- Move buildingKey, jobsForApp, getBotToken, isBotEnabled, getBotConfig,
isAuthorized, getOAuthRedirectUri, buildAuthUrl, cleanCompletedJobs,
and msToTime into lib/helpers.js as state-free functions that accept
config, botTokens, or env as parameters. COMPLETED_RETENTION_DAYS also
lives there so callers and tests share the constant.
- Replace the bodies in index.js with thin wrappers that pass the module-
level state into the pure helpers. Call sites and behavior are
unchanged; index.js shrinks by ~60 lines.
- Move the cleanCompletedJobs logging into the cron caller so the pure
helper returns a result object (jobs, removed, cutoff) that tests can
assert on without capturing stdout.
- Add test/helpers.test.js with 43 assertions across 10 suites covering
the enable/disable gating, per-bot draft isolation, authorization,
OAuth URL construction, retention filter (including endTime -> startTime
-> created fallback and the safety default for jobs missing a
timestamp), and the duration formatter.
- Wire `npm test` to `node --test test/*.test.js` (no new deps, uses the
built-in node:test runner) and document it in the README.
Smoke test confirms unchanged HTTP behavior for /info (known + unknown
bots), the requireBot 404 gate, and the 401 path on jobs/list/completed.
Co-authored-by: Cursor <cursoragent@cursor.com>
Extends the single-Novi codebase into a multi-bot mass-messenger where
each bot has its own token, avatar, label, and per-user authorization.
- Secrets moved out of config.json: per-bot tokens in gitignored
config/botTokens.json (with enabled flag), service-account OAuth in
gitignored config/token.json (rewritten by refresh cron), integration
and Google keys in .env.
- Single Webex integration handles OAuth for all bots via a per-app
redirect URI derived from OAUTH_CALLBACK_URL_TEMPLATE.
- New requireBot middleware and getBotConfig helper reject requests for
unknown or disabled bots at the /CollabCentral/:app boundary.
- New /info endpoint plus dynamic frontend loading (sendMessage,
monitorJobs) so pages self-describe per bot, including bot avatar
fetched from Webex /people/me at startup.
- Job draft state keyed by cookieId + appName so each bot has its own
building queue; job list/detail endpoints filter by appName so users
only see jobs from bots they are authorized on.
- New jobDetail page for a readable per-job view; completed jobs are
retained for 30 days by the cleanup cron.
- Completion adaptive cards use per-bot avatar and label.
- Miscellaneous fixes: off-by-two in the send loop, removed three dead
send/process variants, added defensive init for jobs.* on load,
dropped the deprecated crypto npm shim, and cleaned up stray logger
labels and typos.
Co-authored-by: Cursor <cursoragent@cursor.com>