describe("Phase 2 file validation", () => { beforeEach(() => jest.resetModules()); test("detects a valid PNG and creates checksum/safe name", () => { const { validateUpload } = require("../../app/services/storage/file-validation.service"); const buffer = Buffer.concat([Buffer.from([0x89,0x50,0x4e,0x47,0x0d,0x0a,0x1a,0x0a]), Buffer.from("payload")]); const result = validateUpload({ buffer, mimetype: "image/png", originalname: "../unsafe name.svg" }); expect(result.mimeType).toBe("image/png"); expect(result.safeName).toBe("unsafe_name.png"); expect(result.checksum).toMatch(/^[a-f0-9]{64}$/); }); test("rejects claimed MIME that disagrees with magic bytes", () => { const { validateUpload } = require("../../app/services/storage/file-validation.service"); expect(() => validateUpload({ buffer: Buffer.from("not an image"), mimetype: "image/png", originalname: "x.png" })).toThrow("does not match"); }); test("rejects empty files", () => { const { validateUpload } = require("../../app/services/storage/file-validation.service"); expect(() => validateUpload({ buffer: Buffer.alloc(0), mimetype: "image/png", originalname: "x.png" })).toThrow("Empty"); }); test("builds controlled owner/date keys without original filenames", () => { const { createObjectKey } = require("../../app/services/storage/storage.service"); expect(createObjectKey({ ownerId: "usr_1", mimeType: "application/pdf", purpose: "document", now: new Date("2026-09-03T00:00:00Z"), id: "fixed" })).toBe("documents/usr_1/2026/09/fixed.pdf"); }); });