Harden CMS security and theme contrast
This commit is contained in:
1 parent
2465ff2170
commit
4a1e1115b3
57 files changed
+1023
-231
No files matched your search
@@ -0,0 +1,48 @@
|
||||
import { describe, expect, it } from "vitest";
|
||||
import { apiUnavailable, pagination, positiveBigInt } from "@/lib/api";
|
||||
|
||||
describe("apiUnavailable", () => {
|
||||
it("returns a no-store 503 error without exposing internal details", async () => {
|
||||
const response = apiUnavailable("Account data is temporarily unavailable");
|
||||
|
||||
expect(response.status).toBe(503);
|
||||
expect(response.headers.get("cache-control")).toBe("no-store");
|
||||
await expect(response.json()).resolves.toEqual({
|
||||
error: "Account data is temporarily unavailable",
|
||||
});
|
||||
});
|
||||
});
|
||||
|
||||
describe("positiveBigInt", () => {
|
||||
it.each(["1", "9007199254740993"])("parses positive integer id %s", (raw) => {
|
||||
expect(positiveBigInt(raw)).toBe(BigInt(raw));
|
||||
});
|
||||
|
||||
it.each([null, "", "0", "-1", "1.5", "abc"])("rejects invalid id %s", (raw) => {
|
||||
expect(positiveBigInt(raw)).toBeNull();
|
||||
});
|
||||
});
|
||||
|
||||
describe("pagination", () => {
|
||||
it("rejects fractional and malformed values before they reach Prisma", () => {
|
||||
const params = new URLSearchParams({ page: "2.5", perPage: "10.1" });
|
||||
|
||||
expect(pagination(params, 20, 100)).toEqual({
|
||||
page: 1,
|
||||
perPage: 20,
|
||||
skip: 0,
|
||||
take: 20,
|
||||
});
|
||||
});
|
||||
|
||||
it("clamps valid page sizes to the configured maximum", () => {
|
||||
const params = new URLSearchParams({ page: "3", perPage: "999" });
|
||||
|
||||
expect(pagination(params, 20, 100)).toEqual({
|
||||
page: 3,
|
||||
perPage: 100,
|
||||
skip: 200,
|
||||
take: 100,
|
||||
});
|
||||
});
|
||||
});
|
||||
Reference in new issue
Block a user