From 9a8326de8afe7d49b79d35842eb09c803cef2b82 Mon Sep 17 00:00:00 2001 From: Lily Shen <115414357+lilyshen0722@users.noreply.github.com> Date: Sat, 26 Sep 2026 20:42:39 -0700 Subject: [PATCH] test(telegram): pin that the route uses the service's shape answer, and name the hex arm honestly (TASK-159 follow-up) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Vera's 74641 review of #1937 left two items; both are here rather than in a moved head, so her clearance of `3cde635f` stood. (a) `draws its width from the same constant as the minter` survived every constant mutation, because hex of N bytes is always 2N characters — it claimed a derivation it cannot witness. Renamed to what it pins and given the assertion that makes the title true: the minted code matches `^[0-9a-f]+$`. The derivation claim is carried by `accepts what the minter produces and refuses one character either side`, and the arm now says so. (b) The route-side witness pinned WHERE the shape answer comes from, not that the answer is USED: a belt-and-braces drift — ask the service and then also apply a local regex — stayed green. New arm mocks `isConnectCodeShape` to admit a malformed code and asserts the lookup proceeds, so re-checking the code in the route reddens. --- .../routes/telegram.webhook.connectCode.test.js | 13 +++++++++++++ .../unit/services/telegramConnectCode.test.js | 12 ++++++++++-- 2 files changed, 23 insertions(+), 2 deletions(-) diff --git a/backend/__tests__/unit/routes/telegram.webhook.connectCode.test.js b/backend/__tests__/unit/routes/telegram.webhook.connectCode.test.js index 590daa2fa..00aa13e16 100644 --- a/backend/__tests__/unit/routes/telegram.webhook.connectCode.test.js +++ b/backend/__tests__/unit/routes/telegram.webhook.connectCode.test.js @@ -200,6 +200,19 @@ describe('/commonly-enable hardening', () => { expect(isConnectCodeShape).toHaveBeenCalledWith(JOINED_CODE); }); + // vera 74641: the arm above pins WHERE the answer comes from, not that the + // answer is USED. A belt-and-braces drift -- ask the service and then also + // apply a local regex -- would keep every arm green. Admitting a malformed + // code through the service must therefore let the lookup proceed: if the + // route re-checks the code itself, this refuses instead and reddens. + it('lets the service answer decide, rather than re-checking the code itself', async () => { + Integration.findOne = jest.fn().mockResolvedValue(null); + isConnectCodeShape.mockReturnValueOnce(true); + await enable('not-a-connect-code'); + expect(registerEnableAttempt).toHaveBeenCalledTimes(1); + expect(Integration.findOne).toHaveBeenCalledTimes(1); + }); + it.each(['1964', 'abc123', `${JOINED_CODE}a`, JOINED_CODE.slice(0, 31)])( 'spends no attempt on the malformed code %s', async (input) => { diff --git a/backend/__tests__/unit/services/telegramConnectCode.test.js b/backend/__tests__/unit/services/telegramConnectCode.test.js index bfc840b63..b517c4228 100644 --- a/backend/__tests__/unit/services/telegramConnectCode.test.js +++ b/backend/__tests__/unit/services/telegramConnectCode.test.js @@ -34,8 +34,16 @@ describe('telegramConnectCode', () => { expect(isConnectCodeShape(connectCode.toUpperCase())).toBe(false); }); - it('draws its width from the same constant as the minter', () => { - expect(mintConnectCode().connectCode).toHaveLength(CONNECT_CODE_BYTES * 2); + // vera 74641: the title this arm used to carry ("draws its width from the + // same constant as the minter") claimed a derivation it cannot witness -- + // hex of N bytes is 2N characters whatever the constant is, so it survived + // every constant mutation. The derivation is carried by `accepts what the + // minter produces`; what this arm pins is that the code is HEX, which is + // why its width tracks the byte count. + it('mints hex, so the code is twice CONNECT_CODE_BYTES wide', () => { + const { connectCode } = mintConnectCode(); + expect(connectCode).toMatch(/^[0-9a-f]+$/); + expect(connectCode).toHaveLength(CONNECT_CODE_BYTES * 2); }); });