forked from jappel/leistungsbilanz-ts
Full-codebase review turned up five real correctness/security bugs and
a dozen smaller inconsistencies; all are fixed here with matching test
coverage:
- BMK uniqueness silently allowed German-umlaut duplicates ("Ä1" vs
"ä1") because the DB's normalized index only folds ASCII case. Added
a shared Unicode-aware pre-check used by every circuit/component
insert and rename path (one of which had no pre-check at all).
- CircuitDeviceRow.simultaneityFactor had no upper bound at the row
level (command model and snapshot/restore schema), unlike every
sibling entity, letting a bad value silently corrupt power totals.
- Grid cell editing silently misread German thousands-separator input
("1.500" parsed as 1.5); "." is now rejected outright with a clear
message instead of guessing.
- The editor's shared command runner (runCommand/applyHistory) had no
re-entrancy guard, so a double click/drop could fire the same
command twice and race a BMK collision or revision conflict. Added a
synchronous ref guard plus isSaving on the buttons that lacked it.
- GET .../next-identifier leaked circuit-numbering state for sections
in other projects (no ownership check, 400 instead of 404). Moved
under /projects/:projectId and scoped it.
Also: added the missing circuits.section_id / circuit_device_rows.
circuit_id indexes (migration 0006), gave FormModal a focus trap /
Escape-to-close / focus restore and rebuilt ProjectSettingsModal on
top of it instead of duplicated markup, removed dead code (3 orphaned
domain model files, an unused persistence helper, a wrapper only used
by its own test), pointed the project page at GET /projects/:id
instead of listing+filtering client-side, closed the gap between the
documented 18 MB CSV limit and the ~17.17 MiB actually enforced, added
missing upper bounds on several free-text fields, filled in nine
missing German labels in the revision timeline, replaced a
key-order-fragile JSON.stringify equality check with a real field
comparison, made an implicit sort-order assumption in three
renumbering helpers explicit, cleared the sidebar's target selection
when it no longer resolves after a tree reload, and fixed
updateGlobalDevice to check-then-write instead of write-then-check.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
100 lines
3.6 KiB
TypeScript
100 lines
3.6 KiB
TypeScript
import assert from "node:assert/strict";
|
|
import { describe, it } from "node:test";
|
|
import { getNextCircuitIdentifier } from "../src/server/controllers/circuit.controller.js";
|
|
import {
|
|
circuitListRepository,
|
|
circuitSectionRepository,
|
|
} from "../src/server/composition/application-repositories.js";
|
|
import { circuitNumberingService } from "../src/server/composition/circuit-numbering-service.js";
|
|
|
|
function createMockResponse() {
|
|
let statusCode = 200;
|
|
let body: unknown;
|
|
return {
|
|
response: {
|
|
status(code: number) {
|
|
statusCode = code;
|
|
return this;
|
|
},
|
|
json(value: unknown) {
|
|
body = value;
|
|
return this;
|
|
},
|
|
},
|
|
getStatusCode: () => statusCode,
|
|
getBody: () => body,
|
|
};
|
|
}
|
|
|
|
describe("circuit controller", () => {
|
|
it("returns the next identifier when the section belongs to the project", async () => {
|
|
const originals = {
|
|
findSection: circuitSectionRepository.findById,
|
|
findList: circuitListRepository.findById,
|
|
getNextIdentifier: circuitNumberingService.getNextIdentifier,
|
|
};
|
|
circuitSectionRepository.findById = async () =>
|
|
({ id: "section-1", circuitListId: "list-1", prefix: "-1F" }) as never;
|
|
circuitListRepository.findById = async (projectId: string, circuitListId: string) =>
|
|
projectId === "project-1" && circuitListId === "list-1"
|
|
? ({ id: "list-1", projectId: "project-1" } as never)
|
|
: null;
|
|
circuitNumberingService.getNextIdentifier = async () => "-1F3";
|
|
const mock = createMockResponse();
|
|
try {
|
|
await getNextCircuitIdentifier(
|
|
{ params: { projectId: "project-1", sectionId: "section-1" } } as never,
|
|
mock.response as never
|
|
);
|
|
} finally {
|
|
circuitSectionRepository.findById = originals.findSection;
|
|
circuitListRepository.findById = originals.findList;
|
|
circuitNumberingService.getNextIdentifier = originals.getNextIdentifier;
|
|
}
|
|
assert.deepEqual(mock.getBody(), {
|
|
sectionId: "section-1",
|
|
nextIdentifier: "-1F3",
|
|
});
|
|
});
|
|
|
|
it("returns 404 instead of leaking numbering state for a section from another project", async () => {
|
|
const originals = {
|
|
findSection: circuitSectionRepository.findById,
|
|
findList: circuitListRepository.findById,
|
|
};
|
|
circuitSectionRepository.findById = async () =>
|
|
({ id: "section-1", circuitListId: "list-1", prefix: "-1F" }) as never;
|
|
// The section exists, but its circuit list does not belong to the requesting project.
|
|
circuitListRepository.findById = async () => null;
|
|
const mock = createMockResponse();
|
|
try {
|
|
await getNextCircuitIdentifier(
|
|
{ params: { projectId: "foreign-project", sectionId: "section-1" } } as never,
|
|
mock.response as never
|
|
);
|
|
} finally {
|
|
circuitSectionRepository.findById = originals.findSection;
|
|
circuitListRepository.findById = originals.findList;
|
|
}
|
|
assert.equal(mock.getStatusCode(), 404);
|
|
assert.deepEqual(mock.getBody(), { error: "Section not found" });
|
|
});
|
|
|
|
it("returns 404 for a section that does not exist", async () => {
|
|
const originals = {
|
|
findSection: circuitSectionRepository.findById,
|
|
};
|
|
circuitSectionRepository.findById = async () => null;
|
|
const mock = createMockResponse();
|
|
try {
|
|
await getNextCircuitIdentifier(
|
|
{ params: { projectId: "project-1", sectionId: "missing" } } as never,
|
|
mock.response as never
|
|
);
|
|
} finally {
|
|
circuitSectionRepository.findById = originals.findSection;
|
|
}
|
|
assert.equal(mock.getStatusCode(), 404);
|
|
assert.deepEqual(mock.getBody(), { error: "Section not found" });
|
|
});
|
|
});
|