extends "res://tests/test_case.gd" const ControlPlaneClient = preload("res://scripts/control_plane_client.gd") const RankedProfileState = preload("res://scripts/ranked_profile_state.gd") func test_base_url_validation_rejects_ambiguous_or_insecure_values() -> void: assert_true(ControlPlaneClient.is_valid_base_url("http://127.0.0.1:8080"), "local HTTP endpoint is valid") assert_true(ControlPlaneClient.is_valid_base_url("https://match.example"), "HTTPS endpoint is valid") assert_true(not ControlPlaneClient.is_valid_base_url("match.example"), "scheme is required") assert_true(not ControlPlaneClient.is_valid_base_url("http://match.example/"), "trailing slash is normalized before validation") assert_true(not ControlPlaneClient.is_valid_base_url("http://match example"), "whitespace is rejected") assert_true(not ControlPlaneClient.is_valid_base_url("https://user:pass@match.example"), "userinfo is rejected") assert_true(not ControlPlaneClient.is_valid_base_url("https://match.example?token=secret"), "query strings are rejected") var client := ControlPlaneClient.new() assert_true(client.configure("https://match.example", "session-id:opaque-token"), "safe access token configures") assert_true(not client.configure("https://match.example", "token\nforged-header"), "header injection is rejected") func test_ticket_normalization_preserves_payload_and_derives_expiry() -> void: var payload := {"ticket_id": "ticket-1", "state": "QUEUED", "expires_at": "2026-08-31T12:00:00Z"} var normalized := ControlPlaneClient.normalize_ticket(payload) assert_eq(normalized["ticket_id"], "ticket-1", "normalization preserves ticket identity") assert_true(normalized.has("expires_at_unix"), "RFC3339 expiry is available to the projection") assert_true(int(normalized["expires_at_unix"]) > 0, "expiry is converted to a positive epoch") assert_true(not payload.has("expires_at_unix"), "normalization does not mutate the HTTP payload") func test_ranked_profile_is_backend_display_data_and_rejects_unsafe_values() -> void: var profile := RankedProfileState.new() assert_true(profile.apply({"rating": 1500.0, "rd": 200.0, "volatility": 0.06, "ranked_games": 3, "tier": "GOLD", "provisional": true, "season_id": "s1"}), "valid profile applies") assert_eq(profile.display_text(), "Provisional ยท 3 ranked games", "provisional status overrides tier presentation") assert_true(not profile.apply({"rating": -1.0, "rd": 200.0, "volatility": 0.06, "ranked_games": 3, "tier": "GOLD", "provisional": false}), "negative rating is rejected") assert_true(not profile.available, "unsafe response is not displayed") assert_true(not profile.apply({"rating": 1500.0, "rd": 200.0, "volatility": 0.06, "ranked_games": 3, "tier": "", "provisional": false}), "empty tier is rejected") assert_true(not profile.apply({"rating": 1500.0, "rd": 200.0, "volatility": 0.06, "ranked_games": 3, "tier": "GOLD", "provisional": "false"}), "string boolean is rejected")