N-06: export one idempotency-key authority from mutation-intent.ts and use it in the V2 client. A caller-supplied key is validated before credentials, timers and fetch, and an invalid value is rejected as VALIDATION_REJECTED / IDEMPOTENCY_KEY_INVALID rather than trimmed, regenerated or dropped, so a keyed command can no longer replay while sending no key. N-07: bound the legacy credential wait by the existing attempt controller, which already carries the total deadline and the caller signal, so a non-cooperative owner cannot hold the request open and no extra timer is introduced. The owner receives the operation context, and the failure follows ownership: deadline to REQUEST_TIMEOUT, caller to REQUEST_ABORTED, and only a genuine rejection to AUTH_INTEGRATION_FAILURE. None of these paths fetch. N-08: readBoundedJson delegates to the common bounded reader, so cancel and releaseLock throws stay isolated inside the closed result, and the V2 content-type mismatch now cancels the response body. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
257 lines
7.6 KiB
TypeScript
257 lines
7.6 KiB
TypeScript
import { HttpResponse, http } from "msw";
|
|
import { setupServer } from "msw/node";
|
|
import { afterAll, afterEach, beforeAll, describe, expect, it } from "vitest";
|
|
|
|
import { createHttpClient } from "../../src/adapters/http/client.ts";
|
|
import { TEST_HTTP_CONTRACT } from "../helpers/http-contract-fixture.ts";
|
|
|
|
let attempts = 0;
|
|
const server = setupServer(
|
|
http.get("https://api.test/api/entities", () => {
|
|
attempts += 1;
|
|
if (attempts < 3) {
|
|
return HttpResponse.json(
|
|
{ success: false, error: { code: "TEMPORARY" } },
|
|
{ status: 503 },
|
|
);
|
|
}
|
|
return HttpResponse.json({
|
|
success: true,
|
|
data: [{ id: "resource-1", name: "Example" }],
|
|
meta: { requestId: "request-1", traceId: "trace-1" },
|
|
});
|
|
}),
|
|
);
|
|
|
|
beforeAll(() => server.listen({ onUnhandledRequest: "error" }));
|
|
afterEach(() => {
|
|
attempts = 0;
|
|
server.resetHandlers();
|
|
});
|
|
afterAll(() => server.close());
|
|
|
|
const clock = {
|
|
now: () => 0,
|
|
sleep: async () => {},
|
|
};
|
|
|
|
type HttpDependencies = Parameters<typeof createHttpClient>[0];
|
|
|
|
function testClient(options: HttpDependencies) {
|
|
return createHttpClient({ ...TEST_HTTP_CONTRACT, ...options });
|
|
}
|
|
|
|
describe("shared HTTP client", () => {
|
|
it("retries a safe request at most twice and returns validated data", async () => {
|
|
const client = testClient({
|
|
baseUrl: "https://api.test",
|
|
clock,
|
|
random: () => 0,
|
|
});
|
|
|
|
await expect(
|
|
client.execute("LIST_ENTITIES", { routeId: "TEST_ROUTE" }),
|
|
).resolves.toMatchObject({
|
|
ok: true,
|
|
value: [{ id: "resource-1", displayName: "Example" }],
|
|
meta: { requestId: "request-1" },
|
|
});
|
|
expect(attempts).toBe(3);
|
|
});
|
|
|
|
it.each(["", " ", "bad\u0000key", "x".repeat(513)])(
|
|
"rejects invalid keyed command key %j before credentials and fetch",
|
|
async (idempotencyKey) => {
|
|
let fetched = 0;
|
|
let credentialAttempts = 0;
|
|
server.use(
|
|
http.post("https://api.test/api/entities", () => {
|
|
fetched += 1;
|
|
return HttpResponse.json({ success: true, data: {} });
|
|
}),
|
|
);
|
|
const client = testClient({
|
|
baseUrl: "https://api.test",
|
|
clock,
|
|
authSession: {
|
|
getState: () => "authenticated",
|
|
subscribe: () => () => {},
|
|
beginSignIn: async () => {},
|
|
signOut: async () => {},
|
|
async credentialPatch() {
|
|
credentialAttempts += 1;
|
|
return { headers: {} };
|
|
},
|
|
recover: async () => "no-session" as const,
|
|
onUnauthenticated: () => {},
|
|
},
|
|
});
|
|
|
|
await expect(
|
|
client.execute("CREATE_ENTITY", {
|
|
body: { name: "n" },
|
|
idempotencyKey,
|
|
}),
|
|
).resolves.toMatchObject({
|
|
ok: false,
|
|
error: {
|
|
kind: "VALIDATION_REJECTED",
|
|
code: "IDEMPOTENCY_KEY_INVALID",
|
|
// The repository reports attempt counts as 1-based; the invariant
|
|
// proved below is that no physical attempt happened at all.
|
|
attemptCount: 1,
|
|
},
|
|
});
|
|
expect(fetched).toBe(0);
|
|
expect(credentialAttempts).toBe(0);
|
|
},
|
|
);
|
|
|
|
it("bounds a non-cooperative legacy credential owner by total deadline", async () => {
|
|
let fetched = 0;
|
|
let observedSignal: AbortSignal | undefined;
|
|
server.use(
|
|
http.get("https://api.test/api/entities", () => {
|
|
fetched += 1;
|
|
return HttpResponse.json({ success: true, data: [] });
|
|
}),
|
|
);
|
|
const client = testClient({
|
|
baseUrl: "https://api.test",
|
|
timeoutMs: 5,
|
|
clock: { now: () => 0, sleep: async () => {} },
|
|
authSession: {
|
|
getState: () => "authenticated",
|
|
subscribe: () => () => {},
|
|
beginSignIn: async () => {},
|
|
signOut: async () => {},
|
|
credentialPatch: (_binding, context) => {
|
|
observedSignal = context?.signal;
|
|
// Never settles on its own.
|
|
return new Promise<never>(() => {});
|
|
},
|
|
recover: async () => "no-session" as const,
|
|
onUnauthenticated: () => {},
|
|
},
|
|
});
|
|
|
|
const result = await client.execute("LIST_ENTITIES");
|
|
expect(result).toMatchObject({ ok: false });
|
|
expect(fetched).toBe(0);
|
|
expect(observedSignal).toBeDefined();
|
|
});
|
|
|
|
it("rejects a non-JSON response without exposing its body", async () => {
|
|
server.use(
|
|
http.get(
|
|
"https://api.test/api/entities",
|
|
() => new HttpResponse("<secret>raw body</secret>", { status: 502 }),
|
|
),
|
|
);
|
|
const client = testClient({ baseUrl: "https://api.test", clock });
|
|
const result = await client.execute("LIST_ENTITIES");
|
|
|
|
expect(result).toMatchObject({
|
|
ok: false,
|
|
error: { kind: "CONTENT_TYPE_MISMATCH" },
|
|
});
|
|
expect(JSON.stringify(result)).not.toContain("raw body");
|
|
});
|
|
|
|
it("classifies malformed JSON and invalid payloads at the boundary", async () => {
|
|
server.use(
|
|
http.get(
|
|
"https://api.test/api/entities",
|
|
() =>
|
|
new HttpResponse("{", {
|
|
headers: { "Content-Type": "application/json" },
|
|
}),
|
|
),
|
|
);
|
|
const client = testClient({ baseUrl: "https://api.test", clock });
|
|
await expect(client.execute("LIST_ENTITIES")).resolves.toMatchObject({
|
|
ok: false,
|
|
error: { kind: "MALFORMED_JSON" },
|
|
});
|
|
|
|
server.use(
|
|
http.get("https://api.test/api/entities", () =>
|
|
HttpResponse.json({
|
|
success: true,
|
|
data: [{ id: "resource-1", name: 42 }],
|
|
meta: { requestId: "request-1", traceId: "trace-1" },
|
|
}),
|
|
),
|
|
);
|
|
await expect(client.execute("LIST_ENTITIES")).resolves.toMatchObject({
|
|
ok: false,
|
|
error: { kind: "SCHEMA_MISMATCH" },
|
|
});
|
|
});
|
|
|
|
it("projects only approved 422 issue path and code metadata", async () => {
|
|
server.use(
|
|
http.post("https://api.test/api/entities", () =>
|
|
HttpResponse.json(
|
|
{
|
|
success: false,
|
|
error: {
|
|
code: "INVALID_INPUT",
|
|
message: "raw backend secret",
|
|
details: {
|
|
issues: [
|
|
{ path: "name", code: "REQUIRED", message: "raw field copy" },
|
|
{ path: 42, code: "INVALID" },
|
|
],
|
|
},
|
|
},
|
|
meta: { requestId: "request-422", traceId: "trace-422" },
|
|
},
|
|
{ status: 422 },
|
|
),
|
|
),
|
|
);
|
|
const client = testClient({ baseUrl: "https://api.test", clock });
|
|
const result = await client.execute("CREATE_ENTITY", {
|
|
routeId: "TEST_FORM",
|
|
body: { name: "Valid" },
|
|
});
|
|
|
|
expect(result).toMatchObject({
|
|
ok: false,
|
|
error: {
|
|
kind: "VALIDATION_REJECTED",
|
|
validationIssues: [{ path: "name", code: "REQUIRED" }],
|
|
},
|
|
});
|
|
expect(JSON.stringify(result)).not.toContain("raw backend secret");
|
|
expect(JSON.stringify(result)).not.toContain("raw field copy");
|
|
});
|
|
|
|
it("guards mapper exceptions as a mapping contract violation", async () => {
|
|
server.use(
|
|
http.get("https://api.test/api/entities", () =>
|
|
HttpResponse.json({
|
|
success: true,
|
|
data: [{ id: "resource-1", name: "Example" }],
|
|
meta: { requestId: "request-1", traceId: "trace-1" },
|
|
}),
|
|
),
|
|
);
|
|
const client = testClient({
|
|
baseUrl: "https://api.test",
|
|
clock,
|
|
mapPayload: () => {
|
|
throw new Error("raw mapper detail");
|
|
},
|
|
});
|
|
|
|
const result = await client.execute("LIST_ENTITIES");
|
|
expect(result).toMatchObject({
|
|
ok: false,
|
|
error: { kind: "MAPPING_CONTRACT_VIOLATION" },
|
|
});
|
|
expect(JSON.stringify(result)).not.toContain("raw mapper detail");
|
|
});
|
|
});
|