Files
linkder/apps/web/test/observability.test.ts
serfaandClaude Opus 5 1808ad4cba Move the demo market to Mexico City, priced in US dollars
The showcase was a Barcelona market: Catalan names, +34 numbers, euro
rates and "Carrer Example 12" on every job. Presented to a Mexican
client, all of that reads as somebody else's product.

City comes from NEXT_PUBLIC_CITY_* as before, now Ciudad de México at
19.4326/-99.1332, with MAPBOX_COUNTRY=mx. The seed's fallbacks were
Barcelona literals, so an unset env quietly seeded a different city
than the app rendered — they now agree.

Two db tests pinned the Barcelona centre as a hardcoded constant, which
is why the deck returned zero cards on the first run here: every pro was
a continent outside the radius. They read the same env as the seed now,
so the trap cannot recur.

Money: formatCents defaults to USD/en-US, and the nine hardcoded euro
signs across the card, search rows, quote strip and forms are dollars.
The rate NUMBERS are unchanged and still read high for CDMX — that is a
pricing decision, not a currency one, and is left alone deliberately.

Seed people are Mexican, addressed on real Roma/Condesa streets rotated
by index rather than one placeholder repeated. Phones moved to +52 55,
which moves the demo login to +525500000000 / 000000.

Also in here, from the same session:
- Sending a job now confirms. The mutation always succeeded; the sheet
  just closed with no receipt, which from the customer's side is
  indistinguishable from a dead button. Dismissing that receipt resolves
  as 'sent', so the card does not return to the deck.
- Media moves to DigitalOcean Spaces, with the public origin derived
  from bucket and region instead of a second env var to keep in sync.
- Managed-Postgres TLS: DATABASE_CA_CERT takes a path or inline PEM.
- The client-facing project panel beside the running app.
- Two profiles removed and four renamed to match their photos.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-23 10:56:31 -04:00

113 lines
3.8 KiB
TypeScript

/**
* The scrubber is part of the auth boundary, not a nicety.
*
* On this platform a phone number is the login identity and a 6-digit OTP is
* the credential. If either reaches Bugsink, anyone with access to the error
* tracker can sign in as that user — so these tests assert the redaction, not
* the happy path.
*/
import { describe, expect, it } from 'vitest';
import { beforeSend, REDACTED, scrub } from '../src/lib/observability';
type Event = Parameters<typeof beforeSend>[0];
describe('scrub', () => {
it('redacts secret-bearing keys wherever they are nested', () => {
const out = scrub({
safe: 'keep me',
phoneNumber: '+34600111222',
nested: { deeper: { token: 'abc123', otp: '445566' } },
}) as {
safe: string;
phoneNumber: string;
nested: { deeper: { token: string; otp: string } };
};
expect(out.safe).toBe('keep me');
expect(out.phoneNumber).toBe(REDACTED);
expect(out.nested.deeper.token).toBe(REDACTED);
expect(out.nested.deeper.otp).toBe(REDACTED);
});
it('redacts a phone number found in free text, not just in a named field', () => {
const out = scrub('failed to send to +34600111222 after 3 tries');
expect(out).not.toContain('600111222');
expect(out).toContain(REDACTED);
});
it('redacts a bare six-digit code, which is the shape of our OTP', () => {
expect(scrub('code 123456 expired')).toBe(`code ${REDACTED} expired`);
});
it('survives a circular object rather than throwing away the report', () => {
const a: Record<string, unknown> = { name: 'x' };
a.self = a;
expect(() => scrub(a)).not.toThrow();
});
it('walks arrays', () => {
const out = scrub([{ token: 'a' }, { safe: 'b' }]) as Array<Record<string, string>>;
expect(out[0]!.token).toBe(REDACTED);
expect(out[1]!.safe).toBe('b');
});
});
describe('beforeSend', () => {
it('drops cookies and headers entirely', () => {
const event = {
request: {
url: 'https://linkdr.app/api',
cookies: { session: 'live-credential' },
headers: { authorization: 'Bearer live-credential' },
},
} as unknown as Event;
const out = beforeSend(event)!;
expect(out.request?.cookies).toBeUndefined();
expect(out.request?.headers).toBeUndefined();
});
it('reduces the user to an id — never a phone or email', () => {
const event = {
user: { id: 'user-1', email: 'someone@example.com', phone: '+34600111222' },
} as unknown as Event;
const out = beforeSend(event)!;
expect(out.user).toEqual({ id: 'user-1' });
});
it('scrubs a phone number out of the exception message', () => {
const event = {
exception: { values: [{ value: 'no user for +34600111222' }] },
} as unknown as Event;
const out = beforeSend(event)!;
expect(out.exception!.values![0]!.value).not.toContain('600111222');
});
it('scrubs request body data and the query string', () => {
const event = {
request: {
url: 'https://linkdr.app/verify?code=123456',
query_string: 'code=123456',
data: { phoneNumber: '+34600111222', code: '123456' },
},
} as unknown as Event;
const out = beforeSend(event)!;
expect(out.request!.query_string).not.toContain('123456');
expect(out.request!.url).not.toContain('123456');
expect((out.request!.data as Record<string, string>).phoneNumber).toBe(REDACTED);
});
it('scrubs breadcrumbs, which is where fetch URLs accumulate', () => {
const event = {
breadcrumbs: [{ message: 'POST /phone-number/verify +34600111222', data: { code: '123456' } }],
} as unknown as Event;
const out = beforeSend(event)!;
expect(out.breadcrumbs![0]!.message).not.toContain('600111222');
expect((out.breadcrumbs![0]!.data as Record<string, string>).code).toBe(REDACTED);
});
});