fix(ui): harden getUiCookiePath regex and add missing tests

- Use regex /\/ui(?=\/|$)/ to match "/ui" only as a full path segment,
  preventing false matches on paths like "/my-ui-tool/login".
- Add unit tests for storeLoginToken empty/whitespace guard and
  cookie-at-/ui-path behavior.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
Hendrik Jaks 2026-03-20 00:19:48 +02:00
parent 40eaab5693
commit 11974cae35
2 changed files with 25 additions and 2 deletions

View file

@ -147,6 +147,25 @@ describe("cookieUtils", () => {
global.window = originalWindow;
});
it("should not store empty string token", () => {
storeLoginToken("");
expect(sessionStorage.getItem("token")).toBeNull();
});
it("should not store whitespace-only token", () => {
storeLoginToken(" ");
expect(sessionStorage.getItem("token")).toBeNull();
});
it("should set a JS-accessible cookie at /ui path", () => {
const cookieSpy = vi.spyOn(document, "cookie", "set");
storeLoginToken("my-jwt-token");
expect(cookieSpy).toHaveBeenCalledWith(
expect.stringContaining("path=/ui")
);
vi.restoreAllMocks();
});
});
describe("getCookie", () => {

View file

@ -10,8 +10,12 @@
*/
function getUiCookiePath(): string {
if (typeof window === "undefined") return "/ui";
const idx = window.location.pathname.indexOf("/ui");
if (idx >= 0) return window.location.pathname.substring(0, idx + 3);
// Match "/ui" only as a full path segment (followed by "/" or end of string)
// to avoid false matches like "/my-ui-tool/login" → "/my-ui".
const match = window.location.pathname.match(/\/ui(?=\/|$)/);
if (match && match.index !== undefined) {
return window.location.pathname.substring(0, match.index + 3);
}
return "/ui";
}