"""One tenant must never be able to reach another's products.

The proactive endpoint takes tenant_id from an unauthenticated browser request,
so this is the boundary that matters most in this feature.
"""
from unittest.mock import patch

from app.services.catalog.products import normalise_url
from app.services.pairing.recommendations import decide

A_ROW = {"product_key": "sku:A-1", "name": "Tenant A Product", "description": None,
         "image_url": None, "product_url": "https://a.com/p/1", "category": "x",
         "ctas": []}

ALL_ON = {"features": {"product_recommendation": True}}


def test_a_url_belonging_to_another_tenant_is_unknown():
    """find_by_url is scoped to one schema, so B asking about A's URL finds nothing."""
    def scoped_find(tenant_id, url):
        return A_ROW if tenant_id == "org_a" else {}

    with patch("app.services.pairing.recommendations.get_tool_settings", return_value=ALL_ON), \
         patch("app.services.pairing.recommendations.find_by_url", side_effect=scoped_find):
        out = decide("org_b", "dwell", {"url": "https://a.com/p/1", "dwell_seconds": 60})

    assert out == {"recommend": False, "reason": "page_unknown"}


def test_normalisation_cannot_be_used_to_cross_a_tenant_boundary():
    """Normalisation must not merge two different hosts onto one key."""
    assert normalise_url("https://a.com/p/1") != normalise_url("https://b.com/p/1")
