/**
 * P0-7 smoke test — GET /api/users restricted to ADMIN.
 *
 * Run: npx tsx scripts/smoke/p0-7-users-list.ts
 *
 * Drives the GET handler directly with mocked dependencies, so no live
 * server is required.
 */
import { ok, fail } from './_lib';

// Monkey-patch the modules the route file imports.
const nextAuth = require('next-auth/next') as { getServerSession: (...args: unknown[]) => Promise<unknown> };
const prismaMod = require('../../src/lib/prisma') as { prisma: Record<string, unknown> };

let sessionFixture: unknown = null;
nextAuth.getServerSession = async () => sessionFixture;
prismaMod.prisma.user = {
    findMany: async () => [],
} as unknown;

const route = require('../../src/app/api/users/route') as typeof import('../../src/app/api/users/route');

async function expectStatus(label: string, want: number): Promise<void> {
    const res = await route.GET();
    if (res.status !== want) {
        const body = await res.text();
        fail(label, `expected ${want}, got ${res.status} body=${body}`);
    }
    ok(label, `status ${res.status}`);
}

async function main(): Promise<void> {
    sessionFixture = null;
    await expectStatus('no session → 401', 401);

    sessionFixture = { user: { id: '42', role: 'VIEWER' } };
    await expectStatus('VIEWER → 403', 403);

    sessionFixture = { user: { id: '42', role: 'EDITOR' } };
    await expectStatus('EDITOR → 403', 403);

    sessionFixture = { user: { id: '1', role: 'ADMIN' } };
    await expectStatus('ADMIN → 200', 200);

    ok('P0-7 users-list', 'directory restricted to ADMIN');
}

main().catch((err) => fail('P0-7 users-list', String(err)));
