Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 13 additions & 0 deletions backend/__tests__/unit/routes/telegram.webhook.connectCode.test.js
Original file line number Diff line number Diff line change
Expand Up @@ -200,6 +200,19 @@ describe('/commonly-enable hardening', () => {
expect(isConnectCodeShape).toHaveBeenCalledWith(JOINED_CODE);
});

// vera 74641: the arm above pins WHERE the answer comes from, not that the
// answer is USED. A belt-and-braces drift -- ask the service and then also
// apply a local regex -- would keep every arm green. Admitting a malformed
// code through the service must therefore let the lookup proceed: if the
// route re-checks the code itself, this refuses instead and reddens.
it('lets the service answer decide, rather than re-checking the code itself', async () => {
Integration.findOne = jest.fn().mockResolvedValue(null);
isConnectCodeShape.mockReturnValueOnce(true);
await enable('not-a-connect-code');
expect(registerEnableAttempt).toHaveBeenCalledTimes(1);
expect(Integration.findOne).toHaveBeenCalledTimes(1);
});

it.each(['1964', 'abc123', `${JOINED_CODE}a`, JOINED_CODE.slice(0, 31)])(
'spends no attempt on the malformed code %s',
async (input) => {
Expand Down
12 changes: 10 additions & 2 deletions backend/__tests__/unit/services/telegramConnectCode.test.js
Original file line number Diff line number Diff line change
Expand Up @@ -34,8 +34,16 @@ describe('telegramConnectCode', () => {
expect(isConnectCodeShape(connectCode.toUpperCase())).toBe(false);
});

it('draws its width from the same constant as the minter', () => {
expect(mintConnectCode().connectCode).toHaveLength(CONNECT_CODE_BYTES * 2);
// vera 74641: the title this arm used to carry ("draws its width from the
// same constant as the minter") claimed a derivation it cannot witness --
// hex of N bytes is 2N characters whatever the constant is, so it survived
// every constant mutation. The derivation is carried by `accepts what the
// minter produces`; what this arm pins is that the code is HEX, which is
// why its width tracks the byte count.
it('mints hex, so the code is twice CONNECT_CODE_BYTES wide', () => {
const { connectCode } = mintConnectCode();
expect(connectCode).toMatch(/^[0-9a-f]+$/);
expect(connectCode).toHaveLength(CONNECT_CODE_BYTES * 2);
});
});

Expand Down
Loading