Skip to content

Commit e9dff47

Browse files
committed
test(dogfood): one refusal-code reader for both doors; the cold-boot leg reads only what the boot produces
Claude-Session: https://claude.ai/code/session_011K3zqE8Pv1Evw5hc8tZCnN Co-authored-by: Claude <noreply@anthropic.com>
1 parent 2a25cdf commit e9dff47

1 file changed

Lines changed: 15 additions & 32 deletions

File tree

‎packages/qa/dogfood/test/permission-set-lock-row-provenance.dogfood.test.ts‎

Lines changed: 15 additions & 32 deletions
Original file line numberDiff line numberDiff line change
@@ -45,14 +45,14 @@
4545
//
4646
// ## Why a booted stack, booted twice
4747
//
48-
// Each side has a second producer at boot. The projection echo the read serves
49-
// is minted again by the boot's reconciliation rather than by a save, so boot 2
50-
// (same file) reads the three shapes again before anything is written. The
51-
// stored row's package id is stamped by the list read, not by the boot's own
52-
// hydration (measured: after the cold boot the runtime-package set's registry
53-
// row carries no package id until the first list read), so boot 2 issues that
54-
// read and asserts the stamp is back BEFORE it asserts the edit lands —
55-
// without that precondition an accepted edit would prove nothing.
48+
// The lock's input has one producer, the list read: boot 1 issues it and
49+
// asserts the runtime package was stamped onto the set's registry row BEFORE it
50+
// asserts any edit lands — without that precondition an accepted edit would
51+
// prove nothing. (The boot's own hydration does not stamp the package id; that
52+
// was measured, so no cold-boot leg pretends to exercise it.) The read's input
53+
// has a second producer: the projection echo is minted again by the boot's
54+
// reconciliation rather than by a save, so boot 2, on the same file, reads the
55+
// three shapes again before anything is written.
5656

5757
import { describe, it, expect, beforeAll, afterAll } from 'vitest';
5858
import showcaseStack from '@objectstack/example-showcase';
@@ -98,10 +98,8 @@ function cloneAction(): CloneAction {
9898
return action as CloneAction;
9999
}
100100

101-
/** The `/meta` REST door's refusal carries its code at the top level. */
102-
const metaRefusalCode = (json: any): unknown => json?.code;
103-
/** The data door answers the ADR-0112 envelope, its code nested under `error`. */
104-
const dataRefusalCode = (json: any): unknown => json?.error?.code;
101+
/** Both doors answer this refusal as `{ error: <sentence>, code }`: the code is top-level. */
102+
const refusalCode = (json: any): unknown => json?.code;
105103

106104
describe('[#21789] the permission-set lock reads the row\'s provenance — the three org-owned shapes edit, a code-shipped set stays refused (showcase)', () => {
107105
let prevCwd: string;
@@ -226,10 +224,10 @@ describe('[#21789] the permission-set lock reads the row\'s provenance — the t
226224

227225
it('control: a set the showcase package ships is still refused at both doors with 403 NOT_OVERRIDABLE', async () => {
228226
const put = await putDefinition({ name: SHIPPED, packageQuery: '' }, 'Contributor (customized)');
229-
expect({ status: put.status, code: metaRefusalCode(put.json) }, JSON.stringify(put.json))
227+
expect({ status: put.status, code: refusalCode(put.json) }, JSON.stringify(put.json))
230228
.toEqual({ status: 403, code: 'NOT_OVERRIDABLE' });
231229
const patch = await patchRecord(SHIPPED, 'customized');
232-
expect({ status: patch.status, code: dataRefusalCode(patch.json) }, JSON.stringify(patch.json))
230+
expect({ status: patch.status, code: refusalCode(patch.json) }, JSON.stringify(patch.json))
233231
.toEqual({ status: 403, code: 'NOT_OVERRIDABLE' });
234232
});
235233

@@ -244,10 +242,8 @@ describe('[#21789] the permission-set lock reads the row\'s provenance — the t
244242
});
245243

246244
describe('after a cold boot on the same database file', () => {
247-
// The boot is the other producer on each side: the projection echo is
248-
// minted again by the boot's reconciliation (not by a save), and the
249-
// registry rows are hydrated again (the list read below re-stamps the
250-
// package id, as a Studio page load does).
245+
// The echo the read serves is minted again here by the boot's
246+
// reconciliation, not by a save: nothing is written before the reads.
251247
beforeAll(async () => {
252248
await stack?.stop();
253249
stack = undefined;
@@ -264,22 +260,9 @@ describe('[#21789] the permission-set lock reads the row\'s provenance — the t
264260
}
265261
});
266262

267-
it('after the list read stamps the package id again, the runtime-package set still edits at both doors', async () => {
268-
const list = await stack!.apiAs(token, 'GET', '/meta/permission');
269-
expect(list.status).toBe(200);
270-
// ⛔ The precondition again: without the stamp the edits below prove nothing.
271-
const rows = registryRows(PKG_SET);
272-
expect(rows.map((r) => ({ _packageId: r._packageId ?? null, _provenance: r._provenance ?? null })))
273-
.toEqual([{ _packageId: PKG, _provenance: 'org' }]);
274-
const put = await putDefinition({ name: PKG_SET, packageQuery: `?package=${PKG}` }, 'Runtime package set (after a cold boot)');
275-
expect(put.status, JSON.stringify(put.json)).toBe(200);
276-
const patch = await patchRecord(PKG_SET, 'after a cold boot');
277-
expect(patch.status, JSON.stringify(patch.json)).toBe(200);
278-
});
279-
280263
it('control: the shipped set is still refused at the metadata door with 403 NOT_OVERRIDABLE', async () => {
281264
const put = await putDefinition({ name: SHIPPED, packageQuery: '' }, 'Contributor (customized)');
282-
expect({ status: put.status, code: metaRefusalCode(put.json) }, JSON.stringify(put.json))
265+
expect({ status: put.status, code: refusalCode(put.json) }, JSON.stringify(put.json))
283266
.toEqual({ status: 403, code: 'NOT_OVERRIDABLE' });
284267
});
285268
});

0 commit comments

Comments
 (0)