import os, sys
sys.path.insert(0, os.path.abspath(os.path.join(os.path.dirname(__file__), '..', 'apps', 'api')))
from app.core.security import hash_password, verify_password, issue_access_token, decode_access_token

def test_password_hash_roundtrip():
    hashed = hash_password('Very-Strong-Test-Password-2026!')
    assert hashed != 'Very-Strong-Test-Password-2026!'
    assert verify_password('Very-Strong-Test-Password-2026!', hashed)
    assert not verify_password('wrong-password', hashed)

def test_short_password_rejected():
    try: hash_password('short')
    except ValueError: pass
    else: raise AssertionError('short password must be rejected')

def test_access_token_claims():
    token = issue_access_token('user-123', 'OWNER')
    decoded = decode_access_token(token)
    assert decoded['sub'] == 'user-123'
    assert decoded['role'] == 'OWNER'
    assert decoded['typ'] == 'access'
