xpeditis2.0/apps/backend/src/application/controllers/webhooks-validation.security.spec.ts

29 lines
922 B
TypeScript

import 'reflect-metadata';
import { I18nValidationPipe } from 'nestjs-i18n';
import { WebhooksController } from './webhooks.controller';
describe('Current webhook configuration boundary (OBS-02)', () => {
it.each([
['createWebhook', 0],
['updateWebhook', 1],
])('%s rejects an unvalidated destination at the global pipe', async (method, index) => {
const types = Reflect.getMetadata(
'design:paramtypes',
WebhooksController.prototype,
method as string
);
const pipe = new I18nValidationPipe({
whitelist: true,
forbidNonWhitelisted: true,
transform: true,
transformOptions: { enableImplicitConversion: true },
});
await expect(
pipe.transform(
{ url: 'http://127.0.0.1/internal', events: ['booking.created'] },
{ type: 'body', metatype: types[index as number] }
)
).rejects.toMatchObject({ status: 400 });
});
});