fix: sonarqube denial of service issue
SonarQube Analysis / sonarqube (pull_request) Successful in 4m0s
Tests / backend-unit (pull_request) Successful in 48s
Tests / backend-integration (pull_request) Failing after 4s
Tests / frontend-e2e (pull_request) Failing after 5s

This commit is contained in:
2026-08-14 08:36:16 -05:00
parent 8ffd05f73d
commit dd0a647677
2 changed files with 54 additions and 2 deletions
+27
View File
@@ -44,4 +44,31 @@ describe('isValidEmail', () => {
it('rejects an email with no domain', () => {
expect(isValidEmail('thom@')).toBe(false);
});
it('accepts a multi-label domain', () => {
expect(isValidEmail('thom@mail.example.co.uk')).toBe(true);
});
it('rejects a domain with no dot', () => {
expect(isValidEmail('thom@localhost')).toBe(false);
});
it('rejects an empty domain label', () => {
expect(isValidEmail('thom@example..com')).toBe(false);
expect(isValidEmail('thom@.com')).toBe(false);
});
it('rejects more than one @', () => {
expect(isValidEmail('thom@foo@example.com')).toBe(false);
});
it('rejects an address longer than 254 characters', () => {
expect(isValidEmail(`${'a'.repeat(250)}@example.com`)).toBe(false);
});
it('rejects a long dotless domain without super-linear backtracking', () => {
const start = Date.now();
expect(isValidEmail(`thom@${'a'.repeat(60_000)}`)).toBe(false);
expect(Date.now() - start).toBeLessThan(1000);
});
});