fix: tighten evidence artifact guarantees
This commit is contained in:
@@ -615,6 +615,24 @@ test("real publish create/update, pull, list, and read preserve a complete Evide
|
||||
baseCommit: createdRevision.commit, baseBlob: createdRevision.blob,
|
||||
},
|
||||
});
|
||||
expect(update.statusCode).toBe(200);
|
||||
await realGit(fixture.author, ["pull", "--ff-only", "origin", "main"]);
|
||||
const remotelyEdited = validateCanonicalWorkspace({
|
||||
...updated,
|
||||
evidence: {
|
||||
...updated.evidence,
|
||||
policy: { max_chunk_chars: 9_001, retain_published_generations: 9 },
|
||||
},
|
||||
});
|
||||
writeFileSync(
|
||||
join(fixture.author, "workspaces", "research-clinical.yaml"),
|
||||
serializeWorkspaceYaml(remotelyEdited),
|
||||
);
|
||||
await realGit(fixture.author, ["add", "workspaces/research-clinical.yaml"]);
|
||||
await realGit(fixture.author, ["commit", "-m", "Remote Evidence-only descriptor edit"]);
|
||||
await realGit(fixture.author, ["push", "origin", "main"]);
|
||||
const remoteCommit = await realGit(fixture.author, ["rev-parse", "HEAD"]);
|
||||
|
||||
const pull = await fixture.app.inject({ method: "POST", url: "/workspace-registry/pull" });
|
||||
const list = await fixture.app.inject({ method: "GET", url: "/workspaces" });
|
||||
const read = await fixture.app.inject({ method: "GET", url: "/workspaces/research-clinical" });
|
||||
@@ -623,10 +641,12 @@ test("real publish create/update, pull, list, and read preserve a complete Evide
|
||||
expect(create.statusCode).toBe(200);
|
||||
expect(update.statusCode).toBe(200);
|
||||
expect(pull.statusCode).toBe(200);
|
||||
expect(pull.json().head).toBe(remoteCommit);
|
||||
expect(list.statusCode).toBe(200);
|
||||
expect(list.json().find(({ id }: { id: string }) => id === "research-clinical").workspace).toEqual(updated);
|
||||
expect(list.json().find(({ id }: { id: string }) => id === "research-clinical").workspace)
|
||||
.toEqual(remotelyEdited);
|
||||
expect(read.statusCode).toBe(200);
|
||||
expect(read.json().workspace).toEqual(updated);
|
||||
expect(read.json().workspace).toEqual(remotelyEdited);
|
||||
});
|
||||
|
||||
test("real route reports a safe field for an Evidence-only concurrent edit", async () => {
|
||||
@@ -697,11 +717,18 @@ test.each([
|
||||
label: "inline S3 credential field",
|
||||
source: { type: "s3", uri: "s3://clinical-evidence/published/", access_key: SECRET_CANARY },
|
||||
},
|
||||
])("real validate rejects $label without echoing it", async ({ source }) => {
|
||||
])("real publish rejects $label without echoing it or changing HEAD", async ({ source }) => {
|
||||
const fixture = await createRealRouteFixture();
|
||||
await fixture.registry.bootstrap();
|
||||
const base = await fixture.registry.read("psd-clinical");
|
||||
const invalid = structuredClone(base.workspace) as any;
|
||||
invalid.evidence = { source };
|
||||
const response = await fixture.app.inject({
|
||||
method: "POST", url: "/workspaces/validate",
|
||||
payload: { workspace: { ...workspace, evidence: { source } } },
|
||||
method: "POST", url: "/workspaces/publish",
|
||||
payload: {
|
||||
action: "update", workspace: invalid,
|
||||
baseCommit: base.revision.commit, baseBlob: base.revision.blob,
|
||||
},
|
||||
});
|
||||
|
||||
expect(response.statusCode).toBe(400);
|
||||
|
||||
Reference in New Issue
Block a user