/**
 * PR-29 smoke — Entra ID provider wires in when env is set.
 *
 * Test the boot-time provider assembly contract:
 *   - With AZURE_AD_CLIENT_ID + SECRET set, the Azure AD provider
 *     is in the authOptions.providers list.
 *   - Without those env vars, only Credentials (+ optionally Google)
 *     is present.
 *
 * Run: npx tsx scripts/smoke/pr29-entra-sso.ts
 */
import './_lib';
import { ok, fail } from './_lib';

// Set env BEFORE importing auth.ts (the providers array is built at
// module evaluation time).
process.env.AZURE_AD_CLIENT_ID = 'test-client-id';
process.env.AZURE_AD_CLIENT_SECRET = 'test-client-secret-value';
process.env.AZURE_AD_TENANT_ID = 'common';

async function main(): Promise<void> {
    const authMod = await import('../../src/lib/auth');
    const providers = authMod.authOptions.providers;
    const providerIds = providers.map((p) => {
        // NextAuth provider objects have a `.id` (string) or are functions.
        if (typeof p === 'function') return '<function-provider>';
        return (p as { id?: string }).id ?? '<unknown>';
    });

    if (!providerIds.includes('credentials')) {
        fail('PR-29 credentials', 'Credentials provider missing');
    }
    ok('Credentials provider is always present');

    if (!providerIds.includes('azure-ad')) {
        fail('PR-29 azure-ad', `azure-ad provider missing when AZURE_AD_CLIENT_ID is set. Got: ${providerIds.join(', ')}`);
    }
    ok('azure-ad provider is registered when AZURE_AD_CLIENT_ID + SECRET are set');

    ok('PR-29 entra-sso smoke', 'Entra ID provider boots when configured');
}

main().catch((e) => fail('PR-29 crashed', String(e)));
