- Add zod dep; new src/shared/validation/schemas.ts (BucketName,
JsonUploadPayload, LoginBody, DeleteObjects, CompleteMultipart,
clampMaxKeys, parseOrNull) + test/validation.test.ts
- Dedup timingSafeCompare -> src/shared/utils/crypto.ts (auth
middleware, authenticate use-case, s3/auth now import it)
- Dedup AuthSession -> single type in dto/auth.ts
- Dedup telegram file URL builder + filename sanitizer to shared
modules (file-controller now imports the canonical ones)
- Remove duplicate controllers/home.html (canonical: src/home.html)
- Fix stale bootstrap mocks to real module paths; bootstrap now
asserts public GET vs guarded POST separately
- Fix health assertion to include version field
- package.json: test -> test:unit alias; new test:quarantine for
network/live tests; register previously unlisted test files
Add comprehensive unit tests and repair stale tests that referenced the
old (pre-refactor) src/utils/* layout which no longer exists:
- s3-range: expand to 25 cases (suffix, clamping, malformed, zero-size,
invalid totals, content-range formatting)
- s3-object-stream: rewrite against the real interfaces/s3 module; add
multi-part ordering, ranges spanning parts, S3/CORS headers, fetch-error
propagation
- s3-helpers-edge (new): compress heuristics, virtual-host bucket parsing,
S3 route detection, client-IP/trustProxy, S3 response headers
- s3-auth-edge (new): verifyBodyHash, isS3Request, canonical-query-string
encoding/sorting
- chunked-storage: rewrite against the real ChunkedStorage class (was
importing deleted src/utils/chunked-storage) — chunk split, hashing,
compression, size-limit guards, forwarding
- zip: fix stale import + add path-traversal/duplicate sanitization,
locateZipEntry, empty-name fallback
- s3-docker-registry: fix stale src/config import; correct the rate-limit
test to assert S3 routes INTENTIONALLY bypass rate limiting
- temp-stream (new): streamToTemp hashing, MD5, signature bytes, empty and
oversized streams
- package.json: add the S3/unit files to test and test:s3 scripts
All new unit tests pass when run per-file (the project's documented mode to
avoid cross-file mock pollution). s3-sdk.test.ts (live E2E against a running
server) is deliberately excluded from test:s3.