Establishes the test suite. The repo previously had zero tests and no
test framework installed.
Tooling:
- Vitest 2 added as devDependency. Chosen for ESM-native + TypeScript
out-of-the-box, no Babel/ts-node, and fast cold starts.
- vitest.config.ts sets environment=node and wires the '@/'
path alias so tests can import app modules by the same path the
app uses.
- package.json scripts: 'test' (vitest run, CI-friendly) and
'test:watch'; also adds the long-missing 'typecheck' wrapper for
'tsc --noEmit'.
- tsconfig.json now excludes *.test.ts from the app's build graph so
the production bundle doesn't pull in test files (the editor still
type-checks them via vitest).
Tests:
- admin-session.test.ts (8 cases): sign/verify round-trip for ADMIN
and SUPER_ADMIN, tampered payload rejection (privilege-escalation
attempt — should be rejected because the HMAC no longer matches),
tampered signature rejection, missing-separator token, invalid
base64/JSON payload, and cookie option flags (httpOnly, sameSite,
path, secure under NODE_ENV=test vs production).
- rate-limit.test.ts (4 cases): basic token bucket within window,
independent key tracking, refill after window elapses (fake
timers), and remaining-counter accounting.
12 tests, all green.