Skip to content

test(HNT-3494): add file upload integration test - #390

Draft
mmiermans wants to merge 2 commits into
mmiermans/HNT-3493-jwks-rsa-3from
mmiermans/HNT-3494-upload-test
Draft

mmiermans wants to merge 2 commits into
mmiermans/HNT-3493-jwks-rsa-3from
mmiermans/HNT-3494-upload-test

Conversation

@mmiermans

@mmiermans mmiermans commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Goal

Add test coverage for file uploads through admin-api before the Apollo Server 5 upgrade. A broken upload path currently fails silently: the subgraph receives a null file and still returns HTTP 200.

  • src/server/upload.spec.ts sends a multipart request through the real express app and gateway (FileUploadDataSource) to a stub subgraph. The stub parses the request with graphql-upload, the same way curated-corpus-api does.
  • Prototype-pollution guard: __proto__ and constructor.prototype upload paths go through the upload data source without polluting Object.prototype. This covers profusion's unpatched lodash.set, which arrives with the AS5 upgrade.
  • getAppGateway(overrides) lets the test inject a locally composed supergraph.

Implementation Decisions

  • The test asserts the exact file bytes (including non-UTF-8 bytes), the filename and the mimetype.
  • Verified that it fails when FileUploadDataSource is swapped for a plain RemoteGraphQLDataSource.
  • The stub subgraph is plain graphql + graphql-upload rather than Apollo Server, so the test survives the AS5 upgrade unchanged.

Deployment steps

  • None (test only)

References

JIRA ticket:

Stacked on #389.

@mmiermans
mmiermans force-pushed the mmiermans/HNT-3494-upload-test branch from 787f258 to e91b53e Compare October 1, 2026 19:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant