b6b345f245
- Refactor email verification and password reset utilities to use new email service. - Introduce email delivery queue and notification delivery model for better tracking. - Enhance file validation and storage services for improved security and ownership management. - Add cron job for cleaning inactive notifications with retention policy. - Update document worker to handle document generation and storage more efficiently. - Implement logging improvements in activity and log workers. - Create comprehensive documentation for new API endpoints and services. - Add unit tests for file validation and notification policies to ensure robustness.
21 lines
1.3 KiB
JavaScript
21 lines
1.3 KiB
JavaScript
describe("Phase 2 cross-cutting policies", () => {
|
|
test("email templates escape user-controlled HTML", () => {
|
|
const { loadTemplate } = require("../../app/utils/mail.util");
|
|
const html = loadTemplate("otp", { firstName: "<script>x</script>", otp: "123456" });
|
|
expect(html).toContain("<script>x</script>"); expect(html).not.toContain("<script>x</script>");
|
|
});
|
|
test("security notifications bypass disabled marketing preference", () => {
|
|
const { channelAllowed } = require("../../app/services/notification/notification-policy.service");
|
|
expect(channelAllowed({ eventType: "LOGIN_OTP", channel: "EMAIL", profile: { notificationsEnabled: false } })).toBe(true);
|
|
expect(channelAllowed({ eventType: "MARKETING", channel: "EMAIL", profile: { notificationsEnabled: false } })).toBe(false);
|
|
});
|
|
test("queue policies specify bounded retries and retention", () => {
|
|
jest.resetModules();
|
|
jest.doMock("../../app/config/redisClient", () => ({}));
|
|
jest.doMock("bullmq", () => ({ Queue: jest.fn(function Queue(name, options) { this.name = name; this.opts = options; }) }));
|
|
const emailQueue = require("../../app/queues/email.queue");
|
|
expect(emailQueue.opts.defaultJobOptions.attempts).toBe(5);
|
|
expect(emailQueue.opts.defaultJobOptions.removeOnComplete).toBeTruthy();
|
|
});
|
|
});
|