package exploit

import (
	"context"
	"testing"

	"github.com/Armur-Ai/Pentest-Swarm-AI/internal/pipeline"
	"github.com/Armur-Ai/Pentest-Swarm-AI/internal/scope"
	"github.com/google/uuid"
)

func TestSafeMode_RejectsDestructiveTokens(t *testing.T) {
	e := NewExecutor(&scope.ScopeDefinition{AllowedDomains: []string{"example.com"}}, nil, false).
		WithSafeMode(true)

	for _, cmd := range []string{
		"rm -rf /tmp/evidence",
		"curl example.com -X POST -d 'drop table users'",
		"kill -9 1234",
		"chmod 777 /etc/passwd",
	} {
		step := pipeline.AttackStep{ID: uuid.New(), Name: "t", Command: cmd}
		_, err := e.Execute(context.Background(), step, uuid.New())
		if err == nil {
			t.Errorf("safe-mode should block %q", cmd)
		}
	}
}

func TestSafeMode_OffAllowsDestructive(t *testing.T) {
	// With safe-mode OFF, the same commands fail for OTHER reasons
	// (missing binary, out-of-scope target) but NOT the safe-mode block.
	e := NewExecutor(&scope.ScopeDefinition{AllowedDomains: []string{"example.com"}}, nil, true)

	step := pipeline.AttackStep{ID: uuid.New(), Name: "t", Command: "echo drop"}
	res, err := e.Execute(context.Background(), step, uuid.New())
	// dry-run returns success without running — safe-mode didn't block.
	if err != nil {
		t.Fatalf("safe-mode off + dry-run should not fail: %v", err)
	}
	if res == nil || !res.Success {
		t.Fatalf("dry-run should succeed; got %+v", res)
	}
}
