import { NextResponse } from "next/server"; // THE /api/test ROUTES EXIST ONLY WHEN THE E2E HARNESS STARTED THIS SERVER. // // Every route under this directory is UNAUTHENTICATED and every one of them // mutates live process state: it drops the job registry and the runner // singletons, fabricates a stuck job, restarts a lane — and `worker-token` // SETS A CREDENTIAL. An unauthenticated `GET /api/test/worker-token?set=x` // hands the caller a token of its own choosing for `/api/ops/*` and // `/api/worker/*`; `?unset=1` is a remote kill switch for both. As plain GETs, // all of that is reachable by CSRF from any page the operator's browser loads, // which is why binding to loopback is not an answer — the browser is inside the // loopback. The Caddyfile has no path rule for `/api/test` either. // // So the surface is opt-in, the way the worker endpoint is: `E2E_TEST_ROUTES=1` // is set by editor/playwright.config.ts's E2E_SERVER_ENV, on the webServer that // runs `dev:test` / `start:test` — the one launch the host suite, the sharded // runner and Dockerfile.test all go through — and by nothing else. A real // editor never sets it, and neither does a hand-started `pnpm dev:test`. // // 404 AND NOT 403, deliberately: the answer must be indistinguishable from a // route that was never built. A 403 advertises that the harness exists and that // there is an env var worth guessing. export function testRouteDenied(): NextResponse | null { if (process.env.E2E_TEST_ROUTES === "1") return null; return NextResponse.json({ error: "Not Found" }, { status: 404 }); }