describe("Phase 2 cross-cutting policies", () => { test("email templates escape user-controlled HTML", () => { const { loadTemplate } = require("../../app/utils/mail.util"); const html = loadTemplate("otp", { firstName: "", otp: "123456" }); expect(html).toContain("<script>x</script>"); expect(html).not.toContain(""); }); test("security notifications bypass disabled marketing preference", () => { const { channelAllowed } = require("../../app/services/notification/notification-policy.service"); expect(channelAllowed({ eventType: "LOGIN_OTP", channel: "EMAIL", profile: { notificationsEnabled: false } })).toBe(true); expect(channelAllowed({ eventType: "MARKETING", channel: "EMAIL", profile: { notificationsEnabled: false } })).toBe(false); }); test("queue policies specify bounded retries and retention", () => { jest.resetModules(); jest.doMock("../../app/config/redisClient", () => ({})); jest.doMock("bullmq", () => ({ Queue: jest.fn(function Queue(name, options) { this.name = name; this.opts = options; }) })); const emailQueue = require("../../app/queues/email.queue"); expect(emailQueue.opts.defaultJobOptions.attempts).toBe(5); expect(emailQueue.opts.defaultJobOptions.removeOnComplete).toBeTruthy(); }); });