fix: align the legacy and optional network paths with V3 authority
LEG-01. AuthSessionPort.recover now takes the request's lifetime context, and the raw recovery helper returns data only. The sign-out notification moved to the site that adopts the result, so a recovery that answers after the deadline or a caller abort is observed and discarded instead of logging the user out of a request nobody is waiting on. LEG-02. The V2 client shares V3's credential admission validator instead of checking the allowed set alone. A bearer profile whose patch omits, empties, duplicates or corrupts Authorization now fails closed with zero fetches rather than dispatching an anonymous request under an authenticated profile. OPT-NET-01. A cursor loader rejection is re-thrown exactly as it is with no signal at all. Only a signal that has actually aborted classifies the outcome as PAGINATION_ABORTED, so a real upstream failure stops being filed as a user cancellation. OPT-NET-02. defineMutationIntent and the V3 admission site now share the single isValidIdempotencyKey authority, closing the drift that let a control character through intent definition. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
f4bfdf0365
commit
ca210d3bc5
@@ -0,0 +1,240 @@
|
||||
import { HttpResponse, http } from "msw";
|
||||
import { setupServer } from "msw/node";
|
||||
import { afterAll, afterEach, beforeAll, describe, expect, it, vi } from "vitest";
|
||||
|
||||
import { createHttpClient } from "../../src/adapters/http/client.ts";
|
||||
import { defineRestOperation } from "../../src/contracts/api-operations.ts";
|
||||
import { createRestProviderProfile } from "../../src/contracts/rest-profiles.ts";
|
||||
import { TEST_HTTP_CONTRACT } from "../helpers/http-contract-fixture.ts";
|
||||
|
||||
/**
|
||||
* LEG-01 / LEG-02. The V2 client is not the default path any more, but a
|
||||
* rollback re-activates it, so its credential and recovery authority must match
|
||||
* V3 rather than diverge quietly.
|
||||
*/
|
||||
|
||||
const BEARER_LIST = defineRestOperation({
|
||||
method: "GET",
|
||||
path: "/api/entities",
|
||||
operationId: "LIST_ENTITIES",
|
||||
auth: "external-session",
|
||||
timeoutMs: null,
|
||||
idempotency: "safe",
|
||||
retry: "runtime",
|
||||
requestSource: "search",
|
||||
requestSchema: "EntityListQuery",
|
||||
responseSchema: "EntityListPayload",
|
||||
owner: "test-fixture",
|
||||
contractVersion: 2,
|
||||
protocol: "REST",
|
||||
semantics: "QUERY",
|
||||
replayPolicy: "SAFE",
|
||||
idempotencyKeyPolicy: "NONE",
|
||||
mapperId: "EntityListMapper",
|
||||
successStatuses: [200],
|
||||
responseMediaTypes: ["application/json"],
|
||||
maxResponseBytes: 32_768,
|
||||
providerId: "PRIMARY_API",
|
||||
authProfileId: "REFERENCE_EXTERNAL_BEARER",
|
||||
csrfProfileId: "NO_CSRF_BEARER",
|
||||
pathSchema: "NoRequest",
|
||||
pathParameterNames: [],
|
||||
maxEncodedSearchBytes: 1_024,
|
||||
});
|
||||
|
||||
let observedAuthorization: string | null = null;
|
||||
let requestCount = 0;
|
||||
let nextStatus = 200;
|
||||
|
||||
const server = setupServer(
|
||||
http.get("https://api.test/api/entities", ({ request }) => {
|
||||
requestCount += 1;
|
||||
observedAuthorization = request.headers.get("authorization");
|
||||
if (nextStatus === 401) {
|
||||
return HttpResponse.json(
|
||||
{
|
||||
success: false,
|
||||
error: { code: "UNAUTHENTICATED" },
|
||||
meta: { requestId: "request-1", traceId: "trace-1" },
|
||||
},
|
||||
{ status: 401 },
|
||||
);
|
||||
}
|
||||
return HttpResponse.json({
|
||||
success: true,
|
||||
data: [{ id: "resource-1", name: "Example" }],
|
||||
meta: { requestId: "request-2", traceId: "trace-1" },
|
||||
});
|
||||
}),
|
||||
);
|
||||
|
||||
beforeAll(() => server.listen({ onUnhandledRequest: "error" }));
|
||||
afterEach(() => {
|
||||
observedAuthorization = null;
|
||||
requestCount = 0;
|
||||
nextStatus = 200;
|
||||
server.resetHandlers();
|
||||
});
|
||||
afterAll(() => server.close());
|
||||
|
||||
const clock = { now: () => 0, sleep: async () => {} };
|
||||
|
||||
type HttpDependencies = Parameters<typeof createHttpClient>[0];
|
||||
|
||||
function bearerClient(options: Partial<HttpDependencies>) {
|
||||
return createHttpClient({
|
||||
...TEST_HTTP_CONTRACT,
|
||||
getOperation: (operationId: string) => {
|
||||
if (operationId !== "LIST_ENTITIES") {
|
||||
throw new Error(`Unknown test operation: ${operationId}`);
|
||||
}
|
||||
return BEARER_LIST;
|
||||
},
|
||||
baseUrl: "https://api.test",
|
||||
providerProfile: createRestProviderProfile("PRIMARY_API", "https://api.test", [
|
||||
"omit",
|
||||
]),
|
||||
// The V2 fixture declares `NoRequest` for its path codec, which the shared
|
||||
// schema registry does not carry.
|
||||
validatePath: () => ({ success: true as const, data: {} }),
|
||||
clock,
|
||||
...options,
|
||||
} as HttpDependencies);
|
||||
}
|
||||
|
||||
function sessionStub(
|
||||
overrides: Partial<{
|
||||
getState: () => "authenticated" | "unauthenticated" | "recovery-pending" | "integration-failed";
|
||||
credentialPatch: (...args: never[]) => Promise<{ headers: Record<string, string> }>;
|
||||
recover: (...args: never[]) => Promise<"restored" | "no-session">;
|
||||
onUnauthenticated: () => void;
|
||||
}> = {},
|
||||
) {
|
||||
return {
|
||||
getState: () => "authenticated" as const,
|
||||
subscribe: () => () => {},
|
||||
beginSignIn: async () => {},
|
||||
signOut: async () => {},
|
||||
credentialPatch: async () => ({ headers: { authorization: "Bearer t" } }),
|
||||
recover: async () => "restored" as const,
|
||||
onUnauthenticated: () => {},
|
||||
...overrides,
|
||||
};
|
||||
}
|
||||
|
||||
describe("LEG-02 the bearer profile's required header is enforced", () => {
|
||||
it("refuses to dispatch when a READY patch omits authorization", async () => {
|
||||
const client = bearerClient({
|
||||
authSession: sessionStub({
|
||||
credentialPatch: async () => ({ headers: {} }),
|
||||
}) as never,
|
||||
});
|
||||
|
||||
await expect(client.execute("LIST_ENTITIES")).resolves.toMatchObject({
|
||||
ok: false,
|
||||
error: { kind: "AUTH_INTEGRATION_FAILURE" },
|
||||
});
|
||||
expect(requestCount).toBe(0);
|
||||
});
|
||||
|
||||
it("rejects a malformed or duplicated authorization value", async () => {
|
||||
const hostilePatches: readonly Record<string, string>[] = [
|
||||
{ authorization: "" },
|
||||
{ authorization: "Bearer bad\nvalue" },
|
||||
{ Authorization: "Bearer a", authorization: "Bearer b" },
|
||||
];
|
||||
for (const headers of hostilePatches) {
|
||||
const client = bearerClient({
|
||||
authSession: sessionStub({
|
||||
credentialPatch: async () => ({ headers }),
|
||||
}) as never,
|
||||
});
|
||||
await expect(client.execute("LIST_ENTITIES")).resolves.toMatchObject({
|
||||
ok: false,
|
||||
error: { kind: "AUTH_INTEGRATION_FAILURE" },
|
||||
});
|
||||
}
|
||||
expect(requestCount).toBe(0);
|
||||
});
|
||||
|
||||
it("dispatches with the admitted authorization header", async () => {
|
||||
const client = bearerClient({
|
||||
authSession: sessionStub() as never,
|
||||
});
|
||||
|
||||
await expect(client.execute("LIST_ENTITIES")).resolves.toMatchObject({
|
||||
ok: true,
|
||||
});
|
||||
expect(observedAuthorization).toBe("Bearer t");
|
||||
});
|
||||
});
|
||||
|
||||
describe("LEG-01 recovery notification follows the adopted result", () => {
|
||||
it("does not sign the user out when recovery answers after the deadline", async () => {
|
||||
nextStatus = 401;
|
||||
const onUnauthenticated = vi.fn();
|
||||
let elapsed = 0;
|
||||
const client = bearerClient({
|
||||
clock: {
|
||||
now: () => elapsed,
|
||||
sleep: async () => {},
|
||||
},
|
||||
timeoutMs: 20,
|
||||
authSession: sessionStub({
|
||||
onUnauthenticated,
|
||||
recover: async () => {
|
||||
// The request's own deadline expires while recovery is still out.
|
||||
elapsed = 10_000;
|
||||
await new Promise((resolve) => setTimeout(resolve, 30));
|
||||
return "no-session" as const;
|
||||
},
|
||||
}) as never,
|
||||
});
|
||||
|
||||
const outcome = await client.execute("LIST_ENTITIES");
|
||||
expect(outcome.ok).toBe(false);
|
||||
await new Promise((resolve) => setTimeout(resolve, 60));
|
||||
expect(onUnauthenticated).toHaveBeenCalledTimes(0);
|
||||
});
|
||||
|
||||
it("signs the user out exactly once for an adopted no-session result", async () => {
|
||||
nextStatus = 401;
|
||||
const onUnauthenticated = vi.fn();
|
||||
const client = bearerClient({
|
||||
authSession: sessionStub({
|
||||
onUnauthenticated,
|
||||
recover: async () => "no-session" as const,
|
||||
}) as never,
|
||||
});
|
||||
|
||||
await expect(client.execute("LIST_ENTITIES")).resolves.toMatchObject({
|
||||
ok: false,
|
||||
error: { kind: "AUTH_REQUIRED" },
|
||||
});
|
||||
expect(onUnauthenticated).toHaveBeenCalledTimes(1);
|
||||
});
|
||||
|
||||
it("stays bounded when recovery never settles", async () => {
|
||||
nextStatus = 401;
|
||||
const onUnauthenticated = vi.fn();
|
||||
let elapsed = 0;
|
||||
const client = bearerClient({
|
||||
clock: {
|
||||
now: () => {
|
||||
elapsed += 5;
|
||||
return elapsed;
|
||||
},
|
||||
sleep: async () => {},
|
||||
},
|
||||
timeoutMs: 20,
|
||||
authSession: sessionStub({
|
||||
onUnauthenticated,
|
||||
recover: () => new Promise<"restored">(() => {}),
|
||||
}) as never,
|
||||
});
|
||||
|
||||
const outcome = await client.execute("LIST_ENTITIES");
|
||||
expect(outcome.ok).toBe(false);
|
||||
expect(onUnauthenticated).toHaveBeenCalledTimes(0);
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,149 @@
|
||||
import { describe, expect, it, vi } from "vitest";
|
||||
|
||||
import { createCursorPaginationRuntime } from "../../src/adapters/query-cache/cursor-pagination-runtime.ts";
|
||||
import {
|
||||
defineMutationIntent,
|
||||
isValidIdempotencyKey,
|
||||
} from "../../src/contracts/mutation-intent.ts";
|
||||
import type {
|
||||
CursorPage,
|
||||
CursorPaginationProfile,
|
||||
} from "../../src/contracts/cursor-pagination.ts";
|
||||
import type { Result } from "../../src/application/result.ts";
|
||||
|
||||
const PROFILE: CursorPaginationProfile = Object.freeze({
|
||||
profileId: "TEST_PAGINATION_V1",
|
||||
maxPages: 3,
|
||||
maxTotalItems: 30,
|
||||
maxEstimatedBytes: 32_768,
|
||||
maxCursorBytes: 512,
|
||||
allowSparsePage: false,
|
||||
});
|
||||
|
||||
function page(
|
||||
items: readonly number[],
|
||||
nextCursor: string | null,
|
||||
): CursorPage<number> {
|
||||
return Object.freeze({
|
||||
items: Object.freeze([...items]),
|
||||
nextCursor,
|
||||
hasMore: nextCursor !== null,
|
||||
snapshotToken: "snapshot-1",
|
||||
});
|
||||
}
|
||||
|
||||
/**
|
||||
* OPT-NET-01. A loader rejection is evidence about the data source. Reporting
|
||||
* it as `PAGINATION_ABORTED` because a signal merely *exists* erases a real
|
||||
* network or contract failure and files it under a user decision nobody made.
|
||||
*/
|
||||
describe("OPT-NET-01 cursor pagination abort classification", () => {
|
||||
it("preserves a loader rejection while the signal is still live", async () => {
|
||||
const controller = new AbortController();
|
||||
const runtime = createCursorPaginationRuntime<number>({
|
||||
definitionId: "TEST_PAGINATION",
|
||||
profile: PROFILE,
|
||||
loadPage: async () => {
|
||||
throw new TypeError("upstream exploded");
|
||||
},
|
||||
});
|
||||
|
||||
await expect(
|
||||
runtime.loadAll({ signal: controller.signal }),
|
||||
).rejects.toThrow("upstream exploded");
|
||||
});
|
||||
|
||||
it("keeps the same rejection when no signal is supplied", async () => {
|
||||
const runtime = createCursorPaginationRuntime<number>({
|
||||
definitionId: "TEST_PAGINATION",
|
||||
profile: PROFILE,
|
||||
loadPage: async () => {
|
||||
throw new TypeError("upstream exploded");
|
||||
},
|
||||
});
|
||||
|
||||
await expect(runtime.loadAll({})).rejects.toThrow("upstream exploded");
|
||||
});
|
||||
|
||||
it("classifies a rejection during a real abort as PAGINATION_ABORTED", async () => {
|
||||
const controller = new AbortController();
|
||||
const runtime = createCursorPaginationRuntime<number>({
|
||||
definitionId: "TEST_PAGINATION",
|
||||
profile: PROFILE,
|
||||
loadPage: async () => {
|
||||
controller.abort();
|
||||
throw new TypeError("cancelled upstream");
|
||||
},
|
||||
});
|
||||
|
||||
const result = await runtime.loadAll({ signal: controller.signal });
|
||||
expect(result.ok).toBe(false);
|
||||
expect(result.ok ? null : result.error.code).toBe("PAGINATION_ABORTED");
|
||||
});
|
||||
|
||||
it("does not admit a page that resolves after the abort", async () => {
|
||||
const controller = new AbortController();
|
||||
const loadPage = vi.fn(
|
||||
async (): Promise<Result<CursorPage<number>>> => {
|
||||
controller.abort();
|
||||
await new Promise((resolve) => setTimeout(resolve, 5));
|
||||
return { ok: true, value: page([1, 2], null) };
|
||||
},
|
||||
);
|
||||
const runtime = createCursorPaginationRuntime<number>({
|
||||
definitionId: "TEST_PAGINATION",
|
||||
profile: PROFILE,
|
||||
loadPage,
|
||||
});
|
||||
|
||||
const result = await runtime.loadAll({ signal: controller.signal });
|
||||
expect(result.ok).toBe(false);
|
||||
expect(result.ok ? null : result.error.code).toBe("PAGINATION_ABORTED");
|
||||
});
|
||||
});
|
||||
|
||||
/**
|
||||
* OPT-NET-02. One idempotency-key authority. Two validators drift, and the
|
||||
* looser one becomes the way a control character reaches a request header.
|
||||
*/
|
||||
describe("OPT-NET-02 shared idempotency key validation", () => {
|
||||
const rejected = [
|
||||
"",
|
||||
" ",
|
||||
"key\nwith-newline",
|
||||
"key\u0000null",
|
||||
"key\u007fdelete",
|
||||
"key\u009fc1",
|
||||
"a".repeat(257),
|
||||
];
|
||||
|
||||
it("rejects the same values at intent definition and at admission", () => {
|
||||
for (const value of rejected) {
|
||||
expect(isValidIdempotencyKey(value)).toBe(false);
|
||||
expect(() =>
|
||||
defineMutationIntent({
|
||||
intentId: "intent-1",
|
||||
operationId: "OP",
|
||||
canonicalInputIdentity: "identity",
|
||||
idempotencyKey: value,
|
||||
createdAtMonotonicMs: 1,
|
||||
}),
|
||||
).toThrow(TypeError);
|
||||
}
|
||||
});
|
||||
|
||||
it("accepts the bounded printable and Unicode values both sides allow", () => {
|
||||
for (const value of ["key-1", "a".repeat(256), "키-값", "ключ"]) {
|
||||
expect(isValidIdempotencyKey(value)).toBe(true);
|
||||
expect(
|
||||
defineMutationIntent({
|
||||
intentId: "intent-1",
|
||||
operationId: "OP",
|
||||
canonicalInputIdentity: "identity",
|
||||
idempotencyKey: value,
|
||||
createdAtMonotonicMs: 1,
|
||||
}).idempotencyKey,
|
||||
).toBe(value);
|
||||
}
|
||||
});
|
||||
});
|
||||
Reference in New Issue
Block a user