- pnpm workspace with apps/api (Hono/Drizzle) and apps/pwa (Vite/React 19) - Pinned versions per RESEARCH: hono@4.12.23, drizzle-orm@0.45.2, mysql2@3.22.4, tsdav@2.2.2, ical.js@2.2.1, zod@^3.25.0, node-cron@^4.2.1 - docker-compose.yml with mariadb:11 healthcheck, api depends_on service_healthy, redis stub - docker-compose.dev.yml overrides for local dev (bind mounts, exposed ports) - .env.example lists all env vars (DB_*, OIDC_*, APP_PASSWORD_ENCRYPTION_KEY) - .gitignore excludes .env (never commit secrets) - apps/api/vitest.config.ts with environment: node - Wave 0 test stubs: health, auth/user, broker/crypto, broker/sync, broker/poller
23 lines
739 B
TypeScript
23 lines
739 B
TypeScript
/**
|
|
* Wave 0 stub — Broker: AES-GCM app-password encryption
|
|
*
|
|
* These tests are RED stubs. Implementation lives in:
|
|
* apps/api/src/broker/crypto.ts (Plan 03)
|
|
*
|
|
* Tests will be filled GREEN in Plan 03 when crypto helpers are implemented.
|
|
*/
|
|
|
|
import { describe, it } from 'vitest'
|
|
|
|
describe('encryptPassword / decryptPassword', () => {
|
|
it.todo('roundtrip: decrypt(encrypt(plaintext)) === plaintext (Plan 03)')
|
|
|
|
it.todo('different IVs produce different ciphertext for the same plaintext (Plan 03)')
|
|
|
|
it.todo('decrypting with a tampered authTag throws (Plan 03)')
|
|
|
|
it.todo('decrypting with a tampered ciphertext throws (Plan 03)')
|
|
|
|
it.todo('stored payload is valid JSON with iv, authTag, ciphertext fields (Plan 03)')
|
|
})
|