mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-08-14 19:22:32 +03:00
* feat(radar): shared supporter-key format validator
Extract the "omr_" + 40 hex supporter-key regex out of the
POST /api/radar/settings Zod schema into a pure, client-safe helper
(src/lib/radar/supporterKey.ts) so the format rule lives in exactly one
place and the upcoming activation-screen input can reuse it for a
UX-only pre-check. Server-side Zod validation stays authoritative.
Adds regression coverage: both directions of the format check, a
combined opt-in+supporterKey POST persisting both fields with the key
always masked (never raw) in either the POST or GET response body, and
a flag-off inertia case for the same combined payload shape.
* feat(dashboard): paste-key input on the Radar activation screen
The Radar activation screen had opt-in and the two "get a key" claim
buttons, but nowhere to paste a key someone already has — the last
piece of the supporter flow. Add the field to the activation screen
itself, as the primary path: pasting a key and submitting sends
POST /api/radar/settings with { optIn: true, supporterKey } together,
so pasting a valid key both sets it and unlocks the screen in one step.
Client-side format validation (via the shared isValidSupporterKeyFormat
helper) is a UX nicety only; the server's Zod schema already validates
authoritatively. When a key is already set (hasSupporterKey from
GET /api/radar/settings — e.g. set out of band before this UI existed),
the screen shows the masked form instead of an empty input, with a
"change key" control to paste a new one; the raw key is never
displayed. The existing plain "Activate" button (no key, community
tier) and the two claim/plans buttons are unchanged and still present
below, so all three paths to this screen coexist.
Adds 4 new i18n keys (keySectionTitle, keyInvalidFormatError,
activateWithKeyButton, changeKeyButton) with an English fallback across
all 43 locale files (172 entries) — no __MISSING__ sentinel, no price.
* docs(radar): close the paste-key-input known gap
RADAR.md documented a known gap: the activation screen had no
dedicated key-paste input, only the two claim/plans buttons. That gap
is closed — describe the new input, the combined opt-in+supporterKey
submission, and the masked-key "already activated" state instead.
---------
Co-authored-by: diegosouzapw <diegosouzapw@users.noreply.github.com>
67 lines
3.4 KiB
TypeScript
67 lines
3.4 KiB
TypeScript
/**
|
|
* tests/unit/radar-supporter-key-format.test.ts
|
|
*
|
|
* TDD guard for src/lib/radar/supporterKey.ts — the pure, client-safe
|
|
* "omr_" + 40 lowercase hex chars format check shared by:
|
|
* - the paste-key input on the activation screen (client-side UX check
|
|
* before the fetch — the server always revalidates, this is not a
|
|
* security boundary);
|
|
* - POST /api/radar/settings' Zod schema (server-side, authoritative).
|
|
*
|
|
* Pure module, no DB/network — both directions covered: valid accepted,
|
|
* every invalid shape rejected.
|
|
*/
|
|
|
|
import test from "node:test";
|
|
import assert from "node:assert/strict";
|
|
|
|
const VALID_KEY = "omr_abcdef01234567890abcdef01234567890abcdef";
|
|
|
|
test("isValidSupporterKeyFormat: accepts 'omr_' + 40 lowercase hex chars", async () => {
|
|
const { isValidSupporterKeyFormat } = await import("../../src/lib/radar/supporterKey.ts");
|
|
assert.equal(isValidSupporterKeyFormat(VALID_KEY), true);
|
|
// All-digit and all-letter (a-f) 40-char bodies are both valid hex.
|
|
assert.equal(isValidSupporterKeyFormat("omr_" + "0".repeat(40)), true);
|
|
assert.equal(isValidSupporterKeyFormat("omr_" + "f".repeat(40)), true);
|
|
});
|
|
|
|
test("isValidSupporterKeyFormat: rejects missing/wrong prefix", async () => {
|
|
const { isValidSupporterKeyFormat } = await import("../../src/lib/radar/supporterKey.ts");
|
|
assert.equal(isValidSupporterKeyFormat("abcdef01234567890abcdef01234567890abcdef"), false);
|
|
assert.equal(isValidSupporterKeyFormat("omr-abcdef01234567890abcdef01234567890abcdef"), false);
|
|
assert.equal(isValidSupporterKeyFormat("OMR_abcdef01234567890abcdef01234567890abcdef"), false);
|
|
});
|
|
|
|
test("isValidSupporterKeyFormat: rejects short/long hex bodies", async () => {
|
|
const { isValidSupporterKeyFormat } = await import("../../src/lib/radar/supporterKey.ts");
|
|
assert.equal(isValidSupporterKeyFormat("omr_abcdef"), false, "too short (6 hex chars)");
|
|
assert.equal(isValidSupporterKeyFormat("omr_" + "a".repeat(39)), false, "39 hex chars — one short");
|
|
assert.equal(isValidSupporterKeyFormat("omr_" + "a".repeat(41)), false, "41 hex chars — one over");
|
|
});
|
|
|
|
test("isValidSupporterKeyFormat: rejects uppercase hex", async () => {
|
|
const { isValidSupporterKeyFormat } = await import("../../src/lib/radar/supporterKey.ts");
|
|
assert.equal(isValidSupporterKeyFormat("omr_ABCDEF01234567890abcdef01234567890abcdef"), false);
|
|
});
|
|
|
|
test("isValidSupporterKeyFormat: rejects empty string and whitespace", async () => {
|
|
const { isValidSupporterKeyFormat } = await import("../../src/lib/radar/supporterKey.ts");
|
|
assert.equal(isValidSupporterKeyFormat(""), false);
|
|
assert.equal(isValidSupporterKeyFormat(" "), false);
|
|
assert.equal(isValidSupporterKeyFormat(` ${VALID_KEY} `), false, "surrounding whitespace not trimmed by the helper itself");
|
|
});
|
|
|
|
test("isValidSupporterKeyFormat: rejects non-hex characters in the body", async () => {
|
|
const { isValidSupporterKeyFormat } = await import("../../src/lib/radar/supporterKey.ts");
|
|
assert.equal(isValidSupporterKeyFormat("omr_" + "g".repeat(40)), false);
|
|
assert.equal(isValidSupporterKeyFormat("omr_" + "z".repeat(40)), false);
|
|
});
|
|
|
|
test("SUPPORTER_KEY_REGEX: exported and matches the same behavior as the helper", async () => {
|
|
const { SUPPORTER_KEY_REGEX, isValidSupporterKeyFormat } = await import(
|
|
"../../src/lib/radar/supporterKey.ts"
|
|
);
|
|
assert.ok(SUPPORTER_KEY_REGEX instanceof RegExp);
|
|
assert.equal(SUPPORTER_KEY_REGEX.test(VALID_KEY), isValidSupporterKeyFormat(VALID_KEY));
|
|
});
|