chore: sync the frontend template from 4dc033c to 8157ad4
The product was materialized from the template at `4dc033c` and has stayed on it through 43 template commits, so it was missing all three rounds of adapter remediation — including files it never had, such as the shared `abortable-operation` primitive and the `exact-snapshot` decoder that later fixes are written against. Taking only the newest round was not possible for that reason: the delta is coherent only as a whole. The product had not touched `src/adapters` at all since materialization, so the 140-file delta applied with a three-way merge and no conflicts. `package.json` was the single overlap and merged cleanly: the product owns `name`, the template contributed `check:adapter-inventory`, `check:remediation-ledger` and the image-resolve-signal type fixture. All 24 product-owned files — README, index.html, CI workflow, i18n catalog, home page, generated schemas, evidence scripts, component and visual snapshots — are byte-identical to `main`. `template.lock.json` now pins the synced revision and tree. Verified in this repository, not inherited from the template: six type projects, lint, nine gates (adapter inventory, remediation ledger, registries, diagnostics, realtime boundaries, architecture, browser file/storage boundaries, optional recipes, documentation), the production build, and 2,054 of 2,073 tests. The 19 failures are all in `tests/unit/ci-artifact-contract.test.ts` and are the same pre-existing sandbox RLIMIT, EMFILE, umask and `/tmp` permission behaviour the template records; four suites that failed once under parallel load pass in isolation. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
002ba3624e
commit
4bff9ca151
@@ -2,6 +2,7 @@ import {
|
||||
isCacheInvalidationOpaqueIdentifier,
|
||||
type CacheInvalidationTopicDefinition,
|
||||
} from "../../contracts/cache-invalidation.ts";
|
||||
import { STORAGE_REGISTRY } from "../../contracts/storage-keys.ts";
|
||||
import {
|
||||
createBrowserCrossContextInvalidation,
|
||||
type BroadcastChannelFacade,
|
||||
@@ -31,8 +32,9 @@ type NativeBroadcastChannel = Readonly<{
|
||||
}>;
|
||||
|
||||
const CHANNEL_NAME = "ca-client-cache-invalidation-v1";
|
||||
// N-09. The registry owns the physical-key policy for the pulse.
|
||||
const STORAGE_PULSE_KEY =
|
||||
"ca-frontend:cache-invalidation:v1:pulse";
|
||||
STORAGE_REGISTRY.CACHE_INVALIDATION_PULSE.physicalKey;
|
||||
|
||||
/**
|
||||
* Captures native capabilities without allowing a SecurityError getter or a
|
||||
@@ -59,6 +61,8 @@ export function createBrowserCrossContextInvalidationFromHost(
|
||||
const sourceEpoch = createOpaqueId("page");
|
||||
if (!sourceId || !sourceEpoch) return undefined;
|
||||
|
||||
const capturedLocalStorage = captureLocalStorage(host);
|
||||
|
||||
return createBrowserCrossContextInvalidation({
|
||||
channelName: CHANNEL_NAME,
|
||||
storagePulseKey: STORAGE_PULSE_KEY,
|
||||
@@ -72,8 +76,13 @@ export function createBrowserCrossContextInvalidationFromHost(
|
||||
return eventId;
|
||||
},
|
||||
createBroadcastChannel: broadcastFactory(host),
|
||||
storage: storageFacade(host),
|
||||
storageEvents: storageEventTarget(host),
|
||||
// N-09. One capture, one identity: the write facade and the event
|
||||
// validator must agree about which Storage object they trust. Reading the
|
||||
// getter twice would let a hostile host return a different object.
|
||||
storage: capturedLocalStorage
|
||||
? storageFacade(capturedLocalStorage)
|
||||
: undefined,
|
||||
storageEvents: storageEventTarget(host, capturedLocalStorage),
|
||||
observe: dependencies.observe,
|
||||
});
|
||||
}
|
||||
@@ -182,11 +191,16 @@ function isNativeBroadcastChannel(
|
||||
);
|
||||
}
|
||||
|
||||
function storageFacade(
|
||||
function captureLocalStorage(
|
||||
host: Record<string, unknown>,
|
||||
): StoragePulseFacade | undefined {
|
||||
): object | undefined {
|
||||
const candidate = safeGet(host, "localStorage");
|
||||
if (!candidate || typeof candidate !== "object") return undefined;
|
||||
return candidate && typeof candidate === "object" ? candidate : undefined;
|
||||
}
|
||||
|
||||
function storageFacade(
|
||||
candidate: object,
|
||||
): StoragePulseFacade | undefined {
|
||||
const record = candidate as Record<string, unknown>;
|
||||
const setItem = safeGet(record, "setItem");
|
||||
const removeItem = safeGet(record, "removeItem");
|
||||
@@ -205,6 +219,7 @@ function storageFacade(
|
||||
|
||||
function storageEventTarget(
|
||||
host: Record<string, unknown>,
|
||||
expectedLocalStorage: object | undefined,
|
||||
): StorageEventTargetFacade | undefined {
|
||||
const addEventListener = safeGet(host, "addEventListener");
|
||||
const removeEventListener = safeGet(host, "removeEventListener");
|
||||
@@ -222,15 +237,27 @@ function storageEventTarget(
|
||||
addEventListener(_type: "storage", listener: StoragePulseListener) {
|
||||
const bound = (event: unknown) => {
|
||||
if (!event || typeof event !== "object") {
|
||||
listener({ key: null, newValue: null });
|
||||
listener({
|
||||
key: null,
|
||||
newValue: null,
|
||||
storageArea: "OTHER_OR_UNKNOWN",
|
||||
});
|
||||
return;
|
||||
}
|
||||
const record = event as Record<string, unknown>;
|
||||
const key = safeGet(record, "key");
|
||||
const newValue = safeGet(record, "newValue");
|
||||
const storageArea = safeGet(record, "storageArea");
|
||||
listener({
|
||||
key: typeof key === "string" ? key : null,
|
||||
newValue: typeof newValue === "string" ? newValue : null,
|
||||
// Compared by object identity against the captured area, never by
|
||||
// shape or by re-reading `host.localStorage`.
|
||||
storageArea:
|
||||
expectedLocalStorage !== undefined &&
|
||||
storageArea === expectedLocalStorage
|
||||
? "EXPECTED_LOCAL_STORAGE"
|
||||
: "OTHER_OR_UNKNOWN",
|
||||
});
|
||||
};
|
||||
bindings.set(listener, bound);
|
||||
|
||||
Reference in New Issue
Block a user