#!/usr/bin/env bash set -euo pipefail API_BASE="${API_BASE:-https://wygj-api.localhost}" TOKEN="${TOKEN:-}" CLIENT_ID="${CLIENT_ID:-428a8310cd442757ae699df5d894f051}" fail() { echo "personal-assistant-smoke: $*" >&2 exit 1 } request() { local path="$1" local body_file local status body_file="$(mktemp)" if [[ -n "$TOKEN" ]]; then status="$(curl -ksS --max-time 15 -o "$body_file" -w '%{http_code}' \ -H "Authorization: Bearer $TOKEN" \ -H "clientid: $CLIENT_ID" \ "$API_BASE$path")" || { rm -f "$body_file" fail "request failed: $path" } else status="$(curl -ksS --max-time 15 -o "$body_file" -w '%{http_code}' "$API_BASE$path")" || { rm -f "$body_file" fail "request failed: $path" } fi RESPONSE_BODY="$(tr -d '\n' < "$body_file")" RESPONSE_STATUS="$status" rm -f "$body_file" } assert_protected_or_success() { local label="$1" local path="$2" request "$path" if [[ -z "$TOKEN" ]]; then if [[ "$RESPONSE_STATUS" =~ ^(401|403)$ ]] || printf '%s' "$RESPONSE_BODY" | grep -Eq '"code"[[:space:]]*:[[:space:]]*(401|403)'; then echo "$label=protected" return fi fail "$label allowed anonymous access (HTTP $RESPONSE_STATUS): $RESPONSE_BODY" fi [[ "$RESPONSE_STATUS" == "200" ]] || fail "$label HTTP $RESPONSE_STATUS: $RESPONSE_BODY" printf '%s' "$RESPONSE_BODY" | grep -Eq '"code"[[:space:]]*:[[:space:]]*200([[:space:]]*[,}])' \ || fail "$label business response failed: $RESPONSE_BODY" echo "$label=200" } assert_protected_or_success "memory_candidates" "/api/aihr/personal-assistant/memory-candidates?status=DRAFT" assert_protected_or_success "service_memories" "/api/aihr/service-memories?limit=5" if [[ -z "$TOKEN" ]]; then echo "personal-assistant-smoke: authentication boundary passed; set TOKEN to add read-only authenticated checks" else echo "personal-assistant-smoke: authenticated read-only checks passed" fi