Skip to content

Commit ace768e

Browse files
committed
test(service-settings): the settings producer pin reads every call's scope, not a call count
Claude-Session: https://claude.ai/code/session_01YDt3PzwfrkuFzUBF89WPmM Co-authored-by: Claude <noreply@anthropic.com>
1 parent 73c1a93 commit ace768e

1 file changed

Lines changed: 7 additions & 4 deletions

File tree

‎packages/services/service-settings/src/settings-service.test.ts‎

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2041,10 +2041,13 @@ describe('SettingsService — Phase 3 sys_secret + crypto provider + audit', ()
20412041
await svc.set('mail', 'api_key', 'super-secret-key', { tenantId: 't1' });
20422042
const r = await svc.get<string>('mail', 'api_key', { tenantId: 't1' });
20432043
expect(r.value).toBe('super-secret-key');
2044-
expect(seen).toEqual([
2045-
{ verb: 'encrypt', scope: 'settings', namespace: 'mail', key: 'api_key' },
2046-
{ verb: 'decrypt', scope: 'settings', namespace: 'mail', key: 'api_key' },
2047-
]);
2044+
// Every call — however many reads the service makes — carries this
2045+
// producer's scope and coordinate.
2046+
expect(seen.filter((c) => c.verb === 'encrypt')).toHaveLength(1);
2047+
expect(seen.some((c) => c.verb === 'decrypt')).toBe(true);
2048+
for (const call of seen) {
2049+
expect(call).toMatchObject({ scope: 'settings', namespace: 'mail', key: 'api_key' });
2050+
}
20482051
// The stored ciphertext records the scoped derivation, and no other
20492052
// producer's scope opens it at the same (namespace, key).
20502053
const [secret] = [...secretRows.values()];

0 commit comments

Comments
 (0)