import os


def test_device_credential_round_trip_uses_application_key(monkeypatch):
    monkeypatch.setenv("DEVICE_CREDENTIAL_KEY", "7c051ReJExqTGEVAOssujm3OlgB0G2bqiNQBrKyFBLw=")

    from app.core.device_credentials import decrypt_secret, encrypt_secret

    encrypted = encrypt_secret("test-password")
    assert encrypted != "test-password"
    assert decrypt_secret(encrypted) == "test-password"


def test_device_credential_requires_key(monkeypatch):
    monkeypatch.delenv("DEVICE_CREDENTIAL_KEY", raising=False)

    from app.core.device_credentials import CredentialKeyMissingError, encrypt_secret

    try:
        encrypt_secret("test-password")
    except CredentialKeyMissingError:
        pass
    else:
        raise AssertionError("Credential encryption must fail safely without DEVICE_CREDENTIAL_KEY")
