#!/usr/bin/env bash
# A stand-in for the Bitwarden CLI, used only to capture screenshots.
#
# The plugin resolves `bw` from PATH, so putting this earlier on PATH points it
# at a fixture vault instead of a real one. Nothing here talks to Bitwarden,
# reads a keyring, or touches the network -- which is the point: the README
# screenshots can show a populated vault without showing anyone's credentials.
set -uo pipefail

FIXTURES="$(dirname "$(readlink -f "$0")")/../fixtures.json"
j() { python3 -c "
import json,sys
d=json.load(open('$FIXTURES'))
sys.stdout.write(json.dumps(d[sys.argv[1]]))" "$1"; }

# The vault state the fixture reports. `unlocked` for the populated shots;
# `unauthenticated` drives the login screen, `locked` the unlock screen.
DEMO_STATUS="${QSBW_DEMO_STATUS:-unlocked}"

case "${1:-}" in
  --version) echo "2026.2.0-demo" ;;
  status)    python3 -c "
import json,sys
d=json.load(open('$FIXTURES'))
st=dict(d['status']); st['status']=sys.argv[1]
if sys.argv[1]=='unauthenticated':
    st['userEmail']=''; st['userId']=''
sys.stdout.write(json.dumps(st))" "$DEMO_STATUS" ;;
  # The new generator reaches for `bw serve` first. Exiting immediately is the
  # bind-failure path, which is exactly the fallback we want exercised here.
  serve)     exit 1 ;;
  sync)      echo "Syncing complete." ;;
  lock)      echo "Your vault is locked." ;;
  unlock)    echo "demo-session-token-not-real" ;;
  generate)
    # Roughly honour --passphrase so the generator screenshot looks right.
    if [[ " $* " == *" --passphrase "* ]]; then echo "Correct-Horse-Battery-Staple"
    else echo "Xq7X2mFk9TbW4e"; fi ;;
  list)
    case "${2:-}" in
      items)         j items ;;
      folders)       j folders ;;
      organizations) j organizations ;;
      *)             echo "[]" ;;
    esac ;;
  get)
    case "${2:-}" in
      totp)     echo "418 623" | tr -d ' ' ;;
      password) echo "placeholder" ;;
      # Attachment bytes never come from the fixture file -- the panel only
      # needs a file to appear where it asked for one.
      attachment)
        out=""
        while [ $# -gt 0 ]; do
          if [ "$1" = "--output" ]; then out="${2:-}"; fi
          shift
        done
        [ -n "$out" ] || exit 1
        printf 'placeholder attachment, not real vault data\n' > "$out"
        echo "Saved $out" ;;
      item)     python3 -c "
import json,sys
d=json.load(open('$FIXTURES'))
want=sys.argv[1]
for it in d['items']:
    if it['id']==want: print(json.dumps(it)); break
else: print(json.dumps(d['items'][0]))" "${3:-i1}" ;;
      *) echo "{}" ;;
    esac ;;
  send)
    case "${2:-}" in
      list)   j sends ;;
      create) echo '{"object":"send","id":"s3","name":"New Send","type":0,"accessUrl":"https://vault.bitwarden.com/#/send/demo3","accessCount":0,"maxAccessCount":null,"deletionDate":"2026-08-28T10:00:00.000Z","passwordSet":false,"disabled":false,"text":{"text":"placeholder","hidden":false}}' ;;
      delete) echo "Send deleted." ;;
      *)      echo "[]" ;;
    esac ;;
  encode)  cat ;;
  create|edit|delete) echo '{"object":"item","id":"new"}' ;;
  *) echo "{}" ;;
esac
