Phase 4: move catalog controllers and routes into WarpEngine

- update, files and the 6 /api catalog controllers now live in the engine on
  a new WarpEngine::ApiController base (same rescue/mime behavior as host)
- engine routes serve /update, /file/*path, /api/software*, /api/builds*,
  /api/image/:id, /api/download at unchanged public paths via the root mount;
  host routes keep only TTG endpoints (events, members, wiki, rss, swagger)
- /update secret comes from WarpEngine.config.update_secret and an
  unconfigured secret now rejects every request (previously an empty
  UPDATE_SECRET env accepted empty secrets)
- apipie-rails is an engine dependency (DSL in engine controllers); dummy app
  configures apipie with validation off, mirroring the host
- engine request specs: catalog controller specs moved from host plus new
  /update auth contract spec

Verified: engine suite 53 green, host suite 6 green, /api/software and
/api/builds byte-identical to baselines, /update 401/400 behavior intact,
admin and TTG endpoints OK.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
2026-08-04 19:09:11 +02:00
co-authored by Claude Fable 5
parent ca25f72c76
commit 2b2a9df136
18 changed files with 449 additions and 0 deletions
+16
View File
@@ -0,0 +1,16 @@
require "rails_helper"
RSpec.describe "GET /api/builds", type: :request do
describe "GET /api/builds" do
it "returns the global build matrix" do
get "/api/builds"
expect(response).to have_http_status(:ok)
json = JSON.parse(response.body)
expect(json["platforms"]).to be_a(Hash)
expect(json["platforms"]["tic80"]["label"]).to eq("TIC-80")
expect(json["platforms"]["tic80"]["kinds"]).to include("cartridge")
expect(json["allKinds"]).to be_an(Array)
end
end
end
@@ -0,0 +1,21 @@
require "rails_helper"
RSpec.describe "GET /api/download", type: :request do
describe "GET /api/download" do
it "returns bad_request without path" do
get "/api/download"
expect(response).to have_http_status(:bad_request)
json = JSON.parse(response.body)
expect(json["error"]).to eq("Path is required")
end
it "returns not_found for invalid path" do
get "/api/download", params: { path: "nonexistent/file.tic" }
expect(response).to have_http_status(:not_found)
json = JSON.parse(response.body)
expect(json["error"]).to eq("Not found")
end
end
end
@@ -0,0 +1,29 @@
require "rails_helper"
RSpec.describe "GET /api/softwares/:name/builds", type: :request do
describe "GET /api/softwares/:name/builds" do
let!(:software) { create(:software, name: "test-game", platform: "love") }
let!(:release) { create(:release, software: software, version: "2.0.0") }
before do
WarpEngine::ReleaseAsset.create!(release: release, kind: "html", path: "/test/html")
end
it "returns per-software build info" do
get "/api/softwares/test-game/builds"
expect(response).to have_http_status(:ok)
json = JSON.parse(response.body)
expect(json["platform"]).to eq("love")
expect(json["expected"]).to include("html", "win_x64")
expect(json["releases"]["2.0.0"]["actual"]).to include("html")
expect(json["releases"]["2.0.0"]["missing"]).to include("win_x64")
end
it "returns 404 for unknown software" do
get "/api/softwares/nonexistent/builds"
expect(response).to have_http_status(:not_found)
end
end
end
+42
View File
@@ -0,0 +1,42 @@
require "rails_helper"
RSpec.describe "GET /api/software", type: :request do
describe "GET /api/software" do
it "returns all software with releases" do
create(:software, name: "test-game", title: "Test Game")
get "/api/software"
expect(response).to have_http_status(:ok)
json = JSON.parse(response.body)
expect(json["softwares"]).to be_an(Array)
expect(json["softwares"].length).to eq(1)
end
it "returns per-release and total download counts" do
software = create(:software)
release = create(:release, software: software)
other = create(:release, software: software)
create_list(:download, 3, release: release)
create(:download, release: other)
get "/api/software"
json = JSON.parse(response.body)
sw = json["softwares"].first
expect(sw["totalDownloads"]).to eq(4)
counts = sw["releases"].to_h { |r| [ r["id"], r["downloadCount"] ] }
expect(counts[release.id]).to eq(3)
expect(counts[other.id]).to eq(1)
end
it "excludes soft-deleted software" do
create(:software, deleted_at: Time.current)
get "/api/software"
json = JSON.parse(response.body)
expect(json["softwares"]).to be_empty
end
end
end
+46
View File
@@ -0,0 +1,46 @@
require "rails_helper"
RSpec.describe "GET /update", type: :request do
before do
allow(WarpEngine.config).to receive(:update_secret).and_return("s3cret")
end
it "rejects requests without a secret" do
get "/update", params: { platform: "tic80", name: "game", version: "1.0" }
expect(response).to have_http_status(:unauthorized)
end
it "rejects requests with a wrong secret" do
get "/update", params: { secret: "wrong", platform: "tic80", name: "game", version: "1.0" }
expect(response).to have_http_status(:unauthorized)
end
it "rejects every request when no secret is configured" do
allow(WarpEngine.config).to receive(:update_secret).and_return(nil)
get "/update", params: { secret: "", platform: "tic80", name: "game", version: "1.0" }
expect(response).to have_http_status(:unauthorized)
end
it "requires a version" do
get "/update", headers: { "X-Update-Secret" => "s3cret" }, params: { platform: "tic80", name: "game" }
expect(response).to have_http_status(:bad_request)
expect(response.body).to eq("Version not provided")
end
it "runs the updater with a valid secret" do
updater = instance_double(WarpEngine::SoftwareUpdater::Tic80Service)
allow(WarpEngine::SoftwareUpdater::Tic80Service).to receive(:new).and_return(updater)
expect(updater).to receive(:update).with("game", "1.0")
get "/update", headers: { "X-Update-Secret" => "s3cret" },
params: { platform: "tic80", name: "game", version: "1.0" }
expect(response).to have_http_status(:ok)
expect(response.body).to eq("Updated")
end
end