fix(cardav): improve router security and test coverage

- Remove error message leakage (return generic 'Interner Fehler')
- Remove unused imports (str, collectErrors, MAX_TITLE, MAX_URL)
- Add _resetTestDatabase() for proper test cleanup
- Add test for populated accounts case with shape validation
- Import 'after' from node:test for proper teardown

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
This commit is contained in:
Ulas Kalayci
2026-05-04 16:51:21 +02:00
parent cf68bff25f
commit 930800eed9
3 changed files with 55 additions and 7 deletions
+1 -5
View File
@@ -6,13 +6,9 @@
import { createLogger } from '../logger.js';
import express from 'express';
import * as db from '../db.js';
import * as CardDAVSync from '../services/cardav-sync.js';
import { str, collectErrors, MAX_TITLE } from '../middleware/validate.js';
const log = createLogger('CardDAV');
const MAX_URL = 500;
const router = express.Router();
/**
@@ -26,7 +22,7 @@ router.get('/accounts', async (req, res) => {
res.json({ data: accounts });
} catch (err) {
log.error('Error fetching accounts:', err);
res.status(500).json({ error: err.message || 'Interner Fehler', code: 500 });
res.status(500).json({ error: 'Interner Fehler', code: 500 });
}
});