Skip to content

test : added unit tests for webhook signature verification#788

Closed
tmdeveloper007 wants to merge 0 commit into
Priyanshu-byte-coder:mainfrom
tmdeveloper007:#768
Closed

test : added unit tests for webhook signature verification#788
tmdeveloper007 wants to merge 0 commit into
Priyanshu-byte-coder:mainfrom
tmdeveloper007:#768

Conversation

@tmdeveloper007
Copy link
Copy Markdown
Contributor

Closes #768.

Summary of What Has Been Done:
Added test/github-webhook.test.ts with 20 vitest tests covering the signature verification logic from src/app/api/webhooks/github/route.ts.

Changes Made:
New file: test/github-webhook.test.ts

Test coverage:

  • safeCompare: identical strings, different lengths, same-length different content, empty strings, long strings
  • verifyGitHubSignature: valid HMAC acceptance, invalid signatures, missing/empty/wrong-prefix signatures, tampered body, wrong secret, empty body
  • getExpectedSignature: consistency across calls, different secrets, different bodies, sha256= prefix

Impact it Made:
All 20 tests pass. Webhook endpoint timing-safe comparison and HMAC verification validated.

@vercel
Copy link
Copy Markdown

vercel Bot commented May 23, 2026

@TESTPERSONAL is attempting to deploy a commit to the PRIYANSHU DOSHI's projects Team on Vercel.

A member of the Team first needs to authorize it.

@github-actions github-actions Bot added gssoc26 GSSoC 2026 contribution type:testing GSSoC type bonus: tests (+10 pts) labels May 23, 2026
@github-actions
Copy link
Copy Markdown

GSSoC Label Checklist 🏷️

@Priyanshu-byte-coder — please apply the appropriate labels before merging:

Difficulty (pick one):

  • level:beginner — 20 pts
  • level:intermediate — 35 pts
  • level:advanced — 55 pts
  • level:critical — 80 pts

Quality (optional):

  • quality:clean — ×1.2 multiplier
  • quality:exceptional — ×1.5 multiplier

Validation (required to score):

  • gssoc:approved — counts for points
  • gssoc:invalid / gssoc:spam / gssoc:ai-slop — does not score

Type labels (type:*) are auto-detected from files and title. Review and adjust if needed.
Points formula: (difficulty × quality_multiplier) + type_bonus

@tmdeveloper007 tmdeveloper007 force-pushed the #768 branch 2 times, most recently from b60d00f to a3930ae Compare May 23, 2026 04:29
Copy link
Copy Markdown
Owner

@Priyanshu-byte-coder Priyanshu-byte-coder left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Tests must import from source — not reimplement the function locally.

The test file re-implements the function being tested inside the test itself. This defeats the purpose of testing — changes to the real implementation won't fail these tests.

Fix: import the actual function from its source file and test that import. Example:

import { safeCompare } from '../src/lib/crypto'
// then test safeCompare directly

Also fix:

  • Add "test": "vitest run" to scripts in package.json
  • Add vitest.config.ts with resolve.alias: { '@': path.resolve(__dirname, 'src') }
  • Add EOF newline to test file

@Priyanshu-byte-coder Priyanshu-byte-coder added gssoc:approved GSSoC: PR approved for scoring level:beginner GSSoC: Beginner difficulty (20 pts) labels May 23, 2026
@tmdeveloper007 tmdeveloper007 force-pushed the #768 branch 3 times, most recently from a266f00 to d7d1a32 Compare May 23, 2026 14:59
@vercel
Copy link
Copy Markdown

vercel Bot commented May 23, 2026

Deployment failed with the following error:

The provided GitHub repository does not contain the requested branch or commit reference. Please ensure the repository is not empty.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gssoc:approved GSSoC: PR approved for scoring gssoc26 GSSoC 2026 contribution level:beginner GSSoC: Beginner difficulty (20 pts) type:testing GSSoC type bonus: tests (+10 pts)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

test : add unit tests for webhook signature verification

2 participants