import unittest from unittest.mock import patch from backend.app.config import Settings from backend.app.routers.site import _build_site_info class WelcomeSiteTests(unittest.TestCase): def test_public_response_does_not_expose_playback_url(self): with patch('backend.app.routers.site.get_runtime_settings', return_value=Settings().model_copy(update={'jellyfin_public_url': 'https://watch.example.com'})): self.assertNotIn('mediaServerUrl', _build_site_info(False)) def test_authenticated_response_uses_public_playback_url(self): with patch('backend.app.routers.site.get_runtime_settings', return_value=Settings().model_copy(update={'jellyfin_public_url': 'https://watch.example.com/web/'})): self.assertEqual(_build_site_info(True)['mediaServerUrl'], 'https://watch.example.com/web/') def test_missing_unsafe_or_credential_urls_have_no_watch_link(self): for url in ['', 'javascript:alert(1)', '//internal', 'https://user:secret@example.com', 'https://[broken']: with self.subTest(url=url), patch('backend.app.routers.site.get_runtime_settings', return_value=Settings().model_copy(update={'jellyfin_public_url': url})): self.assertIsNone(_build_site_info(True)['mediaServerUrl'])