af3c24275d
- Backend: NestJS 10 + TypeORM (better-sqlite3) feature-modular layout.
- Entities: user, setting, category, challenge, challenge_file, solve,
refresh_token, blog_post. Auto-run migrations + idempotent 6-system-
category seed on startup.
- Argon2id password hashing with policy check; JWT access + rotating
refresh tokens (HttpOnly cookie); CSRF middleware (SameSite + custom
X-CSRF-Token header); global JWT auth guard with @Public() opt-out;
per-IP login backoff + per-IP registration rate limit.
- Endpoints: auth (login/refresh/logout/csrf), users (first-admin
registration), system (bootstrap/event status/SSE), admin (guarded
user CRUD with last-admin invariant), frontend module (uploads +
SPA fallback).
- Security: helmet+CSP+HSTS-gated-by-TLS, CORS allowlist, structured
global exception filter, Zod request validation pipes, OpenAPI 3.1
served at /api/docs and /api/docs-json, 10 canonical themes under
backend/themes/.
- Frontend: Angular 17 standalone components, lazy-loaded feature routes,
signals, functional HttpInterceptorFn (csrf + auth), functional
CanActivateFn auth guard, HttpOnly-cookie-based auth service.
- Tests: Jest + supertest, 46 tests across 13 suites covering
migrations, env schema, theme loader, event status, login backoff,
registration rate limit, ApiError shape, bootstrap integration,
auth refresh rotation, admin guard, last-admin invariant, SSE flat
payloads. Single-command runner: `npm test`.
62 lines
2.2 KiB
TypeScript
62 lines
2.2 KiB
TypeScript
process.env.DATABASE_PATH = ':memory:';
|
|
process.env.THEMES_DIR = './themes';
|
|
process.env.FRONTEND_DIST = './frontend/dist';
|
|
|
|
import { Test } from '@nestjs/testing';
|
|
import { INestApplication } from '@nestjs/common';
|
|
import { HttpAdapterHost } from '@nestjs/core';
|
|
import request from 'supertest';
|
|
import { AppModule } from '../../backend/src/app.module';
|
|
import { GlobalExceptionFilter } from '../../backend/src/common/filters/global-exception.filter';
|
|
|
|
describe('SSE flattened payloads', () => {
|
|
let app: INestApplication;
|
|
|
|
beforeAll(async () => {
|
|
const moduleRef = await Test.createTestingModule({ imports: [AppModule] }).compile();
|
|
app = moduleRef.createNestApplication();
|
|
const httpAdapterHost = app.get(HttpAdapterHost);
|
|
app.useGlobalFilters(new GlobalExceptionFilter(httpAdapterHost));
|
|
await app.init();
|
|
});
|
|
|
|
afterAll(async () => {
|
|
await app.close();
|
|
});
|
|
|
|
it('event/stream emits a flattened { status, countdownMs, serverNowUtc, startUtc, endUtc } payload', (done) => {
|
|
const server = app.getHttpServer();
|
|
const req = request(server).get('/api/v1/event/stream');
|
|
let received = false;
|
|
req
|
|
.buffer(true)
|
|
.parse((res, cb) => {
|
|
const chunks: Buffer[] = [];
|
|
res.on('data', (chunk: Buffer) => {
|
|
chunks.push(chunk);
|
|
if (received) return;
|
|
const text = Buffer.concat(chunks).toString('utf8');
|
|
const match = /data: ({.*?})\n/.exec(text);
|
|
if (match) {
|
|
try {
|
|
const payload = JSON.parse(match[1]);
|
|
expect(payload).toHaveProperty('status');
|
|
expect(payload).toHaveProperty('countdownMs');
|
|
expect(payload).toHaveProperty('serverNowUtc');
|
|
expect(payload).toHaveProperty('startUtc');
|
|
expect(payload).toHaveProperty('endUtc');
|
|
expect(['Stopped', 'Running']).toContain(payload.status);
|
|
received = true;
|
|
(res as any).destroy();
|
|
done();
|
|
} catch (e) {
|
|
done(e);
|
|
}
|
|
}
|
|
});
|
|
res.on('end', () => cb(null, Buffer.concat(chunks)));
|
|
res.on('error', (err) => cb(err, null));
|
|
})
|
|
.end(() => {});
|
|
}, 10_000);
|
|
}); |