test: use portable file reads under Vitest
This commit is contained in:
@@ -1,7 +1,9 @@
|
||||
import { readFile } from "node:fs/promises";
|
||||
|
||||
import { describe, expect, it } from "vitest";
|
||||
|
||||
async function repositoryFile(path: string): Promise<string> {
|
||||
return Bun.file(new URL(`../${path}`, import.meta.url)).text();
|
||||
return readFile(new URL(`../${path}`, import.meta.url), "utf8");
|
||||
}
|
||||
|
||||
describe("production deployment contract", () => {
|
||||
|
||||
@@ -1,3 +1,5 @@
|
||||
import { readFile } from "node:fs/promises";
|
||||
|
||||
import { describe, expect, it } from "vitest";
|
||||
|
||||
const protectedEntryPoints = [
|
||||
@@ -11,16 +13,20 @@ const protectedEntryPoints = [
|
||||
describe("administrative security boundaries", () => {
|
||||
for (const path of protectedEntryPoints) {
|
||||
it(`${path} repeats server-side admin authorization`, async () => {
|
||||
const source = await Bun.file(new URL(`../${path}`, import.meta.url)).text();
|
||||
const source = await readFile(
|
||||
new URL(`../${path}`, import.meta.url),
|
||||
"utf8",
|
||||
);
|
||||
expect(source).toContain("requireAdmin");
|
||||
expect(source).toMatch(/await requireAdmin\(\)/u);
|
||||
});
|
||||
}
|
||||
|
||||
it("same-origin media checks visibility before falling back to admin auth", async () => {
|
||||
const source = await Bun.file(
|
||||
const source = await readFile(
|
||||
new URL("../app/media/[id]/route.ts", import.meta.url),
|
||||
).text();
|
||||
"utf8",
|
||||
);
|
||||
expect(source).toContain("getMediaVisibility");
|
||||
expect(source).toContain("getAdminSession");
|
||||
expect(source.indexOf("getMediaVisibility")).toBeLessThan(
|
||||
|
||||
Reference in New Issue
Block a user