Files
OmniRoute/tests/unit/radar-supporter-key-format.test.ts
Diego Rodrigues de Sa e Souza 0d7c019eec campo de colar chave omr_ na tela de ativação (#9758)
* feat(radar): shared supporter-key format validator

Extract the "omr_" + 40 hex supporter-key regex out of the
POST /api/radar/settings Zod schema into a pure, client-safe helper
(src/lib/radar/supporterKey.ts) so the format rule lives in exactly one
place and the upcoming activation-screen input can reuse it for a
UX-only pre-check. Server-side Zod validation stays authoritative.

Adds regression coverage: both directions of the format check, a
combined opt-in+supporterKey POST persisting both fields with the key
always masked (never raw) in either the POST or GET response body, and
a flag-off inertia case for the same combined payload shape.

* feat(dashboard): paste-key input on the Radar activation screen

The Radar activation screen had opt-in and the two "get a key" claim
buttons, but nowhere to paste a key someone already has — the last
piece of the supporter flow. Add the field to the activation screen
itself, as the primary path: pasting a key and submitting sends
POST /api/radar/settings with { optIn: true, supporterKey } together,
so pasting a valid key both sets it and unlocks the screen in one step.

Client-side format validation (via the shared isValidSupporterKeyFormat
helper) is a UX nicety only; the server's Zod schema already validates
authoritatively. When a key is already set (hasSupporterKey from
GET /api/radar/settings — e.g. set out of band before this UI existed),
the screen shows the masked form instead of an empty input, with a
"change key" control to paste a new one; the raw key is never
displayed. The existing plain "Activate" button (no key, community
tier) and the two claim/plans buttons are unchanged and still present
below, so all three paths to this screen coexist.

Adds 4 new i18n keys (keySectionTitle, keyInvalidFormatError,
activateWithKeyButton, changeKeyButton) with an English fallback across
all 43 locale files (172 entries) — no __MISSING__ sentinel, no price.

* docs(radar): close the paste-key-input known gap

RADAR.md documented a known gap: the activation screen had no
dedicated key-paste input, only the two claim/plans buttons. That gap
is closed — describe the new input, the combined opt-in+supporterKey
submission, and the masked-key "already activated" state instead.

---------

Co-authored-by: diegosouzapw <diegosouzapw@users.noreply.github.com>
2026-08-08 08:10:14 -03:00

67 lines
3.4 KiB
TypeScript

/**
* tests/unit/radar-supporter-key-format.test.ts
*
* TDD guard for src/lib/radar/supporterKey.ts — the pure, client-safe
* "omr_" + 40 lowercase hex chars format check shared by:
* - the paste-key input on the activation screen (client-side UX check
* before the fetch — the server always revalidates, this is not a
* security boundary);
* - POST /api/radar/settings' Zod schema (server-side, authoritative).
*
* Pure module, no DB/network — both directions covered: valid accepted,
* every invalid shape rejected.
*/
import test from "node:test";
import assert from "node:assert/strict";
const VALID_KEY = "omr_abcdef01234567890abcdef01234567890abcdef";
test("isValidSupporterKeyFormat: accepts 'omr_' + 40 lowercase hex chars", async () => {
const { isValidSupporterKeyFormat } = await import("../../src/lib/radar/supporterKey.ts");
assert.equal(isValidSupporterKeyFormat(VALID_KEY), true);
// All-digit and all-letter (a-f) 40-char bodies are both valid hex.
assert.equal(isValidSupporterKeyFormat("omr_" + "0".repeat(40)), true);
assert.equal(isValidSupporterKeyFormat("omr_" + "f".repeat(40)), true);
});
test("isValidSupporterKeyFormat: rejects missing/wrong prefix", async () => {
const { isValidSupporterKeyFormat } = await import("../../src/lib/radar/supporterKey.ts");
assert.equal(isValidSupporterKeyFormat("abcdef01234567890abcdef01234567890abcdef"), false);
assert.equal(isValidSupporterKeyFormat("omr-abcdef01234567890abcdef01234567890abcdef"), false);
assert.equal(isValidSupporterKeyFormat("OMR_abcdef01234567890abcdef01234567890abcdef"), false);
});
test("isValidSupporterKeyFormat: rejects short/long hex bodies", async () => {
const { isValidSupporterKeyFormat } = await import("../../src/lib/radar/supporterKey.ts");
assert.equal(isValidSupporterKeyFormat("omr_abcdef"), false, "too short (6 hex chars)");
assert.equal(isValidSupporterKeyFormat("omr_" + "a".repeat(39)), false, "39 hex chars — one short");
assert.equal(isValidSupporterKeyFormat("omr_" + "a".repeat(41)), false, "41 hex chars — one over");
});
test("isValidSupporterKeyFormat: rejects uppercase hex", async () => {
const { isValidSupporterKeyFormat } = await import("../../src/lib/radar/supporterKey.ts");
assert.equal(isValidSupporterKeyFormat("omr_ABCDEF01234567890abcdef01234567890abcdef"), false);
});
test("isValidSupporterKeyFormat: rejects empty string and whitespace", async () => {
const { isValidSupporterKeyFormat } = await import("../../src/lib/radar/supporterKey.ts");
assert.equal(isValidSupporterKeyFormat(""), false);
assert.equal(isValidSupporterKeyFormat(" "), false);
assert.equal(isValidSupporterKeyFormat(` ${VALID_KEY} `), false, "surrounding whitespace not trimmed by the helper itself");
});
test("isValidSupporterKeyFormat: rejects non-hex characters in the body", async () => {
const { isValidSupporterKeyFormat } = await import("../../src/lib/radar/supporterKey.ts");
assert.equal(isValidSupporterKeyFormat("omr_" + "g".repeat(40)), false);
assert.equal(isValidSupporterKeyFormat("omr_" + "z".repeat(40)), false);
});
test("SUPPORTER_KEY_REGEX: exported and matches the same behavior as the helper", async () => {
const { SUPPORTER_KEY_REGEX, isValidSupporterKeyFormat } = await import(
"../../src/lib/radar/supporterKey.ts"
);
assert.ok(SUPPORTER_KEY_REGEX instanceof RegExp);
assert.equal(SUPPORTER_KEY_REGEX.test(VALID_KEY), isValidSupporterKeyFormat(VALID_KEY));
});