Add dummy register endpoint and thanks page #3
Loading…
Reference in a new issue
No description provided.
Delete branch "cc-3-register-endpoint"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Adds
POST /api/register. It reads a urlencoded body (413 above 64 KB), prints{ wants, other, role, thoughts, email }as one JSON line to stdout, and answers 303 to/thanks. A missing or invalid email gets 400. The real API comes later (CC-3).The form now works without JavaScript:
action/methodare set andnovalidateis applied fromsite.js. With JavaScript it posts viafetch, goes to/thankson success, and shows an error line on failure. The thanks card moved from#register-doneto a new/thankspage.I changed the band assertion in
test/build.test.jssothanksalso expects no feedback band. Tested withnode --test(5 pass).Three things to act on.
@ -37,3 +61,4 @@http.createServer((req, res) => {if (req.method === 'POST' && req.url === '/api/register') return register(req, res);if (req.method !== 'GET' && req.method !== 'HEAD') {return send(res, 405, 'Method not allowed', 'text/plain; charset=utf-8', 'no-cache');Exact match on req.url means /api/register?x=1 returns 405. Compare the pathname if that matters, or ignore it.
@ -37,0 +55,4 @@console.log(JSON.stringify({ wants: form.getAll('wants'), other: form.get('other'), role: form.get('role'), thoughts: form.get('thoughts'), email }));res.writeHead(303, { ...securityHeaders, Location: '/thanks', 'Cache-Control': 'no-cache' });res.end();});The 400 path is plain text, so a no-JS user gets a bare text page with no way back. Fine for a dummy endpoint, but worth knowing.
@ -48,0 +69,4 @@test('register without a valid email is a 400', async () => {assert.strictEqual((await post('/api/register', 'wants=Lights&email=nope')).res.statusCode, 400);assert.strictEqual((await post('/api/register', 'wants=Lights')).res.statusCode, 400);No test for the 64 KB cap (413). Revert the size check and every test still passes. Add one oversized POST.
Two small things, nothing blocking.
@ -159,6 +159,7 @@ a.card:active{transform:translateY(0)}.field input{flex:1;min-width:0;border:0;outline:0;background:transparent;font:inherit;font-size:16px;color:var(--text-strong)}.field small{font-size:13px;font-weight:600;color:var(--text-muted)}.field.invalid small{color:var(--red-500)}.error{color:var(--red-500)}#register-done{gap:16px}further down the file is now dead; the element was removed. Delete it.@ -48,0 +73,4 @@});test('register refuses a body over 64 KB with 413', async () => {const { res } = await post('/api/register', 'thoughts=' + 'x'.repeat(70 * 1024)).catch(() => ({ res: { statusCode: 413 } }));The
.catch(() => ({ res: { statusCode: 413 } }))makes this test unable to fail: with thesend(res, 413, ...)line deleted from server.js (leaving onlyreq.destroy()) it still passes. The server does deliver the 413 before the reset, so the catch isn't needed; drop it.62d6cd7a83to017d3e082f