fix: harden the legacy HTTP rollback path
N-06: export one idempotency-key authority from mutation-intent.ts and use it in the V2 client. A caller-supplied key is validated before credentials, timers and fetch, and an invalid value is rejected as VALIDATION_REJECTED / IDEMPOTENCY_KEY_INVALID rather than trimmed, regenerated or dropped, so a keyed command can no longer replay while sending no key. N-07: bound the legacy credential wait by the existing attempt controller, which already carries the total deadline and the caller signal, so a non-cooperative owner cannot hold the request open and no extra timer is introduced. The owner receives the operation context, and the failure follows ownership: deadline to REQUEST_TIMEOUT, caller to REQUEST_ABORTED, and only a genuine rejection to AUTH_INTEGRATION_FAILURE. None of these paths fetch. N-08: readBoundedJson delegates to the common bounded reader, so cancel and releaseLock throws stay isolated inside the closed result, and the V2 content-type mismatch now cancels the response body. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
4fe924ee0f
commit
c9e820aed5
@@ -59,6 +59,88 @@ describe("shared HTTP client", () => {
|
||||
expect(attempts).toBe(3);
|
||||
});
|
||||
|
||||
it.each(["", " ", "bad\u0000key", "x".repeat(513)])(
|
||||
"rejects invalid keyed command key %j before credentials and fetch",
|
||||
async (idempotencyKey) => {
|
||||
let fetched = 0;
|
||||
let credentialAttempts = 0;
|
||||
server.use(
|
||||
http.post("https://api.test/api/entities", () => {
|
||||
fetched += 1;
|
||||
return HttpResponse.json({ success: true, data: {} });
|
||||
}),
|
||||
);
|
||||
const client = testClient({
|
||||
baseUrl: "https://api.test",
|
||||
clock,
|
||||
authSession: {
|
||||
getState: () => "authenticated",
|
||||
subscribe: () => () => {},
|
||||
beginSignIn: async () => {},
|
||||
signOut: async () => {},
|
||||
async credentialPatch() {
|
||||
credentialAttempts += 1;
|
||||
return { headers: {} };
|
||||
},
|
||||
recover: async () => "no-session" as const,
|
||||
onUnauthenticated: () => {},
|
||||
},
|
||||
});
|
||||
|
||||
await expect(
|
||||
client.execute("CREATE_ENTITY", {
|
||||
body: { name: "n" },
|
||||
idempotencyKey,
|
||||
}),
|
||||
).resolves.toMatchObject({
|
||||
ok: false,
|
||||
error: {
|
||||
kind: "VALIDATION_REJECTED",
|
||||
code: "IDEMPOTENCY_KEY_INVALID",
|
||||
// The repository reports attempt counts as 1-based; the invariant
|
||||
// proved below is that no physical attempt happened at all.
|
||||
attemptCount: 1,
|
||||
},
|
||||
});
|
||||
expect(fetched).toBe(0);
|
||||
expect(credentialAttempts).toBe(0);
|
||||
},
|
||||
);
|
||||
|
||||
it("bounds a non-cooperative legacy credential owner by total deadline", async () => {
|
||||
let fetched = 0;
|
||||
let observedSignal: AbortSignal | undefined;
|
||||
server.use(
|
||||
http.get("https://api.test/api/entities", () => {
|
||||
fetched += 1;
|
||||
return HttpResponse.json({ success: true, data: [] });
|
||||
}),
|
||||
);
|
||||
const client = testClient({
|
||||
baseUrl: "https://api.test",
|
||||
timeoutMs: 5,
|
||||
clock: { now: () => 0, sleep: async () => {} },
|
||||
authSession: {
|
||||
getState: () => "authenticated",
|
||||
subscribe: () => () => {},
|
||||
beginSignIn: async () => {},
|
||||
signOut: async () => {},
|
||||
credentialPatch: (_binding, context) => {
|
||||
observedSignal = context?.signal;
|
||||
// Never settles on its own.
|
||||
return new Promise<never>(() => {});
|
||||
},
|
||||
recover: async () => "no-session" as const,
|
||||
onUnauthenticated: () => {},
|
||||
},
|
||||
});
|
||||
|
||||
const result = await client.execute("LIST_ENTITIES");
|
||||
expect(result).toMatchObject({ ok: false });
|
||||
expect(fetched).toBe(0);
|
||||
expect(observedSignal).toBeDefined();
|
||||
});
|
||||
|
||||
it("rejects a non-JSON response without exposing its body", async () => {
|
||||
server.use(
|
||||
http.get(
|
||||
|
||||
Reference in New Issue
Block a user