Step 11 (Run Tests) is recorded as PASS based on the implement skill's
internal Step 16 gate (./scripts/run-tests.sh --full, all-green) per
test-run/SKILL.md § Functional Mode — same runner, immediately
preceding invocation, no value in a second run.
Step 12 (Test-Spec Sync, cycle-update mode):
- traceability-matrix.md: rows added for AZ-491 AC-1..AC-6,
AZ-493 AC-1..AC-6, AZ-495 (doc convention), AZ-496 AC-1..AC-N
(dependency bump); AZ-494 AC-1/AC-2 rows now cross-reference
new SEC-12 / SEC-13 blackbox IDs.
- security-tests.md: SEC-12 (wrong iss returns 401) and SEC-13
(wrong aud returns 401) appended for AZ-494.
- environment.md: Environment Variables table extended with
GOOGLE_MAPS_API_KEY, JWT_SECRET, JWT_ISSUER, JWT_AUDIENCE,
INTEGRATION_TEST_DB_RESET. Closes a cycle-2 oversight where
JWT_SECRET was never recorded.
Step 13 (Update Docs, task mode):
- tests_unit.md: consolidated the duplicate
AuthenticationServiceCollectionExtensionsTests entry that
spanned AZ-487 + AZ-494 into one coherent block.
- ripple_log_cycle3.md created: per-task source files +
every doc that was touched (architecture, module-layout,
api_program, tests_unit, tests_integration, traceability,
performance-tests, security-tests, environment, security_report,
owasp_review, deploy_cycle2, retro_2026-05-11_cycle2). Notes
which docs were intentionally NOT touched and the open
cross-repo doc ripple (AC-7).
Autodev state advanced to Step 13 completed. Next: Step 14 Security
Audit (optional gate).
Co-authored-by: Cursor <cursoragent@cursor.com>
4.8 KiB
Module: Tests/SatelliteProvider.Tests
Purpose
Unit test project for component-internal logic. Original AZ-2/AZ-3 era had only a placeholder dummy; the suite has since grown across the AZ-285..AZ-380 baseline + cycle 1 (AZ-484) + cycle 2 (AZ-487, AZ-488) tracks. The "dummy test only" note in older revisions of this file is obsolete — the project now hosts the full unit suite executed by scripts/run-tests.sh --unit-only and CI's 01-test.yml.
Public Interface (test classes)
Existing baseline (pre-cycle-2) test classes cover TileService, RegionService, RouteService, geo math, repositories, validators, idempotency, and migration helpers — not enumerated exhaustively here. Cycle-2 additions:
AZ-487 + AZ-494 — JWT validation baseline + iss/aud
Authentication/AuthenticationServiceCollectionExtensionsTests— coversAddSatelliteJwtregistration +TokenValidationParametersshape across both AZs:- AZ-487 baseline:
AddSatelliteJwt_RegistersJwtBearerScheme,AddSatelliteJwt_ThrowsOnMissingSecret,AddSatelliteJwt_ThrowsOnShortSecret. - AZ-494 extension:
AddSatelliteJwt_ThrowsOnMissingIssuer,_ThrowsOnEmptyIssuer,_ThrowsOnMissingAudience,_ThrowsOnEmptyAudience, plus updated_ConfiguresTokenValidationParameters_AsPerContractand_PrefersEnvironmentVariableOverConfigurationassertingValidateIssuer = true+ValidIssuer+ValidateAudience = true+ValidAudience.
- AZ-487 baseline:
Authentication/JwtTokenFactoryTests—Create_ProducesTokenValidatedByMatchingParameters,CreateExpired_TokenFailsValidationWithLifetimeException,Create_WithExtraClaims_PropagatesClaimsThroughValidation,TamperSignature_TokenFailsValidationWithSignatureException. The factory itself lives inSatelliteProvider.TestSupportafter AZ-491 (single source of truth); this project consumes it viaProjectReference.
AZ-488 — UAV tile upload
UavTileQualityGateTests— one happy path + ≥ 1 reject path per rule (Rule 1 INVALID_FORMAT × 2, Rule 2 SIZE_OUT_OF_BAND × 2, Rule 3 WRONG_DIMENSIONS × 1, Rule 4 CAPTURED_AT_FUTURE / _TOO_OLD × 2, Rule 5 IMAGE_TOO_UNIFORM × 1) + rule-ordering determinism. Uses aFixedTimeProviderfor Rule-4 isolation andUavTileImageFactoryfor deterministic JPEG fixtures.UavTileUploadHandlerTests— end-to-end with a mockedITileRepository: 1-item happy path, 3-item mixed batch (file written +InsertAsynccalled only for accepted), per-source UPSERT pass-through.UavTileFilePathTests— verifiesBuildUavTileFilePathproducestiles/uav/{z}/{x}/{y}.jpgfor sample (z, x, y) tuples and that integer-typed coordinates make string-injection of path traversal impossible.Authentication/PermissionsRequirementTests—PermissionsAuthorizationHandlercorrectly accepts apermissionsclaim shaped as a single string OR as a JSON array, rejects when the requested permission is absent, and short-circuits when the principal has nopermissionsclaim at all.TestUtilities/UavTileImageFactory— programmatic JPEG factories used by the gate + handler tests:CreateValidJpeg(width, height, seed),CreateUniformJpeg,CreatePng(for Rule 1 negative path).
Internal Logic
- Tests follow Arrange / Act / Assert. Time-dependent paths inject a
FixedTimeProvider(cycle-2 addition) so Rule 4 has deterministic age windows. JwtSecurityTokenHandler.MapInboundClaims = falseis set explicitly in JWT tests so claims read by their original names (sub,permissions, …) rather than the framework-remapped names.
Dependencies
- Project references:
SatelliteProvider.Services.TileDownloader,SatelliteProvider.Services.RegionProcessing,SatelliteProvider.Services.RouteManagement,SatelliteProvider.Common,SatelliteProvider.DataAccess,SatelliteProvider.Api(for the Authentication tests — added in AZ-487),SatelliteProvider.TestSupport(added by AZ-491; provides the canonicalJwtTokenFactoryconsumed by both this project andSatelliteProvider.IntegrationTests). - NuGet: xUnit (2.5.3), Moq (4.20.72), FluentAssertions (8.8.0), coverlet.collector (6.0.0), Microsoft.NET.Test.Sdk (17.8.0), Microsoft.Extensions.* (Caching.Memory, Configuration, DI, Logging, Options, Http),
Microsoft.AspNetCore.Authentication.JwtBearer8.0.25 (consumed transitively via theProjectReferencetoSatelliteProvider.Api; AZ-487 added the dependency at 8.0.21, AZ-496 bumped it to 8.0.25),SixLabors.ImageSharp3.1.11 (added by AZ-488 for the gate tests). appsettings.jsoncopied to output (used by Authentication tests for theJwtsection binding scenario).
Consumers
- CI pipeline (
01-test.yml) andscripts/run-tests.sh --unit-onlyrundotnet testagainst this project.
Tests
This IS the test module. Cycle-2 added ~25 unit tests on top of the existing baseline; the full project executes in seconds (no external services required).