fix: harden bounded state sidecars

N-05: the conditional-validator key was a colon join over components that may
themselves contain colons, so two distinct valid bindings could collide and one
definition's ETag could be prepared for another. The key is now a validated,
byte-bounded fixed tuple encoded with JSON.stringify.

N-09: capture localStorage exactly once and compare StorageEvent.storageArea
against that object identity, so a pulse from sessionStorage or any other area
is rejected instead of matching on key and value alone. The pulse key is
registered in the storage registry as CACHE_INVALIDATION_PULSE.

N-10: race loadPage against the caller signal and re-check before observing a
page, so a non-cooperative loader can neither hold loadAll forever nor have a
post-abort completion accumulated into a successful result.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
DongHyeonka
2026-08-13 23:35:48 +09:00
co-authored by Claude Opus 5
parent b893d95b36
commit 4fe924ee0f
9 changed files with 261 additions and 19 deletions
@@ -44,6 +44,31 @@ describe("conditional validator CAS sidecar", () => {
expect(store.acceptNotModified(binding, 7, true)).toBe(false);
});
it("keeps colon-bearing validator tuples injective", () => {
const selectedScope = scope();
// N-05. Both bindings are individually valid and, under a delimiter join,
// encode to the same key.
const first = {
definitionId: "resource:detail",
identityToken: "identity-token-00000001",
representationVersion: 1,
scope: selectedScope.snapshot,
};
const second = {
definitionId: "resource",
identityToken: "detail:identity-token-00000001",
representationVersion: 1,
scope: selectedScope.snapshot,
};
const store = createConditionalValidatorStore();
expect(store.install(first, '"etag-a"', 7)).toBe(true);
expect(store.install(second, '"etag-b"', 7)).toBe(true);
expect(store.prepare(first, 7)).toBe('"etag-a"');
expect(store.prepare(second, 7)).toBe('"etag-b"');
});
it("rejects malformed validators and bounded-capacity overflow", () => {
const firstScope = scope();
const store = createConditionalValidatorStore(1);