Add e2e auth test suite, retention crons, and email-verification UX
CI / build-and-test (push) Has been cancelled
CI / build-and-test (push) Has been cancelled
- E2E suite (23 tests, `npm run test:e2e -w @lawdesk/api`): boots the real Fastify app against a disposable Dockerized Postgres (never a real DB) and covers signup/login/lockout/rate limits, CSRF (incl. forged-token rejection), logout, password reset, email verification, the superadmin verified-email promotion gate, and cross-firm tenancy isolation - packages/db: DATABASE_SSL=disable opt-out for local/test databases that don't speak TLS; refused in production - retention-sweep.ts cron enforcing Privacy Policy windows (sessions, tokens, login attempts, tool usage, contact messages, audit log) + sweep-orphaned-storage.ts Spaces reconciliation + scripts/README - Expose emailVerified on the session user; in-app verify-email banner with resend, and verified=1|0 toasts on the login page - Silence Fastify logger under NODE_ENV=test; fix footer resource link; document login-attempt/tool-usage retention in the Privacy Policy Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
97e1d4c60b
commit
d9b807662a
@@ -13,6 +13,7 @@ declare module 'fastify' {
|
||||
role: string;
|
||||
isSuperadmin: boolean;
|
||||
isSuspended: boolean;
|
||||
emailVerified: boolean;
|
||||
};
|
||||
}
|
||||
interface FastifyInstance {
|
||||
@@ -47,6 +48,7 @@ async function plugin(app: FastifyInstance) {
|
||||
role: session.user.role,
|
||||
isSuperadmin,
|
||||
isSuspended: session.user.isSuspended,
|
||||
emailVerified: Boolean(session.user.emailVerifiedAt),
|
||||
};
|
||||
});
|
||||
|
||||
|
||||
Reference in New Issue
Block a user