perf: add bans.user_id index, Redis cache layer, rate-limit improvements, radio contest/giveaway columns, and tests

- Add DB index on bans.user_id to speed up per-request ban lookups (migration 0008)
- Replace in-process rate limiter with Redis-backed implementation with in-memory fallback
- Add Redis caching layer for site settings with TTL invalidation (migration 0009)
- Add rate limiting to resetPassword to prevent token brute-force attacks
- Update all rateLimit callers to await the now-async function
- Flesh out RadioContests and RadioGiveaways models with title, description, prize, date, and winner columns
- Update radio contest/giveaway pages to display new fields
- Add tests for rate limiter (4 tests) and password-reset actions (3 tests)
- Add REDIS_URL environment variable (optional, falls back to in-memory)
This commit is contained in:
openhands committed 2026-07-08 12:49:24 +02:00
1 parent 43c0ba6614
commit 5c638cd6bc
25 files changed
+449 -63

No files matched your search

+86
View File
@@ -0,0 +1,86 @@
import { beforeEach, describe, expect, it, vi } from "vitest";
const { mockFindFirst, mockUpsert, mockFindUnique, mockUpdate, mockDelete, mockSendMail, mockRedirect } = vi.hoisted(
() => ({
mockFindFirst: vi.fn(),
mockUpsert: vi.fn(),
mockFindUnique: vi.fn(),
mockUpdate: vi.fn(),
mockDelete: vi.fn(),
mockSendMail: vi.fn(),
mockRedirect: vi.fn(),
}),
);
vi.mock("next/navigation", () => ({
redirect: (...args: unknown[]) => {
mockRedirect(...args);
throw new Error("redirect");
},
}));
vi.mock("@/lib/prisma", () => ({
prisma: {
user: { findFirst: mockFindFirst, update: mockUpdate },
passwordReset: { upsert: mockUpsert, findUnique: mockFindUnique, delete: mockDelete },
},
}));
vi.mock("@/lib/services/email", () => ({
sendMail: mockSendMail,
}));
vi.mock("@/lib/rate-limit", () => ({
rateLimit: vi.fn().mockResolvedValue({ ok: true, retryAfter: 0 }),
clientIp: vi.fn().mockResolvedValue("127.0.0.1"),
}));
vi.mock("@/env", () => ({
env: { APP_URL: "http://localhost:3000", HOTEL_NAME: "TestHotel" },
}));
import { requestReset } from "./password-reset";
beforeEach(() => {
vi.clearAllMocks();
});
describe("requestReset", () => {
it("sends a reset email when the user exists", async () => {
mockFindFirst.mockResolvedValue({ id: 1 });
mockUpsert.mockResolvedValue({});
const fd = new FormData();
fd.set("email", "[email protected]");
await expect(requestReset(fd)).rejects.toThrow("redirect");
expect(mockFindFirst).toHaveBeenCalledWith(
expect.objectContaining({ where: { mail: "[email protected]" } }),
);
expect(mockUpsert).toHaveBeenCalled();
expect(mockSendMail).toHaveBeenCalledWith(
"[email protected]",
expect.stringContaining("password reset"),
expect.stringContaining("http://localhost:3000/reset"),
);
});
it("does not send email when user is not found", async () => {
mockFindFirst.mockResolvedValue(null);
const fd = new FormData();
fd.set("email", "[email protected]");
await expect(requestReset(fd)).rejects.toThrow("redirect");
expect(mockSendMail).not.toHaveBeenCalled();
});
it("rate limits and does not throw on email without @", async () => {
const fd = new FormData();
fd.set("email", "not-an-email");
await expect(requestReset(fd)).rejects.toThrow("redirect");
expect(mockFindFirst).not.toHaveBeenCalled();
});
});