Files
vyndr/tests/unit/session41AuditFixes.test.js
T
builtbykev 32069863dc Session 41: P0 audit fixes — MLB stat_types, broken routes, tier mismatch, self-hosted fonts (1940 tests)
- Backend: whitelist MLB stat_types in analyze.js + scan.js gates (mirrors
  python validation.py); fixes MLB scans 400ing.
- Routes: /settings -> /profile, /report -> /blog redirect pages.
- Profile: read tier from useAuth().tier (nav's source) to kill the
  Free-vs-DESK mismatch.
- Fonts: self-host Inter/JetBrains Mono/IBM Plex Mono via next/font, drop the
  503ing fonts.googleapis.com <link>; rewire literal font-family refs to vars.
- Kept /settings/security (real MFA page) intact — NOT clobbered to a redirect.
- +33 tests (1907 -> 1940), 149 suites; web build clean (exit 0).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-17 21:55:40 -04:00

81 lines
3.1 KiB
JavaScript
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
// Session 41 — P0 audit fixes. Frontend assertions read page source as text
// (same pattern as the Phase DH suites); backend stat-gate acceptance is
// covered in tests/integration/analyze.test.js.
const fs = require('fs');
const path = require('path');
const ROOT = path.join(__dirname, '..', '..');
const WEB = path.join(ROOT, 'web', 'src');
const read = (rel) => fs.readFileSync(path.join(WEB, rel), 'utf8');
describe('Session 41 — backend MLB stat_type whitelist', () => {
const analyze = fs.readFileSync(path.join(ROOT, 'src', 'routes', 'analyze.js'), 'utf8');
const scan = fs.readFileSync(path.join(ROOT, 'src', 'routes', 'scan.js'), 'utf8');
const mlbStats = ['hits', 'strikeouts', 'total_bases', 'rbi', 'home_runs', 'earned_runs', 'hits_allowed', 'innings_pitched'];
it.each(mlbStats)('/api/analyze gate whitelists MLB stat %s', (stat) => {
expect(analyze).toContain(`'${stat}'`);
});
it.each(mlbStats)('/api/scan (parlay) gate whitelists MLB stat %s', (stat) => {
expect(scan).toContain(`'${stat}'`);
});
});
describe('Session 41 — broken-route redirects', () => {
it('/settings redirects to /profile', () => {
const src = read('app/settings/page.tsx');
expect(src).toContain("from 'next/navigation'");
expect(src).toContain("redirect('/profile')");
});
it('/report redirects to /blog (THE REPORT link target)', () => {
const src = read('app/report/page.tsx');
expect(src).toContain("redirect('/blog')");
});
it('/settings/security stays the real MFA page (NOT clobbered into a redirect)', () => {
// The audit spec wanted this redirected too, but it is a working MFA
// enrollment flow — overwriting it would be a security-feature regression.
const src = read('app/settings/security/page.tsx');
expect(src).toContain('mfa');
expect(src).not.toContain("redirect('/profile')");
});
});
describe('Session 41 — profile reads tier from useAuth', () => {
const src = read('app/profile/page.tsx');
it('destructures tier from useAuth (same source as the nav)', () => {
expect(src).toMatch(/tier:\s*authTier/);
});
it('derives the displayed tier from the auth session', () => {
expect(src).toContain('authTier || profile.tier');
});
});
describe('Session 41 — self-hosted fonts (no Google Fonts CDN)', () => {
const layout = read('app/layout.tsx');
const globals = read('app/globals.css');
it('layout uses next/font instead of a runtime <link>', () => {
expect(layout).toContain("from 'next/font/google'");
expect(layout).toContain('Inter(');
expect(layout).toContain('JetBrains_Mono(');
});
it('removed the runtime Google Fonts stylesheet <link>', () => {
// The historical reference survives in a code comment; what must be gone
// is the actual CDN stylesheet href that caused the 503.
expect(layout).not.toMatch(/href=["'][^"']*fonts\.googleapis\.com/);
expect(layout).not.toContain('rel="stylesheet"');
});
it('globals.css :root maps --sans/--mono onto the next/font variables', () => {
expect(globals).toContain('--sans: var(--font-sans)');
expect(globals).toContain('--mono: var(--font-mono)');
});
});