Establishes the test suite. The repo previously had zero tests and no test framework installed. Tooling: - Vitest 2 added as devDependency. Chosen for ESM-native + TypeScript out-of-the-box, no Babel/ts-node, and fast cold starts. - vitest.config.ts sets environment=node and wires the '@/' path alias so tests can import app modules by the same path the app uses. - package.json scripts: 'test' (vitest run, CI-friendly) and 'test:watch'; also adds the long-missing 'typecheck' wrapper for 'tsc --noEmit'. - tsconfig.json now excludes *.test.ts from the app's build graph so the production bundle doesn't pull in test files (the editor still type-checks them via vitest). Tests: - admin-session.test.ts (8 cases): sign/verify round-trip for ADMIN and SUPER_ADMIN, tampered payload rejection (privilege-escalation attempt — should be rejected because the HMAC no longer matches), tampered signature rejection, missing-separator token, invalid base64/JSON payload, and cookie option flags (httpOnly, sameSite, path, secure under NODE_ENV=test vs production). - rate-limit.test.ts (4 cases): basic token bucket within window, independent key tracking, refill after window elapses (fake timers), and remaining-counter accounting. 12 tests, all green. |
||
|---|---|---|
| .next_old | ||
| docs | ||
| nginx/conf.d | ||
| prisma | ||
| public | ||
| scripts | ||
| src | ||
| .env.example | ||
| .gitignore | ||
| docker-compose.dev.yaml | ||
| docker-compose.yaml | ||
| Dockerfile | ||
| Dockerfile.dev | ||
| eslint.config.mjs | ||
| next.config.ts | ||
| package-lock.json | ||
| package.json | ||
| postcss.config.mjs | ||
| tsconfig.json | ||
| vitest.config.ts | ||
This is a Next.js project bootstrapped with create-next-app.
Getting Started
First, run the development server:
npm run dev
# or
yarn dev
# or
pnpm dev
# or
bun dev
Open http://localhost:3000 with your browser to see the result.
You can start editing the page by modifying app/page.tsx. The page auto-updates as you edit the file.
This project uses next/font to automatically optimize and load Geist, a new font family for Vercel.
Learn More
To learn more about Next.js, take a look at the following resources:
- Next.js Documentation - learn about Next.js features and API.
- Learn Next.js - an interactive Next.js tutorial.
You can check out the Next.js GitHub repository - your feedback and contributions are welcome!
Deploy on Vercel
The easiest way to deploy your Next.js app is to use the Vercel Platform from the creators of Next.js.
Check out our Next.js deployment documentation for more details.