cli: avoid data-dir initialization for version; create db parent dirs; redact generated passwords in CLI output

- Prevent 'nx9-wg version' from creating data directories by avoiding database initialization.
- Create parent directories when an explicit --database path is provided.
- Redact printed generated administrator passwords; announce file path or redact instead.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
thakaresandCopilot committed 2026-08-16 16:26:24 +05:30
commit 2ac6c81dfe
140 files changed
+31342

No files matched your search

@@ -0,0 +1,106 @@
//! Tests for client profile repository operations and built-in profiles.
use nx9_wg_core::types::client_profile::{ClientProfile, ConnectionType, DeviceCategory, NatType};
use nx9_wg_db::Store;
#[tokio::test]
async fn test_client_profiles_crud_and_builtin_protection() {
let store = Store::connect_in_memory().await.unwrap();
store.migrate().await.unwrap();
// Verify built-in profiles pre-populated by migration
let profiles = store.list_client_profiles().await.unwrap();
assert!(
profiles.len() >= 10,
"expected at least 10 built-in profiles"
);
// Check specific built-ins
let mobile = store.get_client_profile("default-mobile").await.unwrap();
assert!(mobile.is_some());
let mobile = mobile.unwrap();
assert_eq!(mobile.connection_type, ConnectionType::Mobile);
assert_eq!(mobile.mtu, 1280);
assert_eq!(mobile.persistent_keepalive, Some(25));
assert!(mobile.is_builtin);
let cgnat = store.get_client_profile("default-cgnat").await.unwrap();
assert!(cgnat.is_some());
let cgnat = cgnat.unwrap();
assert_eq!(cgnat.nat_type, NatType::Cgnat);
assert_eq!(cgnat.mtu, 1360);
// Verify built-in cannot be modified or deleted
let mut modified_builtin = mobile.clone();
modified_builtin.mtu = 1400;
assert!(
store
.update_client_profile(&modified_builtin)
.await
.is_err()
);
assert!(store.delete_client_profile("default-mobile").await.is_err());
// Create a custom profile
let now = chrono::Utc::now().naive_utc();
let custom = ClientProfile {
id: "office-fiber".to_string(),
name: "Office Fiber Direct".to_string(),
provider: Some("att".to_string()),
device: Some(DeviceCategory::Linux),
connection_type: ConnectionType::Wired,
nat_type: NatType::Direct,
mtu: 1420,
dns: Some("1.1.1.1, 1.0.0.1".to_string()),
persistent_keepalive: Some(15),
is_builtin: false,
description: Some("Direct fiber connection at headquarters".to_string()),
created_at: now,
updated_at: now,
};
store.create_client_profile(&custom).await.unwrap();
let fetched = store
.get_client_profile("office-fiber")
.await
.unwrap()
.unwrap();
assert_eq!(fetched.name, "Office Fiber Direct");
assert_eq!(fetched.provider.as_deref(), Some("att"));
assert_eq!(fetched.mtu, 1420);
assert!(!fetched.is_builtin);
// Update custom profile
let mut updated = fetched.clone();
updated.description = Some("Updated headquarters fiber".to_string());
updated.mtu = 1440;
store.update_client_profile(&updated).await.unwrap();
let fetched_updated = store
.get_client_profile("office-fiber")
.await
.unwrap()
.unwrap();
assert_eq!(fetched_updated.mtu, 1440);
assert_eq!(
fetched_updated.description.as_deref(),
Some("Updated headquarters fiber")
);
// List distinct providers
let providers = store.list_distinct_providers().await.unwrap();
assert!(providers.contains(&"att".to_string()));
assert!(providers.contains(&"tmobile".to_string()));
assert!(providers.contains(&"starlink".to_string()));
// Delete custom profile
store.delete_client_profile("office-fiber").await.unwrap();
assert!(
store
.get_client_profile("office-fiber")
.await
.unwrap()
.is_none()
);
}