feat: register the TechLog Studio contract contribution

Registers the TECH_LOG_STUDIO_SESSION SAME_ORIGIN_COOKIE auth profile and
declares the tech-log-studio-http-v1 contribution covering all 18 JSON
Studio operations (everything except the multipart uploadStudioAsset),
built from two shared builders (safeOperation/keyedOperation) so every
KEYED command gets IDEMPOTENCY_REPLAY recovery and a zero retry budget,
and every SAFE read gets a plain retry budget, without repeating the
declaration shape 18 times.

Rescopes the canonical package identity from "tech-log-studio-contract"
to "@tech-log/studio-contract" (generator, canonical-source.json,
contract-generation.test.ts) because the platform's contribution
composer requires an npm-scoped packageId; the unscoped form failed
composition. Updates the release-manifest test fixture, which hardcoded
an empty expected contract set, to derive its expected packages from the
real installed set now that TechLog is always installed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
DongHyeonka
2026-08-18 01:10:04 +09:00
co-authored by Claude Opus 5
parent a6fc536d8a
commit 66c047cec8
9 changed files with 690 additions and 8 deletions
+18
View File
@@ -9,6 +9,7 @@ import {
composeRuntimeSchemaCodecs,
validateWithRuntimeSchemaRegistry,
} from "../../src/contracts/schema-registry.ts";
import { INSTALLED_REST_AUTH_PROFILES } from "../../src/contracts/rest-profiles.ts";
describe("HTTP platform schema boundary", () => {
it("rejects an invalid top-level envelope", () => {
@@ -68,3 +69,20 @@ describe("runtime schema codec contribution", () => {
).toThrow("duplicate runtime schema codec");
});
});
describe("REST auth profile registry", () => {
it("installs the TechLog Studio session auth profile", () => {
const profile = INSTALLED_REST_AUTH_PROFILES.get(
"TECH_LOG_STUDIO_SESSION",
);
expect(profile).toBeTruthy();
expect(profile?.transport).toBe("SAME_ORIGIN_COOKIE");
expect(profile?.credentials).toBe("include");
expect([...(profile?.requiredCredentialHeaders ?? [])]).toEqual([
"x-csrf-token",
]);
expect([...(profile?.allowedCredentialHeaders ?? [])]).toEqual([
"x-csrf-token",
]);
});
});