diff --git a/backend/__tests__/unit/routes/telegram.webhook.connectCode.test.js b/backend/__tests__/unit/routes/telegram.webhook.connectCode.test.js index 590daa2fa..00aa13e16 100644 --- a/backend/__tests__/unit/routes/telegram.webhook.connectCode.test.js +++ b/backend/__tests__/unit/routes/telegram.webhook.connectCode.test.js @@ -200,6 +200,19 @@ describe('/commonly-enable hardening', () => { expect(isConnectCodeShape).toHaveBeenCalledWith(JOINED_CODE); }); + // vera 74641: the arm above pins WHERE the answer comes from, not that the + // answer is USED. A belt-and-braces drift -- ask the service and then also + // apply a local regex -- would keep every arm green. Admitting a malformed + // code through the service must therefore let the lookup proceed: if the + // route re-checks the code itself, this refuses instead and reddens. + it('lets the service answer decide, rather than re-checking the code itself', async () => { + Integration.findOne = jest.fn().mockResolvedValue(null); + isConnectCodeShape.mockReturnValueOnce(true); + await enable('not-a-connect-code'); + expect(registerEnableAttempt).toHaveBeenCalledTimes(1); + expect(Integration.findOne).toHaveBeenCalledTimes(1); + }); + it.each(['1964', 'abc123', `${JOINED_CODE}a`, JOINED_CODE.slice(0, 31)])( 'spends no attempt on the malformed code %s', async (input) => { diff --git a/backend/__tests__/unit/services/telegramConnectCode.test.js b/backend/__tests__/unit/services/telegramConnectCode.test.js index bfc840b63..b517c4228 100644 --- a/backend/__tests__/unit/services/telegramConnectCode.test.js +++ b/backend/__tests__/unit/services/telegramConnectCode.test.js @@ -34,8 +34,16 @@ describe('telegramConnectCode', () => { expect(isConnectCodeShape(connectCode.toUpperCase())).toBe(false); }); - it('draws its width from the same constant as the minter', () => { - expect(mintConnectCode().connectCode).toHaveLength(CONNECT_CODE_BYTES * 2); + // vera 74641: the title this arm used to carry ("draws its width from the + // same constant as the minter") claimed a derivation it cannot witness -- + // hex of N bytes is 2N characters whatever the constant is, so it survived + // every constant mutation. The derivation is carried by `accepts what the + // minter produces`; what this arm pins is that the code is HEX, which is + // why its width tracks the byte count. + it('mints hex, so the code is twice CONNECT_CODE_BYTES wide', () => { + const { connectCode } = mintConnectCode(); + expect(connectCode).toMatch(/^[0-9a-f]+$/); + expect(connectCode).toHaveLength(CONNECT_CODE_BYTES * 2); }); });