feat(watcher): gate receipt watch with WATCHER_MAILBOXES
Limit Pub/Sub INBOX watch and receipt processing to an allowlisted mailbox set; leave the agent CLI usable for all connected accounts. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -0,0 +1,46 @@
|
||||
import assert from "node:assert/strict";
|
||||
import { describe, it } from "node:test";
|
||||
import {
|
||||
isWatcherMailboxAllowed,
|
||||
parseWatcherMailboxes,
|
||||
} from "../src/config.js";
|
||||
|
||||
describe("parseWatcherMailboxes", () => {
|
||||
it("returns empty set for blank input", () => {
|
||||
assert.equal(parseWatcherMailboxes("").size, 0);
|
||||
assert.equal(parseWatcherMailboxes(null).size, 0);
|
||||
assert.equal(parseWatcherMailboxes(" , ").size, 0);
|
||||
});
|
||||
|
||||
it("normalizes and splits emails", () => {
|
||||
const set = parseWatcherMailboxes(
|
||||
" Eleven16th@gmail.com , other@Example.COM ",
|
||||
);
|
||||
assert.deepEqual([...set].sort(), [
|
||||
"eleven16th@gmail.com",
|
||||
"other@example.com",
|
||||
]);
|
||||
});
|
||||
});
|
||||
|
||||
describe("isWatcherMailboxAllowed", () => {
|
||||
it("allows all when allowlist is empty", () => {
|
||||
const empty = new Set();
|
||||
assert.equal(isWatcherMailboxAllowed("anyone@x.com", empty), true);
|
||||
assert.equal(isWatcherMailboxAllowed(null, empty), true);
|
||||
});
|
||||
|
||||
it("requires membership when allowlist is set", () => {
|
||||
const allow = parseWatcherMailboxes("eleven16th@gmail.com");
|
||||
assert.equal(
|
||||
isWatcherMailboxAllowed("eleven16th@gmail.com", allow),
|
||||
true,
|
||||
);
|
||||
assert.equal(
|
||||
isWatcherMailboxAllowed("Eleven16th@Gmail.com", allow),
|
||||
true,
|
||||
);
|
||||
assert.equal(isWatcherMailboxAllowed("other@gmail.com", allow), false);
|
||||
assert.equal(isWatcherMailboxAllowed(null, allow), false);
|
||||
});
|
||||
});
|
||||
Reference in New Issue
Block a user