|
| 1 | +#include <catch2/catch_test_macros.hpp> |
| 2 | +#include <crow/json.h> |
| 3 | + |
| 4 | +#include "mcp_dry_run.hpp" |
| 5 | + |
| 6 | +namespace flapi { |
| 7 | +namespace test { |
| 8 | + |
| 9 | +TEST_CASE("MCPDryRun::extractFlag: missing key yields false and no change", |
| 10 | + "[security][mcp][dryrun]") { |
| 11 | + crow::json::wvalue args; |
| 12 | + args["id"] = 42; |
| 13 | + |
| 14 | + bool extracted = MCPDryRun::extractFlag(args); |
| 15 | + |
| 16 | + REQUIRE_FALSE(extracted); |
| 17 | + // The original argument must still be present. |
| 18 | + auto dumped = args.dump(); |
| 19 | + REQUIRE(dumped.find("\"id\":42") != std::string::npos); |
| 20 | +} |
| 21 | + |
| 22 | +TEST_CASE("MCPDryRun::extractFlag: _dryRun=true is consumed and returns true", |
| 23 | + "[security][mcp][dryrun]") { |
| 24 | + crow::json::wvalue args; |
| 25 | + args["id"] = 42; |
| 26 | + args["_dryRun"] = true; |
| 27 | + |
| 28 | + bool extracted = MCPDryRun::extractFlag(args); |
| 29 | + |
| 30 | + REQUIRE(extracted); |
| 31 | + auto dumped = args.dump(); |
| 32 | + // The flag must be stripped so downstream validators do not see it. |
| 33 | + REQUIRE(dumped.find("_dryRun") == std::string::npos); |
| 34 | + // Other arguments must survive untouched. |
| 35 | + REQUIRE(dumped.find("\"id\":42") != std::string::npos); |
| 36 | +} |
| 37 | + |
| 38 | +TEST_CASE("MCPDryRun::extractFlag: _dryRun=false is consumed and returns false", |
| 39 | + "[security][mcp][dryrun]") { |
| 40 | + crow::json::wvalue args; |
| 41 | + args["_dryRun"] = false; |
| 42 | + |
| 43 | + bool extracted = MCPDryRun::extractFlag(args); |
| 44 | + |
| 45 | + REQUIRE_FALSE(extracted); |
| 46 | + auto dumped = args.dump(); |
| 47 | + REQUIRE(dumped.find("_dryRun") == std::string::npos); |
| 48 | +} |
| 49 | + |
| 50 | +TEST_CASE("MCPDryRun::extractFlag: non-boolean _dryRun is rejected and stripped", |
| 51 | + "[security][mcp][dryrun]") { |
| 52 | + // A string or numeric _dryRun is treated as not-set; we still strip the |
| 53 | + // key so it never reaches the validator. This is conservative: only an |
| 54 | + // explicit boolean true engages dry-run. |
| 55 | + crow::json::wvalue args; |
| 56 | + args["_dryRun"] = "yes"; |
| 57 | + |
| 58 | + bool extracted = MCPDryRun::extractFlag(args); |
| 59 | + |
| 60 | + REQUIRE_FALSE(extracted); |
| 61 | + auto dumped = args.dump(); |
| 62 | + REQUIRE(dumped.find("_dryRun") == std::string::npos); |
| 63 | +} |
| 64 | + |
| 65 | +TEST_CASE("MCPDryRun::formatResult: produces JSON with dry_run, tool, sql, params", |
| 66 | + "[security][mcp][dryrun]") { |
| 67 | + std::map<std::string, std::string> params = { |
| 68 | + {"id", "42"}, |
| 69 | + {"region", "EU"}, |
| 70 | + }; |
| 71 | + std::string rendered = "SELECT * FROM customers WHERE id = 42 AND region = 'EU'"; |
| 72 | + |
| 73 | + std::string payload = MCPDryRun::formatResult("customer_lookup", rendered, params); |
| 74 | + |
| 75 | + auto parsed = crow::json::load(payload); |
| 76 | + REQUIRE(parsed); |
| 77 | + REQUIRE(parsed["dry_run"].b() == true); |
| 78 | + REQUIRE(parsed["tool_name"].s() == std::string("customer_lookup")); |
| 79 | + REQUIRE(parsed["rendered_sql"].s() == rendered); |
| 80 | + // Parameters must round-trip as a JSON object keyed by name. |
| 81 | + REQUIRE(parsed["parameters"]["id"].s() == std::string("42")); |
| 82 | + REQUIRE(parsed["parameters"]["region"].s() == std::string("EU")); |
| 83 | +} |
| 84 | + |
| 85 | +TEST_CASE("MCPDryRun::formatResult: empty parameter map still emits a parameters object", |
| 86 | + "[security][mcp][dryrun]") { |
| 87 | + std::string payload = MCPDryRun::formatResult( |
| 88 | + "no_arg_tool", "SELECT 1", /*parameters=*/{}); |
| 89 | + |
| 90 | + auto parsed = crow::json::load(payload); |
| 91 | + REQUIRE(parsed); |
| 92 | + REQUIRE(parsed["dry_run"].b() == true); |
| 93 | + REQUIRE(parsed.has("parameters")); |
| 94 | +} |
| 95 | + |
| 96 | +} // namespace test |
| 97 | +} // namespace flapi |
0 commit comments