Org assignment history, mobile support, and a correctness pass
Data model - employee_assignments records org placement over time (valid_from/valid_to), written by a trigger on `employees` rather than inside each RPC: ~70 `update employees` statements spread over fifteen migrations mean per-call bookkeeping would miss paths today and again with every future RPC. A partial unique index enforces the one-open-interval invariant the trigger relies on when closing the current row. - The Organigramm gains a Stichtag (default today). Membership comes from entry/exit/karenz, past placement from the new history, future placement projected from pending_org_changes. Placements predating the migration are backfilled with today's values and flagged as such in the UI, since employee_history only ever stored free text and cannot be reconstructed. Correctness - Reports and exports silently truncated at PostgREST's 1000-row cap (db.max_rows); employee_history is already past it at ~800 staff. Every whole-table read now pages explicitly. - XLSX date cells were a day early: ExcelJS converts a Date to an Excel serial straight off getTime(), so a Date built at local midnight lands on the previous day's serial in any positive-offset zone. - Date handling is pinned to Europe/Vienna throughout, and date-only strings are formatted without a Date round-trip. The dashboard's YTD window was built by round-tripping a local Date through toISOString(), which shifted it a day early and dropped 31 December entirely. - Export routes parsed measure/group/split/eventType with unchecked `as` casts, so an unknown value reached column headers as `undefined` and the Content-Disposition filename. Parsed against the label maps now, with the filename slugged as a backstop. - toXlsx keyed columns by header text, silently dropping the second of any two columns sharing a name — split columns take their header from data. - The org chart tree walks had no cycle guard; nothing in the schema forbids a manager_id cycle, and one would hang the tab rather than misreport. - The login page reflected ?error= verbatim, letting anyone put arbitrary text on the real sign-in screen; messages are looked up by code now. - React Flow needs elementsSelectable on, or it sets pointer-events:none on the whole node and the expand control stops responding. UI - Mobile: the shell was unusable below lg — a fixed 236px margin pushed content off-screen with no mobile navigation at all. The sidebar is now a drawer, dvh replaces vh, safe-area insets are honoured, inputs are 16px so iOS stops zooming on focus, and form grids stack. - Org chart nodes redesigned: per-kind accent stripes and icons, vacant roles called out, expand control moved to the bottom edge carrying the child count. - Pagination is windowed; it previously rendered one link per page (54 for the employee list, unbounded for the audit log). - Positions page reduced to open positions with a single "Besetzen" action. - The employee Organisation tab links into the org chart focused on that person, reusing the chart's existing search-match highlighting. Also included, uncommitted until now - Dependants, HR notes, academic titles, split address fields, position validity and role/employment fields, with their migrations and UI. - Docker/compose deployment setup, data-model and security-review docs.
This commit is contained in:
@@ -1,11 +1,25 @@
|
||||
import { describe, expect, it } from "vitest";
|
||||
import { daysBetween, fmtAge, fmtDate, initials, tenure } from "@/lib/format";
|
||||
import { addDaysIso, daysBetweenIso, fmtAge, fmtDate, initials, tenure, toIsoDate, yearsBetweenIso } from "@/lib/format";
|
||||
|
||||
describe("fmtDate", () => {
|
||||
it("formats an ISO date string in de-AT order", () => {
|
||||
expect(fmtDate("2026-03-05")).toBe("05.03.2026");
|
||||
});
|
||||
|
||||
// A date-only column has no time and no zone. Routing it through a Date
|
||||
// would anchor it to UTC midnight and render the previous day wherever the
|
||||
// renderer sits west of UTC — including a server/browser hydration split.
|
||||
it("never shifts a date-only string across a day boundary", () => {
|
||||
expect(fmtDate("2026-01-01")).toBe("01.01.2026");
|
||||
expect(fmtDate("2026-12-31")).toBe("31.12.2026");
|
||||
});
|
||||
|
||||
it("renders a timestamp in Vienna time regardless of the runtime zone", () => {
|
||||
// 23:30 UTC on 5 March is already 6 March in Vienna (UTC+1 before the
|
||||
// DST switch); the same instant is still 5 March in UTC.
|
||||
expect(fmtDate("2026-03-05T23:30:00Z")).toBe("06.03.2026");
|
||||
});
|
||||
|
||||
it("returns an em dash for null/undefined/empty input", () => {
|
||||
expect(fmtDate(null)).toBe("–");
|
||||
expect(fmtDate(undefined)).toBe("–");
|
||||
@@ -67,12 +81,47 @@ describe("tenure", () => {
|
||||
});
|
||||
});
|
||||
|
||||
describe("daysBetween", () => {
|
||||
describe("daysBetweenIso", () => {
|
||||
it("computes whole days between two dates", () => {
|
||||
expect(daysBetween("2026-01-01", "2026-01-11")).toBe(10);
|
||||
expect(daysBetweenIso("2026-01-01", "2026-01-11")).toBe(10);
|
||||
});
|
||||
|
||||
it("returns a negative number when the second date precedes the first", () => {
|
||||
expect(daysBetween("2026-01-11", "2026-01-01")).toBe(-10);
|
||||
expect(daysBetweenIso("2026-01-11", "2026-01-01")).toBe(-10);
|
||||
});
|
||||
|
||||
// Both ends are anchored at UTC midnight, so the DST switch in between
|
||||
// cannot turn 30 calendar days into 29.96 and round down.
|
||||
it("is exact across a DST transition", () => {
|
||||
expect(daysBetweenIso("2026-03-15", "2026-04-15")).toBe(31);
|
||||
expect(daysBetweenIso("2026-10-15", "2026-11-15")).toBe(31);
|
||||
});
|
||||
});
|
||||
|
||||
describe("addDaysIso", () => {
|
||||
it("rolls over month and year boundaries", () => {
|
||||
expect(addDaysIso("2026-12-31", 1)).toBe("2027-01-01");
|
||||
expect(addDaysIso("2026-01-31", 1)).toBe("2026-02-01");
|
||||
});
|
||||
|
||||
it("handles a leap day", () => {
|
||||
expect(addDaysIso("2028-02-28", 1)).toBe("2028-02-29");
|
||||
});
|
||||
});
|
||||
|
||||
describe("yearsBetweenIso", () => {
|
||||
it("counts only completed years", () => {
|
||||
expect(yearsBetweenIso("1990-05-15", "2026-05-15")).toBe(36);
|
||||
expect(yearsBetweenIso("1990-05-15", "2026-05-14")).toBe(35);
|
||||
});
|
||||
});
|
||||
|
||||
describe("toIsoDate", () => {
|
||||
it("passes a date-only string through untouched", () => {
|
||||
expect(toIsoDate("2026-01-01")).toBe("2026-01-01");
|
||||
});
|
||||
|
||||
it("resolves a timestamp to the Vienna calendar day", () => {
|
||||
expect(toIsoDate("2026-03-05T23:30:00Z")).toBe("2026-03-06");
|
||||
});
|
||||
});
|
||||
|
||||
168
tests/unit/orgchart-data.test.ts
Normal file
168
tests/unit/orgchart-data.test.ts
Normal file
@@ -0,0 +1,168 @@
|
||||
import { describe, expect, it } from "vitest";
|
||||
import { resolveOrgSnapshot } from "@/lib/orgchart-data";
|
||||
|
||||
const DIV = "div-1";
|
||||
const TEAM_A = "team-a";
|
||||
const TEAM_B = "team-b";
|
||||
|
||||
type EmployeeInput = Parameters<typeof resolveOrgSnapshot>[0]["employees"][number];
|
||||
type AssignmentInput = Parameters<typeof resolveOrgSnapshot>[0]["assignments"][number];
|
||||
|
||||
function emp(id: string, overrides: Partial<EmployeeInput> = {}): EmployeeInput {
|
||||
return {
|
||||
id,
|
||||
personnel_number: 1000,
|
||||
first_name: "Test",
|
||||
last_name: id,
|
||||
job_title: "Mitarbeiter:in",
|
||||
manager_id: null,
|
||||
team_id: TEAM_A,
|
||||
division_id: DIV,
|
||||
is_lead: false,
|
||||
org_level: 3,
|
||||
entry_date: "2020-01-01",
|
||||
exit_date: null,
|
||||
karenz_start_date: null,
|
||||
karenz_return_date: null,
|
||||
...overrides,
|
||||
};
|
||||
}
|
||||
|
||||
function assignment(employeeId: string, overrides: Partial<AssignmentInput> = {}): AssignmentInput {
|
||||
return {
|
||||
employee_id: employeeId,
|
||||
manager_id: null,
|
||||
team_id: TEAM_A,
|
||||
division_id: DIV,
|
||||
job_title: "Mitarbeiter:in",
|
||||
is_lead: false,
|
||||
org_level: 3,
|
||||
valid_from: "2020-01-01",
|
||||
...overrides,
|
||||
};
|
||||
}
|
||||
|
||||
const TEAMS = [
|
||||
{ id: TEAM_A, department_id: "dept-1" },
|
||||
{ id: TEAM_B, department_id: "dept-2" },
|
||||
];
|
||||
const DEPARTMENTS = [
|
||||
{ id: "dept-1", division_id: DIV },
|
||||
{ id: "dept-2", division_id: "div-2" },
|
||||
];
|
||||
|
||||
function snapshot(args: Partial<Parameters<typeof resolveOrgSnapshot>[0]> & { asOf: string }) {
|
||||
return resolveOrgSnapshot({ employees: [], assignments: [], teams: TEAMS, departments: DEPARTMENTS, pending: [], ...args });
|
||||
}
|
||||
|
||||
describe("membership as of a date", () => {
|
||||
it("excludes someone who had not started yet and includes them once they have", () => {
|
||||
const employees = [emp("a", { entry_date: "2026-06-01" })];
|
||||
expect(snapshot({ asOf: "2026-05-31", employees }).employees).toHaveLength(0);
|
||||
expect(snapshot({ asOf: "2026-06-01", employees }).employees).toHaveLength(1);
|
||||
});
|
||||
|
||||
it("excludes someone from their exit date onwards", () => {
|
||||
const employees = [emp("a", { exit_date: "2026-06-30" })];
|
||||
expect(snapshot({ asOf: "2026-06-29", employees }).employees).toHaveLength(1);
|
||||
expect(snapshot({ asOf: "2026-06-30", employees }).employees).toHaveLength(0);
|
||||
});
|
||||
|
||||
it("keeps someone on Karenz in the chart", () => {
|
||||
const employees = [emp("a", { karenz_start_date: "2026-01-01", karenz_return_date: "2026-12-01" })];
|
||||
expect(snapshot({ asOf: "2026-06-01", employees }).employees).toHaveLength(1);
|
||||
});
|
||||
});
|
||||
|
||||
describe("placement as of a date", () => {
|
||||
it("uses the assignment interval covering the date, not today's row on employees", () => {
|
||||
const employees = [emp("a", { team_id: TEAM_B, job_title: "Heutiger Titel" })];
|
||||
const assignments = [assignment("a", { team_id: TEAM_A, job_title: "Damaliger Titel" })];
|
||||
const [result] = snapshot({ asOf: "2024-03-01", employees, assignments }).employees;
|
||||
expect(result.team_id).toBe(TEAM_A);
|
||||
expect(result.job_title).toBe("Damaliger Titel");
|
||||
});
|
||||
|
||||
it("falls back to the employee row when no assignment covers the date", () => {
|
||||
const employees = [emp("a", { team_id: TEAM_B })];
|
||||
const [result] = snapshot({ asOf: "2024-03-01", employees, assignments: [] }).employees;
|
||||
expect(result.team_id).toBe(TEAM_B);
|
||||
});
|
||||
});
|
||||
|
||||
describe("orphan re-rooting", () => {
|
||||
// Without this the whole reporting line below an absent manager silently
|
||||
// disappears from the chart instead of moving up a level.
|
||||
it("drops a manager reference to somebody not employed on that date", () => {
|
||||
const employees = [
|
||||
emp("boss", { exit_date: "2026-01-01", org_level: 2, is_lead: true }),
|
||||
emp("report", { manager_id: "boss" }),
|
||||
];
|
||||
const assignments = [assignment("report", { manager_id: "boss" })];
|
||||
const result = snapshot({ asOf: "2026-06-01", employees, assignments }).employees;
|
||||
expect(result).toHaveLength(1);
|
||||
expect(result[0].id).toBe("report");
|
||||
expect(result[0].manager_id).toBeNull();
|
||||
});
|
||||
});
|
||||
|
||||
describe("future projection from pending changes", () => {
|
||||
const leadB = emp("lead-b", { id: "lead-b", team_id: TEAM_B, division_id: "div-2", is_lead: true, org_level: 2 });
|
||||
|
||||
it("moves an employee into the target team and under that team's lead", () => {
|
||||
const employees = [emp("a", { manager_id: "lead-a" }), leadB];
|
||||
const assignments = [assignment("a", { manager_id: "lead-a" }), assignment("lead-b", { team_id: TEAM_B, division_id: "div-2", is_lead: true, org_level: 2 })];
|
||||
const pending = [{ employee_id: "a", effective_date: "2026-08-01", payload: { new_team_id: TEAM_B } }];
|
||||
|
||||
const result = snapshot({ asOf: "2026-09-01", employees, assignments, pending });
|
||||
const moved = result.employees.find((e) => e.id === "a")!;
|
||||
expect(moved.team_id).toBe(TEAM_B);
|
||||
expect(moved.division_id).toBe("div-2");
|
||||
expect(moved.manager_id).toBe("lead-b");
|
||||
expect(result.projectedCount).toBe(1);
|
||||
});
|
||||
|
||||
it("lets a later change win over an earlier one", () => {
|
||||
const employees = [emp("a")];
|
||||
const assignments = [assignment("a")];
|
||||
const pending = [
|
||||
{ employee_id: "a", effective_date: "2026-08-01", payload: { new_team_id: TEAM_B, new_title: "Zwischenstand" } },
|
||||
{ employee_id: "a", effective_date: "2026-09-01", payload: { new_team_id: TEAM_A, new_title: "Endstand" } },
|
||||
];
|
||||
const [result] = snapshot({ asOf: "2026-10-01", employees, assignments, pending }).employees;
|
||||
expect(result.team_id).toBe(TEAM_A);
|
||||
expect(result.job_title).toBe("Endstand");
|
||||
});
|
||||
|
||||
it("leaves an untouched employee's manager exactly as recorded", () => {
|
||||
// Deliberately deviating from the resolve rule: real data drifts, and a
|
||||
// snapshot must not silently "repair" reporting lines it was not asked
|
||||
// to change.
|
||||
const employees = [emp("a", { manager_id: "someone-else" }), emp("someone-else", { id: "someone-else" }), leadB];
|
||||
const assignments = [assignment("a", { manager_id: "someone-else" })];
|
||||
const [result] = snapshot({ asOf: "2026-09-01", employees, assignments }).employees;
|
||||
expect(result.manager_id).toBe("someone-else");
|
||||
});
|
||||
|
||||
it("ignores pending changes for a date the caller did not ask about", () => {
|
||||
// loadOrgAsOf only fetches pending rows for a future date, so an empty
|
||||
// list here must simply mean "no projection", not "drop the employee".
|
||||
const employees = [emp("a")];
|
||||
const assignments = [assignment("a")];
|
||||
const result = snapshot({ asOf: "2026-09-01", employees, assignments, pending: [] });
|
||||
expect(result.projectedCount).toBe(0);
|
||||
expect(result.employees).toHaveLength(1);
|
||||
});
|
||||
});
|
||||
|
||||
describe("historyStartsAt", () => {
|
||||
it("reports the earliest recorded assignment so the UI can flag older dates", () => {
|
||||
const employees = [emp("a"), emp("b", { id: "b" })];
|
||||
const assignments = [assignment("a", { valid_from: "2023-05-01" }), assignment("b", { valid_from: "2021-02-01" })];
|
||||
expect(snapshot({ asOf: "2026-01-01", employees, assignments }).historyStartsAt).toBe("2021-02-01");
|
||||
});
|
||||
|
||||
it("is null when nothing is recorded yet", () => {
|
||||
expect(snapshot({ asOf: "2026-01-01", employees: [emp("a")] }).historyStartsAt).toBeNull();
|
||||
});
|
||||
});
|
||||
@@ -4,6 +4,7 @@ import {
|
||||
aggregateReport,
|
||||
deriveStatusAsOf,
|
||||
groupKeyFor,
|
||||
groupKeysFor,
|
||||
measureValue,
|
||||
MEASURE_LABELS,
|
||||
type OrgLookups,
|
||||
@@ -30,6 +31,14 @@ function emp(overrides: Partial<ReportEmployee> = {}): ReportEmployee {
|
||||
paygrade: "B",
|
||||
birth_date: "1990-01-01",
|
||||
gender: "w",
|
||||
worker_type: "Angestellte:r",
|
||||
collective_agreement: "Handel",
|
||||
work_days: ["Mo", "Di", "Mi", "Do", "Fr"],
|
||||
is_betriebsrat: false,
|
||||
has_dienstwagen: false,
|
||||
is_laterale_fuehrung: false,
|
||||
is_c_level: false,
|
||||
dependents_count: 0,
|
||||
...overrides,
|
||||
};
|
||||
}
|
||||
@@ -71,6 +80,35 @@ describe("groupKeyFor", () => {
|
||||
it("derives entry_year from entry_date", () => {
|
||||
expect(groupKeyFor(emp({ entry_date: "2019-06-01" }), "entry_year", lookups)).toBe("2019");
|
||||
});
|
||||
|
||||
it("resolves the Rolle & Anstellung boolean dimensions as Ja/Nein", () => {
|
||||
const e = emp({ is_betriebsrat: true, has_dienstwagen: false, is_laterale_fuehrung: true, is_c_level: false });
|
||||
expect(groupKeyFor(e, "betriebsrat", lookups)).toBe("Ja");
|
||||
expect(groupKeyFor(e, "dienstwagen", lookups)).toBe("Nein");
|
||||
expect(groupKeyFor(e, "laterale_fuehrung", lookups)).toBe("Ja");
|
||||
expect(groupKeyFor(e, "c_level", lookups)).toBe("Nein");
|
||||
});
|
||||
|
||||
it("resolves worker_type/collective_agreement directly", () => {
|
||||
const e = emp({ worker_type: "Arbeiter:in", collective_agreement: "Süßwaren" });
|
||||
expect(groupKeyFor(e, "worker_type", lookups)).toBe("Arbeiter:in");
|
||||
expect(groupKeyFor(e, "collective_agreement", lookups)).toBe("Süßwaren");
|
||||
});
|
||||
|
||||
it("resolves has_dependents from dependents_count", () => {
|
||||
expect(groupKeyFor(emp({ dependents_count: 0 }), "has_dependents", lookups)).toBe("Nein");
|
||||
expect(groupKeyFor(emp({ dependents_count: 2 }), "has_dependents", lookups)).toBe("Ja");
|
||||
});
|
||||
});
|
||||
|
||||
describe("groupKeysFor", () => {
|
||||
it("returns a single-element array for every ordinary dimension", () => {
|
||||
expect(groupKeysFor(emp(), "division", lookups)).toEqual(["Produktion"]);
|
||||
});
|
||||
|
||||
it("returns one key per work day for the weekday dimension", () => {
|
||||
expect(groupKeysFor(emp({ work_days: ["Mo", "Mi"] }), "weekday", lookups)).toEqual(["Mo", "Mi"]);
|
||||
});
|
||||
});
|
||||
|
||||
describe("measureValue", () => {
|
||||
@@ -118,6 +156,11 @@ describe("measureValue", () => {
|
||||
];
|
||||
expect(measureValue(rows, "avg_tenure")).toBeCloseTo(3, 0);
|
||||
});
|
||||
|
||||
it("computes avg_dependents as the mean dependents_count", () => {
|
||||
const rows = [emp({ dependents_count: 0 }), emp({ dependents_count: 2 }), emp({ dependents_count: 4 })];
|
||||
expect(measureValue(rows, "avg_dependents")).toBeCloseTo(2, 5);
|
||||
});
|
||||
});
|
||||
|
||||
describe("aggregateReport", () => {
|
||||
@@ -173,6 +216,23 @@ describe("aggregateReport", () => {
|
||||
expect(measureValue(employees, "avg_age", asOf)).toBe(30);
|
||||
expect(measureValue(employees, "avg_tenure", asOf)).toBeCloseTo(1.42, 1);
|
||||
});
|
||||
|
||||
it("counts an employee once per work day for the weekday dimension, and sorts Mo→So instead of by value", () => {
|
||||
const employees = [
|
||||
emp({ id: "1", work_days: ["Mo", "Di", "Mi", "Do", "Fr"] }),
|
||||
emp({ id: "2", work_days: ["Mo", "Mi", "Fr"] }),
|
||||
];
|
||||
const rows = aggregateReport(employees, "headcount", "weekday", null, lookups);
|
||||
expect(rows.map((r) => r.key)).toEqual(["Mo", "Di", "Mi", "Do", "Fr"]);
|
||||
expect(rows.find((r) => r.key === "Mo")).toMatchObject({ value: 2, count: 2 });
|
||||
expect(rows.find((r) => r.key === "Di")).toMatchObject({ value: 1, count: 1 });
|
||||
});
|
||||
|
||||
it("sorts a weekday split chronologically within each group", () => {
|
||||
const employees = [emp({ id: "1", division_id: "div-1", work_days: ["Fr", "Mo"] })];
|
||||
const rows = aggregateReport(employees, "headcount", "division", "weekday", lookups);
|
||||
expect(rows[0].split?.map((s) => s.key)).toEqual(["Mo", "Fr"]);
|
||||
});
|
||||
});
|
||||
|
||||
describe("deriveStatusAsOf", () => {
|
||||
|
||||
@@ -1,6 +1,14 @@
|
||||
import { NextRequest } from "next/server";
|
||||
import { afterEach, describe, expect, it, vi } from "vitest";
|
||||
import { sanitizeForSpreadsheetCell, toCsv } from "@/lib/export";
|
||||
import { exportFilename, sanitizeForSpreadsheetCell, toCsv } from "@/lib/export";
|
||||
import {
|
||||
parseEventDateParam,
|
||||
parseEventType,
|
||||
parseGroupDimension,
|
||||
parseIsoDateParam,
|
||||
parseMeasure,
|
||||
parseSplitDimension,
|
||||
} from "@/lib/reports";
|
||||
import { sanitizeIlikeTerm } from "@/lib/supabase/query";
|
||||
|
||||
// The route under test imports lib/supabase/admin.ts, which is guarded by
|
||||
@@ -44,6 +52,60 @@ describe("sanitizeIlikeTerm", () => {
|
||||
});
|
||||
});
|
||||
|
||||
describe("report query-string parsing", () => {
|
||||
it("falls back to a known dimension instead of passing an unknown one through", () => {
|
||||
expect(parseMeasure("bogus")).toBe("headcount");
|
||||
expect(parseGroupDimension("bogus")).toBe("division");
|
||||
expect(parseMeasure("fte")).toBe("fte");
|
||||
expect(parseGroupDimension("weekday")).toBe("weekday");
|
||||
});
|
||||
|
||||
it("treats an unknown split or event type as 'none' rather than a value", () => {
|
||||
expect(parseSplitDimension("bogus")).toBeNull();
|
||||
expect(parseSplitDimension("")).toBeNull();
|
||||
expect(parseSplitDimension("location")).toBe("location");
|
||||
expect(parseEventType("bogus")).toBeNull();
|
||||
expect(parseEventType("Eintritt")).toBe("Eintritt");
|
||||
});
|
||||
|
||||
// Object.hasOwn, not `in`: a plain `value in LABELS` check would accept
|
||||
// "constructor" or "toString" off the prototype chain as a valid dimension.
|
||||
it("does not accept inherited Object properties as dimensions", () => {
|
||||
expect(parseGroupDimension("constructor")).toBe("division");
|
||||
expect(parseSplitDimension("toString")).toBeNull();
|
||||
expect(parseEventType("hasOwnProperty")).toBeNull();
|
||||
});
|
||||
|
||||
it("rejects a Stichtag that is not a real calendar date", () => {
|
||||
expect(parseIsoDateParam("2026-03-05")).toBe("2026-03-05");
|
||||
expect(parseIsoDateParam("2026-02-30")).toBeUndefined();
|
||||
expect(parseIsoDateParam("heute")).toBeUndefined();
|
||||
expect(parseIsoDateParam('2026-03-05"; rm -rf /')).toBeUndefined();
|
||||
});
|
||||
|
||||
it("keeps the open-interval sentinel but still rejects free text", () => {
|
||||
expect(parseEventDateParam("open")).toBe("open");
|
||||
expect(parseEventDateParam("2026-01-01")).toBe("2026-01-01");
|
||||
expect(parseEventDateParam("whenever")).toBeUndefined();
|
||||
});
|
||||
});
|
||||
|
||||
describe("exportFilename", () => {
|
||||
// The base is assembled from query-string values and lands in a
|
||||
// Content-Disposition header, so a quote in it would otherwise break out
|
||||
// of the quoted filename.
|
||||
it("strips characters that would escape the Content-Disposition filename", () => {
|
||||
const name = exportFilename('bericht"; attachment; filename="evil', "csv");
|
||||
expect(name).not.toContain('"');
|
||||
expect(name).not.toContain(";");
|
||||
expect(name.endsWith(".csv")).toBe(true);
|
||||
});
|
||||
|
||||
it("keeps an ordinary base readable", () => {
|
||||
expect(exportFilename("bericht-headcount-division", "xlsx")).toMatch(/^bericht-headcount-division-\d{4}-\d{2}-\d{2}\.xlsx$/);
|
||||
});
|
||||
});
|
||||
|
||||
describe("cron auth guard (/api/cron/apply-pending-changes)", () => {
|
||||
afterEach(() => {
|
||||
vi.unstubAllEnvs();
|
||||
|
||||
Reference in New Issue
Block a user