import { describe, expect, test } from "bun:test"; import { getClientAddress, hashClientAddress, } from "./visitor-identifiers"; describe("privacy-preserving visitor tracking", () => { test("uses the first valid forwarded address", () => { const headers = new Headers({ "x-forwarded-for": "203.0.113.9, 10.0.0.1", "x-real-ip": "192.0.2.2", }); expect(getClientAddress(headers)).toBe("203.0.113.9"); }); test("rejects untrusted non-IP identifiers", () => { expect( getClientAddress(new Headers({ "x-forwarded-for": "unknown" })), ).toBeNull(); }); test("creates a stable identifier without retaining the address", () => { const address = "203.0.113.9"; const identifier = hashClientAddress(address, "test-secret"); expect(identifier).toBe(hashClientAddress(address, "test-secret")); expect(identifier).not.toContain(address); expect(identifier).toHaveLength(64); }); });