fix(labs): strict numeric parsing, atomic confirm guard, test integrity
- normalize.ts num(): parseFloat truncated at the first comma, so "1,200" silently became 1 (1000x error) and "5,5" became 5. Now strictly matches either US thousands-grouping or a plain number spanning the whole string; anything else (incl. ambiguous "5,5") returns null instead of a wrong value. - labs.ts confirm handler: the pending-status check ran before the request body was read, so two concurrent confirms could both pass it and double-insert. Added a guarded UPDATE ... WHERE status = 'pending' as the first statement inside the existing synchronous transaction; zero rows affected throws and the route returns 409, with the fast-path check kept for the common case. - Added missing `await` on two rejects.toThrow assertions (llm.test.ts, extract.test.ts) that were previously resolving before the assertion settled. - Bumped the 11th-failed-login rate-limit test to a 30s timeout — 10 sequential argon2id verifies can exceed bun:test's 5s default under load.
This commit is contained in:
@@ -54,7 +54,7 @@ describe("auth", () => {
|
||||
// The global window applies to everyone, including a request with the correct password.
|
||||
const blocked = await app.request("/api/login", json({ password: "hunter2hunter2" }));
|
||||
expect(blocked.status).toBe(429);
|
||||
});
|
||||
}, 30000); // 10 sequential argon2id verifies can exceed the 5s default timeout
|
||||
|
||||
test("unknown /api/* returns 404 when authed, 401 when unauthed", async () => {
|
||||
const app = makeApp();
|
||||
|
||||
Reference in New Issue
Block a user