- Remove .prettierrc (dead config, Biome replaces Prettier) - Rename lighthouserc.json to lighthouserc.cjs with module.exports for ESM compat - Add logger.warn to empty catch blocks in auth, register, site-settings, prisma-cache, redis, security, rate-limit - Unify ActionResult type: action-helper.ts uses 'ok' consistent with safe-action-shared.ts - Add noUnusedLocals + noUnusedParameters to tsconfig + fix 25 pre-existing unused vars - Replace barrel export src/types/index.ts with direct @/types/common imports - Make trustHost conditional (development only) in auth.ts - Add pre-flight URL validation to update-Nitrov3.sh to catch image.library.url misconfigurations - Improve NITRO_IMAGE_LIBRARY_URL content validation in pre-flight & post-compute checks
32 lines
923 B
TypeScript
32 lines
923 B
TypeScript
import { readFileSync } from "node:fs";
|
|
import { resolve } from "node:path";
|
|
import { describe, expect, it } from "vitest";
|
|
|
|
describe("admin CSRF wiring", () => {
|
|
it("defaults CSRF on for mutating withAdmin handlers", () => {
|
|
const source = readFileSync(
|
|
resolve(process.cwd(), "src/lib/api-handler.ts"),
|
|
"utf8",
|
|
);
|
|
expect(source).toContain("options.requireCsrf !== false");
|
|
});
|
|
|
|
it("issues a csrf meta tag from the admin layout", () => {
|
|
const source = readFileSync(
|
|
resolve(process.cwd(), "src/app/admin/layout.tsx"),
|
|
"utf8",
|
|
);
|
|
expect(source).toContain("setCsrfCookie");
|
|
expect(source).toContain('meta name="csrf-token"');
|
|
});
|
|
|
|
it("provides adminFetch helper that sets x-csrf-token", () => {
|
|
const source = readFileSync(
|
|
resolve(process.cwd(), "src/lib/admin-fetch.ts"),
|
|
"utf8",
|
|
);
|
|
expect(source).toContain("x-csrf-token");
|
|
expect(source).toContain("getCsrfToken");
|
|
});
|
|
});
|