Go to file
dimitar 1b917540f4 test: Phase 4 — vitest setup + unit tests for admin-session and rate-limit
Establishes the test suite. The repo previously had zero tests and no
test framework installed.

Tooling:
- Vitest 2 added as devDependency. Chosen for ESM-native + TypeScript
  out-of-the-box, no Babel/ts-node, and fast cold starts.
- vitest.config.ts sets environment=node and wires the '@/'
  path alias so tests can import app modules by the same path the
  app uses.
- package.json scripts: 'test' (vitest run, CI-friendly) and
  'test:watch'; also adds the long-missing 'typecheck' wrapper for
  'tsc --noEmit'.
- tsconfig.json now excludes *.test.ts from the app's build graph so
  the production bundle doesn't pull in test files (the editor still
  type-checks them via vitest).

Tests:
- admin-session.test.ts (8 cases): sign/verify round-trip for ADMIN
  and SUPER_ADMIN, tampered payload rejection (privilege-escalation
  attempt — should be rejected because the HMAC no longer matches),
  tampered signature rejection, missing-separator token, invalid
  base64/JSON payload, and cookie option flags (httpOnly, sameSite,
  path, secure under NODE_ENV=test vs production).
- rate-limit.test.ts (4 cases): basic token bucket within window,
  independent key tracking, refill after window elapses (fake
  timers), and remaining-counter accounting.

12 tests, all green.
2026-08-02 13:05:06 +02:00
.next_old superAdmin and admin implemented 2026-08-01 23:42:42 +02:00
docs superAdmin and admin implemented 2026-08-01 23:42:42 +02:00
nginx/conf.d init 2026-06-20 18:17:30 +02:00
prisma feat(db): add AdminUser and Code models with migration 2026-07-29 18:54:40 +02:00
public init 2026-06-20 18:17:30 +02:00
scripts feat(security): Phase 1 — harden auth, rate limiting, CSRF, upload validation 2026-08-02 10:24:28 +02:00
src test: Phase 4 — vitest setup + unit tests for admin-session and rate-limit 2026-08-02 13:05:06 +02:00
.env.example feat(security): Phase 1 — harden auth, rate limiting, CSRF, upload validation 2026-08-02 10:24:28 +02:00
.gitignore docs: add implementation plan and gitignore for old build artifacts 2026-07-29 19:08:14 +02:00
docker-compose.dev.yaml local dev setup 2026-07-29 16:52:54 +02:00
docker-compose.yaml t v3 2026-06-22 23:28:41 +02:00
Dockerfile prisma fix 2026-06-22 05:14:47 +02:00
Dockerfile.dev local dev setup 2026-07-29 16:52:54 +02:00
eslint.config.mjs init 2026-06-20 18:17:30 +02:00
next.config.ts perf: Phase 3 — parallel uploads + security headers, powered-by-header off 2026-08-02 12:21:23 +02:00
package-lock.json test: Phase 4 — vitest setup + unit tests for admin-session and rate-limit 2026-08-02 13:05:06 +02:00
package.json test: Phase 4 — vitest setup + unit tests for admin-session and rate-limit 2026-08-02 13:05:06 +02:00
postcss.config.mjs init 2026-06-20 18:17:30 +02:00
tsconfig.json test: Phase 4 — vitest setup + unit tests for admin-session and rate-limit 2026-08-02 13:05:06 +02:00
vitest.config.ts test: Phase 4 — vitest setup + unit tests for admin-session and rate-limit 2026-08-02 13:05:06 +02:00

This is a Next.js project bootstrapped with create-next-app.

Getting Started

First, run the development server:

npm run dev
# or
yarn dev
# or
pnpm dev
# or
bun dev

Open http://localhost:3000 with your browser to see the result.

You can start editing the page by modifying app/page.tsx. The page auto-updates as you edit the file.

This project uses next/font to automatically optimize and load Geist, a new font family for Vercel.

Learn More

To learn more about Next.js, take a look at the following resources:

You can check out the Next.js GitHub repository - your feedback and contributions are welcome!

Deploy on Vercel

The easiest way to deploy your Next.js app is to use the Vercel Platform from the creators of Next.js.

Check out our Next.js deployment documentation for more details.