Skip to content

Commit e085a8c

Browse files
test(spec): the last data/ file group's test titles state each cited decision in words instead of a tracker number (stage 19) (#21882)
Part of #20749 Clause-②: no Stage 19 of this card: the next area of class (e), the test strings shipped under `packages/spec/src`, as ruled in `5902360492` on #20513. This stage takes the last `data/` group: the name-ordered test files directly under `packages/spec/src/data/` from `query-transport.test.ts` to `validation.test.ts`, plus `data/driver/`. Those 18 files carried 82 messages and 86 tracker ids, citing 39 records. Every one of those ids now either states what its record decided, in words (form D), or is dropped where the title already says it. Text only: no assertion, identifier, test count or code comment changes. After this PR `data/` carries no tracker id in a test string. ## Census at the base (`124533b388`) Instruments: `census10.cjs` (md5 `9d08602ab972b4b8643c90d64d40fa41`), `census.cjs` (md5 `6e42a45a926d375013c32d62f16a296e`), `census-wide.cjs` (md5 `c98410a19529c439adb0afbfb00026a2`) and `dirtable.cjs` (md5 `dda605c54745b4a60cc14c9a686e4eff`). They are byte-identical to the copies stages 10 to 18 used. A literal counts as a test title when its folded message is argument 0 of a `describe` / `it` / `test` call, `.each` / `.skip` / `.only` chains included. Everything else is an "other" string. The base is `124533b388`, the claim's base and stage 18's landing. Both instruments read **942 messages / 994 ids in 208 files**, the seat's reading and stage 18's head reading. | directory | files | messages / ids | titles | other | |:--|--:|--:|--:|--:| | `ui/` | 84 | 396 / 419 | 378 / 401 | 18 / 18 | | `api/` | 40 | 189 / 201 | 181 / 193 | 8 / 8 | | `system/` | 34 | 154 / 165 | 128 / 138 | 26 / 27 | | (files directly in `src/`) | 30 | 118 / 120 | 117 / 119 | 1 / 1 | | `data/` (this PR) | 18 | 82 / 86 | 81 / 85 | 1 / 1 | | `ai/` | 1 | 2 / 2 | 0 | 2 / 2 | | `contracts/` | 1 | 1 / 1 | 0 | 1 / 1 | | **total** | **208** | **942 / 994** | **885 / 936** | **57 / 58** | The group reads **82 messages / 86 ids in 18 files**, the seat's figures, file for file: 11 files directly under `data/` (34 ids) and 7 in `data/driver/` (52 ids). | file (under `data/`) | messages / ids | titles | other | |:--|--:|--:|--:| | `driver/config-registry.test.ts` | 3 / 3 | 3 / 3 | 0 | | `driver/driver-credential-refusal.test.ts` | 27 / 30 | 27 / 30 | 0 | | `driver/driver-placeholder-refusal.test.ts` | 9 / 10 | 9 / 10 | 0 | | `driver/memory.test.ts` | 1 / 1 | 1 / 1 | 0 | | `driver/pg-url-grammar.test.ts` | 2 / 2 | 2 / 2 | 0 | | `driver/postgres.test.ts` | 3 / 3 | 3 / 3 | 0 | | `driver/turso.test.ts` | 3 / 3 | 3 / 3 | 0 | | `query-transport.test.ts` | 5 / 5 | 5 / 5 | 0 | | `query.test.ts` | 11 / 11 | 10 / 10 | 1 / 1 | | `record-surface.test.ts` | 2 / 2 | 2 / 2 | 0 | | `search-fields.test.ts` | 6 / 6 | 6 / 6 | 0 | | `secret-mask.test.ts` | 1 / 1 | 1 / 1 | 0 | | `seed.test.ts` | 1 / 1 | 1 / 1 | 0 | | `tree-reference-self-only.test.ts` | 1 / 1 | 1 / 1 | 0 | | `unique-scope-message.test.ts` | 1 / 1 | 1 / 1 | 0 | | `unique-scope.test.ts` | 1 / 1 | 1 / 1 | 0 | | `validation-boundary-description.test.ts` | 4 / 4 | 4 / 4 | 0 | | `validation.test.ts` | 1 / 1 | 1 / 1 | 0 | | **18 files** | **82 / 86** | **81 / 85** | **1 / 1** | The one "other" string is the `expect` message at `query.test.ts:202`, declared to the text-only tool. Three more test files sit in the same name range and carry no id: `seed-loader`, `type-compat` and `driver/mongo`. They are not touched. - **Controls.** Lit: `ui/dashboard.test.ts`, outside the group, reads 21 ids at the head as at the base. Dark: `search-fields.test.ts` and `driver/driver-credential-refusal.test.ts` read 0 at the head while 16 and 29 of their comment lines still carry a number. Planted in scratch copies of head files: an id put into a `seed.test.ts` title reads 1 / 1, and an id put into a `secret-mask.test.ts` comment reads 0. - **A wider pattern** (any `#` plus digits) reads the same totals as the gate pattern in all 18 files at the base, and 0 in all 18 at the head. - **At the head:** 860 messages / 908 ids in 190 files. The 18 files read 0 / 0, `data/` reads 0 / 0, and no other file moved. ## How the area was chosen `data/` has been taken in name-ordered file groups near the ~100-id bound. Stage 18's re-cut named this group at 86 ids, the whole remainder of `data/`, and this census reads 86, so the rule needed no re-cut. **Named for the next stages** (re-cut from the head census, 860 / 908): - `ui/` 419 ids in 84 files, about four stages. It has no subdirectory, so the same name-ordered rule applies. The first group near 100 runs from `action-confirm-params-guard.test.ts` to `component-record-block-field-security.test.ts`: 32 files, 97 messages / 102 ids. It holds three "other" strings: two `expect` messages in `action-requires-confirmation-docblock.pin.test.ts` (`:168`, `:175`) and one in `component-props-unknown-members.pin.test.ts` (`:322`). That stage should check whether any of them is a needle. - `api/` 201, two stages. `system/` 165, two. The files directly in `src/`, 120, one. - The three docblock needles (`ai/build-progress.test.ts:236`, `:237`, `contracts/approval-service.test.ts:274`), one stage with their docblocks. ## What each id became - **16 literals (17 ids)** now state a decision in words. - **12 literals (15 ids)** get their subject back in words, where the number stood for a thing, such as "the #9041 arm". - **54 literals (54 ids)** drop a number the title already explains. Every cited record was read with its comments through REST. 33 answer 200. Six answer 404, and each decision was read from what landed, the landing commit and its CHANGELOG entry: - #6345 (`e2798fab76`, one driver vocabulary: `mongo` → `mongodb`, turso gets a config contract); - #8495 (`4bfe1a539d`, `${…}` refused in memory `persistence.path` / `persistence.key` at publish); - #8696 (`90a12fb18d`, a bound secret injected on the mongodb DSN branch); - #8876 (`d634e665b0`, `urlUserinfoUsername`, the username half of the userinfo grammar); - #9040 (`24206416a7`, a credential in the mongo `options` passthrough refused at publish); - #9041 (`d491625c17`, bound `credentialsRef` with a user-less mongo `config.url` refused at publish). **Stated in words:** | record(s) | literal (under `data/`) | now reads | |:--|:--|:--| | #4410 | `driver/config-registry.test.ts:71` | "DatasourceSchema × driver config — parsed against the contract its driver ships". Ruled enforce: `data/driver/` became the one contract, and `DatasourceSchema` parses `config` against it. | | #6969 | `driver/config-registry.test.ts:178` | "… — what a boot flag may offer, derived from the one driver table". The CLI's hand-written `--database-driver` lists were replaced by a set derived from the shared table. | | #8155 | `driver/driver-credential-refusal.test.ts:851` | "accepts the blessed shape byte-identically: bare-username URL + bound secret, what the stored-credential remedy prescribes". Ruled shape (b): the operator moves the credential to the secret store; a URL-embedded one is told to keep a bare `user@host` and bind the secret. | | #8336, #8495 | `driver/driver-placeholder-refusal.test.ts:234` | "memory `initialData` stays UNJUDGED — the deliberate seed-data exclusion holds". The placeholder refusal excluded seed data; #8495 extended it to `persistence.path` / `persistence.key` only. | | #9091 | `driver/pg-url-grammar.test.ts:39` | "pg-url-grammar server twin — still asks the parser `pg` itself runs". A postgres `config.url` that `pg` cannot open is refused at publish. | | #11072 | `driver/pg-url-grammar.test.ts:55` | "pg-url-grammar browser twin — degrades to the shape-only checks, with no `pg` parse". Ruled option A: a `browser` export condition whose bundle drops the `pg` parse. | | #16066 | `query-transport.test.ts:38` | "§1 what the transport declares — a flattened spelling of the AST, never a second semantics". Ruled: the wire dialect is declared in spec as a 1:1 alias table; `QuerySchema` itself does not grow. | | #4721 | `query.test.ts:202` (`expect` message) | "this parsed to `order: asc` before the sort node was closed". Ruled (a)+(b): `SortNodeSchema` strict, with `direction` → `order` as a prescription. | | #2604 | `record-surface.test.ts:59` | "deriveRecordFlowSurface — viewing a record may route, a create or edit task is always an overlay". Decision D1: view is a state and may route; create and edit are tasks and never route. | | #2578 | `record-surface.test.ts:64` | "view keeps the field-count detail surface verbatim: …". The detail surface is derived from the field count: heavy → page, light → drawer. | | #4254 | `search-fields.test.ts:120` | "the ingress gate that refuses an unsearchable `$searchFields` entry no longer admits `$searchFields=id`". Ruled: an unknown or unsearchable `searchFields` entry answers 400, never a wider scan. | | #6674 | `search-fields.test.ts:257` | "a virtual field declared in searchableFields — not admitted, since no driver stores it". Promoted on the #4254 precedent: a declared entry that can never match is not admitted. | | #7572 | `secret-mask.test.ts:40` | "SECRET_MASK — the credential read mask (ADR-0100), declared once for every masked read". Option A: one declaration in spec, re-exported by objectql and aliased by service-settings. | | #8323 | `unique-scope-message.test.ts:137` | "… the accept/reject line does not move, and bare `true` keeps its meaning". Ruled: no unannounced reinterpretation of bare `unique: true`. | | #3696 | `unique-scope.test.ts:19` | "UniqueScope (ADR-0120) — bare `true` on a field is unique per organization; global uniqueness must be said". Field-level `true` became a composite per-organization index, and `'global'` the explicit opt-in. | | #3184 | `validation.test.ts:1120` | "ValidationRule - events property — insert and update only; a delete guard is a beforeDelete hook". Decision: trim `delete` from the enum, not enforce it. | **Subject back in words** (12 literals, 15 ids). In `driver/driver-credential-refusal.test.ts` and `driver/driver-placeholder-refusal.test.ts`, numbers that named a sibling refusal now name it: "#9041" becomes "the user-less URL arm" or "the user-less URL refusal", "#9147's arm" becomes "the no-username arm", "#9040" becomes "the options-passthrough credential refusal" or "the passthrough read path", "#8082" becomes "the URL userinfo refusal" or "check", "the inverted #8078 pin" becomes "the pin that once recorded them as accepted, inverted", "#8336" in "the deep judgement" becomes "the deep placeholder judgement", and "the honest #4410 boundary" becomes "the honest boundary of config validation". **Dropped where already stated** (54 literals, 54 ids). A number goes only where the title already says its decision. Examples: "QueryAST.joins — REMOVED (#4286)" and its three siblings; "FieldNode — the nested-select object form is REMOVED (#4196)"; "AggregationNode.distinct — REMOVED (#6815, ADR-0049)", which keeps `(ADR-0049)`; the four `#13879 —` describe prefixes, each of which states its semantics; "`$driver` — inline credential refusal (#7990)" and the other refusal-family describes; "TursoConfigSchema refuses what the turso driver refuses (#19977)". `(ADR-0049)`, `(ADR-0100)` and `(ADR-0120)` stay: they cite decision records by number, not tracker ids. ## Readers - **Test-name filters:** none. No tracked script, workflow or config passes `-t` / `--testNamePattern`. - **Snapshots:** none. No `__snapshots__` directory is tracked under `packages/spec`, and none of the 18 files calls a snapshot matcher. - **Projects:** none of the 18 files is listed in `packages/spec/vitest.repo-tests.json`; all 18 run in the `local` project. - **By substring:** every old literal, plus a window around each id (245 needles), was searched across the tracked tree outside its own file. No gate, doc, filter, snapshot or `scripts/check-*.mjs` self-test reads one. The 11 hits are: - 7 code comments citing "the #4254 ingress gate" (`lint` `validate-searchable-fields.ts` / `.test.ts`, `validate-react-page-props.test.ts`, `metadata-protocol` `protocol.search-title-namefield.test.ts`, `spec` `data/search-fields.ts:198`); - two release-owned CHANGELOG lines; - a sibling title in this card's `ui/` stage (`ui/dashboard.test.ts:717`); - a sibling title in `metadata-protocol` (`protocol.query-transport-dialect.test.ts:176`). None reads a spec test title. - **The files by name:** outside CHANGELOGs, `data/query.test.ts` is named by `test-typecheck-debt.json`, which keys on the file and on error signatures, not on a title, and by two code comments; `data/secret-mask.test.ts` by one code comment. ## Text-only proof Stage 10's scratch tool (`textonly10.cjs`, md5 `d5e4801dbb4329ab1984da91e92fc47c`) compares base and head file by file on three legs: 1. **Skeleton:** the full AST, with string pieces masked. It must be identical. 2. **Comments:** every comment, byte-equal. 3. **Strings:** each changed string leaf must sit in a test-call title position or on a declared line, must carry a tracker id before, and must carry no `#` plus digits after. This stage declares one line, `query.test.ts:202`. - **Result:** 18 of 18 files SAME on all three legs, with the per-file counts predicted in writing before the run. - **Totals:** 82 changed string leaves in 82 literals: 81 titles and 1 declared. The diff's `+` and `-` lines are exactly the 82 planned lines, and every file keeps its line count. - **Controls (10 of 10 as predicted, on scratch copies, each anchor hit once):** identifier rename DIFF; numeric literal DIFF; comment edit COMMENT DIFF; a non-title string given an id VIOLATION; a rewritten title given a new id VIOLATION; a title that was id-free at base edited VIOLATION; one title reverted to base SAME; an `it.each` row given an id VIOLATION; an undeclared `expect` message changed VIOLATION; a title re-split into a `+` chain DIFF. - **`.each` titles:** five `describe.each` titles lose only their trailing id. No `$driver` / `$name` placeholder, row or table value changes. **Test counts:** the 18 files were run at the base, in a separate base worktree, and at the head, with `--project local --project repo`. Both sides read 737 tests, all passed, with the same count and status sequence per file in 18 of 18. 476 full test names change, and each equals the base name with the planned replacements applied (0 mismatches). No full name repeats on either side. ## Changeset: `skip-changeset` Measured, not assumed: - `npm pack --dry-run` of `@objectstack/spec` lists 2068 files. 0 of the 18 touched files are in it, and no `*.test.ts` at all. The controls `src/data/query.zod.ts` and `dist/index.mjs` are in it. - In the built `dist/`, a new phrase and an old literal each read in 0 files. The control `Unrecognized key` reads in 42. So this PR publishes nothing, and no changeset is added. ## Verification (at `8788de7a4a`) - `pnpm turbo run build` over all packages: 71 / 71. - `@objectstack/spec`: - `vitest run --project local`: 616 files, 18426 passed, 1 todo. - `typecheck`: exit 0, including `check:test-typecheck` (52 files / 246 errors / 135 pinned signatures held). Its program holds all 18 touched files, counted with `tsc --listFilesOnly -p tsconfig.test.json`. - `check:generated`: all 15 generated artifacts up to date. - **Gates:** `dispatch-gates --commands` derived 79 families, the same set as stages 13 to 18, and all 79 exit 0. `--ran` reconciles: 79 derived, 79 run, 0 NOT-MEASURED, 0 UNRUN, every family with its exit code recorded. - The five roster families whose rosters sit under a touched directory were also run, and each exits 0: `check:meta-url-spelling`, `check:spec-changes`, `check:authz-resolver`, `check:error-code-casing` and `check:filter-alias-parity`. - The reconciliation printed `STALE TREE`: `scripts/engine-double-contract.pinned.json` moved on `main` after the base. This diff adds and changes no engine double, `check:engine-double-contract` exits 0 on this tree, and the queue re-runs it on the merged generation. - **ESLint, a proven narrowing:** `--no-inline-config` over the 18 files reads 0 errors and 0 warnings. The population comes from ESLint's own config: 18 configured, 0 ignored. No file sets `parserOptions.project` or `projectService`, so no untouched file's verdict can move. - `check-governed-merges --test`: NOT governed, 164 changed lines. ## `main` since the base Re-fetched just before this PR opened, `origin/main` was two commits past the base (`5e0b489bca`: #21871, #21873). Neither touches any of the 18 files, and neither touches `packages/spec`. So `main` was not merged. `git merge-tree` onto `5e0b489bca` is clean. No open PR touches the 18 files. ## Acceptance notes - **No needle in this group.** The one "other" string is an `expect` message, not the expected value of an assertion over a source docblock. The three known needles are untouched. - **Same-id test titles in this card's later stages** go with those stages: `api/protocol.test.ts:677` (#4286), `ui/dashboard.test.ts:717` (#15680) and `ui/view-authoring-wire-split.test.ts:192` (#4721). - **Same-id test titles in other packages** are their lanes' test-string shares. A search of `describe` / `it` / `test` lines outside `packages/spec/src` finds 49 lines citing ids this PR handled, in 12 packages: `service-datasource` 18 (8 files), `metadata-protocol` 7 (4), `objectql` 6 (4), `cli` 5 (3), `lint` 4 (3), `driver-sql` 3 (3), and one each in `client`, `driver-turso`, `platform-objects`, `plugin-security`, `rest` and `service-settings`. Examples: `cli/src/commands/database-driver-flag-derivation.test.ts:63` ("#6969 — …"), `driver-sql/src/sql-driver-unique-tenancy.test.ts:48` ("(#3696)"), `lint/src/validate-searchable-fields.test.ts:809` ("[#6674] …"). - **Code comments still carry ids** in these files and their sources, for example the `[#6674]` and `[#4483]` blocks in `search-fields.test.ts`, the `[#16066]` header of `query-transport.test.ts` and `data/search-fields.ts:198`. Comments are not this card's share, and none is touched here. --- _Generated by [Claude Code](https://claude.ai/code/session_01T9u38rswFp5Rw8DswRUReJ)_ Co-authored-by: Claude <noreply@anthropic.com>
1 parent 07c842d commit e085a8c

18 files changed

Lines changed: 82 additions & 82 deletions

‎packages/spec/src/data/driver/config-registry.test.ts‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -68,7 +68,7 @@ describe('driver config registry', () => {
6868
});
6969
});
7070

71-
describe('DatasourceSchema × driver config (#4410)', () => {
71+
describe('DatasourceSchema × driver config — parsed against the contract its driver ships', () => {
7272
const base = { name: 'warehouse', driver: 'postgres' };
7373

7474
/**
@@ -175,7 +175,7 @@ describe('DatasourceSchema × driver config (#4410)', () => {
175175
* the first one is the way that actually matters — reading the CONFIG-CONTRACT
176176
* column instead of the SELECTION column silently widens every boot host's flag.
177177
*/
178-
describe('DATABASE_DRIVER_SELECTION_IDS — what a boot flag may offer (#6969)', () => {
178+
describe('DATABASE_DRIVER_SELECTION_IDS — what a boot flag may offer, derived from the one driver table', () => {
179179
it('offers no contract-only spelling, whatever the derivation is rewritten to read', () => {
180180
// The wrong-column guard. `sqlite3` / `better-sqlite3` / `mariadb` /
181181
// `inmemory` resolve a config CONTRACT and are refused as a SELECTION, so a
@@ -285,7 +285,7 @@ describe('the `memory` row: contract face kept, selection face withdrawn', () =>
285285
* alone would be green before and after the guard and would prove nothing, so
286286
* the population is the point of this describe.
287287
*/
288-
describe('driver lookups — an OFF-vocabulary id is refused, never answered with a non-schema (#16903)', () => {
288+
describe('driver lookups — an OFF-vocabulary id is refused, never answered with a non-schema', () => {
289289
/**
290290
* The consumer that actually reaches these, spelled as the cast it is.
291291
* `getDriverConfigJsonSchemaById` and both resolvers are published

‎packages/spec/src/data/driver/driver-credential-refusal.test.ts‎

Lines changed: 27 additions & 27 deletions
Original file line numberDiff line numberDiff line change
@@ -77,7 +77,7 @@ const FAMILY = [
7777
},
7878
] as const;
7979

80-
describe.each(FAMILY)('$driver — inline credential refusal (#7990)', (f) => {
80+
describe.each(FAMILY)('$driver — inline credential refusal', (f) => {
8181
it(`refuses an inline \`${f.key}\`, naming the key's replacement mechanisms`, () => {
8282
const result = f.schema.safeParse({ ...f.valid, [f.key]: 'hunter2' });
8383
expect(result.success).toBe(false);
@@ -136,7 +136,7 @@ describe.each(FAMILY)('$driver — inline credential refusal (#7990)', (f) => {
136136
});
137137
});
138138

139-
describe('DatasourceSchema — the refusal reaches the authored artefact (#7990)', () => {
139+
describe('DatasourceSchema — the refusal reaches the authored artefact', () => {
140140
it('re-paths the refusal under `config.<key>` for the author', () => {
141141
const result = DatasourceSchema.safeParse({
142142
name: 'prod',
@@ -170,7 +170,7 @@ describe('DatasourceSchema — the refusal reaches the authored artefact (#7990)
170170
expect(DatasourceSchema.parse(refBased)).toEqual(result.data);
171171
});
172172

173-
it('query-parameter credentials are REFUSED at `config.url` too (#8337 — the authored artefact door)', () => {
173+
it('query-parameter credentials are REFUSED at `config.url` too — at the authored artefact door', () => {
174174
// Same envelope note as the #8082 pin below: the zod issue's `code` and
175175
// re-pathed location are the whole envelope at this layer; the publish
176176
// door wraps every schema refusal uniformly (`422 INVALID_METADATA`).
@@ -187,7 +187,7 @@ describe('DatasourceSchema — the refusal reaches the authored artefact (#7990)
187187
expect(issue!.message).toContain('external.credentialsRef');
188188
});
189189

190-
it('embedded-in-URL credentials are REFUSED at `config.url` (#8082 — the inverted #8078 pin)', () => {
190+
it('embedded-in-URL credentials are REFUSED at `config.url` — the pin that once recorded them as accepted, inverted', () => {
191191
// This test used to pin the ACCEPTANCE of exactly this input as a measured
192192
// fact (#7990 open question). The 2026-08-12 #8082 ruling (Option A)
193193
// closed the door, so the pin inverts rather than disappears: same input,
@@ -258,7 +258,7 @@ const URL_FAMILY = [
258258
},
259259
] as const;
260260

261-
describe.each(URL_FAMILY)('$name — URL-embedded credential refusal (#8082)', (f) => {
261+
describe.each(URL_FAMILY)('$name — URL-embedded credential refusal', (f) => {
262262
const refusalAt = (config: Record<string, unknown>) => {
263263
const result = f.schema.safeParse(config);
264264
if (result.success) return undefined;
@@ -299,7 +299,7 @@ describe.each(URL_FAMILY)('$name — URL-embedded credential refusal (#8082)', (
299299
expect(refusalAt(f.make(`${scheme}://[2001:db8::1]:6543/prod`))).toBeUndefined();
300300
});
301301

302-
it('accepts a bare username (`user@host`) — `username` is a writable key, only the secret is refused (#7990 posture)', () => {
302+
it('accepts a bare username (`user@host`) — `username` is a writable key, only the secret is refused', () => {
303303
const config = f.make(f.sample('svc@'));
304304
expect(refusalAt(config)).toBeUndefined();
305305
const parsed = f.schema.safeParse(config);
@@ -356,7 +356,7 @@ const QUERY_FAMILY = [
356356
},
357357
] as const;
358358

359-
describe.each(QUERY_FAMILY)('$name — URL query-parameter credential refusal (#8337)', (f) => {
359+
describe.each(QUERY_FAMILY)('$name — URL query-parameter credential refusal', (f) => {
360360
const refusalAt = (config: Record<string, unknown>) => {
361361
const result = f.schema.safeParse(config);
362362
if (result.success) return undefined;
@@ -428,7 +428,7 @@ describe.each(QUERY_FAMILY)('$name — URL query-parameter credential refusal (#
428428
});
429429
});
430430

431-
describe('the deliberately-absent entries (#8337) — measured as NOT read, so not refused', () => {
431+
describe('the deliberately-absent entries — measured as NOT read, so not refused', () => {
432432
it('mysql `?password=` stays accepted: mysql2 seeds `password` from userinfo and skips the query key', () => {
433433
// `mysql2`'s `parseUrl` runs `if (key in options) continue;` over the
434434
// query, and `password` is always pre-set from userinfo — the parameter
@@ -445,7 +445,7 @@ describe('the deliberately-absent entries (#8337) — measured as NOT read, so n
445445
});
446446
});
447447

448-
describe('urlCredentialQueryParams — the shared value-level parse (#8337)', () => {
448+
describe('urlCredentialQueryParams — the shared value-level parse', () => {
449449
const TURSO = CREDENTIAL_URL_QUERY_PARAMS.turso;
450450

451451
it('finds the declared parameter with a non-empty value, at any position, once', () => {
@@ -495,7 +495,7 @@ describe('urlCredentialQueryParams — the shared value-level parse (#8337)', ()
495495
});
496496
});
497497

498-
describe('urlUserinfoPassword — the shared value-level parse (#8082)', () => {
498+
describe('urlUserinfoPassword — the shared value-level parse', () => {
499499
it('judges the DSN forms real drivers take, which `new URL()` rejects or mangles', () => {
500500
// postgres/mongo multi-host DSNs are not WHATWG URLs; the detector must
501501
// judge them rather than fail open on a parse error.
@@ -536,8 +536,8 @@ describe('urlUserinfoPassword — the shared value-level parse (#8082)', () => {
536536
});
537537
});
538538

539-
describe('urlUserinfoUsername — the username half of the same grammar (#8876)', () => {
540-
it('judges the multi-host DSN forms `new URL()` rejects — the reason this helper exists (#8696)', () => {
539+
describe('urlUserinfoUsername — the username half of the same grammar', () => {
540+
it('judges the multi-host DSN forms `new URL()` rejects — the reason this helper exists', () => {
541541
// `new URL('mongodb://app@h1:27017,h2:27017/app')` throws ERR_INVALID_URL
542542
// (measured in the filing); the accessor must judge it, not fail open.
543543
expect(urlUserinfoUsername('mongodb://app@h1:27017,h2:27017/app')).toBe('app');
@@ -609,7 +609,7 @@ describe('urlUserinfoUsername — the username half of the same grammar (#8876)'
609609
* is wrapped uniformly by the publish door (metadata-protocol's
610610
* `422 INVALID_METADATA`, whose `issues[]` carry these codes verbatim).
611611
*/
612-
describe('mongo options passthrough — credential refusal (#9040)', () => {
612+
describe('mongo options passthrough — credential refusal', () => {
613613
const VALID = { database: 'events', host: 'mongo.internal', username: 'svc' } as const;
614614
const refusalAt = (options: Record<string, unknown>) => {
615615
const result = MongoConfigSchema.safeParse({ ...VALID, options });
@@ -666,7 +666,7 @@ describe('mongo options passthrough — credential refusal (#9040)', () => {
666666
expect(issue!.message).toContain('external.credentialsRef');
667667
});
668668

669-
it('`auth.username` alone is NOT credential material (#8876 asymmetry) — stays accepted', () => {
669+
it('`auth.username` alone is NOT credential material — stays accepted', () => {
670670
// The schema's question is "is a secret being persisted?", and a username
671671
// is not one. (The client separately refuses a username-only `auth` block
672672
// at construction — `credentials must be an object with 'username' and
@@ -675,7 +675,7 @@ describe('mongo options passthrough — credential refusal (#9040)', () => {
675675
expect(refusalAt({ auth: { username: 'app' } })).toBeUndefined();
676676
});
677677

678-
it('an EMPTY `auth.password` carries no secret — the passthrough twin of `user:@host` (#8082)', () => {
678+
it('an EMPTY `auth.password` carries no secret — the passthrough twin of `user:@host`', () => {
679679
expect(refusalAt({ auth: { username: 'app', password: '' } })).toBeUndefined();
680680
});
681681

@@ -799,7 +799,7 @@ describe('mongo options passthrough — nested credential-SPELLED keys refused a
799799
* refusal is wrapped uniformly by the publish door (metadata-protocol's
800800
* `422 INVALID_METADATA`, whose `issues[]` carry these codes verbatim).
801801
*/
802-
describe('datasource — bound credentialsRef + user-less mongo url refused (#9041)', () => {
802+
describe('datasource — bound credentialsRef + user-less mongo url refused', () => {
803803
const BOUND = { credentialsRef: 'sys_secret:01J9ZK4T2N' } as const;
804804
const parse = (ds: Record<string, unknown>) => DatasourceSchema.safeParse(ds);
805805
const refusalOf = (ds: Record<string, unknown>) => {
@@ -828,7 +828,7 @@ describe('datasource — bound credentialsRef + user-less mongo url refused (#90
828828
expect(issue!.message).toContain('silent no-op');
829829
});
830830

831-
it('judges a legacy `driver: mongo` row identically (alias-resolved, like the #9040 read path)', () => {
831+
it('judges a legacy `driver: mongo` row identically (alias-resolved, like the passthrough read-path redaction)', () => {
832832
const issue = refusalOf({
833833
name: 'events',
834834
driver: 'mongo',
@@ -848,7 +848,7 @@ describe('datasource — bound credentialsRef + user-less mongo url refused (#90
848848
expect(issue).toBeDefined();
849849
});
850850

851-
it('accepts the blessed shape byte-identically: bare-username URL + bound secret (#8155)', () => {
851+
it('accepts the blessed shape byte-identically: bare-username URL + bound secret, what the stored-credential remedy prescribes', () => {
852852
const ds = {
853853
name: 'events',
854854
driver: 'mongodb',
@@ -892,7 +892,7 @@ describe('datasource — bound credentialsRef + user-less mongo url refused (#90
892892
}
893893
});
894894

895-
it('the COMPOSED branch is #9147\'s arm, never this one — a composed config reports neither #9041 nor a `config.url` path', () => {
895+
it('the COMPOSED branch belongs to the no-username arm, never this one — a composed config reports neither the user-less URL refusal nor a `config.url` path', () => {
896896
// With no `url` the discrete `username` is live and the factory
897897
// interpolates the bound secret into the URI it composes (the branch
898898
// beside commit 90a12fb18's DSN one), so a composed config that NAMES a
@@ -955,7 +955,7 @@ describe('datasource — bound credentialsRef + user-less mongo url refused (#90
955955
expect(result.error!.issues.some((i) => i.message.includes("the URL's own userinfo"))).toBe(false);
956956
});
957957

958-
it('composes with the #9040 passthrough refusal — one artefact, both findings, own paths', () => {
958+
it('composes with the options-passthrough credential refusal — one artefact, both findings, own paths', () => {
959959
// The PM-mechanism composition pin: the datasource-level commit d491625c1 refinement
960960
// and the config-level commit 24206416a `credentialFreeMongoOptions` judge the same
961961
// artefact independently — an input violating both reports both.
@@ -992,7 +992,7 @@ describe('datasource — bound credentialsRef + user-less mongo url refused (#90
992992
expect(result.success, JSON.stringify(result.error?.issues)).toBe(true);
993993
});
994994

995-
it('composes with the #8082 userinfo refusal the other way: a password-bearing URL has a USER', () => {
995+
it('composes with the URL userinfo refusal the other way: a password-bearing URL has a USER', () => {
996996
// `user:password@host` violates #8082, but its userinfo NAMES a user — so
997997
// this refusal correctly stays out and the author gets exactly the #8082
998998
// prescription (bind the secret), not a contradictory second message.
@@ -1030,7 +1030,7 @@ describe('datasource — bound credentialsRef + user-less mongo url refused (#90
10301030
* schema refusal is wrapped uniformly by the publish door (metadata-protocol's
10311031
* `422 INVALID_METADATA`, whose `issues[]` carry these codes verbatim).
10321032
*/
1033-
describe('datasource — bound credentialsRef + composed mongo config naming no username refused (#9147)', () => {
1033+
describe('datasource — bound credentialsRef + composed mongo config naming no username refused', () => {
10341034
const BOUND = { credentialsRef: 'sys_secret:01J9ZK4T2N' } as const;
10351035
/** The composed branch's minimum viable target — no `url`, so the URI is built. */
10361036
const COMPOSED = { database: 'events', host: 'mongo.internal' } as const;
@@ -1067,7 +1067,7 @@ describe('datasource — bound credentialsRef + composed mongo config naming no
10671067
expect(issue!.message).not.toContain('add the username to the URL');
10681068
});
10691069

1070-
it('judges a legacy `driver: mongo` row identically (alias-resolved, like #9041 and the #9040 read path)', () => {
1070+
it('judges a legacy `driver: mongo` row identically (alias-resolved, like the user-less URL arm and the passthrough read path)', () => {
10711071
expect(refusalOf({
10721072
name: 'events',
10731073
driver: 'mongo',
@@ -1092,7 +1092,7 @@ describe('datasource — bound credentialsRef + composed mongo config naming no
10921092
})).toBeDefined();
10931093
});
10941094

1095-
it('an empty `config.url` routes HERE, not to #9041 — the arms split on the factory\'s own branch test', () => {
1095+
it('an empty `config.url` routes HERE, not to the user-less URL arm — the arms split on the factory\'s own branch test', () => {
10961096
const result = parse({
10971097
name: 'events',
10981098
driver: 'mongodb',
@@ -1119,7 +1119,7 @@ describe('datasource — bound credentialsRef + composed mongo config naming no
11191119
expect(DatasourceSchema.parse(ds)).toEqual(result.data);
11201120
});
11211121

1122-
it('near-miss ① `url` present naming NO user — exactly ONE refusal fires, and it is #9041\'s', () => {
1122+
it('near-miss ① `url` present naming NO user — exactly ONE refusal fires, and it is the user-less URL arm\'s', () => {
11231123
// The arms partition the input: the author must never receive two messages
11241124
// prescribing different fixes for one datasource.
11251125
const result = parse({
@@ -1133,7 +1133,7 @@ describe('datasource — bound credentialsRef + composed mongo config naming no
11331133
expect(result.error!.issues.some((i) => i.message.includes("add `username` to `config`"))).toBe(false);
11341134
});
11351135

1136-
it('near-miss ② a discrete `username` present — the branch where the bound secret is LIVE (#8696)', () => {
1136+
it('near-miss ② a discrete `username` present — the branch where the bound secret is LIVE', () => {
11371137
const ds = {
11381138
name: 'events',
11391139
driver: 'mongodb',
@@ -1192,7 +1192,7 @@ describe('datasource — bound credentialsRef + composed mongo config naming no
11921192
expect(result.error!.issues.some((i) => i.message.includes("add `username` to `config`"))).toBe(false);
11931193
});
11941194

1195-
it('composes with the #9040 passthrough refusal — one artefact, both findings, own paths', () => {
1195+
it('composes with the options-passthrough credential refusal — one artefact, both findings, own paths', () => {
11961196
const result = parse({
11971197
name: 'events',
11981198
driver: 'mongodb',

0 commit comments

Comments
 (0)