mirror of
https://github.com/garrytan/gstack.git
synced 2026-10-05 10:57:15 +02:00
test: replace product tests that fake the product with real-boundary tests (F)
- design: serve.test.ts drove an inline mirror server; now two tests run the real serve() on an ephemeral port (reload confinement, submit exit 0). - setup-gbrain: rollback + voyage tests execute the template-extracted init blocks (3 sites) instead of drifted local bash copies. - terminal-agent: internalHandler source greps replaced by a behavioral /internal/grant + /internal/revoke auth matrix (no/wrong/valid token). - /health: server-security-surface and the server-auth / security-audit-r2 / sidebar-tabs source greps fold into one liveness-only check on the real body; the L4 sidecar wiring gets a behavioral /pty-inject-scan test. - delete tautologies (browser-manager onDisconnect, memory-command #12), ios swiftui tap fixture self-check, memory-ingest put_page grep, detach source greps, sidebar-agent absence pins, dead-CSS pins + the dead CSS, security-audit-r2 Task 1 + the test-only meta-commands re-export, duplicate generated-SKILL.md checks. - make-pdf coverage-gaps cases move into their owner test files.
This commit is contained in:
1 parent
6dc624eda6
commit
5ec930d569
33 files changed
+638
-1830
No files matched your search
@@ -91,6 +91,29 @@ describe('GET /health never carries a token (IRON RULE)', () => {
|
||||
});
|
||||
});
|
||||
|
||||
describe('GET /health is liveness-only', () => {
|
||||
beforeEach(() => __resetRegistry());
|
||||
|
||||
// Folds the former server-auth / security-audit-r2 / sidebar-tabs /
|
||||
// server-security-surface source greps into one check on the real body.
|
||||
// #2557: no `security` field (its only data source had no writer).
|
||||
const FORBIDDEN = ['token', 'security', 'currentUrl', 'currentMessage', 'agentStatus', 'messageQueue', 'agentStartTime', 'chatEnabled'];
|
||||
|
||||
for (const [label, browserManager, headers] of [
|
||||
['default mode', () => new BrowserManager(), {}],
|
||||
['headed mode + pinned extension Origin', headedBrowserManager, { Origin: PINNED_ORIGIN }],
|
||||
] as const) {
|
||||
test(`${label}: no token, security, browsing-state or chat fields; terminal port survives`, async () => {
|
||||
const handle = buildFetchHandler(makeConfig({ browserManager: browserManager() }));
|
||||
const resp = await handle.fetchLocal(new Request('http://127.0.0.1:34567/health', { headers }), null);
|
||||
expect(resp.status).toBe(200);
|
||||
const body = await resp.json() as Record<string, unknown>;
|
||||
expect(FORBIDDEN.filter((key) => key in body)).toEqual([]);
|
||||
expect('terminalPort' in body).toBe(true);
|
||||
});
|
||||
}
|
||||
});
|
||||
|
||||
describe('POST /extension-token pinned-origin bootstrap', () => {
|
||||
beforeEach(() => __resetRegistry());
|
||||
|
||||
|
||||
Reference in new issue
Block a user