| quick-260907-let |
01 |
api |
| nestjs |
| next-intl |
| vitest |
| inbox-provider |
| imap |
| exchange-ews |
|
| phase |
provides |
| 14-portal-alert-mailbox-inbox-extraction |
ImapProvider/ExchangeInboxProvider.testConnection (apps/api/src/inbox), shared by DKV and now Tender-Radar |
|
| phase |
provides |
| 17-eigene-ausschreibungs-quellen-je-nutzer |
per-user TenderEmailConfig ownership (userId @unique) and the extractTriageContext auth-context pattern |
|
|
| POST /modules/tender-radar/email-config/test — per-user connection test, no persistence |
| TenderEmailConfigService.testConnection(userId, dto) with stored-credential fallback for username AND password |
| Verbindung testen button in EmailAlertConfigForm with wait/success/error feedback |
|
| tender-radar |
| inbox |
| windows-ledger |
|
| tokens |
tasks |
commits |
| 6600 |
2 |
2 |
|
| added |
patterns |
|
|
| Optional trailing-constructor-param provider injection (ImapProvider/ExchangeInboxProvider) so existing 2-arg spec call sites stay type-correct — mirrors TendersController.tenderIngestionService |
|
|
| created |
modified |
|
|
| apps/api/src/tenders/tender-email-config.service.ts |
| apps/api/src/tenders/tenders.controller.ts |
| apps/api/src/tenders/tender-email-config.service.spec.ts |
| apps/api/src/tenders/tenders.controller.spec.ts |
| apps/web/src/lib/tender-radar-api.ts |
| apps/web/src/app/(portal)/modules/tender-radar/settings/components/EmailAlertConfigForm.tsx |
| apps/web/src/app/(portal)/modules/tender-radar/settings/components/EmailAlertConfigForm.test.tsx |
| apps/web/src/app/(portal)/modules/tender-radar/my-sources/my-sources.test.tsx |
| apps/web/src/messages/de.json |
| apps/web/src/messages/en.json |
|
|
| testConnection backfills BOTH username and password independently from stored, decrypted credentials — broader than saveConfig's credChanged branching, since a fully-blank test-connection form needs both fields, not just the one the caller didn't touch on a partial re-save. |
| Route-order comment corrected to state the accurate reason: NestJS resolves routes per HTTP verb, so a GET :id placeholder cannot shadow this POST route today. Ordering is defensive consistency with the surrounding email-config handlers, not a live 404 risk. |
|
| A per-user connection-test endpoint (userId from extractTriageContext, never the body) is now the second instance of this pattern after DkvController.testConnection — a template for any future per-user inbox-config module. |
|
|
| id |
description |
requirement |
verification |
human_judgment |
| D1 |
POST /modules/tender-radar/email-config/test resolves userId from the auth context, never the body, and delegates to TenderEmailConfigService.testConnection |
WINDOWS-16 |
| kind |
ref |
status |
| unit |
apps/api/src/tenders/tenders.controller.spec.ts#POST /email-config/test resolves userId from the auth context, even when the body carries a different identity field (T-QT16-01, IDOR) |
pass |
|
| kind |
ref |
status |
| unit |
apps/api/src/tenders/tenders.controller.spec.ts#declares getEmailConfig/saveEmailConfig/testEmailConnection before getTender so GET /:id cannot shadow "email-config" |
pass |
|
|
false |
|
| id |
description |
requirement |
verification |
human_judgment |
| D2 |
TenderEmailConfigService.testConnection falls back to the same user's stored, decrypted credentials when username/password are left blank, and selects IMAP vs Exchange provider by dto.protocol |
WINDOWS-16 |
| kind |
ref |
status |
| unit |
apps/api/src/tenders/tender-email-config.service.spec.ts#testConnection (Quick 260907-let, WINDOWS #16) — all 3 cases |
pass |
|
|
false |
|
| id |
description |
requirement |
verification |
human_judgment |
| D3 |
"Verbindung testen" button in EmailAlertConfigForm — wait state, success/error feedback, form-change clears the previous result |
WINDOWS-16 |
| kind |
ref |
status |
| unit |
apps/web/.../EmailAlertConfigForm.test.tsx#clicking "Verbindung testen" calls testEmailConnection once with a body carrying no password field |
pass |
|
| kind |
ref |
status |
| unit |
apps/web/.../EmailAlertConfigForm.test.tsx#a failed connection test shows the server's error message in the document |
pass |
|
|
false |
|
| id |
description |
requirement |
verification |
human_judgment |
rationale |
| D4 |
Browser UAT against a real mailbox: false-positive-free failure on a bad server, success on a real one, password-optional retest, credential-free API logs |
WINDOWS-16 |
|
true |
The plan's own human-check block states this explicitly: the capability proves itself only against a real IMAP/EWS mailbox, never against mocks. Runs at phase end (human_verify_mode = end-of-phase); the Docker rebuild/restart needed to exercise it belongs to the user, not this executor. |
|
|
25min |
2026-09-07 |
complete |