describe("Phase 2 cross-cutting policies", () => {
test("email templates escape user-controlled HTML", () => {
const { loadTemplate } = require("../../app/utils/mail.util");
const html = loadTemplate("otp", { firstName: "", otp: "123456" });
expect(html).toContain("<script>x</script>"); expect(html).not.toContain("");
});
test("security notifications bypass disabled marketing preference", () => {
const { channelAllowed } = require("../../app/services/notification/notification-policy.service");
expect(channelAllowed({ eventType: "LOGIN_OTP", channel: "EMAIL", profile: { notificationsEnabled: false } })).toBe(true);
expect(channelAllowed({ eventType: "MARKETING", channel: "EMAIL", profile: { notificationsEnabled: false } })).toBe(false);
});
test("queue policies specify bounded retries and retention", () => {
jest.resetModules();
jest.doMock("../../app/config/redisClient", () => ({}));
jest.doMock("bullmq", () => ({ Queue: jest.fn(function Queue(name, options) { this.name = name; this.opts = options; }) }));
const emailQueue = require("../../app/queues/email.queue");
expect(emailQueue.opts.defaultJobOptions.attempts).toBe(5);
expect(emailQueue.opts.defaultJobOptions.removeOnComplete).toBeTruthy();
});
});