Skip to content
182 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1import assert from "node:assert/strict";
2import { test } from "node:test";
3
4import { CONTACT } from "./legal.ts";
5import {
6 HAVE_AN_INVITE,
7 INVITES_CONTACT,
8 cleanCode,
Merge invite emails that confirm the address: the emailed link carries a proof only that email has, so signing up from it needs no code; shared links and typed codes still confirm9 cleanProof,
10 invitePath,
11 inviteSignUpCopy,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look12 inviteFor,
13 inviteLink,
14 inviteState,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas15 landingFor,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look16 looksAutomated,
17 moreInvitesMailto,
18 remainingLine,
Merge shared invite links: label, uses, expiry, domains; joined through recorded (identity 0038)19 sharedDomainsHint,
20 sharedInviteLine,
21 sharedInviteLink,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look22 signUpCopy,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas23 suggestUsername,
24 welcomeCookie,
25 clearWelcome,
26 welcomes,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look27} from "./invites.ts";
28
29const CODE = "g1t-k7m2-q9xd-4hpw-abcd-0123-4567-89ef-ghjk";
30
31test("while invite-only, nobody is offered a plain sign-up", () => {
Sign-up buttons say Sign up everywhere; only the sign-up page says registration takes an invite32 // Sign up everywhere; only the sign-up page says registration takes an invite.
33 assert.deepEqual(signUpCopy(), { primary: "Sign up", secondary: null });
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look34 assert.equal(HAVE_AN_INVITE, "/register#invite");
35});
36
37test("asking for more invites goes to support with the [g1t Invites] subject", () => {
38 assert.equal(INVITES_CONTACT, CONTACT.support);
39 assert.equal(moreInvitesMailto(), "mailto:hey@flagon.io?subject=%5Bg1t%20Invites%5D%20More%20invites");
40 assert.equal(
41 moreInvitesMailto("acme"),
42 "mailto:hey@flagon.io?subject=%5Bg1t%20Invites%5D%20More%20invites%20for%20acme",
43 );
44});
45
46test("an invite link is on g1t.sh unless told otherwise", () => {
47 assert.equal(inviteLink(CODE), `https://g1t.sh/invite/${CODE}`);
48 assert.equal(inviteLink(CODE, "http://localhost:8787/"), `http://localhost:8787/invite/${CODE}`);
49});
50
Merge invite emails that confirm the address: the emailed link carries a proof only that email has, so signing up from it needs no code; shared links and typed codes still confirm51const PROOF = "4f9c2a7e0b13d5c84f9c2a7e0b13d5c84f9c2a7e0b13d5c84f9c2a7e0b13d5c8";
52
53test("an invite email's proof is kept only when it looks like one, and goes along to the invite's page", () => {
54 assert.equal(cleanProof(PROOF), PROOF);
55 assert.equal(cleanProof(` ${PROOF.toUpperCase()} `), PROOF);
56 assert.equal(cleanProof("not-a-proof"), null);
57 assert.equal(cleanProof("abc"), null);
58 assert.equal(cleanProof("a".repeat(500)), null);
59 assert.equal(cleanProof(null), null);
60 assert.equal(invitePath(CODE, PROOF), `/invite/${CODE}?proof=${PROOF}`);
61 assert.equal(invitePath(CODE, null), `/invite/${CODE}`);
62 assert.equal(invitePath(CODE), `/invite/${CODE}`);
63});
64
65test("signing up from the invite email says the address is confirmed already; otherwise the code step applies", () => {
66 const base = { address: "ada@example.com", emailProven: false, workspace: { name: "Flagon, Inc." }, repository: null };
67 const proven = inviteSignUpCopy({ ...base, emailProven: true });
68 assert.equal(proven.intro, "You join Flagon, Inc. as soon as you create it.");
69 assert.match(proven.confirmed ?? "", /^ada@example\.com is confirmed: you came here from the invite we emailed to it/);
70 assert.match(proven.hint, /confirmed already/);
71 assert.doesNotMatch(proven.hint, /code/);
72
73 // No proof (a code typed in, or a link passed on): nothing new is said.
74 const plain = inviteSignUpCopy(base);
75 assert.equal(plain.intro, "You join Flagon, Inc. as soon as you confirm your email.");
76 assert.equal(plain.confirmed, null);
77 assert.equal(plain.hint, "Your invite was sent here. We email it a code to confirm it before you start.");
78
79 // An invite for anyone with the code has no address to prove.
80 const open = inviteSignUpCopy({ ...base, address: null, emailProven: true, workspace: null });
81 assert.equal(open.confirmed, null);
82 assert.equal(open.intro, "It takes a minute.");
83 assert.equal(open.hint, "We email it a code to confirm it before you start.");
84
85 const repo = inviteSignUpCopy({ ...base, workspace: null, repository: { name: "flagon-io/g1t" }, emailProven: true });
86 assert.equal(repo.intro, "You get flagon-io/g1t as soon as you create it.");
87});
88
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look89test("a pasted link or code is tidied to the code", () => {
90 assert.equal(cleanCode(CODE), CODE);
91 assert.equal(cleanCode(` ${CODE} `), CODE);
92 assert.equal(cleanCode(`https://g1t.sh/invite/${CODE}`), CODE);
93 assert.equal(cleanCode(`https://g1t.sh/register?invite=${CODE}&next=%2F`), CODE);
94 assert.equal(cleanCode("g1t-k7m2 q9xd"), "g1t-k7m2q9xd");
95 assert.equal(cleanCode(null), "");
96 assert.equal(cleanCode("x".repeat(500)).length, 80);
97});
98
99test("each invite says where it stands and whom it is for", () => {
100 const base = { redeemedBy: null, email: null, workspace: null };
101 assert.deepEqual(inviteState({ ...base, status: "pending" }), { label: "Pending", tone: "pending" });
102 assert.deepEqual(inviteState({ ...base, status: "redeemed", redeemedBy: "ada" }), { label: "Joined as @ada", tone: "done" });
Merge email confirmation gate: a code and a link, nothing until confirmed (identity 0036)103 assert.deepEqual(inviteState({ ...base, status: "awaiting_confirmation", redeemedBy: "ada" }), {
104 label: "@ada is confirming their email",
105 tone: "pending",
106 });
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look107 assert.deepEqual(inviteState({ ...base, status: "expired" }), { label: "Expired", tone: "dead" });
108 assert.deepEqual(inviteState({ ...base, status: "revoked" }), { label: "Revoked", tone: "dead" });
109 assert.equal(inviteFor({ ...base, status: "pending" }), "Anyone with the link");
110 assert.equal(inviteFor({ ...base, status: "pending", email: "ada@example.com", workspace: "acme" }), "ada@example.com · joins acme");
111});
112
113test("what is left reads plainly", () => {
114 assert.equal(remainingLine({ limit: 5, used: 2, remaining: 3 }), "3 of 5 invites left");
115 assert.equal(remainingLine({ limit: 1, used: 0, remaining: 1 }), "1 of 1 invite left");
116 assert.equal(remainingLine({ limit: 5, used: 5, remaining: 0 }), "You have used all 5 of your invites");
117 assert.equal(remainingLine({ limit: null, used: 40, remaining: null }), "No limit on your invites");
118});
119
120test("bots that fill the hidden field or answer instantly are turned away", () => {
121 const form = (fields: Record<string, string>) => ({ get: (name: string) => fields[name] ?? null });
122 const now = 1_000_000;
123 assert.equal(looksAutomated(form({ website: "http://spam.example" }), now), true);
124 assert.equal(looksAutomated(form({ started: String(now - 200) }), now), true);
125 assert.equal(looksAutomated(form({ started: String(now - 10_000) }), now), false);
126 assert.equal(looksAutomated(form({}), now), false);
127 assert.equal(looksAutomated(form({ website: " " }), now), false);
128});
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas129
130test("a username is suggested from the invited address", () => {
131 assert.equal(suggestUsername("ada.lovelace@example.com"), "ada-lovelace");
132 assert.equal(suggestUsername("Margaret_Hamilton+g1t@example.com"), "margaret-hamilton");
133 assert.equal(suggestUsername("--x--@example.com"), "x");
134 assert.equal(suggestUsername(`${"a".repeat(38)}.b@example.com`), "a".repeat(38));
135 assert.equal(suggestUsername("...@example.com"), "");
136 assert.equal(suggestUsername(null), "");
137});
138
139test("an invite lands in its workspace, else its repository", () => {
140 assert.equal(landingFor({ workspace: { slug: "Flagon-IO" }, repository: null }), "flagon-io");
141 assert.equal(landingFor({ workspace: null, repository: { name: "flagon-io/g1t" } }), "flagon-io/g1t");
142 assert.equal(landingFor({ workspace: null, repository: null }), null);
143});
144
145test("the welcome is for one place, and ends", () => {
146 const set = welcomeCookie("flagon-io/g1t", true);
147 assert.match(set, /^g1t_welcome=flagon-io%2Fg1t; Path=\/; Max-Age=300; HttpOnly; SameSite=Lax; Secure$/);
148 const header = `a=1; ${set.split(";")[0]}; b=2`;
149 assert.equal(welcomes(header, "flagon-io/g1t"), true);
150 assert.equal(welcomes(header, "flagon-io"), false);
151 assert.equal(welcomes("g1t_welcome=flagon-io", "Flagon-IO"), true);
152 assert.equal(welcomes("g1t_welcome=%E0%A4%A", "flagon-io"), false);
153 assert.equal(welcomes("g1t_welcome=..%2F..%2Fx", "../../x"), false);
154 assert.equal(welcomes(null, "flagon-io"), false);
155 assert.match(clearWelcome(false), /^g1t_welcome=; Path=\/; Max-Age=0; HttpOnly; SameSite=Lax$/);
156});
Merge shared invite links: label, uses, expiry, domains; joined through recorded (identity 0038)157
158test("a shared invite link names its group above the sign-up form", () => {
159 assert.equal(sharedInviteLine("Cloudflare judges"), "Invited as part of Cloudflare judges");
160 assert.equal(sharedInviteLine(" Hacker News readers "), "Invited as part of Hacker News readers");
161 // A one-person invite has no group, and says nothing of the kind.
162 assert.equal(sharedInviteLine(null), null);
163 assert.equal(sharedInviteLine(undefined), null);
164 assert.equal(sharedInviteLine(" "), null);
165});
166
167test("a shared invite link is sign-up with its code filled in", () => {
168 assert.equal(sharedInviteLink(CODE), `https://g1t.sh/register?invite=${CODE}`);
169 assert.equal(sharedInviteLink(CODE, "http://localhost:5173/"), `http://localhost:5173/register?invite=${CODE}`);
170 // The register page reads the code back out of its own link.
171 assert.equal(cleanCode(sharedInviteLink(CODE)), CODE);
172});
173
174test("a shared link limited to domains says which, on the email field", () => {
175 assert.equal(sharedDomainsHint([]), undefined);
176 assert.equal(sharedDomainsHint(null), undefined);
177 assert.equal(sharedDomainsHint(["cloudflare.com"]), "This invite is for addresses at cloudflare.com. Use yours there.");
178 assert.equal(
179 sharedDomainsHint(["a.com", "b.com", "c.com"]),
180 "This invite is for addresses at a.com, b.com or c.com. Use yours there.",
181 );
182});

This file's history is long; its oldest lines are credited to the oldest commit read.