fix: code cleanup — path traversal, test leaks, dead code, consistency

- Add path traversal protection to GET /api/cases/:name and fix-plan
- Use safePathSchema for LinkCaseSchema.path
- Fix QR auth test timer leak (afterAll → afterEach) and env var try/finally
- Remove dead terminal size check after Zod validation in resize route
- Remove no-op sampleCount guard in adaptive timing
- Replace hardcoded values with constants in notification-manager and subagent-windows
- Add Zod validation to POST /api/auth/revoke
- Use _apiPut instead of raw fetch in subagent-windows
- Add SwipeHandler.cleanup() for consistency with other mobile handlers
- Move NiceConfig/ProcessStats from types/plan.ts to types/common.ts

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
arkon
2026-03-01 17:26:31 +01:00
co-authored by Claude Opus 4.6
parent f94ab08cbe
commit d094d9ec50
11 changed files with 94 additions and 71 deletions
+9 -7
View File
@@ -38,8 +38,8 @@ describe('QR Token Manager (unit)', () => {
tm.startTokenRotation();
});
afterAll(() => {
// Clean up any lingering timers
afterEach(() => {
// Clean up rotation timer for this test's TunnelManager
tm?.stopTokenRotation();
});
@@ -234,11 +234,13 @@ describe('QR Auth Integration', () => {
const savedPass = process.env.CODEMAN_PASSWORD;
delete process.env.CODEMAN_PASSWORD;
const res = await fetch(`${baseUrl}/q/ANYCODE`, { redirect: 'manual' });
expect(res.status).toBe(302);
expect(res.headers.get('location')).toBe('/');
process.env.CODEMAN_PASSWORD = savedPass;
try {
const res = await fetch(`${baseUrl}/q/ANYCODE`, { redirect: 'manual' });
expect(res.status).toBe(302);
expect(res.headers.get('location')).toBe('/');
} finally {
process.env.CODEMAN_PASSWORD = savedPass;
}
});
it('GET /api/tunnel/qr should return authEnabled flag', async () => {