fix: complete diagnostic extension remediation
This commit is contained in:
@@ -73,3 +73,33 @@ failed and no diagnostic secret was emitted.
|
||||
## Blockers
|
||||
|
||||
None.
|
||||
|
||||
## Round 2 remediation
|
||||
|
||||
The final review found two remaining contract gaps. The binding resolver already treated
|
||||
`auth: none` as credential-free, but the runtime renderer and diagnostic connector still required
|
||||
the API-key file. Rendering and connector construction now make that requirement conditional on
|
||||
the declared REST authentication mode, so a DWH/vector `auth: none` workspace passes resolver,
|
||||
runtime rendering, and diagnostics with no API-key file.
|
||||
|
||||
SSH forwarding previously changed the PostgreSQL connection host to `127.0.0.1` without retaining
|
||||
the original target for TLS hostname validation. Forwarded probes now carry `SSH_TARGET_HOST` as
|
||||
`tlsServername` into the PostgreSQL TLS options; private CA and verified system trust behavior are
|
||||
unchanged.
|
||||
|
||||
TDD RED: the new end-to-end no-key test failed at the unconditional runtime
|
||||
`API_KEY_FILE` requirement, while the SSH test showed no `tlsServername` on the loopback probe or
|
||||
database-client request. TDD GREEN: the focused backend workspace tests passed `40/40`.
|
||||
|
||||
Round 2 final verification:
|
||||
|
||||
```text
|
||||
backend: npx vitest run
|
||||
31 test files passed; 332 tests passed
|
||||
|
||||
backend: npx tsc --noEmit -p .
|
||||
exit 0
|
||||
|
||||
repository: git diff --check
|
||||
exit 0
|
||||
```
|
||||
|
||||
Reference in New Issue
Block a user