Files
SnapOtter/tests/unit/web/uuid.test.ts
T
SnapOtterandGitHub ae6a4c8b7c fix: error-only Sentry telemetry, storm-proof capture, and crash fixes (#476)
Removes Sentry tracing entirely (BullMQ idle polling burned 4.8M transactions in 2 days at the baked 0.1 rate), decouples PostHog sampling, and replaces the type-only error scrub with a vetted-field sanitizer plus SafeError/ToolInputError contracts. One classified capture path with per-signature throttles and a per-process ceiling makes storms impossible (NODE-1E was 4,541 events from one 30s loop). Browser errors move to a dedicated web Sentry project with their own source maps. Adds the SNAPOTTER_TELEMETRY runtime kill switch and silences test fleets.

Crash fixes: remote 204/304 SSRF process kill (NODE-20), conversion-preset boot crash loop (NODE-21), Redis version preflight + unhandled subscribe rejection (NODE-1T), Sign PDF on plain-http origins (NODE-1K/1M), wavesurfer/pdf.js teardown rejections (NODE-1P/1N), bundle-import ZlibError to 400 (NODE-1Z), chart-maker input errors declassified (NODE-1H/1J), asset requests skip the session DB lookup (NODE-1D).
2026-07-10 21:41:49 +08:00

31 lines
1.1 KiB
TypeScript

import { afterEach, describe, expect, it, vi } from "vitest";
import { safeRandomUUID } from "@/lib/uuid";
const V4_SHAPE = /^[0-9a-f]{8}-[0-9a-f]{4}-4[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$/;
describe("safeRandomUUID", () => {
afterEach(() => {
vi.unstubAllGlobals();
});
it("returns v4-shaped uuids", () => {
const id = safeRandomUUID();
expect(id).toMatch(V4_SHAPE);
expect(safeRandomUUID()).not.toBe(id);
});
it("works when crypto.randomUUID is unavailable (insecure context)", () => {
// Simulate a plain-http origin, where the browser exposes getRandomValues
// but not randomUUID. `delete crypto.randomUUID` would be a silent no-op
// here (the method lives on Crypto.prototype, not as an own property), so
// stub the global with a clone that genuinely lacks it.
const getRandomValues = crypto.getRandomValues.bind(crypto);
vi.stubGlobal("crypto", { getRandomValues });
expect(crypto.randomUUID).toBeUndefined();
const id = safeRandomUUID();
expect(id).toMatch(V4_SHAPE);
expect(safeRandomUUID()).not.toBe(id);
});
});