diff --git a/apps/api/src/index.ts b/apps/api/src/index.ts index ca93be5f..666c3e5a 100644 --- a/apps/api/src/index.ts +++ b/apps/api/src/index.ts @@ -104,19 +104,10 @@ await teamsRoutes(app); await docsRoutes(app); // Public health check (minimal - no internal details) -app.get("/api/v1/health", async () => { - let dbOk = false; - try { - db.select().from(schema.settings).limit(1).all(); - dbOk = true; - } catch { - /* db unreachable */ - } - return { - status: dbOk ? "healthy" : "degraded", - version: APP_VERSION, - }; -}); +app.get("/api/v1/health", async () => ({ + status: "ok", + version: APP_VERSION, +})); // Admin health check (full diagnostics) app.get("/api/v1/admin/health", async (request, reply) => { diff --git a/tests/integration/api.test.ts b/tests/integration/api.test.ts index e93c4cb0..629005a5 100644 --- a/tests/integration/api.test.ts +++ b/tests/integration/api.test.ts @@ -1164,7 +1164,7 @@ describe("Health & Config", () => { }); expect(res.statusCode).toBe(200); const body = JSON.parse(res.body); - expect(body.status).toBe("healthy"); + expect(body.status).toBe("ok"); expect(body.version).toBeDefined(); expect(body.uptime).toBeUndefined(); expect(body.database).toBeUndefined(); @@ -1206,6 +1206,29 @@ describe("Health & Config", () => { }); expect(res.statusCode).toBe(401); }); + + it("returns 403 for authenticated non-admin user", async () => { + // Create a regular user and log in as them + await app.inject({ + method: "POST", + url: "/api/auth/register", + headers: { authorization: `Bearer ${adminToken}` }, + payload: { username: "health_nonadmin", password: "Password1234", role: "user" }, + }); + const loginRes = await app.inject({ + method: "POST", + url: "/api/auth/login", + payload: { username: "health_nonadmin", password: "Password1234" }, + }); + const userToken = JSON.parse(loginRes.body).token; + + const res = await app.inject({ + method: "GET", + url: "/api/v1/admin/health", + headers: { authorization: `Bearer ${userToken}` }, + }); + expect(res.statusCode).toBe(403); + }); }); describe("GET /api/v1/config/auth", () => { diff --git a/tests/integration/test-server.ts b/tests/integration/test-server.ts index 75ece0dd..c44b25ed 100644 --- a/tests/integration/test-server.ts +++ b/tests/integration/test-server.ts @@ -116,19 +116,10 @@ export async function buildTestApp(): Promise { await docsRoutes(app); // Public health check (minimal - no internal details) - app.get("/api/v1/health", async () => { - let dbOk = false; - try { - db.select().from(schema.settings).limit(1).all(); - dbOk = true; - } catch { - /* db unreachable */ - } - return { - status: dbOk ? "healthy" : "degraded", - version: APP_VERSION, - }; - }); + app.get("/api/v1/health", async () => ({ + status: "ok", + version: APP_VERSION, + })); // Admin health check (full diagnostics) app.get("/api/v1/admin/health", async (request, reply) => {