test: bind the port-sharing test servers to ephemeral ports; guard new fixed ports

Four ports were shared by two files each — 3162 (qr-auth / auth-security), 3170
(multiuser-auth / routes/ws-routes), 3230 and 3231 (cod54-hook-event-auth /
routes/voice-routes). Files run serially (`fileParallelism: false`), so the pairs
never met inside one run; they collide between two runs on one host, or with
anything else holding the port. All six files now bind port 0 and read the
number back (`boundPort` for WebServer, `server.address()` after each listen for
the raw Fastify / ws servers).

test/test-ports-guard.test.ts fails on a WebServer built under test/ whose port
argument is not the literal 0 — `new WebServer(…)`, a subclass, or a destructured
alias (`{ WebServer: T }`, as quick-start.test.ts does) — outside a legacy list of
the 43 files that construct one with a non-zero port today; the follow-up sweep
converts them. A converted file cannot stay listed. What it does not cover (helper
parameters, `import { WebServer as X }`, raw listen sites) is written down in it.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Randalix
2026-10-08 14:56:42 +02:00
co-authored by Claude Opus 5.5
parent 03629c966e
commit bb4e7943c5
7 changed files with 187 additions and 52 deletions
+5 -7
View File
@@ -14,14 +14,12 @@
* 12. QR auth bypass in auth middleware
* 13. GET /api/tunnel/qr SVG endpoint (auth/no-auth, caching, errors)
*
* Port: 3162 (qr-auth tests), 3163 (qr-svg endpoint tests)
* Port: ephemeral (`new WebServer(0, …)`, read back through `boundPort`)
*/
import { describe, it, expect, beforeAll, afterAll, beforeEach } from 'vitest';
import { TunnelManager } from '../src/tunnel-manager.js';
import { WebServer } from '../src/web/server.js';
const QR_AUTH_PORT = 3162;
const QR_SVG_PORT = 3163;
const TEST_PASS = 'qr-test-pass-xyz';
const TEST_USER = 'admin';
@@ -312,9 +310,9 @@ describe('QR Auth Integration', () => {
beforeAll(async () => {
process.env.CODEMAN_PASSWORD = TEST_PASS;
process.env.CODEMAN_USERNAME = TEST_USER;
server = new WebServer(QR_AUTH_PORT, false, true);
server = new WebServer(0, false, true);
await server.start();
baseUrl = `http://localhost:${QR_AUTH_PORT}`;
baseUrl = `http://localhost:${server.boundPort}`;
});
afterAll(async () => {
@@ -608,9 +606,9 @@ describe('QR SVG Endpoint (GET /api/tunnel/qr)', () => {
beforeAll(async () => {
process.env.CODEMAN_PASSWORD = TEST_PASS;
process.env.CODEMAN_USERNAME = TEST_USER;
server = new WebServer(QR_SVG_PORT, false, true);
server = new WebServer(0, false, true);
await server.start();
baseUrl = `http://localhost:${QR_SVG_PORT}`;
baseUrl = `http://localhost:${server.boundPort}`;
});
afterAll(async () => {