Skip to content

Commit 8ca554d

Browse files
hotlongclaude
andcommitted
test(rest): the execctx census reads /audit as refusing on its own reading
With the umbrella isolated, /audit now refuses an absent context at its own authoring-door gate, like /meta/_drafts. The audit door's caller resolution keeps its catch on the invocation line and adds no prose mention, so the census's site and mention counts do not move. Claude-Session: https://claude.ai/code/session_local_1d2a197c-c20e-4e90-9be8-413d4d432289 Co-authored-by: Claude <noreply@anthropic.com>
1 parent 89c2ba9 commit 8ca554d

2 files changed

Lines changed: 8 additions & 6 deletions

File tree

‎packages/rest/src/execctx-consumer-census.test.ts‎

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -542,7 +542,7 @@ describe('[#13160] §4 the 20 locally-caught sites — the half with no shared f
542542
}
543543
}, 180_000);
544544

545-
it('⭐ with the umbrella ISOLATED, six of the inner sites do NOT refuse on their own reading', async () => {
545+
it('⭐ with the umbrella ISOLATED, four of the inner sites do NOT refuse on their own reading', async () => {
546546
// ⛔ Counterfactual, not a production posture — production mounts the
547547
// umbrella, and section 4's first case measures that it refuses. What
548548
// this separates is DOUBLE-guarded from SINGLE-guarded: an absent
@@ -560,12 +560,16 @@ describe('[#13160] §4 the 20 locally-caught sites — the half with no shared f
560560
'DELETE /api/v1/meta/:type/:name',
561561
'POST /api/v1/meta/:type/:name/publish',
562562
'POST /api/v1/meta/:type/:name/rollback',
563+
// [#20441] An authoring door now, like `_drafts`: the authoring
564+
// capability is asked at its head, so an absent context is refused
565+
// there even with the umbrella isolated. It moved from the list
566+
// below, whose length the title states.
567+
'GET /api/v1/meta/:type/:name/audit',
563568
];
564569
const SERVES_ON_ITS_OWN = [
565570
'GET /api/v1/meta/:type', // list — org scope only
566571
'GET /api/v1/meta/:type/:name', // item read — org scope only
567572
'GET /api/v1/meta/:type/:name/layers',
568-
'GET /api/v1/meta/:type/:name/audit',
569573
'GET /api/v1/meta/:type/:name/published',
570574
];
571575

‎packages/rest/src/rest-server.ts‎

Lines changed: 2 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -7605,8 +7605,7 @@ export class RestServer {
76057605
//
76067606
// `auditCtx` is this door's one caller resolution; the org
76077607
// scope below reads the same value.
7608-
const auditCtx = await this.resolveExecCtx(environmentId, req)
7609-
.catch(rethrowAuthzStoreUnavailable);
7608+
const auditCtx = await this.resolveExecCtx(environmentId, req).catch(rethrowAuthzStoreUnavailable);
76107609
if (refuseNonAuthoringCaller(auditCtx, res, 'Reading a metadata item\'s audit trail')) return;
76117610
const p = await this.resolveProtocol(environmentId, req);
76127611
if (typeof p.auditMetaItem !== 'function') {
@@ -7719,8 +7718,7 @@ export class RestServer {
77197718
// read on the two lines that need it.
77207719
//
77217720
// `auditCtx` is the caller resolved at the head of this door
7722-
// (#20441), not a second resolution — `resolveExecCtx` is
7723-
// memoised per request (WeakMap keyed by `req`) anyway.
7721+
// (#20441), not a second resolution.
77247722
//
77257723
// The `(p as any)` casts this door carried came off when
77267724
// `MetadataProtocol` declared `auditMetaItem` (the #11006

0 commit comments

Comments
 (0)