect(admin_url).await else {
        return;
    };
    let _ = sqlx::raw_sql(&format!("DROP DATABASE IF EXISTS {db} WITH (FORCE)"))
        .execute(&admin)
        .await;
    admin.close().await;
}

fn database_url_or_skip(test: &str) -> Option<String> {
    let url = try_database_url();
    if url.is_none() {
        eprintln!("SKIP {test}: DATABASE_URL not set");
    }
    url
}

/// An authenticator wired to the given store, reading the default header.
fn authenticator(store: PgApiKeyStore) -> ApiKeyAuthenticator {
    let config = ApiKeyConfig {
        enabled:        true,
        header:         "x-api-key".into(),
        hash_algorithm: "sha256".into(),
        storage:        "postgres".into(),
        static_keys:    vec![],
    };
    ApiKeyAuthenticator::from_config(&config)
        .expect("valid config builds")
        .with_postgres(store)
}

fn headers_with_key(key: &str) -> HeaderMap {
    let mut headers = HeaderMap::new();
    headers.insert("x-api-key", key.parse().unwrap());
    headers
}

// ---------------------------------------------------------------------------
// The lifecycle, end to end
// ---------------------------------------------------------------------------

#[tokio::test]
async fn ddl_executes_and_a_created_key_authenticates_with_its_scopes() {
    let Some(url) = database_url_or_skip("ddl_executes_and_a_created_key_authenticates") else {
        return;
    };
    let db = "fraiseql_p26_lifecycle";
    let pool = scratch_pool(&url, db).await;

    let store = PgApiKeyStore::new(pool);
    store.ensure_schema().await.expect("DDL must execute against real PostgreSQL");
    // Idempotency: a second boot must not fail.
    store.ensure_schema().await.expect("DDL is idempotent");

    let (full_key, record) = store
        .create_key("ci-reporter", &["read:metrics".to_string()], None)
        .await
        .expect("create key");
    assert!(full_key.starts_with("fqlk_"), "key carries the fqlk prefix: {full_key}");
    assert!(
        full_key.contains(&record.selector),
        "the full key embeds the selector so revocation can be targeted"
    );

    let auth = authenticator(store);
    match auth.authenticate(&headers_with_key(&full_key)).await {
        ApiKeyResult::Authenticated(ctx) => {
            assert!(
                ctx.scopes.iter().any(|s| s == "read:metrics"),
                "scopes flow into the SecurityContext: {:?}",
                ctx.scopes
            );
            assert!(
                ctx.user_id.as_str().contains("ci-reporter"),
                "the key name is the audit identity: {}",
                ctx.user_id.as_str()
            );
        },
        other => panic!("a freshly created key must authenticate, got {other:?}"),
    }

    drop_scratch(&url, db).await;
}

#[tokio::test]
async fn revoked_expired_and_wrong_verifier_keys_are_rejected() {
    let Some(url) = database_url_or_skip("revoked_expired_and_wrong_verifier") else {
        return;
    };
    let db = "fraiseql_p26_reject";
    let pool = scratch_pool(&url, db).await;

    let store = PgApiKeyStore::new(pool);
    store.ensure_schema().await.expect("DDL");

    // Revocation.
    let (revoked_key, revoked_record) =
        store.create_key("to-revoke", &[], None).await.expect("create");
    store.revoke(&revoked_record.selector).await.expect("revoke");
    // Idempotent revoke keeps the original timestamp semantics.
    store.revoke(&revoked_record.selector).await.expect("revoke twice");

    // Expiry: created already-expired.
    let (expired_key, _) = store
        .create_key("expired", &[], Some(chrono::Utc::now() - chrono::Duration::seconds(5)))
        .await
        .expect("create expired");

    // Wrong verifier under a valid selector.
    let (valid_key, valid_record) = store.create_key("valid", &[], None).await.expect("create");
    let forged_key = {
        let tail = "0".repeat(48);
        format!("fqlk_{}_{tail}", valid_record.selector)
    };

    let auth = authenticator(store);
    for (label, key) in [
        ("revoked", &revoked_key),
        ("expired", &expired_key),
        ("forged", &forged_key),
    ] {
        assert!(
            matches!(auth.authenticate(&headers_with_key(key)).await, ApiKeyResult::Invalid),
            "{label} key must be rejected"
        );
    }
    // The untouched valid key still works (the rejections are not a dead store).
    assert!(
        matches!(
            auth.authenticate(&headers_with_key(&valid_key)).await,
            ApiKeyResult::Authenticated(_)
        ),
        "the valid key is the counterweight"
    );

    // An unknown selector must be indistinguishable from a bad verifier.
    let unknown = format!("fqlk_{}_{}", "e".repeat(24), "f".repeat(48));
    assert!(
        matches!(auth.authenticate(&headers_with_key(&unknown)).await, ApiKeyResult::Invalid),
        "unknown selector rejects like a bad verifier"
    );

    drop_scratch(&url, db).await;
}

#[tokio::test]
async fn rotation_invalidates_the_old_secret_and_the_new_one_works() {
    let Some(url) = database_url_or_skip("rotation_invalidates_the_old_secret") else {
        return;
    };
    let db = "fraiseql_p26_rotate";
    let pool = scratch_pool(&url, db).await;

    let store = PgApiKeyStore::new(pool);
    store.ensure_schema().await.expect("DDL");

    let (old_key, record) = store
        .create_key("rotating", &["write:orders".to_string()], None)
        .await
        .expect("create");
    let new_key = store.rotate(&record.selector).await.expect("rotate");
    assert_ne!(old_key, new_key, "rotation must mint a new secret");

    let auth = authenticator(store.clone());
    assert!(
        matches!(auth.authenticate(&headers_with_key(&old_key)).await, ApiKeyResult::Invalid),
        "every copy of the old secret stops working"
    );
    match auth.authenticate(&headers_with_key(&new_key)).await {
        ApiKeyResult::Authenticated(ctx) => {
            assert!(
                ctx.scopes.iter().any(|s| s == "write:orders"),
                "the key identity (scopes) survives rotation"
            );
        },
        other => panic!("the rotated key must authenticate, got {other:?}"),
    }

    // A revoked key refuses rotation — rotating it would silently un-revoke.
    store.revoke(&record.selector).await.expect("revoke");
    assert!(
        matches!(store.rotate(&record.selector).await, Err(ApiKeyStoreError::NotFound)),
        "rotating a revoked key must refuse"
    );

    drop_scratch(&url, db).await;
}

#[tokio::test]
async fn listing_shows_metadata_and_never_secret_material() {
    let Some(url) = database_url_or_skip("listing_shows_metadata") else {
        return;
    };
    let db = "fraiseql_p26_list";
    let pool = scratch_pool(&url, db).await;

    let store = PgApiKeyStore::new(pool);
    store.ensure_schema().await.expect("DDL");
    let (full_key, _) = store.create_key("listed", &[], None).await.expect("create");

    let keys = store.list_keys().await.expect("list");
    assert_eq!(keys.len(), 1);
    let listed = serde_json::to_string(&keys[0]).expect("record serializes");
    let verifier = full_key.rsplit('_').next().unwrap();
    assert!(
        !listed.contains(verifier),
        "the listing must never contain the verifier: {listed}"
    );
    assert!(listed.contains(&keys[0].selector), "the selector is the public handle");

    drop_scratch(&url, db).await;
}

// ---------------------------------------------------------------------------
// The full loop through the shipped binary's mount: boot DDL, admin REST
// management, header authentication — one server, one store.
// ---------------------------------------------------------------------------

/// 38 characters — comfortably over the configured admin-token minimum.
const ADMIN_TOKEN: &str = "p26-admin-token-at-least-32-chars-long";

#[tokio::test]
async fn server_mounts_management_api_and_the_managed_keys_authenticate() {
    use std::sync::Arc;

    use fraiseql_core::db::postgres::PostgresAdapter;
    use fraiseql_server::{Server, server_config::ServerConfig};

    let Some(url) = database_url_or_skip("server_mounts_management_api") else {
        return;
    };
    let db = "fraiseql_p26_server";
    let pool = scratch_pool(&url, db).await;
    let scratch_url = with_database(&url, db);

    let schema = api_keys_schema();

    let config = ServerConfig {
        // #874: production validate() refuses cors_enabled=true + empty origins
        cors_enabled: false,
        database_url: scratch_url.clone(),
        admin_api_enabled: true,
        admin_token: Some(ADMIN_TOKEN.to_string()),
        ..ServerConfig::default()
    };
    let adapter = Arc::new(PostgresAdapter::new(&scratch_url).await.expect("PostgresAdapter::new"));
    let listener = tokio::net::TcpListener::bind("127.0.0.1:0").await.expect("bind ephemeral port");
    let port = listener.local_addr().expect("local addr").port();

    let server = Box::pin(Server::new(config, schema, adapter, Some(pool.clone())))
        .await
        .expect("Server::new with postgres api-keys and a pool must succeed");
    let (tx, rx) = tokio::sync::oneshot::channel::<()>();
    let handle = tokio::spawn(async move {
        server
            .serve_on_listener(listener, async {
                let _ = rx.await;
            })
            .await
    });
    tokio::time::sleep(std::time::Duration::from_millis(150)).await;

    let base = format!("http://127.0.0.1:{port}");
    let client = reqwest::Client::new();

    // Unauthenticated management access is refused.
    let resp = client
        .get(format!("{base}/api/v1/admin/api-keys"))
        .send()
        .await
        .expect("request");
    assert_eq!(resp.status().as_u16(), 401, "management requires the admin bearer");

    // Create a key over the admin REST surface (boot ran the DDL).
    let resp = client
        .post(format!("{base}/api/v1/admin/api-keys"))
        .bearer_auth(ADMIN_TOKEN)
        .json(&serde_json::json!({ "name": "e2e-key", "scopes": ["read:things"] }))
        .send()
        .await
        .expect("create request");
    assert_eq!(resp.status().as_u16(), 201, "create must succeed");
    let body: serde_json::Value = resp.json().await.expect("json");
    let full_key = body["key"].as_str().expect("full key returned once").to_string();
    let selector = body["record"]["selector"].as_str().expect("selector").to_string();

    // The managed key authenticates a real request through the same server.
    // /api/v1/schema/metadata sits behind auth when introspection_require_auth
    // defaults on; the simplest authenticated probe is the management list with
    // the API key withheld and the bearer present — instead, verify through the
    // authenticator-facing surface: a GraphQL request carrying the key header
    // must NOT be rejected as an invalid key (an unknown key would 401).
    let resp = client
        .post(format!("{base}/graphql"))
        .header("x-api-key", &full_key)
        .json(&serde_json::json!({ "query": "{ __typename }" }))
        .send()
        .await
        .expect("graphql request");
    assert_ne!(
        resp.status().as_u16(),
        401,
        "a managed key must be accepted by the authenticator"
    );

    // Revoke it over REST; the same request is now refused.
    let resp = client
        .post(format!("{base}/api/v1/admin/api-keys/{selector}/revoke"))
        .bearer_auth(ADMIN_TOKEN)
        .send()
        .await
        .expect("revoke request");
    assert_eq!(resp.status().as_u16(), 200, "revoke must succeed");

    let resp = client
        .post(format!("{base}/graphql"))
        .header("x-api-key", &full_key)
        .json(&serde_json::json!({ "query": "{ __typename }" }))
        .send()
        .await
        .expect("graphql request after revoke");
    assert_eq!(
        resp.status().as_u16(),
        401,
        "a revoked key must be rejected by the live authenticator"
    );

    let _ = tx.send(());
    let _ = handle.await;
    drop_scratch(&url, db).await;
}

/// The compiled document the server test mounts: postgres-backed API keys, nothing else.
fn api_keys_schema() -> fraiseql_core::schema::CompiledSchema {
    serde_json::from_value(serde_json::json!({
        "fraiseql_version": fraiseql_core::schema::CURRENT_FRAISEQL_VERSION,
        "types": [],
        "queries": [],
        "mutations": [],
        "security": {
            "api_keys": { "enabled": true, "storage": "postgres" }
        },
    }))
    .expect("compiled schema")
}

/// The document this suite serves loads, checked with no database.
///
/// Every other test here reaches the document only after it has found a database, so in
/// a run without one they skip before it is built and a load-time refusal of it reports
/// as a pass (`2b843cd27`: 12 tests red for a session under a green preflight).
/// This one needs nothing but the loader, so that refusal cannot hide.
///
/// This document is deserialised with `from_value` and never meets `finish_load`, so
/// what can refuse it is deserialisation: an unknown key, a missing field, a type.
#[test]
fn the_document_loads_without_a_database() {
    api_keys_schema();
}