Keep private email out of the Honestly export
All checks were successful
CI / Lint, Typen, Tests, Build (push) Successful in 11m30s
CI / Migrationen auf leerer Datenbank (push) Successful in 10m6s

The Email column exported employees.email, which is the person's
private address. That does not belong in a file sent to an outside
survey provider, least of all as the address invitations go to in the
employer's name.

The column now stays as a placeholder for the work email, which does
not exist in the schema yet and will be added later. It is empty until
then, but keeps its place so the column mapping set up in Honestly does
not have to change once the address arrives. The export no longer
reads employees.email at all, so it cannot end up in another column
by accident either.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
2026-09-18 15:07:43 +02:00
parent 779d6116b2
commit 683e7cc2d7
3 changed files with 35 additions and 12 deletions

View File

@@ -21,7 +21,9 @@ const standorte = new Map([["wien", "Wien"], ["wolkersdorf", "Wolkersdorf"]]);
function person(teil: Partial<Parameters<typeof baueHonestlyZeilen>[0][number]> = {}) {
return {
personnel_number: 4711,
email: "anna.berger@example.test",
// Die private Adresse, wie sie auf der Zeile aus der Datenbank steht —
// sie darf im Export nirgends auftauchen.
email: "anna.privat@example.test",
first_name: "Anna",
last_name: "Berger",
location_id: "wien",
@@ -97,18 +99,33 @@ describe("baueHonestlyZeilen", () => {
const zeile = Object.fromEntries(honestlySpalten(tiefe).map((s) => [s.header, s.get(zeilen[0])]));
expect(zeile).toMatchObject({
Personalnummer: 4711,
Email: "anna.berger@example.test",
Firstname: "Anna",
"Last Name": "Berger",
Location: "Wien",
});
});
it("lässt eine fehlende E-Mail leer, statt sie zu erfinden", () => {
// Die Adresse ist privat und freiwillig (20260811140000). Eine leere
// Zelle fällt in Honestly auf; ein Platzhalter bekäme eine Einladung.
const { zeilen } = baueHonestlyZeilen([person({ email: null })], maps, standorte);
expect(honestlySpalten(1)[1].get(zeilen[0])).toBe("");
it("lässt die E-Mail leer, bis es die Firmenadresse gibt", () => {
// Die Spalte ist ein Platzhalter für die Firmen-E-Mail. Die private
// Adresse (employees.email) gehört nicht in eine Datei an einen fremden
// Anbieter — auch nicht, wenn sie vorhanden ist.
const { zeilen, tiefe } = baueHonestlyZeilen([person()], maps, standorte);
const zeile = Object.fromEntries(honestlySpalten(tiefe).map((s) => [s.header, s.get(zeilen[0])]));
expect(zeile.Email).toBe("");
});
it("trägt die private Adresse in keine Spalte ein", () => {
// Nicht nur „Email" prüfen: rutschte sie in eine andere Spalte, fiele es
// dort erst in Honestly auf.
const { zeilen, tiefe } = baueHonestlyZeilen([person()], maps, standorte);
const csv = toCsv(zeilen, honestlySpalten(tiefe));
expect(csv).not.toContain("anna.privat@example.test");
});
it("behält die Spalte Email, auch solange sie leer ist", () => {
// Die Zuordnung in Honestly wird einmal eingerichtet. Kommt die
// Firmenadresse später dazu, soll sich an der Datei nur der Inhalt ändern.
expect(honestlySpalten(1).map((s) => s.header)).toContain("Email");
});
it("gibt Personen ohne Einheit eine leere Kette, aber eine Zeile", () => {