Skip to content

Commit 0ffcc8a

Browse files
authored
Merge branch 'main' into test/issue-1463
2 parents bd7a548 + 2476b24 commit 0ffcc8a

25 files changed

Lines changed: 2023 additions & 429 deletions

app/api/compare/route.test.ts

Lines changed: 93 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,93 @@
1+
import { describe, it, expect, vi, beforeEach } from 'vitest';
2+
import { GET } from './route';
3+
4+
vi.mock('@/lib/github', () => ({
5+
getFullDashboardData: vi.fn(),
6+
}));
7+
8+
import { getFullDashboardData } from '@/lib/github';
9+
10+
const makeRequest = (search: string) => new Request(`http://localhost:3000/api/compare?${search}`);
11+
12+
describe('GET /api/compare', () => {
13+
beforeEach(() => {
14+
vi.clearAllMocks();
15+
vi.mocked(getFullDashboardData).mockResolvedValue({
16+
calendar: { totalContributions: 50, weeks: [] },
17+
} as never);
18+
});
19+
20+
// ── Validation ────────────────────────────────────────────────────────────
21+
22+
it('returns 400 when user1 is missing', async () => {
23+
const res = await GET(makeRequest('user2=octocat'));
24+
expect(res.status).toBe(400);
25+
});
26+
27+
it('returns 400 when user2 is missing', async () => {
28+
const res = await GET(makeRequest('user1=octocat'));
29+
expect(res.status).toBe(400);
30+
});
31+
32+
it('returns 400 when both users are missing', async () => {
33+
const res = await GET(makeRequest(''));
34+
expect(res.status).toBe(400);
35+
});
36+
37+
it('returns 400 for invalid GitHub username format for user1', async () => {
38+
const res = await GET(makeRequest('user1=-invalid&user2=octocat'));
39+
expect(res.status).toBe(400);
40+
const data = await res.json();
41+
expect(data.details.fieldErrors.user1).toBeDefined();
42+
});
43+
44+
it('returns 400 for invalid GitHub username format for user2', async () => {
45+
const res = await GET(makeRequest('user1=octocat&user2=-invalid'));
46+
expect(res.status).toBe(400);
47+
const data = await res.json();
48+
expect(data.details.fieldErrors.user2).toBeDefined();
49+
});
50+
51+
it('returns 400 for username exceeding 39 characters', async () => {
52+
const res = await GET(makeRequest(`user1=${'a'.repeat(40)}&user2=octocat`));
53+
expect(res.status).toBe(400);
54+
});
55+
56+
it('returns 400 when comparing a user with themselves', async () => {
57+
const res = await GET(makeRequest('user1=octocat&user2=octocat'));
58+
expect(res.status).toBe(400);
59+
const data = await res.json();
60+
expect(data.details.fieldErrors.user2).toContain('Cannot compare a user with themselves.');
61+
});
62+
63+
it('returns 400 for self-comparison regardless of case', async () => {
64+
const res = await GET(makeRequest('user1=OctoCat&user2=octocat'));
65+
expect(res.status).toBe(400);
66+
});
67+
68+
// ── Success ──────────────────────────────────────────────────────────────
69+
70+
it('returns 200 with comparison data for valid users', async () => {
71+
const res = await GET(makeRequest('user1=alice&user2=bob'));
72+
expect(res.status).toBe(200);
73+
const data = await res.json();
74+
expect(data.user1).toBeDefined();
75+
expect(data.user2).toBeDefined();
76+
});
77+
78+
// ── Error handling ────────────────────────────────────────────────────────
79+
80+
it('returns 404 when user1 is not found on GitHub', async () => {
81+
vi.mocked(getFullDashboardData).mockRejectedValueOnce(new Error('Not found'));
82+
const res = await GET(makeRequest('user1=ghost123&user2=octocat'));
83+
expect(res.status).toBe(404);
84+
});
85+
86+
it('returns 404 when user2 is not found on GitHub', async () => {
87+
vi.mocked(getFullDashboardData)
88+
.mockResolvedValueOnce({ calendar: { totalContributions: 0, weeks: [] } } as never)
89+
.mockRejectedValueOnce(new Error('Not found'));
90+
const res = await GET(makeRequest('user1=octocat&user2=ghost123'));
91+
expect(res.status).toBe(404);
92+
});
93+
});

app/api/compare/route.ts

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,23 +1,23 @@
11
import { NextResponse } from 'next/server';
22
import { getFullDashboardData } from '@/lib/github';
3+
import { compareParamsSchema } from '@/lib/validations';
34

45
export const revalidate = 3600;
56

67
export async function GET(request: Request) {
78
const { searchParams } = new URL(request.url);
8-
const user1 = searchParams.get('user1');
9-
const user2 = searchParams.get('user2');
109

11-
if (!user1 || !user2) {
10+
const parseResult = compareParamsSchema.safeParse(Object.fromEntries(searchParams.entries()));
11+
12+
if (!parseResult.success) {
13+
const fieldErrors = parseResult.error.flatten();
1214
return NextResponse.json(
13-
{ error: 'Both user1 and user2 query parameters are required.' },
15+
{ error: 'Invalid parameters', details: fieldErrors },
1416
{ status: 400 }
1517
);
1618
}
1719

18-
if (user1.toLowerCase() === user2.toLowerCase()) {
19-
return NextResponse.json({ error: 'Cannot compare a user with themselves.' }, { status: 400 });
20-
}
20+
const { user1, user2 } = parseResult.data;
2121

2222
try {
2323
const [result1, result2] = await Promise.allSettled([

app/api/notify/route.test.ts

Lines changed: 39 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -95,4 +95,43 @@ describe('GET /api/notify', () => {
9595
const res = await GET(makeRequest('GET', undefined, 'user=testuser'));
9696
expect(res.status).toBe(200);
9797
});
98+
99+
it('masks the email address in GET responses to prevent PII exposure', async () => {
100+
vi.mocked(Notification.findOne).mockResolvedValue({
101+
username: 'testuser',
102+
email: 'john.doe@gmail.com',
103+
frequency: 'weekly',
104+
notifyOnCommit: true,
105+
notifyOnStreak: false,
106+
notifyOnMilestone: true,
107+
} as never);
108+
109+
const res = await GET(makeRequest('GET', undefined, 'user=testuser'));
110+
const body = await res.json();
111+
112+
expect(res.status).toBe(200);
113+
// Assert the exact masked output for a known input
114+
expect(body.data.email).toBe('jo***@gm***.com');
115+
// The full email must never be returned
116+
expect(body.data.email).not.toBe('john.doe@gmail.com');
117+
});
118+
119+
it('masks emails without a TLD dot correctly (no trailing dot)', async () => {
120+
vi.mocked(Notification.findOne).mockResolvedValue({
121+
username: 'localuser',
122+
email: 'admin@localhost',
123+
frequency: 'daily',
124+
notifyOnCommit: true,
125+
notifyOnStreak: true,
126+
notifyOnMilestone: true,
127+
} as never);
128+
129+
const res = await GET(makeRequest('GET', undefined, 'user=localuser'));
130+
const body = await res.json();
131+
132+
expect(res.status).toBe(200);
133+
expect(body.data.email).toBe('ad***@lo***');
134+
// Must not have a trailing dot
135+
expect(body.data.email.endsWith('.')).toBe(false);
136+
});
98137
});

app/api/notify/route.ts

Lines changed: 28 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,31 @@ import dbConnect from '@/lib/mongodb';
33
import { Notification } from '@/models/Notification';
44
import { NotificationPayload, NotificationResponse } from '@/types/index';
55

6+
/**
7+
* Masks an email address to prevent PII exposure in unauthenticated responses.
8+
* Example: "john.doe@gmail.com" → "jo***@gm***.com"
9+
*/
10+
function maskEmail(email: string): string {
11+
const [local, domain] = email.split('@');
12+
if (!local || !domain) return '***@***.***';
13+
14+
const maskedLocal = local.slice(0, Math.min(2, local.length)) + '***';
15+
16+
const dotIndex = domain.lastIndexOf('.');
17+
if (dotIndex === -1) {
18+
// Domain without a TLD (e.g., "localhost") — mask without trailing dot
19+
const maskedDomain = domain.slice(0, Math.min(2, domain.length)) + '***';
20+
return `${maskedLocal}@${maskedDomain}`;
21+
}
22+
23+
const domainName = domain.slice(0, dotIndex);
24+
const tld = domain.slice(dotIndex + 1);
25+
26+
const maskedDomain = domainName.slice(0, Math.min(2, domainName.length)) + '***';
27+
28+
return `${maskedLocal}@${maskedDomain}.${tld}`;
29+
}
30+
631
// ─── POST /api/notify ────────────────────────────────────────────────────────
732
// Register or update email notification preferences for a user
833
export async function POST(req: NextRequest): Promise<NextResponse<NotificationResponse>> {
@@ -106,13 +131,15 @@ export async function GET(req: NextRequest): Promise<NextResponse<NotificationRe
106131
);
107132
}
108133

134+
// Mask the email to prevent PII exposure in unauthenticated GET responses.
135+
// The full email is only accepted on POST (write) — never returned on GET (read).
109136
return NextResponse.json(
110137
{
111138
success: true,
112139
message: 'Notification preferences fetched successfully.',
113140
data: {
114141
username: notification.username,
115-
email: notification.email,
142+
email: maskEmail(notification.email),
116143
frequency: notification.frequency,
117144
preferences: {
118145
notifyOnCommit: notification.notifyOnCommit,

app/api/streak/route.test.ts

Lines changed: 50 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1342,4 +1342,54 @@ describe('GET /api/streak', () => {
13421342
expect(body).toContain('strictly for organizations');
13431343
});
13441344
});
1345+
1346+
describe('JSON output mode (format=json)', () => {
1347+
it('returns JSON with correct Content-Type when format=json is set', async () => {
1348+
const response = await GET(makeRequest({ user: 'octocat', format: 'json' }));
1349+
expect(response.status).toBe(200);
1350+
expect(response.headers.get('Content-Type')).toContain('application/json');
1351+
});
1352+
1353+
it('returns stats, monthlyStats, and calendar in JSON response', async () => {
1354+
const response = await GET(makeRequest({ user: 'octocat', format: 'json' }));
1355+
const data = await response.json();
1356+
1357+
expect(data.user).toBe('octocat');
1358+
expect(data.stats).toBeDefined();
1359+
expect(data.stats.currentStreak).toBeDefined();
1360+
expect(data.stats.longestStreak).toBeDefined();
1361+
expect(data.stats.totalContributions).toBeDefined();
1362+
expect(data.monthlyStats).toBeDefined();
1363+
expect(data.monthlyStats.currentMonthTotal).toBeDefined();
1364+
expect(data.calendar).toBeDefined();
1365+
expect(data.calendar.totalContributions).toBe(10);
1366+
expect(data.calendar.weeks).toHaveLength(2);
1367+
});
1368+
1369+
it('includes Cache-Control header in JSON response', async () => {
1370+
const response = await GET(makeRequest({ user: 'octocat', format: 'json' }));
1371+
expect(response.headers.get('Cache-Control')).toContain('s-maxage=');
1372+
});
1373+
1374+
it('includes X-Cache-Status header in JSON response', async () => {
1375+
const response = await GET(makeRequest({ user: 'octocat', format: 'json' }));
1376+
expect(response.headers.get('X-Cache-Status')).toBe('HIT');
1377+
});
1378+
1379+
it('returns SVG when format is not set (default)', async () => {
1380+
const response = await GET(makeRequest({ user: 'octocat' }));
1381+
expect(response.headers.get('Content-Type')).toBe('image/svg+xml');
1382+
});
1383+
1384+
it('falls back to SVG for invalid format values', async () => {
1385+
const response = await GET(makeRequest({ user: 'octocat', format: 'xml' }));
1386+
expect(response.headers.get('Content-Type')).toBe('image/svg+xml');
1387+
});
1388+
1389+
it('uses org name as user field when org parameter is provided', async () => {
1390+
const response = await GET(makeRequest({ user: 'octocat', org: 'github', format: 'json' }));
1391+
const data = await response.json();
1392+
expect(data.user).toBe('github');
1393+
});
1394+
});
13451395
});

app/api/streak/route.ts

Lines changed: 42 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -93,6 +93,7 @@ export async function GET(request: Request) {
9393
tz: tzParam,
9494
disable_particles,
9595
glow,
96+
format,
9697
} = parseResult.data;
9798

9899
const themeName = theme || 'dark';
@@ -106,6 +107,8 @@ export async function GET(request: Request) {
106107
: year
107108
? `${year}-12-31T23:59:59Z`
108109
: undefined;
110+
const currentYear = new Date().getUTCFullYear();
111+
const isHistoricalYear = !!year && Number(year) < currentYear;
109112

110113
let timezone = 'UTC';
111114
if (tzParam) {
@@ -194,6 +197,42 @@ export async function GET(request: Request) {
194197
}
195198
}
196199

200+
// ─── JSON output mode ──────────────────────────────────────────────────
201+
if (format === 'json') {
202+
const stats = calculateStreak(calendar, timezone, undefined, grace);
203+
const monthlyStats = calculateMonthlyStats(
204+
calendar,
205+
timezone,
206+
getMonthlyReferenceDate(year, timezone)
207+
);
208+
209+
const secondsToMidnight = tzParam
210+
? getSecondsUntilMidnightInTimezone(timezone)
211+
: getSecondsUntilUTCMidnight();
212+
const cacheControl = refresh
213+
? 'no-cache, no-store, must-revalidate'
214+
: `public, s-maxage=${secondsToMidnight}, stale-while-revalidate=86400`;
215+
216+
return NextResponse.json(
217+
{
218+
user: targetEntity,
219+
stats,
220+
monthlyStats,
221+
calendar: {
222+
totalContributions: calendar.totalContributions,
223+
weeks: calendar.weeks,
224+
},
225+
},
226+
{
227+
headers: {
228+
'Cache-Control': cacheControl,
229+
'X-Cache-Status': refresh ? `BYPASS, fetched=${new Date().toISOString()}` : 'HIT',
230+
},
231+
}
232+
);
233+
}
234+
235+
// ─── SVG output mode (default) ──────────────────────────────────────────
197236
let svg = '';
198237
if (view === 'monthly') {
199238
const stats = calculateMonthlyStats(
@@ -224,7 +263,9 @@ export async function GET(request: Request) {
224263
: getSecondsUntilUTCMidnight();
225264
const cacheControl = refresh
226265
? 'no-cache, no-store, must-revalidate'
227-
: `public, s-maxage=${secondsToMidnight}, stale-while-revalidate=86400`;
266+
: isHistoricalYear
267+
? 'public, s-maxage=31536000, immutable'
268+
: `public, s-maxage=${secondsToMidnight}, stale-while-revalidate=86400`;
228269

229270
return new NextResponse(svg, {
230271
headers: {

app/compare/page.tsx

Lines changed: 15 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,7 @@
11
import { Suspense } from 'react';
22
import type { Metadata } from 'next';
33
import CompareClient from './CompareClient';
4+
import { Footer } from '../components/Footer';
45

56
export const metadata: Metadata = {
67
title: 'Compare | CommitPulse',
@@ -14,14 +15,19 @@ export const metadata: Metadata = {
1415

1516
export default function ComparePage() {
1617
return (
17-
<Suspense
18-
fallback={
19-
<div className="min-h-screen flex items-center justify-center pt-28 pb-16">
20-
<div className="w-8 h-8 rounded-full border-2 border-emerald-500 border-t-transparent animate-spin"></div>
21-
</div>
22-
}
23-
>
24-
<CompareClient />
25-
</Suspense>
18+
<>
19+
<Suspense
20+
fallback={
21+
<div className="min-h-screen flex items-center justify-center pt-28 pb-16">
22+
<div className="w-8 h-8 rounded-full border-2 border-emerald-500 border-t-transparent animate-spin"></div>
23+
</div>
24+
}
25+
>
26+
<CompareClient />
27+
</Suspense>
28+
<div className="mx-auto max-w-7xl px-6 pb-8">
29+
<Footer />
30+
</div>
31+
</>
2632
);
2733
}

0 commit comments

Comments
 (0)