WP-00: application foundation
Scaffolds the project: Next.js 16 App Router with strict TypeScript, Prisma 7 on PostgreSQL 16, Tailwind 4, Vitest, Playwright, CI, and a standalone Docker image that applies migrations on boot. Makes the no-tracker rule of PLAN.md 3.7 enforceable rather than stated. A per-request nonce-based CSP names no external origin, a unit test fails if any network directive gains one, and a second test fails if a tracking package appears in package.json. The end-to-end test drives the standalone server the Docker image runs, not `next dev`, so a proxy matcher that stopped matching could not pass unnoticed. Environment is validated at import, so a missing DATABASE_URL fails at boot with a readable message instead of surfacing later as a driver error mid-export. ENCRYPTION_KEY is checked to be 32 bytes. Three deviations from the plan, recorded in PLAN.md and README: Next 16 rather than 15, `proxy.ts` rather than the now-deprecated `middleware.ts`, and database-backed sessions rather than Auth.js v5, which is still beta and whose JWTs would make the session revocation required by compliance item 23 awkward. Verified locally against PostgreSQL 16: migrations apply, extensions created, typecheck, lint, 9 unit tests and the end-to-end header test all pass. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Cr9dkEHwbDgkWPnyGj1Rjv
This commit is contained in:
32 files changed
+7533
-1
No files matched your search
@@ -0,0 +1,64 @@
|
||||
import { describe, expect, it } from 'vitest';
|
||||
|
||||
import {
|
||||
buildContentSecurityPolicy,
|
||||
NETWORK_DIRECTIVES,
|
||||
} from '@/lib/security/csp';
|
||||
|
||||
function parse(policy: string): Map<string, string[]> {
|
||||
return new Map(
|
||||
policy.split('; ').map((directive) => {
|
||||
const [name, ...values] = directive.split(' ');
|
||||
return [name ?? '', values];
|
||||
}),
|
||||
);
|
||||
}
|
||||
|
||||
/** Any source that is neither a keyword, a nonce, nor a safe scheme. */
|
||||
function externalOrigins(values: string[]): string[] {
|
||||
return values.filter((value) => {
|
||||
if (value.startsWith("'")) return false; // 'self', 'none', 'nonce-…', …
|
||||
if (value === 'blob:' || value === 'data:') return false;
|
||||
return true;
|
||||
});
|
||||
}
|
||||
|
||||
describe('Content-Security-Policy', () => {
|
||||
const policy = buildContentSecurityPolicy({ nonce: 'dGVzdC1ub25jZQ==' });
|
||||
const directives = parse(policy);
|
||||
|
||||
it('names no external origin on any network directive', () => {
|
||||
// PLAN.md §3.7 — the audited product shipped Segment, LinkedIn Ads, Google
|
||||
// Ads, DoubleClick, Clarity, Hotjar and Bugsnag. This assertion is what
|
||||
// keeps that from creeping back in as a "small" addition.
|
||||
for (const directive of NETWORK_DIRECTIVES) {
|
||||
const values = directives.get(directive) ?? [];
|
||||
expect(
|
||||
externalOrigins(values),
|
||||
`${directive} autorise une origine tierce`,
|
||||
).toEqual([]);
|
||||
}
|
||||
});
|
||||
|
||||
it('carries the request nonce on script-src', () => {
|
||||
expect(directives.get('script-src')).toContain("'nonce-dGVzdC1ub25jZQ=='");
|
||||
});
|
||||
|
||||
it('never allows unsafe-eval outside development', () => {
|
||||
expect(policy).not.toContain("'unsafe-eval'");
|
||||
});
|
||||
|
||||
it('allows unsafe-eval in development only, for React Refresh', () => {
|
||||
const devPolicy = buildContentSecurityPolicy({
|
||||
nonce: 'dGVzdA==',
|
||||
isDevelopment: true,
|
||||
});
|
||||
expect(devPolicy).toContain("'unsafe-eval'");
|
||||
});
|
||||
|
||||
it('forbids inline scripts, framing and object embedding', () => {
|
||||
expect(directives.get('script-src')).not.toContain("'unsafe-inline'");
|
||||
expect(directives.get('frame-ancestors')).toEqual(["'none'"]);
|
||||
expect(directives.get('object-src')).toEqual(["'none'"]);
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,49 @@
|
||||
import { describe, expect, it, vi } from 'vitest';
|
||||
|
||||
/**
|
||||
* The env module validates at import, so each case needs a fresh module
|
||||
* registry with process.env set beforehand.
|
||||
*/
|
||||
async function loadEnv(values: Record<string, string | undefined>) {
|
||||
const previous = { ...process.env };
|
||||
process.env = { ...previous, ...values } as NodeJS.ProcessEnv;
|
||||
try {
|
||||
vi.resetModules();
|
||||
return await import('@/lib/env');
|
||||
} finally {
|
||||
process.env = previous;
|
||||
}
|
||||
}
|
||||
|
||||
const VALID_KEY = Buffer.alloc(32, 7).toString('base64');
|
||||
|
||||
describe('configuration d’environnement', () => {
|
||||
it('accepte une configuration complète', async () => {
|
||||
const { env } = await loadEnv({
|
||||
DATABASE_URL: 'postgresql://user:pass@localhost:5432/planflow',
|
||||
ENCRYPTION_KEY: VALID_KEY,
|
||||
APP_URL: 'https://planflow.example',
|
||||
});
|
||||
|
||||
expect(env.DATABASE_URL).toContain('planflow');
|
||||
expect(env.APP_URL).toBe('https://planflow.example');
|
||||
});
|
||||
|
||||
it('refuse une clé de chiffrement qui ne fait pas 32 octets', async () => {
|
||||
await expect(
|
||||
loadEnv({
|
||||
DATABASE_URL: 'postgresql://user:pass@localhost:5432/planflow',
|
||||
ENCRYPTION_KEY: Buffer.alloc(16, 1).toString('base64'),
|
||||
}),
|
||||
).rejects.toThrow(/ENCRYPTION_KEY/);
|
||||
});
|
||||
|
||||
it('refuse une URL de base non PostgreSQL', async () => {
|
||||
await expect(
|
||||
loadEnv({
|
||||
DATABASE_URL: 'mysql://user:pass@localhost:3306/planflow',
|
||||
ENCRYPTION_KEY: VALID_KEY,
|
||||
}),
|
||||
).rejects.toThrow(/DATABASE_URL/);
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,65 @@
|
||||
import { readFileSync } from 'node:fs';
|
||||
import { fileURLToPath } from 'node:url';
|
||||
|
||||
import { describe, expect, it } from 'vitest';
|
||||
|
||||
/**
|
||||
* PLAN.md §3.7 bans analytics and advertising dependencies outright.
|
||||
*
|
||||
* The CSP stops such a package at runtime; this stops it at review time, with a
|
||||
* message that says why. The audited product carried ten of these, so the
|
||||
* failure mode is not hypothetical — it is what happens when nobody is looking.
|
||||
*/
|
||||
const BANNED = [
|
||||
'segment',
|
||||
'@segment/',
|
||||
'analytics-node',
|
||||
'react-ga',
|
||||
'gtag',
|
||||
'google-analytics',
|
||||
'mixpanel',
|
||||
'amplitude',
|
||||
'hotjar',
|
||||
'clarity-js',
|
||||
'satismeter',
|
||||
'fullstory',
|
||||
'logrocket',
|
||||
'bugsnag',
|
||||
'sentry',
|
||||
'datadog',
|
||||
'posthog',
|
||||
'heap-analytics',
|
||||
'intercom',
|
||||
];
|
||||
|
||||
interface PackageJson {
|
||||
dependencies?: Record<string, string>;
|
||||
devDependencies?: Record<string, string>;
|
||||
}
|
||||
|
||||
describe('dépendances', () => {
|
||||
const packageJson: PackageJson = JSON.parse(
|
||||
readFileSync(
|
||||
fileURLToPath(new URL('../../package.json', import.meta.url)),
|
||||
'utf8',
|
||||
),
|
||||
);
|
||||
|
||||
const installed = [
|
||||
...Object.keys(packageJson.dependencies ?? {}),
|
||||
...Object.keys(packageJson.devDependencies ?? {}),
|
||||
];
|
||||
|
||||
it('ne contient aucun traceur publicitaire ou analytique', () => {
|
||||
const offenders = installed.filter((name) =>
|
||||
BANNED.some((banned) => name.toLowerCase().includes(banned)),
|
||||
);
|
||||
|
||||
expect(
|
||||
offenders,
|
||||
'PLAN.md §3.7 interdit les traceurs tiers dans une application RH. ' +
|
||||
"Pour de la télémétrie technique, passer par l'interface abstraite " +
|
||||
'auto-hébergée plutôt que par un service externe.',
|
||||
).toEqual([]);
|
||||
});
|
||||
});
|
||||
Reference in new issue
Block a user