- eslint.config.js: disable React Compiler rules (v7 flat.recommended enables
them; codebase does not use the Compiler); add e2e/ to disableTypeChecked
block; promote exhaustive-deps to error
- API broker: remove redundant as-casts (outboxWorker, poller, reminderScheduler,
expand, sync, vevent, spike); add targeted ical.js no-unsafe-assignment/argument
disables with justifying comments inside try blocks
- API routes/sse.ts: fix no-misused-promises on async writeSSE callback with
void+IIFE+catch pattern
- API routes/lists.ts: let → const for updateValues
- API tests: remove unused imports (beforeEach, eq, vi); rename unused vars
with _ prefix; remove unused lastActiveId assignment
- PWA components: void navigate() and void queryClient.invalidateQueries() on
all fire-and-forget call sites; fix CalendarShell explicit-type-casts;
Couldn't → HTML entity
- PWA test files: as unknown as Response for partial mock objects; string | null
type annotation on mockLastSyncedUid; remove async from test callbacks without
await; act(() => {}) not await act(async () => {}) for sync ops
- sw.ts: restructure Notification.data?.url access as let+if so disable
comments land on the exact violation lines; void self.skipWaiting()
97 lines
3.1 KiB
TypeScript
97 lines
3.1 KiB
TypeScript
/**
|
|
* devAuthBypass() middleware — unit tests.
|
|
*
|
|
* Tests the three behavioral cases:
|
|
* 1. NODE_ENV='production' → pure passthrough (hard guard), regardless of DEV_AUTH_BYPASS
|
|
* 2. NODE_ENV!='production' + DEV_AUTH_BYPASS unset → passthrough (no user injected)
|
|
* 3. NODE_ENV!='production' + DEV_AUTH_BYPASS='true' → DEV_USER injected into context
|
|
*/
|
|
|
|
import { describe, it, expect, afterEach } from 'vitest'
|
|
import { Hono } from 'hono'
|
|
|
|
// We import after env manipulation since devAuthBypass() reads env vars at call time.
|
|
// Each test resets the module registry via vi.resetModules() to re-evaluate the function
|
|
// with the current process.env values.
|
|
|
|
describe('devAuthBypass middleware', () => {
|
|
const originalNodeEnv = process.env.NODE_ENV
|
|
const originalBypassFlag = process.env.DEV_AUTH_BYPASS
|
|
|
|
afterEach(() => {
|
|
// Restore env after each test
|
|
process.env.NODE_ENV = originalNodeEnv
|
|
if (originalBypassFlag === undefined) {
|
|
delete process.env.DEV_AUTH_BYPASS
|
|
} else {
|
|
process.env.DEV_AUTH_BYPASS = originalBypassFlag
|
|
}
|
|
})
|
|
|
|
it('is a pure passthrough in production (NODE_ENV=production), even when DEV_AUTH_BYPASS=true', async () => {
|
|
process.env.NODE_ENV = 'production'
|
|
process.env.DEV_AUTH_BYPASS = 'true'
|
|
|
|
// Import after env setup
|
|
const { devAuthBypass } = await import('../../src/auth/devBypass.js')
|
|
|
|
const app = new Hono()
|
|
app.use('/api/*', devAuthBypass())
|
|
|
|
let capturedUser: unknown = undefined
|
|
app.get('/api/test', (c) => {
|
|
capturedUser = c.get('user')
|
|
return c.json({ ok: true })
|
|
})
|
|
|
|
const res = await app.request('/api/test')
|
|
expect(res.status).toBe(200)
|
|
// Hard guard: user must NOT be injected in production
|
|
expect(capturedUser).toBeUndefined()
|
|
})
|
|
|
|
it('is a passthrough when NODE_ENV!=production and DEV_AUTH_BYPASS is not set', async () => {
|
|
process.env.NODE_ENV = 'test'
|
|
delete process.env.DEV_AUTH_BYPASS
|
|
|
|
const { devAuthBypass } = await import('../../src/auth/devBypass.js')
|
|
|
|
const app = new Hono()
|
|
app.use('/api/*', devAuthBypass())
|
|
|
|
let capturedUser: unknown = undefined
|
|
app.get('/api/test', (c) => {
|
|
capturedUser = c.get('user')
|
|
return c.json({ ok: true })
|
|
})
|
|
|
|
const res = await app.request('/api/test')
|
|
expect(res.status).toBe(200)
|
|
expect(capturedUser).toBeUndefined()
|
|
})
|
|
|
|
it('injects DEV_USER when NODE_ENV!=production and DEV_AUTH_BYPASS=true', async () => {
|
|
process.env.NODE_ENV = 'test'
|
|
process.env.DEV_AUTH_BYPASS = 'true'
|
|
|
|
const { devAuthBypass, DEV_USER } = await import('../../src/auth/devBypass.js')
|
|
|
|
const app = new Hono()
|
|
app.use('/api/*', devAuthBypass())
|
|
|
|
let capturedUser: unknown = undefined
|
|
app.get('/api/test', (c) => {
|
|
capturedUser = c.get('user')
|
|
return c.json({ ok: true })
|
|
})
|
|
|
|
const res = await app.request('/api/test')
|
|
expect(res.status).toBe(200)
|
|
// User must be the fixed DEV_USER
|
|
expect(capturedUser).toBeDefined()
|
|
expect(capturedUser).toEqual(DEV_USER)
|
|
expect((capturedUser as typeof DEV_USER).displayName).toBe('Dev User')
|
|
expect((capturedUser as typeof DEV_USER).oidcSub).toBe('dev-user')
|
|
})
|
|
})
|