Skip to content

Commit e2d139e

Browse files
committed
test(objectql): re-judge the two engine-level write-response pins under A-prime (#7823)
They pinned exactly the limb the ruling relocates — the engine omitting internal fields from its own insert/update results, which is what broke signIn. Replaced wholesale (fixture-triage rule): they now pin the LIVENESS half — engine write results KEEP the flagged value — so re-adding an engine-level strip (the regression that broke authentication) goes red here, while the external-body guarantee is pinned at the ingress by the tripwire and the dogfood suites. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RDTnVvsgA6cUZ4xFVtPZRy
1 parent bac5b4a commit e2d139e

1 file changed

Lines changed: 22 additions & 9 deletions

File tree

‎packages/objectql/src/internal-fields.test.ts‎

Lines changed: 22 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -232,23 +232,36 @@ describe('#7728: the `internal` field flag omits a value from the generic data p
232232
});
233233
});
234234

235-
describe('the write-response surfaces', () => {
236-
it('omits the flagged field from the create body', async () => {
235+
describe('the write-response surfaces (RELOCATED to the ingress — #7823 A-prime)', () => {
236+
// These two pins used to assert the OPPOSITE: that the engine omitted the
237+
// flagged field from its own insert/update results. That conflated "never
238+
// returned on the generic data path" with "never returned to the
239+
// engine-level caller that performed the write" — and for
240+
// `sys_session.token` those are opposite requirements: better-auth's
241+
// `createWithHooks` reads the minted session row back off the insert
242+
// result, so the engine-side strip broke `signIn`/`signUp` outright
243+
// (measured: `verify signIn: no token in response`). Under the 2026-08-13
244+
// A-prime ruling the ENGINE keeps write results whole, and the external
245+
// 201/200 bodies are stripped at the generic-data-path ingress
246+
// (`omitInternalFieldsFromWriteResponse` in @objectstack/metadata-protocol,
247+
// held there by its own tripwire test across every `*Data` face — that is
248+
// where #7728's fourth surface, the sys_api_key PATCH body, stays closed).
249+
//
250+
// The assertions below are the LIVENESS half of that ruling: they go RED
251+
// if anyone re-adds an engine-level write-response strip, which is the
252+
// exact regression that broke authentication.
253+
it('the create RESULT keeps the flagged field — mint reads it back off this value', async () => {
237254
const created = await seed();
238-
expect(Object.keys(created)).not.toContain('key');
239-
// The create still returns a usable record — the mint path reads `id`
240-
// off exactly this value.
255+
expect(created.key).toBe(HASH);
241256
expect(created.id).toBeTruthy();
242257
});
243258

244-
it('omits the flagged field from the by-id update body', async () => {
245-
// The surface measured leaking on `sys_api_key` itself: that object has
246-
// `update` open (#7727) and its revoke/restore row actions PATCH it.
259+
it('the by-id update RESULT keeps the flagged field — engine callers are privileged writers', async () => {
247260
const created = await seed();
248261
const updated = await ctx.engine.update('itest_api_key', { id: created.id, revoked: true }, {
249262
context: { isSystem: true },
250263
} as any);
251-
expect(Object.keys(updated)).not.toContain('key');
264+
expect(updated.key).toBe(HASH);
252265
expect(updated.revoked).toBe(true);
253266
});
254267
});

0 commit comments

Comments
 (0)