test: cover the config-editor globals regression + secrets surfaces

- endpoint-level: a deployment/program edit via /config/* leaves castle.yaml
  globals byte-identical (the exact regression that shipped — the endpoints were
  tested but nobody asserted globals survived)
- write_program_file leaves globals untouched (core)
- /secrets/info reports the backend

Still uncovered (tracked): castle mesh CLI, direct-read refactor (dns/stacks),
backend-aware doctor, and all frontend (no test runner configured).
This commit is contained in:
2026-07-07 08:46:38 -07:00
parent faa9a99a5a
commit d6f5678948
3 changed files with 58 additions and 0 deletions

View File

@@ -22,3 +22,12 @@ def test_set_override_rejected_on_file_backend(client: TestClient) -> None:
def test_get_missing_override_is_404(client: TestClient) -> None:
assert client.get("/secrets/overrides/primer/NOPE").status_code == 404
def test_secrets_info_reports_backend(client: TestClient) -> None:
r = client.get("/secrets/info")
assert r.status_code == 200
body = r.json()
assert body["backend"] == "file" # conftest forces file in tests
assert body["writable"] is True
assert "role" in body