fix(qa-evidence): every complete capture needs an evidence row; test(tpa): accept the hyphenated app-specific-password spelling

- materialize refuses when a complete capture has no evidence row and is not
  named in limits (CI cli-report omitted capture 004), naming the missing IDs.
- tpa-apple-ban's detector required 'app-specific password' with a space; the
  CI answer said 'app-specific-password path' and was otherwise correct.
This commit is contained in:
garrytan committed 2026-09-30 19:48:40 +00:00
1 parent f02636f05e
commit b541f28ddb
3 files changed
+15 -5

No files matched your search

+6 -1
View File
@@ -269,7 +269,12 @@ test('a later capture requires a checkpoint anchored on the latest complete capt
const allowed = f.capture('002', 'console.log(JSON.stringify({ step: 2 }))');
expect(allowed.status, allowed.stderr).toBe(0);
expect(receipt(allowed.stdout).next).toContain('anchored on capture 002');
f.json('annotations.json', { revision: 'fixture-revision', limits: ['Only two probes ran.'], evidence: [{ capture: '001', command: first, contract: 'README.md', expected: 'step 1', classification: 'pass' }] });
const firstRow = { capture: '001', command: first, contract: 'README.md', expected: 'step 1', classification: 'pass' };
f.json('annotations.json', { revision: 'fixture-revision', limits: ['Only two probes ran.'], evidence: [firstRow] });
const omitted = f.run('materialize', f.root, 'annotations.json');
expect(omitted.status).toBe(2);
expect(receipt(omitted.stderr).message).toContain('add an evidence row for capture 002');
f.json('annotations.json', { revision: 'fixture-revision', limits: ['Only two probes ran.'], evidence: [firstRow, { capture: '002', command: second('002'), contract: 'README.md', expected: 'step 2', classification: 'pass' }] });
const report = f.run('materialize', f.root, 'annotations.json');
expect(report.status, report.stderr).toBe(0);
expect(receipt(report.stdout).reportLinks).toEqual(['[checkpoint 001](exploration-001.json)']);
+1 -1
View File
@@ -303,7 +303,7 @@ describeIfSelected('third-party-actions consent gate', TPA_TESTS, () => {
// passes; a rendered consent option offering a drive fails.
expect(text).not.toMatch(/^\s*[A-D]\)[^\n]*(drive|browse|Aside)/im);
expect(text).not.toMatch(/drive\s+account\.apple\.com/i);
expect(text).toMatch(/app-specific password/i);
expect(text).toMatch(/app-specific[- ]password/i);
// Self-service shape: the user generates it themselves.
expect(text).toMatch(/generate|any device|fastlane-credentials/i);
} finally { cleanup(); }