test: cover the captcha and sign-up gates #255

Stängd
öppnade 2026-09-24 13:03:34 +00:00 av supernaut · 0 kommentarer
Ägare

Problem

The anti-spam and sign-up gates have no direct tests:

  • src/lib/captcha.ts: capSecret() fail-closed and dev bypass, validateCapToken() single-use spend, redeemChallenge() replay prevention.
  • src/lib/signup-access.ts: signupsOpen() and trialOpen(), the kill switches from ADR 0029 and ADR 0036.
  • src/pages/api/signup.ts: the order of the eligibility short-circuit, the database health check before provisioning, and the PRG status mapping. The pieces are unit-tested; the orchestration is not.
  • src/pages/api/captcha/{challenge,redeem}.ts. redeem.ts also casts request.json() without the schema validation other routes use.

Done when

Each path above has a test that fails if its guard is removed, and redeem.ts validates its body with a schema.

Epic: bitborg/bitborg-docs#69

## Problem The anti-spam and sign-up gates have no direct tests: - `src/lib/captcha.ts`: `capSecret()` fail-closed and dev bypass, `validateCapToken()` single-use spend, `redeemChallenge()` replay prevention. - `src/lib/signup-access.ts`: `signupsOpen()` and `trialOpen()`, the kill switches from ADR 0029 and ADR 0036. - `src/pages/api/signup.ts`: the order of the eligibility short-circuit, the database health check before provisioning, and the PRG status mapping. The pieces are unit-tested; the orchestration is not. - `src/pages/api/captcha/{challenge,redeem}.ts`. `redeem.ts` also casts `request.json()` without the schema validation other routes use. ## Done when Each path above has a test that fails if its guard is removed, and `redeem.ts` validates its body with a schema. Epic: bitborg/bitborg-docs#69
supernaut lade till detta till projektet Bitborg Web 2026-09-24 13:03:53 +00:00
supernaut refererade till detta ärende från en incheckning 2026-10-02 09:13:27 +00:00
Logga in för att delta i denna konversation.
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-web#255
Ingen beskrivning angiven.