import { describe, expect, it } from "vitest";
import { decryptCredential, encryptCredential } from "./credential-crypto";

describe("site credential encryption", () => {
  it("round-trips a token without storing it in plaintext", () => {
    const encrypted = encryptCredential("sensitive-test-token", "test-key-material");
    expect(encrypted).not.toContain("sensitive-test-token");
    expect(decryptCredential(encrypted, "test-key-material")).toBe("sensitive-test-token");
  });

  it("rejects a different key or tampered ciphertext", () => {
    const encrypted = encryptCredential("sensitive-test-token", "test-key-material");
    expect(() => decryptCredential(encrypted, "wrong-key")).toThrow();
    const parts = encrypted.split(":");
    parts[3] = (parts[3][0] === "A" ? "B" : "A") + parts[3].slice(1);
    expect(() => decryptCredential(parts.join(":"), "test-key-material")).toThrow();
  });
});
