/**
 * auditor-zod-validation smoke — guards the 2026-06-01 T1D fix.
 *
 * Auditor finding: four routes hand-parsed request bodies without
 * Zod schema validation:
 *   - /api/search        (searchParams, no length cap)
 *   - /api/notifications/test (req.json with only existence check)
 *   - /api/executive/tokens (POST + DELETE)
 *   - /api/chat          (parseJsonBounded for size, no shape check)
 *
 * Fix: each route now imports its schema from @/lib/validations and
 * calls .safeParse on the input, returning 400 on failure.
 *
 * This smoke walks each route + schema file and asserts the wiring
 * stays in place.
 */
import './_lib';
import { ok, fail } from './_lib';
import { readFileSync, existsSync } from 'fs';
import path from 'path';

const ROOT = path.resolve(__dirname, '../..');
const read = (rel: string): string => readFileSync(path.join(ROOT, rel), 'utf8');

function assert(label: string, cond: boolean, detail: string): void {
    if (!cond) fail(label, detail);
    ok(label);
}

function main(): void {
    // Schema files exist.
    const schemaFiles = [
        'src/lib/validations/search.schema.ts',
        'src/lib/validations/notification-test.schema.ts',
        'src/lib/validations/executive-token.schema.ts',
        'src/lib/validations/chat.schema.ts',
    ];
    for (const f of schemaFiles) {
        assert(`schema present: ${path.basename(f)}`, existsSync(path.join(ROOT, f)), `${f} missing`);
    }

    // Each is re-exported from the index barrel.
    const index = read('src/lib/validations/index.ts');
    for (const f of schemaFiles) {
        const base = path.basename(f, '.ts');
        assert(`index exports: ${base}`,
            new RegExp(`export\\s+\\*\\s+from\\s+['"]\\.\\/${base}['"]`).test(index),
            `index.ts no longer exports ./${base}`);
    }

    // /api/search uses searchQuerySchema.safeParse.
    const search = read('src/app/api/search/route.ts');
    assert('search route: imports searchQuerySchema', /searchQuerySchema/.test(search),
        'search route no longer imports searchQuerySchema.');
    assert('search route: calls safeParse',
        /searchQuerySchema\.safeParse\(/.test(search),
        'search route no longer calls searchQuerySchema.safeParse — input is hand-parsed.');

    // /api/notifications/test uses testNotificationSchema.
    const notif = read('src/app/api/notifications/test/route.ts');
    assert('notifications/test: imports testNotificationSchema',
        /testNotificationSchema/.test(notif),
        'notifications/test no longer imports testNotificationSchema.');
    assert('notifications/test: calls safeParse',
        /testNotificationSchema\.safeParse\(/.test(notif),
        'notifications/test no longer calls testNotificationSchema.safeParse.');

    // /api/executive/tokens uses both createExecTokenSchema + deleteExecTokenSchema.
    const exec = read('src/app/api/executive/tokens/route.ts');
    assert('executive/tokens: imports both schemas',
        /createExecTokenSchema/.test(exec) && /deleteExecTokenSchema/.test(exec),
        'executive/tokens no longer imports both auditor T1D schemas.');
    assert('executive/tokens: POST calls createExecTokenSchema.safeParse',
        /createExecTokenSchema\.safeParse\(/.test(exec),
        'executive/tokens POST no longer calls createExecTokenSchema.safeParse.');
    assert('executive/tokens: DELETE calls deleteExecTokenSchema.safeParse',
        /deleteExecTokenSchema\.safeParse\(/.test(exec),
        'executive/tokens DELETE no longer calls deleteExecTokenSchema.safeParse.');

    // /api/chat uses chatRequestSchema.
    const chat = read('src/app/api/chat/route.ts');
    assert('chat: imports chatRequestSchema', /chatRequestSchema/.test(chat),
        'chat route no longer imports chatRequestSchema.');
    assert('chat: calls safeParse on body',
        /chatRequestSchema\.safeParse\(/.test(chat),
        'chat route no longer calls chatRequestSchema.safeParse.');

    // Unit test coverage exists.
    assert('test file: auditor-t1d.test.ts exists',
        existsSync(path.join(ROOT, 'src/lib/validations/__tests__/auditor-t1d.test.ts')),
        'Auditor T1D schema test file missing.');

    ok('auditor-zod-validation', 'all 4 hand-parsing routes now use Zod schemas');
}

main();
