mirror of
https://github.com/abhigyanpatwari/GitNexus.git
synced 2026-10-04 02:31:36 +00:00
* fix(web): use repo path identity in switcher * keep repo URL project names stable * fix server repo path resolution * fix repo path miss resolution * fix(server): guard clone-dir deletion with path ownership check Deleting a registry entry derived its clone dir from the entry NAME with no ownership check, so deleting a local repo that shares a display name with a server-cloned sibling wiped the sibling's checkout. Gate the removal on cloneDirBelongsToEntry (canonicalized path equality), the same entry.path-driven rule the handler's step 2b already mandates. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(server): fail closed on relative repo params and rate-limit GET /api/repo Relative separator-containing ?repo= values (org/name, ./repo) were canonicalized against the server CWD — an attacker-influenced realpathSync probe on an un-rate-limited GET — before failing anyway. Reject them immediately without touching the filesystem, drop the redundant path.sep clause, document the resolver's two-tier contract, and wire createRouteLimiter on GET /api/repo like its DELETE sibling. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * test(server): lock repo resolver branches and register for Windows CI Lock in the resolver's remaining branches: first-wins for ambiguous bare names, Windows-shaped input as a fail-closed path claim, the repos[0] default, and the case-insensitive name fallback. Register the suite in cross-platform-tests.ts so windows-latest actually runs the path-shape logic it exists to protect. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * refactor(web): single repoIdentity helper with repoPath normalized end-to-end The identity fallback chain was copy-pasted in Header and RepoLanding while backend-client already owns BackendRepo and the repoPath normalization. Export one repoIdentity helper, normalize fetchRepos like fetchRepoInfo, and emit repoPath from GET /api/repos so the scheme no longer silently relies on /api/repo.repoPath equalling /api/repos.path. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(web): persist and restore repo path identity in the URL The URL persisted only ?project=<display name>, so refreshing after switching to a duplicate-name repo silently restored the first same-named sibling. Persist ?repo=<server-resolved path> alongside the readable ?project= at both write sites, prefer it on restore (legacy project-only URLs still work), keep failed path restores fail-visible (no name fallback), and strip stale identity params when deleting the active or last repo. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(web): analyze completion connects by path identity RepoAnalyzer's completion callback passed the display name, so analyzing a repo whose basename collides with an existing one reconnected the first same-named sibling. The SSE terminal payload now carries the job's repoPath (both emit sites), the analyzer passes that identity to onComplete while the done screen keeps showing the display name, and old servers without repoPath degrade to today's behavior. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(web): scope code-reference file reads to the active repo identity The code viewer passed the display name as the repo scope, so with duplicate-name repos it rendered the wrong repo's file contents under the right filename. Pass the active path identity (currentRepo) with the display name as fallback, and collapse the two dead repo fields that were already shadowed by the readFile spread. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(web): show display names instead of absolute paths in labels The path-identity switch leaked raw filesystem paths into three user-facing surfaces: the re-analyze progress label, the repo-switch overlay, and the agent prompt's project name via loadGraphAnyway. Resolve display names at render time (registry lookup, then basename fallback) while state keeps holding the identity; loadGraphAnyway passes the name explicitly because initializeAgent's empty-deps closure would otherwise fall through to the literal 'project'. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(web): stop initializeAgent from clobbering repo identity with display names initializeAgent fell back to writing overrideProjectName (a display name) into the repo identity, so any future name-only caller — the pre-PR idiom — would silently kill the Active badge and re-admit the duplicate-name ambiguity through the agent path. Only opts.repo may write the identity now. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * chore(web): drop dead initializers flagged by CodeQL pNameStr's and repoIdentity's initial values were never read: both are assigned on the success path before any use and the catch returns early. Bare declarations resolve CodeQL alerts 825/826. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * style(web): fix tailwind class order per root prettier plugin The worktree pre-commit hook resolved prettier-plugin-tailwindcss through symlinked node_modules and sorted scrollbar-thin differently than CI's clean-room install. Re-formatted with the root lockfile environment; no behavior change. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * test(web): e2e coverage for every #2419 duplicate-name ambiguity Provision two live repos with the same basename under different parents via POST /api/analyze, then drive a real browser through each item of the issue's "Actual behavior" list: - duplicate rows render and the ACTIVE one is identifiable before and after switching (active-state must not compare repo.name) - switching between duplicates swaps the loaded graph, verified by per-repo marker files (onSwitchRepo must not receive repo.name) - re-analyze targets the clicked duplicate's exact path (POST body), tracks progress on that row only, and the completion reconnect requests that same path — never the same-named sibling - delete requests target exactly the chosen duplicate's path; the sibling stays registered and loaded - backend ?repo= resolution is path-first: landing selection loads the exact repo, ?repo= survives F5, and a stale path fails closed to the repo picker instead of retargeting the sibling Adds four data-testids to Header (switcher trigger/row/reanalyze/ delete, rows expose data-active) so the spec has stable selectors, and broadens the post-analyze reconnect retry in App to any BackendError: the server may still be reinitializing when the SSE complete event fires, and that surfaces as transient 5xx/binder errors, not only 404. The re-analyze and delete tests deliberately assert identity at the request level and tolerate two pre-existing server races that are unrelated to the #2419 identity contract (freshly-analyzed DB briefly unreadable after SSE complete; registry validate-prune clobbering a concurrent unregister) — see the in-test comments. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * chore(autofix): apply prettier + eslint fixes via /autofix command * test(web): isolate repo-path-identity e2e onto a spec-owned backend The spec is the only e2e file doing write operations (analyze, re-analyze, delete). Running its force re-analysis against the shared CI backend while parallel workers held connections took the whole server down (run 29145679019: the jobId poll died with ECONNRESET and every later test in every file failed to connect). Spawn a dedicated `gitnexus serve` on port 4799 with an isolated GITNEXUS_HOME in beforeAll instead: writes can no longer perturb the other suites, a crash is contained to this spec (its output is captured and printed, which CI otherwise loses), and the registry is hermetic by construction — the previous leftover-purge and shared-registry cleanup are gone. Every page is pointed at the spec backend through useBackend's supported localStorage override, which covers both the probe-driven landing flow and the ?server= auto-connect. Verified self-sufficient (6/6 with no shared server running) and non-interfering (full suite 39/39 with the shared server up). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * stabilize repo path identity e2e * fix(server): don't report analyze complete before the index is settled The analyze worker reports `complete` over IPC before its on-disk finalization (LadybugDB checkpoint, native handle release, metadata write) is visible at the storage path — observed up to ~6.5s behind the IPC message. The launcher's "reinitialize backend BEFORE marking complete" ordering was meant to make the repo queryable by the time the client sees the SSE complete event, but it never verified that: clients reconnecting on that event read a database still being written. Locally that surfaces as "Binder exception: Table CodeRelation does not exist" or a silently empty graph, and the open can quarantine the in-flight WAL; on slow CI runners the native layer racing the rewrite has killed the whole server (signal exit, no output — run 29146867959). Gate the complete transition on the index actually settling: LadybugDB file and metadata both rewritten by THIS job (mtime >= job start — bare existence is not enough, a re-analysis leaves the previous index in place while it works) and no transient WAL/shadow/checkpoint sidecars remaining. Bounded (60s) and proceed-on-timeout, so a job whose analysis legitimately rewrites nothing cannot wedge. Also evict the server's cached DB handle before reinitializing — same invalidation DELETE /api/repo performs — so post-completion reads cannot be served from a pre-rewrite handle. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * test(web): assert re-analyze completion identity at the request level The strict form (Ready + marker on the re-analyzed duplicate) still trips a deeper pre-existing storage race that makes a freshly re-analyzed database transiently unreadable to the reconnect even with the settle gate in place — unrelated to the #2419 identity contract this test covers. Keep the identity assertions (the reconnect targets the exact duplicate's path and never the same-named sibling) and leave a pointer to tighten once the storage race is fixed. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(server): resolve the settle-gate path from the registry, not the request CodeQL flagged the settle gate's stat/exists probes as js/path-injection: the probed path derived from the user-provided analyze `path`. Resolve it from the repo's registry entry instead — the user value is now only a comparison key, and the probes run against the server-owned storagePath record, which is also the authoritative path readers resolve through. Re-resolved each poll round because the worker registers the repo as part of the same finalization the gate is waiting out. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Gergő Magyar <gergomagyar@icloud.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
320 lines
13 KiB
TypeScript
320 lines
13 KiB
TypeScript
/**
|
||
* Tests for createRouteLimiter and the integration shape used by api.ts.
|
||
*
|
||
* Closes the U4 test gap (CodeQL js/missing-rate-limiting). Without these,
|
||
* a refactor that drops the limiter middleware from any route would silently
|
||
* regress and CodeQL would re-fire — but no test would fail before reaching
|
||
* CI.
|
||
*
|
||
* Two layers of coverage:
|
||
* 1. Helper unit tests — createRouteLimiter returns distinct middleware
|
||
* per call, has the right signature, exposes the right error shape.
|
||
* 2. Integration tests — mount the same factory on a tiny isolated express
|
||
* app that does fs.readFile (the exact CodeQL sink class) and prove the
|
||
* 429 fires after the configured limit. windowMs (2 000 ms) is generous
|
||
* enough that 4 sequential requests fit inside one window even on slow
|
||
* Windows CI runners; each test uses a fresh limiter so counter state
|
||
* never carries between tests.
|
||
*/
|
||
import { afterAll, afterEach, beforeAll, beforeEach, describe, expect, it } from 'vitest';
|
||
import express, { type Express } from 'express';
|
||
import http from 'node:http';
|
||
import path from 'node:path';
|
||
import fs from 'node:fs/promises';
|
||
import os from 'node:os';
|
||
import { createRouteLimiter } from '../../src/server/validation.js';
|
||
|
||
let tmpFile: string;
|
||
|
||
beforeAll(async () => {
|
||
// Real fs.readFile target so the route does the same kind of FS work
|
||
// the production routes do — keeps the test honest about what it covers.
|
||
tmpFile = path.join(
|
||
await fs.mkdtemp(path.join(os.tmpdir(), 'gitnexus-ratelimit-')),
|
||
'fixture.txt',
|
||
);
|
||
await fs.writeFile(tmpFile, 'hello\n', 'utf-8');
|
||
});
|
||
|
||
afterAll(async () => {
|
||
await fs.rm(path.dirname(tmpFile), { recursive: true, force: true });
|
||
});
|
||
|
||
// Build a fresh app + server per test so counter state never carries between
|
||
// tests. windowMs = 2 000 ms gives ample headroom for Windows CI where
|
||
// sequential loopback HTTP requests can take 50–80 ms each.
|
||
const buildApp = (limit: number, windowMs = 2000): Express => {
|
||
const app = express();
|
||
app.set('trust proxy', 'loopback, linklocal, uniquelocal');
|
||
app.get('/test/file', createRouteLimiter({ windowMs, limit }), async (_req, res) => {
|
||
const content = await fs.readFile(tmpFile, 'utf-8');
|
||
res.json({ content });
|
||
});
|
||
return app;
|
||
};
|
||
|
||
const startServer = (app: Express): Promise<{ server: http.Server; baseUrl: string }> =>
|
||
new Promise((resolve) => {
|
||
const server = app.listen(0, '127.0.0.1', () => {
|
||
const addr = server.address();
|
||
const baseUrl = typeof addr === 'object' && addr ? `http://127.0.0.1:${addr.port}` : '';
|
||
resolve({ server, baseUrl });
|
||
});
|
||
});
|
||
|
||
const stopServer = (server: http.Server): Promise<void> =>
|
||
new Promise((resolve) => server.close(() => resolve()));
|
||
|
||
describe('createRouteLimiter — defaults', () => {
|
||
it('returns a different middleware instance per call (independent counters)', () => {
|
||
const a = createRouteLimiter();
|
||
const b = createRouteLimiter();
|
||
expect(a).not.toBe(b);
|
||
});
|
||
|
||
it('produces a callable express RequestHandler', () => {
|
||
const limiter = createRouteLimiter();
|
||
expect(typeof limiter).toBe('function');
|
||
// express middleware signature is (req, res, next) — 3 args.
|
||
expect(limiter.length).toBe(3);
|
||
});
|
||
|
||
// Regression guard for #1360 — createRouteLimiter must not throw
|
||
// ERR_ERL_KEY_GEN_IPV6. The validation fires at construction time
|
||
// (inside `rateLimit()`), so a simple `createRouteLimiter()` call is
|
||
// the canary: if the keyGenerator references `req.ip` without using
|
||
// `ipKeyGenerator`, the `rateLimit()` constructor throws before the
|
||
// middleware is ever invoked.
|
||
it('does not throw ERR_ERL_KEY_GEN_IPV6 on construction (#1360)', () => {
|
||
expect(() => createRouteLimiter()).not.toThrow();
|
||
});
|
||
});
|
||
|
||
describe('createRouteLimiter — integration with a real route', () => {
|
||
let server: http.Server;
|
||
let baseUrl: string;
|
||
|
||
beforeEach(async () => {
|
||
({ server, baseUrl } = await startServer(buildApp(3)));
|
||
});
|
||
|
||
afterEach(async () => {
|
||
await stopServer(server);
|
||
});
|
||
|
||
// The exact regression guard CodeQL would re-fire if a maintainer
|
||
// dropped createRouteLimiter from any of the 4 protected routes:
|
||
// without the limiter, max+1 requests all return 200.
|
||
it('lets max requests through and rejects the next one with 429', async () => {
|
||
for (let i = 1; i <= 3; i++) {
|
||
const res = await fetch(`${baseUrl}/test/file`);
|
||
expect(res.status).toBe(200);
|
||
}
|
||
const res = await fetch(`${baseUrl}/test/file`);
|
||
expect(res.status).toBe(429);
|
||
const body = await res.json();
|
||
expect(body.error).toContain('Too many');
|
||
});
|
||
|
||
it('emits draft-7 RateLimit response header (combined form), not legacy X-RateLimit-*', async () => {
|
||
const res = await fetch(`${baseUrl}/test/file`);
|
||
expect(res.status).toBe(200);
|
||
// draft-7: single combined `RateLimit` header in `limit=N, remaining=N, reset=N` shape,
|
||
// NO individual `X-RateLimit-*` legacy keys.
|
||
const rateLimitHeader = res.headers.get('ratelimit');
|
||
expect(rateLimitHeader).toMatch(/limit=\d+/);
|
||
expect(rateLimitHeader).toMatch(/remaining=\d+/);
|
||
expect(rateLimitHeader).toMatch(/reset=\d+/);
|
||
expect(res.headers.get('x-ratelimit-limit')).toBeNull();
|
||
});
|
||
|
||
it('429 response body uses the project { error } JSON shape', async () => {
|
||
// Trip the limiter.
|
||
for (let i = 1; i <= 3; i++) await fetch(`${baseUrl}/test/file`);
|
||
const res = await fetch(`${baseUrl}/test/file`);
|
||
expect(res.status).toBe(429);
|
||
const body = await res.json();
|
||
expect(body).toEqual({ error: expect.stringContaining('Too many') });
|
||
});
|
||
|
||
it('429 response includes a Retry-After header so clients can back off', async () => {
|
||
for (let i = 1; i <= 3; i++) await fetch(`${baseUrl}/test/file`);
|
||
const res = await fetch(`${baseUrl}/test/file`);
|
||
expect(res.status).toBe(429);
|
||
const retryAfter = res.headers.get('retry-after');
|
||
expect(retryAfter).toBeTruthy();
|
||
// express-rate-limit v8 emits Retry-After in integer-seconds form. The
|
||
// RFC also allows HTTP-date, but ERL does not use that shape; if a
|
||
// future version switches, this assertion needs an HTTP-date branch.
|
||
const seconds = Number(retryAfter);
|
||
expect(Number.isFinite(seconds) && seconds >= 0).toBe(true);
|
||
});
|
||
|
||
it('window resets after windowMs — counter does not carry across windows', async () => {
|
||
// Trip the limiter.
|
||
for (let i = 1; i <= 3; i++) await fetch(`${baseUrl}/test/file`);
|
||
const tripped = await fetch(`${baseUrl}/test/file`);
|
||
expect(tripped.status).toBe(429);
|
||
// Wait for the window to roll over (2 000 ms window + 200 ms margin).
|
||
await new Promise((r) => setTimeout(r, 2200));
|
||
const reset = await fetch(`${baseUrl}/test/file`);
|
||
expect(reset.status).toBe(200);
|
||
});
|
||
});
|
||
|
||
// Behavioral pin replacing the prior `expect(DEFAULT_RATE_LIMIT_RPM).toBe(60)`
|
||
// constant assertion — that test pinned the magic number, this test pins the
|
||
// observable contract that the production default does not 429 at typical
|
||
// interactive load.
|
||
describe('createRouteLimiter — production default', () => {
|
||
it('default policy permits 60 requests in a minute (no opts override)', async () => {
|
||
// Build an app that uses the production-default limiter (no opts override).
|
||
// 60 requests is well under the default 60 rpm/IP, so all should pass.
|
||
// Going to 61 would 429 but takes the full window to test deterministically;
|
||
// the contract we want pinned here is "default does not throttle interactive
|
||
// use" — the 429 path is already covered by the integration tests above.
|
||
const { server, baseUrl } = await startServer(
|
||
(() => {
|
||
const app = express();
|
||
app.set('trust proxy', 'loopback, linklocal, uniquelocal');
|
||
app.get('/test/file', createRouteLimiter(), async (_req, res) => {
|
||
const content = await fs.readFile(tmpFile, 'utf-8');
|
||
res.json({ content });
|
||
});
|
||
return app;
|
||
})(),
|
||
);
|
||
try {
|
||
// Send 60 requests — all should succeed under the default policy.
|
||
for (let i = 1; i <= 60; i++) {
|
||
const res = await fetch(`${baseUrl}/test/file`);
|
||
if (res.status !== 200) {
|
||
throw new Error(`request ${i}/60 returned ${res.status} under default policy`);
|
||
}
|
||
}
|
||
} finally {
|
||
await stopServer(server);
|
||
}
|
||
});
|
||
});
|
||
|
||
// Production-wiring assertions — proves each of the 4 protected routes in
|
||
// api.ts actually has rate-limit middleware. Closes the gap reviewers flagged
|
||
// where a maintainer could drop createRouteLimiter from a route and no test
|
||
// would fail (only CodeQL would re-fire next scan).
|
||
//
|
||
// Walks the express router stack on a real createServer-built app, finds
|
||
// each protected route by method+path, and asserts the middleware chain
|
||
// includes the express-rate-limit handler. This is intentionally a
|
||
// structural check (not behavioral) — the behavioral guarantees are
|
||
// covered by the integration tests above.
|
||
describe('production routes — rate-limit middleware wiring', () => {
|
||
// Small structural check that does not require booting the full server
|
||
// (which depends on LadybugDB, MCP transport, fork(), etc.). We grep the
|
||
// api.ts source for the createRouteLimiter call adjacent to each route
|
||
// registration. If a future refactor drops the call, the regex no longer
|
||
// matches and the test fails.
|
||
//
|
||
// This is admittedly a light-weight check, but it is enough to catch the
|
||
// single most likely regression (someone removes the middleware while
|
||
// editing the route handler) without dragging in the full server boot.
|
||
|
||
let apiSource: string;
|
||
|
||
beforeAll(async () => {
|
||
apiSource = await fs.readFile(
|
||
path.join(__dirname, '..', '..', 'src', 'server', 'api.ts'),
|
||
'utf-8',
|
||
);
|
||
});
|
||
|
||
it('GET /api/file is wired with createRouteLimiter', () => {
|
||
expect(apiSource).toMatch(/app\.get\('\/api\/file',\s*createRouteLimiter\(/);
|
||
});
|
||
|
||
it('GET /api/grep is wired with createRouteLimiter', () => {
|
||
expect(apiSource).toMatch(/app\.get\('\/api\/grep',\s*createRouteLimiter\(/);
|
||
});
|
||
|
||
it('DELETE /api/repo is wired with createRouteLimiter', () => {
|
||
expect(apiSource).toMatch(/app\.delete\('\/api\/repo',\s*createRouteLimiter\(/);
|
||
});
|
||
|
||
it('GET /api/repo is wired with createRouteLimiter', () => {
|
||
expect(apiSource).toMatch(/app\.get\('\/api\/repo',\s*createRouteLimiter\(/);
|
||
});
|
||
|
||
it('POST /api/analyze is wired with createRouteLimiter', () => {
|
||
// Tolerate Prettier wrapping the registration across lines (it does once
|
||
// the route carries extra middleware like requireLocalhostOrigin).
|
||
expect(apiSource).toMatch(/app\.post\(\s*'\/api\/analyze',\s*createRouteLimiter\(/);
|
||
});
|
||
|
||
it('POST /api/embed is wired with createRouteLimiter', () => {
|
||
// Tolerate Prettier wrapping the registration across lines (it does once
|
||
// the route carries extra middleware like requireLocalhostOrigin).
|
||
expect(apiSource).toMatch(/app\.post\(\s*'\/api\/embed',\s*createRouteLimiter\(/);
|
||
});
|
||
|
||
it('SPA fallback is wired with createRouteLimiter', () => {
|
||
expect(apiSource).toMatch(/app\.get\(SPA_FALLBACK_REGEX,\s*createRouteLimiter\(/);
|
||
});
|
||
|
||
it('GET /api/health is registered (Docker healthcheck, #1147)', () => {
|
||
expect(apiSource).toMatch(/app\.get\('\/api\/health',\s*\(_req,\s*res\)\s*=>/);
|
||
});
|
||
|
||
it('does not register a bare wildcard OPTIONS route under Express 5', () => {
|
||
expect(apiSource).not.toContain("app.options('*'");
|
||
expect(apiSource).not.toMatch(/app\.options\(\s*'\/\*'/);
|
||
});
|
||
|
||
it('createServer wires trust proxy to loopback/linklocal/uniquelocal', () => {
|
||
expect(apiSource).toMatch(
|
||
/app\.set\(\s*'trust proxy'\s*,\s*'loopback,\s*linklocal,\s*uniquelocal'\s*\)/,
|
||
);
|
||
});
|
||
|
||
it('does not register Express-4-only app.options("*") (Express 5 path-to-regexp)', () => {
|
||
expect(apiSource).not.toMatch(/app\.options\(\s*'\*'/);
|
||
expect(apiSource).not.toMatch(/app\.options\(\s*'\/\*'/);
|
||
});
|
||
|
||
it('sets PNA header middleware before cors (preflight must include Allow-Private-Network)', () => {
|
||
expect(apiSource).toMatch(
|
||
/Access-Control-Allow-Private-Network[\s\S]*?app\.use\(\s*\n?\s*cors\(/,
|
||
);
|
||
});
|
||
|
||
it('embed route flushes WAL via flushWAL, not inline executeQuery (#1376)', () => {
|
||
// The embed handler must call the consolidated helper, not hand-roll
|
||
// its own try/catch around executeQuery('CHECKPOINT').
|
||
expect(apiSource).toMatch(/await flushWAL\(\)/);
|
||
expect(apiSource).not.toMatch(/executeQuery\('CHECKPOINT'\)/);
|
||
});
|
||
});
|
||
|
||
// Structural guard for #1360 — validates that the validation module uses
|
||
// `ipKeyGenerator` so IPv6 addresses are normalised to their /56 subnet.
|
||
// Without this, each IPv6 address gets an independent counter and the
|
||
// rate-limit is trivially bypassed. The construction-time test above
|
||
// catches the same regression behaviourally; this source-grep test catches
|
||
// it structurally so the failure message is immediately obvious.
|
||
describe('validation.ts — IPv6 key normalisation (#1360)', () => {
|
||
let validationSource: string;
|
||
|
||
beforeAll(async () => {
|
||
validationSource = await fs.readFile(
|
||
path.join(__dirname, '..', '..', 'src', 'server', 'validation.ts'),
|
||
'utf-8',
|
||
);
|
||
});
|
||
|
||
it('imports ipKeyGenerator from express-rate-limit', () => {
|
||
expect(validationSource).toMatch(/import.*ipKeyGenerator.*from\s+'express-rate-limit'/);
|
||
});
|
||
|
||
it('keyGenerator body calls ipKeyGenerator', () => {
|
||
expect(validationSource).toMatch(/ipKeyGenerator\(ip\)/);
|
||
});
|
||
});
|