Publish documentation / publish (push) Successful in 1m27s
Add PostgreSQL-backed memory, editable evidence with source review and activation, and human-approved archive repairs across the harness, API, and UI. Include migrations, deployment support, regression coverage, and validation documentation. Refresh permissions from validated session roles so existing administrator logins can access newly deployed archive management features.
49 lines
2.4 KiB
TypeScript
49 lines
2.4 KiB
TypeScript
import Fastify from "fastify";
|
|
import { expect, test, vi } from "vitest";
|
|
import { sessionRoutes } from "../src/routes/sessions.js";
|
|
import type { PrincipalContext } from "../src/auth/principal.js";
|
|
|
|
test.each([
|
|
[false, "m", 403], [false, "e", 403], [false, "reject", 204],
|
|
[true, "m", 204], [true, "e", 204], [true, "forged", 400],
|
|
] as const)("archive repair response enforces the responding principal (%s, %s)", async (admin, choice, status) => {
|
|
const app = Fastify();
|
|
const principal: PrincipalContext = { issuer: "test", subject: "reviewer", isAdmin: admin,
|
|
roles: admin ? ["admin"] : ["user"],
|
|
permissions: admin ? ["session.use", "memory.manage", "evidence.manage"] : ["session.use"] };
|
|
app.addHook("preHandler", async request => { request.principal = principal; });
|
|
const respond = vi.fn(() => true);
|
|
sessionRoutes(app, {
|
|
tht: {}, mgr: { get: () => ({ ownerKey: "test\0reviewer", bridge: {
|
|
respond, pendingWidget: () => ({ id: "gate", widget: "archive-repair", repair: { options: [
|
|
{ id: "m", archive: "memory" }, { id: "e", archive: "evidence" },
|
|
] } }),
|
|
} }) },
|
|
} as unknown as Parameters<typeof sessionRoutes>[1]);
|
|
try {
|
|
const result = await app.inject({ method: "POST", url: "/sessions/s/response",
|
|
payload: { ui_response: { id: "gate", choices: [choice] } } });
|
|
expect(result.statusCode).toBe(status);
|
|
expect(respond).toHaveBeenCalledTimes(status === 204 ? 1 : 0);
|
|
} finally { await app.close(); }
|
|
});
|
|
|
|
test("an administrator cannot attribute a repair to another runtime's principal", async () => {
|
|
const app = Fastify();
|
|
app.addHook("preHandler", async request => { request.principal = {
|
|
issuer: "test", subject: "second-admin", isAdmin: true, roles: ["admin"],
|
|
permissions: ["session.use", "memory.manage"],
|
|
}; });
|
|
const respond = vi.fn();
|
|
sessionRoutes(app, { tht: {}, mgr: { get: () => ({ ownerKey: "test\0first-admin", bridge: {
|
|
respond, pendingWidget: () => ({ id: "gate", widget: "archive-repair",
|
|
repair: { options: [{ id: "m", archive: "memory" }] } }),
|
|
} }) } } as unknown as Parameters<typeof sessionRoutes>[1]);
|
|
try {
|
|
const result = await app.inject({ method: "POST", url: "/sessions/s/response",
|
|
payload: { ui_response: { id: "gate", choices: ["m"] } } });
|
|
expect(result.statusCode).toBe(409);
|
|
expect(respond).not.toHaveBeenCalled();
|
|
} finally { await app.close(); }
|
|
});
|