Database: - Add missing indexes (users.credits, users_currency(type,amount), users_settings.respects_received, camera_web.timestamp, messenger_offline.user_id) via migrations 0020/0021 - Use partial .select() everywhere instead of SELECT * (tickets, users, rooms, audit logs, catalog tree, polls, radio, password reset) - Add queryPrepared/queryPreparedOne (server-side prepared statements) and switch the login check to a prepared statement; drop dead cache options from the pool config - Raise total_users/total_rooms COUNT(*) cache TTL to 5m Caching: - Consolidate the three cache helpers (cached, redisCache, cachedQuery) into a single memory-first implementation backed by Redis - invalidateKey now clears the in-process cache as well as Redis - Cache homepage sections, news list, and leaderboard tabs; share one news_list cache key between homepage and news archive - siteSettings: in-process cache with TTL so repeated getters no longer pay a Redis round-trip per call - Share a 10s poll cache across all radio SSE connections - Normalize timestamps after cache reads (Redis JSON round-trip) Assets: - Enable AVIF/WebP via images.formats and remove unoptimized from news covers and the homepage hero (149KB jpg) with proper sizes/priority - Support ?format=webp|avif|png in the /imaging proxy via sharp Other: - Fix pnpm supply-chain minimumReleaseAge failures by excluding the freshly-published packages (next 16.3.1, hookform resolvers 5.8.0, resend 6.20.0) - Remove unused before/after fields from housekeeping AuditEntry
92 lines
2.9 KiB
TypeScript
92 lines
2.9 KiB
TypeScript
// @ts-nocheck
|
|
import { beforeEach, describe, expect, it, vi } from "vitest";
|
|
import { checkLogin } from "@/lib/auth/password";
|
|
import { clientIp, rateLimit } from "@/lib/rate-limit";
|
|
import { captchaConfig, verifyCaptcha } from "@/lib/services/captcha";
|
|
import { siteSettings } from "@/lib/services/site-settings";
|
|
import { precheckLogin } from "./auth-precheck";
|
|
|
|
const { queryPreparedOne } = vi.hoisted(() => {
|
|
const queryPreparedOne = vi.fn().mockResolvedValue(null);
|
|
return { queryPreparedOne };
|
|
});
|
|
|
|
vi.mock("@/env", () => ({ env: { CONVERT_PASSWORDS: false } }));
|
|
vi.mock("@/lib/auth/password", () => ({ checkLogin: vi.fn() }));
|
|
vi.mock("@/lib/db", () => ({ queryPreparedOne }));
|
|
vi.mock("@/lib/rate-limit", () => ({ clientIp: vi.fn(), rateLimit: vi.fn() }));
|
|
vi.mock("@/lib/services/captcha", () => ({
|
|
captchaConfig: vi.fn(),
|
|
verifyCaptcha: vi.fn(),
|
|
}));
|
|
vi.mock("@/lib/services/site-settings", () => ({
|
|
siteSettings: { getBool: vi.fn() },
|
|
}));
|
|
|
|
beforeEach(() => {
|
|
vi.clearAllMocks();
|
|
vi.mocked(clientIp).mockResolvedValue("1.2.3.4");
|
|
vi.mocked(rateLimit).mockResolvedValue({ ok: true });
|
|
vi.mocked(checkLogin).mockResolvedValue({ valid: true } as never);
|
|
vi.mocked(captchaConfig).mockResolvedValue({ provider: "none" } as never);
|
|
queryPreparedOne.mockResolvedValue(null);
|
|
});
|
|
|
|
describe("precheckLogin", () => {
|
|
it("returns ok for valid login without 2FA", async () => {
|
|
queryPreparedOne.mockResolvedValue({
|
|
password: "hash",
|
|
twoFactorConfirmedAt: null,
|
|
mail: null,
|
|
mailVerified: "0",
|
|
});
|
|
expect(await precheckLogin("user", "pass")).toBe("ok");
|
|
});
|
|
|
|
it("returns twofactor when 2FA is set up", async () => {
|
|
queryPreparedOne.mockResolvedValue({
|
|
password: "hash",
|
|
twoFactorConfirmedAt: new Date(),
|
|
mail: null,
|
|
mailVerified: "0",
|
|
});
|
|
expect(await precheckLogin("user", "pass")).toBe("twofactor");
|
|
});
|
|
|
|
it("returns invalid for empty inputs", async () => {
|
|
expect(await precheckLogin("", "")).toBe("invalid");
|
|
});
|
|
|
|
it("returns captcha when captcha required", async () => {
|
|
vi.mocked(captchaConfig).mockResolvedValue({
|
|
provider: "hcaptcha",
|
|
} as never);
|
|
vi.mocked(verifyCaptcha).mockResolvedValue(false);
|
|
queryPreparedOne.mockResolvedValue({
|
|
password: "hash",
|
|
twoFactorConfirmedAt: null,
|
|
mail: null,
|
|
mailVerified: "0",
|
|
});
|
|
expect(await precheckLogin("user", "pass", "bad-token")).toBe("captcha");
|
|
});
|
|
|
|
it("returns invalid when user not found (dummy hash check)", async () => {
|
|
queryPreparedOne.mockResolvedValue(null);
|
|
const result = await precheckLogin("nonexistent", "pass");
|
|
expect(result).toBe("invalid");
|
|
expect(checkLogin).toHaveBeenCalled();
|
|
});
|
|
|
|
it("returns unverified when email verification required", async () => {
|
|
queryPreparedOne.mockResolvedValue({
|
|
password: "hash",
|
|
twoFactorConfirmedAt: null,
|
|
mail: "[email protected]",
|
|
mailVerified: "0",
|
|
});
|
|
vi.mocked(siteSettings.getBool).mockResolvedValue(true);
|
|
expect(await precheckLogin("user", "pass")).toBe("unverified");
|
|
});
|
|
});
|