#!/usr/bin/env bash

# panama-keyring reports the login keyring's state, and the Settings page reads
# nothing but its JSON.
#
# The state that matters is LOCKED, and it is also the one that cannot be
# rehearsed on a real desktop: locking the login keyring breaks every saved
# password on the machine and can only be undone by typing the password into a
# dialog. So the secret service is stubbed here instead. Nothing touches the
# real keyring -- this contract is safe to run on the daily driver, which is the
# entire reason it is written this way.

set -uo pipefail

repo_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)"
helper="$repo_dir/config/dot/quickshell/scripts/panama-keyring"

fail() {
    printf 'keyring helper contract: %s\n' "$1" >&2
    exit 1
}

stub_dir="$(mktemp -d /tmp/panama-keyring.XXXXXX)"
trap 'rm -rf "$stub_dir"' EXIT

# A stand-in for the `gi` module the helper imports. PANAMA_KEYRING_FAKE decides
# what the fake service reports, so one stub covers every case.
mkdir -p "$stub_dir/gi/repository"
cat >"$stub_dir/gi/__init__.py" <<'STUB'
def require_version(*_args, **_kwargs):
    return None
STUB
cat >"$stub_dir/gi/repository/__init__.py" <<'STUB'
import os


class _Collection:
    def __init__(self, label, locked):
        self._label = label
        self._locked = locked

    def get_label(self):
        return self._label

    def get_locked(self):
        return self._locked


class _Service:
    def get_collections(self):
        mode = os.environ.get("PANAMA_KEYRING_FAKE", "unlocked")
        if mode == "nologin":
            return [_Collection("Some App", False)]
        return [_Collection("Login", mode == "locked"), _Collection("", False)]


class _ServiceFactory:
    @staticmethod
    def get_sync(_flags, _cancellable):
        if os.environ.get("PANAMA_KEYRING_FAKE") == "unavailable":
            raise RuntimeError("no secret service")
        return _Service()

    # unlock_sync is what the `unlock` action calls; record that it was reached.
    @staticmethod
    def _noop(*_args, **_kwargs):
        return None


class Secret:
    class ServiceFlags:
        LOAD_COLLECTIONS = 1

    Service = _ServiceFactory
STUB

run() {
    PYTHONPATH="$stub_dir" PANAMA_KEYRING_FAKE="$1" python3 "$helper" "${2:-status}"
}

# ── Unlocked: the normal state after any sign-in ─────────────────────────────
out="$(run unlocked)"
jq -e . >/dev/null 2>&1 <<<"$out" || fail "status did not emit JSON: $out"
jq -e '.available == true and .locked == false and .hasLogin == true' >/dev/null <<<"$out" \
    || fail "an unlocked login keyring was misreported: $out"

# ── Locked: the state the whole card exists for ──────────────────────────────
out="$(run locked)"
jq -e '.available == true and .locked == true' >/dev/null <<<"$out" \
    || fail "a locked login keyring was not reported as locked: $out"

# ── No secret service at all is a state, not a crash ─────────────────────────
out="$(run unavailable)"
jq -e . >/dev/null 2>&1 <<<"$out" \
    || fail "a missing secret service produced no JSON, so the page would show nothing: $out"
jq -e '.available == false and .error != ""' >/dev/null <<<"$out" \
    || fail "a missing secret service must be reported with a reason: $out"

# ── No login keyring: not locked, because there is nothing to lock ───────────
out="$(run nologin)"
jq -e '.available == true and .hasLogin == false and .locked == false' >/dev/null <<<"$out" \
    || fail "a machine with no login keyring must not report itself locked: $out"

# ── The daemon origin is reported, since it is the crash diagnostic ──────────
jq -e '.daemon | test("^(pam|dbus|none|unknown)$")' >/dev/null <<<"$(run unlocked)" \
    || fail "the daemon origin must be one of pam/dbus/none/unknown"

printf 'keyring helper contract: PASS\n'
