mirror of
https://github.com/garrytan/gstack.git
synced 2026-10-04 02:16:56 +02:00
test: replace product tests that fake the product with real-boundary tests (F)
- design: serve.test.ts drove an inline mirror server; now two tests run the real serve() on an ephemeral port (reload confinement, submit exit 0). - setup-gbrain: rollback + voyage tests execute the template-extracted init blocks (3 sites) instead of drifted local bash copies. - terminal-agent: internalHandler source greps replaced by a behavioral /internal/grant + /internal/revoke auth matrix (no/wrong/valid token). - /health: server-security-surface and the server-auth / security-audit-r2 / sidebar-tabs source greps fold into one liveness-only check on the real body; the L4 sidecar wiring gets a behavioral /pty-inject-scan test. - delete tautologies (browser-manager onDisconnect, memory-command #12), ios swiftui tap fixture self-check, memory-ingest put_page grep, detach source greps, sidebar-agent absence pins, dead-CSS pins + the dead CSS, security-audit-r2 Task 1 + the test-only meta-commands re-export, duplicate generated-SKILL.md checks. - make-pdf coverage-gaps cases move into their owner test files.
This commit is contained in:
1 parent
6dc624eda6
commit
5ec930d569
33 files changed
+638
-1830
No files matched your search
@@ -22,17 +22,6 @@ function sliceBetween(source: string, startMarker: string, endMarker: string): s
|
||||
}
|
||||
|
||||
describe('Server auth security', () => {
|
||||
// Test 1 (IRON RULE, inverted in v1.62): /health NEVER serves a token in
|
||||
// ANY mode. Both carve-outs (headed-mode disjunct + chrome-extension://
|
||||
// Origin disjunct) are gone. Token bootstrap moved to POST /extension-token
|
||||
// with a pinned extension Origin.
|
||||
test('/health never serves a token — no headed-mode or chrome-extension carve-out', () => {
|
||||
const healthBlock = sliceBetween(SERVER_SRC, "url.pathname === '/health'", "url.pathname === '/connect'");
|
||||
expect(healthBlock).not.toContain('token: authToken');
|
||||
expect(healthBlock).not.toContain("getConnectionMode() === 'headed'");
|
||||
expect(healthBlock).not.toContain("startsWith('chrome-extension://')");
|
||||
});
|
||||
|
||||
// Test 1a: the pinned-origin bootstrap endpoint exists and gates on both
|
||||
// the exact extension Origin and a loopback Host.
|
||||
test('POST /extension-token gates on pinned Origin and loopback Host', () => {
|
||||
@@ -47,13 +36,6 @@ describe('Server auth security', () => {
|
||||
expect(tokenBlock).toContain('403');
|
||||
});
|
||||
|
||||
// Test 1b: /health does not expose sensitive browsing state
|
||||
test('/health does not expose currentUrl or currentMessage', () => {
|
||||
const healthBlock = sliceBetween(SERVER_SRC, "url.pathname === '/health'", "url.pathname === '/connect'");
|
||||
expect(healthBlock).not.toContain('currentUrl');
|
||||
expect(healthBlock).not.toContain('currentMessage');
|
||||
});
|
||||
|
||||
// Test 1c: newtab must check domain restrictions (CSO finding #5)
|
||||
// Domain check for newtab is now unified with goto in the scope check section:
|
||||
// (command === 'goto' || command === 'newtab') && args[0] → checkDomain
|
||||
|
||||
Reference in new issue
Block a user