Repo has zero test files and no test script in either `package.json` (root) or `cli/package.json`. No `.github/workflows` — nothing runs on push/PR (already flagged in branch protection: no required status checks because none exist).
For a security-sensitive Worker (auth, PIN hashing, rate limiting, size limits) this is risky — the last hardening PR (#3) was reviewed by hand because there's no automated way to catch a regression like the CSP breaking the shipped template.
Ask:
- Add a test runner (Vitest fits Cloudflare Workers well, has official `@cloudflare/vitest-pool-workers` support) and cover: bearer auth, PIN hash verify, rate limiting math, draft ID validation regex, upload size rejection.
- Add a `.github/workflows/ci.yml` that runs on PR: `npm install`, tests, and at minimum `node --check src/index.js cli/index.js`.
- Once CI exists, wire it into branch protection as a required status check.
Repo has zero test files and no test script in either `package.json` (root) or `cli/package.json`. No `.github/workflows` — nothing runs on push/PR (already flagged in branch protection: no required status checks because none exist).
For a security-sensitive Worker (auth, PIN hashing, rate limiting, size limits) this is risky — the last hardening PR (#3) was reviewed by hand because there's no automated way to catch a regression like the CSP breaking the shipped template.
Ask: