Skip to content

Commit 304318e

Browse files
committed
test(spec): add a pure sibling-strip control beside the grantedPermissions pins (#14865)
A control that also asserts the new key survives goes red at the pre-change schema for the survival reason, so its strip half is never evaluated there. This one involves no grantedPermissions at all: green before and after the key, red only if the envelope door goes passthrough — the reading the ablation needs. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0174WZTU6XcFcS7g2kykC53i
1 parent d443727 commit 304318e

1 file changed

Lines changed: 6 additions & 0 deletions

File tree

‎packages/spec/src/system/environment-artifact.test.ts‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -278,6 +278,12 @@ describe('grantedPermissions — install-time granted set per plugin manifest `i
278278
expect(Object.keys(parsed.grantedPermissions ?? {})).toEqual(['@acme/plugin-crm', '@acme/plugin-reports']);
279279
});
280280

281+
it('pure control: with no grantedPermissions present at all, an unknown top-level sibling is stripped (green before and after this key; red only if the door goes passthrough)', () => {
282+
const parsed = EnvironmentArtifactSchema.parse({ ...wireMinimal, notAnEnvelopeKey: { anything: 1 } });
283+
expect(parsed).not.toHaveProperty('notAnEnvelopeKey');
284+
expect(Object.keys(parsed).sort()).toEqual(['checksum', 'commitId', 'environmentId', 'metadata', 'schemaVersion']);
285+
});
286+
281287
it('positive control: an unknown top-level sibling is STILL stripped — the door admits the declared key, not everything', () => {
282288
const parsed = EnvironmentArtifactSchema.parse({
283289
...wireMinimal,

0 commit comments

Comments
 (0)