/**
 * debug-endpoints-gone smoke (2026-06-15).
 *
 * The temporary diagnostic/seed endpoints (api/debug/env, api/debug/notifications,
 * api/seed) were removed — they were caller-less dead surface (the debug/env
 * route self-declared "to be removed after the 2FA prod outage 2026-05-31" and
 * an ADMIN could read live env/2FA state in prod through it). This structural
 * smoke fails if any of them is reintroduced, so the attack surface can't
 * silently come back.
 */
import './_lib';
import { ok, fail } from './_lib';
import { existsSync } from 'fs';
import path from 'path';

const ROOT = path.resolve(__dirname, '../..');

const GONE = [
    'src/app/api/debug/env/route.ts',
    'src/app/api/debug/notifications/route.ts',
    'src/app/api/seed/route.ts',
];

function main(): void {
    for (const rel of GONE) {
        if (existsSync(path.join(ROOT, rel))) {
            fail('debug-endpoints-gone', `${rel} was reintroduced — remove it (caller-less diagnostic/seed surface must not ship).`);
        }
        ok(`removed: ${rel}`);
    }
    ok('debug-endpoints-gone', 'diagnostic/seed endpoints remain absent');
}

main();
