test: add comprehensive thumb validation and blob transformation tests master
Add extensive test coverage for external embed thumb validation and blob reference transformation in feed responses. **Thumb Validation Tests** (post_thumb_validation_test.go): 7 test cases covering strict blob reference validation: 1. ❌ Reject thumb as URL string (must be blob ref) 2. ❌ Reject thumb missing $type field 3. ❌ Reject thumb missing ref field 4. ❌ Reject thumb missing mimeType field 5. ✅ Accept valid blob reference 6. ✅ Accept missing thumb (unfurl will handle) 7. Security: Prevents URL injection attacks via thumb field **Feed Blob Transform Tests** (feed_test.go): 6 test cases for GetCommunityFeed blob URL transformation: 1. Transforms blob refs to PDS URLs 2. Preserves community PDSURL in PostView 3. Generates correct getBlob endpoint URLs 4. Handles posts without embeds 5. Handles posts without thumbs 6. End-to-end feed query validation **Integration Test Updates:** - Update post creation tests for content length validation - Update post handler tests with proper context setup - Update E2E tests for nested external embed structure - Add helper for creating communities with PDS credentials - Add createTestUser helper for unique test isolation **Test Isolation:** - Use unique DIDs per test (via t.Name() suffix) - Prevent cross-test data contamination - Proper cleanup with defer db.Close() **Example Validation:** ```go // ❌ This should fail validation: "thumb": "https://example.com/thumb.jpg" // URL string // ✅ This should pass validation: "thumb": { "$type": "blob", "ref": {"$link": "bafyrei..."}, "mimeType": "image/jpeg", "size": 52813 } ``` **Coverage:** - Blob validation: 7 test cases - Blob transformation: 6 test cases - Feed integration: 99 added lines in feed_test.go - Total: 13 new test scenarios This ensures security (no URL injection), correctness (proper blob format), and functionality (URLs work in API responses).