@@ -77,7 +77,7 @@ const FAMILY = [
7777 } ,
7878] as const ;
7979
80- describe . each ( FAMILY ) ( '$driver — inline credential refusal (#7990) ' , ( f ) => {
80+ describe . each ( FAMILY ) ( '$driver — inline credential refusal' , ( f ) => {
8181 it ( `refuses an inline \`${ f . key } \`, naming the key's replacement mechanisms` , ( ) => {
8282 const result = f . schema . safeParse ( { ...f . valid , [ f . key ] : 'hunter2' } ) ;
8383 expect ( result . success ) . toBe ( false ) ;
@@ -136,7 +136,7 @@ describe.each(FAMILY)('$driver — inline credential refusal (#7990)', (f) => {
136136 } ) ;
137137} ) ;
138138
139- describe ( 'DatasourceSchema — the refusal reaches the authored artefact (#7990) ' , ( ) => {
139+ describe ( 'DatasourceSchema — the refusal reaches the authored artefact' , ( ) => {
140140 it ( 're-paths the refusal under `config.<key>` for the author' , ( ) => {
141141 const result = DatasourceSchema . safeParse ( {
142142 name : 'prod' ,
@@ -170,7 +170,7 @@ describe('DatasourceSchema — the refusal reaches the authored artefact (#7990)
170170 expect ( DatasourceSchema . parse ( refBased ) ) . toEqual ( result . data ) ;
171171 } ) ;
172172
173- it ( 'query-parameter credentials are REFUSED at `config.url` too (#8337 — the authored artefact door) ' , ( ) => {
173+ it ( 'query-parameter credentials are REFUSED at `config.url` too — at the authored artefact door' , ( ) => {
174174 // Same envelope note as the #8082 pin below: the zod issue's `code` and
175175 // re-pathed location are the whole envelope at this layer; the publish
176176 // door wraps every schema refusal uniformly (`422 INVALID_METADATA`).
@@ -187,7 +187,7 @@ describe('DatasourceSchema — the refusal reaches the authored artefact (#7990)
187187 expect ( issue ! . message ) . toContain ( 'external.credentialsRef' ) ;
188188 } ) ;
189189
190- it ( 'embedded-in-URL credentials are REFUSED at `config.url` (#8082 — the inverted #8078 pin) ' , ( ) => {
190+ it ( 'embedded-in-URL credentials are REFUSED at `config.url` — the pin that once recorded them as accepted, inverted ' , ( ) => {
191191 // This test used to pin the ACCEPTANCE of exactly this input as a measured
192192 // fact (#7990 open question). The 2026-08-12 #8082 ruling (Option A)
193193 // closed the door, so the pin inverts rather than disappears: same input,
@@ -258,7 +258,7 @@ const URL_FAMILY = [
258258 } ,
259259] as const ;
260260
261- describe . each ( URL_FAMILY ) ( '$name — URL-embedded credential refusal (#8082) ' , ( f ) => {
261+ describe . each ( URL_FAMILY ) ( '$name — URL-embedded credential refusal' , ( f ) => {
262262 const refusalAt = ( config : Record < string , unknown > ) => {
263263 const result = f . schema . safeParse ( config ) ;
264264 if ( result . success ) return undefined ;
@@ -299,7 +299,7 @@ describe.each(URL_FAMILY)('$name — URL-embedded credential refusal (#8082)', (
299299 expect ( refusalAt ( f . make ( `${ scheme } ://[2001:db8::1]:6543/prod` ) ) ) . toBeUndefined ( ) ;
300300 } ) ;
301301
302- it ( 'accepts a bare username (`user@host`) — `username` is a writable key, only the secret is refused (#7990 posture) ' , ( ) => {
302+ it ( 'accepts a bare username (`user@host`) — `username` is a writable key, only the secret is refused' , ( ) => {
303303 const config = f . make ( f . sample ( 'svc@' ) ) ;
304304 expect ( refusalAt ( config ) ) . toBeUndefined ( ) ;
305305 const parsed = f . schema . safeParse ( config ) ;
@@ -356,7 +356,7 @@ const QUERY_FAMILY = [
356356 } ,
357357] as const ;
358358
359- describe . each ( QUERY_FAMILY ) ( '$name — URL query-parameter credential refusal (#8337) ' , ( f ) => {
359+ describe . each ( QUERY_FAMILY ) ( '$name — URL query-parameter credential refusal' , ( f ) => {
360360 const refusalAt = ( config : Record < string , unknown > ) => {
361361 const result = f . schema . safeParse ( config ) ;
362362 if ( result . success ) return undefined ;
@@ -428,7 +428,7 @@ describe.each(QUERY_FAMILY)('$name — URL query-parameter credential refusal (#
428428 } ) ;
429429} ) ;
430430
431- describe ( 'the deliberately-absent entries (#8337) — measured as NOT read, so not refused' , ( ) => {
431+ describe ( 'the deliberately-absent entries — measured as NOT read, so not refused' , ( ) => {
432432 it ( 'mysql `?password=` stays accepted: mysql2 seeds `password` from userinfo and skips the query key' , ( ) => {
433433 // `mysql2`'s `parseUrl` runs `if (key in options) continue;` over the
434434 // query, and `password` is always pre-set from userinfo — the parameter
@@ -445,7 +445,7 @@ describe('the deliberately-absent entries (#8337) — measured as NOT read, so n
445445 } ) ;
446446} ) ;
447447
448- describe ( 'urlCredentialQueryParams — the shared value-level parse (#8337) ' , ( ) => {
448+ describe ( 'urlCredentialQueryParams — the shared value-level parse' , ( ) => {
449449 const TURSO = CREDENTIAL_URL_QUERY_PARAMS . turso ;
450450
451451 it ( 'finds the declared parameter with a non-empty value, at any position, once' , ( ) => {
@@ -495,7 +495,7 @@ describe('urlCredentialQueryParams — the shared value-level parse (#8337)', ()
495495 } ) ;
496496} ) ;
497497
498- describe ( 'urlUserinfoPassword — the shared value-level parse (#8082) ' , ( ) => {
498+ describe ( 'urlUserinfoPassword — the shared value-level parse' , ( ) => {
499499 it ( 'judges the DSN forms real drivers take, which `new URL()` rejects or mangles' , ( ) => {
500500 // postgres/mongo multi-host DSNs are not WHATWG URLs; the detector must
501501 // judge them rather than fail open on a parse error.
@@ -536,8 +536,8 @@ describe('urlUserinfoPassword — the shared value-level parse (#8082)', () => {
536536 } ) ;
537537} ) ;
538538
539- describe ( 'urlUserinfoUsername — the username half of the same grammar (#8876) ' , ( ) => {
540- it ( 'judges the multi-host DSN forms `new URL()` rejects — the reason this helper exists (#8696) ' , ( ) => {
539+ describe ( 'urlUserinfoUsername — the username half of the same grammar' , ( ) => {
540+ it ( 'judges the multi-host DSN forms `new URL()` rejects — the reason this helper exists' , ( ) => {
541541 // `new URL('mongodb://app@h1:27017,h2:27017/app')` throws ERR_INVALID_URL
542542 // (measured in the filing); the accessor must judge it, not fail open.
543543 expect ( urlUserinfoUsername ( 'mongodb://app@h1:27017,h2:27017/app' ) ) . toBe ( 'app' ) ;
@@ -609,7 +609,7 @@ describe('urlUserinfoUsername — the username half of the same grammar (#8876)'
609609 * is wrapped uniformly by the publish door (metadata-protocol's
610610 * `422 INVALID_METADATA`, whose `issues[]` carry these codes verbatim).
611611 */
612- describe ( 'mongo options passthrough — credential refusal (#9040) ' , ( ) => {
612+ describe ( 'mongo options passthrough — credential refusal' , ( ) => {
613613 const VALID = { database : 'events' , host : 'mongo.internal' , username : 'svc' } as const ;
614614 const refusalAt = ( options : Record < string , unknown > ) => {
615615 const result = MongoConfigSchema . safeParse ( { ...VALID , options } ) ;
@@ -666,7 +666,7 @@ describe('mongo options passthrough — credential refusal (#9040)', () => {
666666 expect ( issue ! . message ) . toContain ( 'external.credentialsRef' ) ;
667667 } ) ;
668668
669- it ( '`auth.username` alone is NOT credential material (#8876 asymmetry) — stays accepted' , ( ) => {
669+ it ( '`auth.username` alone is NOT credential material — stays accepted' , ( ) => {
670670 // The schema's question is "is a secret being persisted?", and a username
671671 // is not one. (The client separately refuses a username-only `auth` block
672672 // at construction — `credentials must be an object with 'username' and
@@ -675,7 +675,7 @@ describe('mongo options passthrough — credential refusal (#9040)', () => {
675675 expect ( refusalAt ( { auth : { username : 'app' } } ) ) . toBeUndefined ( ) ;
676676 } ) ;
677677
678- it ( 'an EMPTY `auth.password` carries no secret — the passthrough twin of `user:@host` (#8082) ' , ( ) => {
678+ it ( 'an EMPTY `auth.password` carries no secret — the passthrough twin of `user:@host`' , ( ) => {
679679 expect ( refusalAt ( { auth : { username : 'app' , password : '' } } ) ) . toBeUndefined ( ) ;
680680 } ) ;
681681
@@ -799,7 +799,7 @@ describe('mongo options passthrough — nested credential-SPELLED keys refused a
799799 * refusal is wrapped uniformly by the publish door (metadata-protocol's
800800 * `422 INVALID_METADATA`, whose `issues[]` carry these codes verbatim).
801801 */
802- describe ( 'datasource — bound credentialsRef + user-less mongo url refused (#9041) ' , ( ) => {
802+ describe ( 'datasource — bound credentialsRef + user-less mongo url refused' , ( ) => {
803803 const BOUND = { credentialsRef : 'sys_secret:01J9ZK4T2N' } as const ;
804804 const parse = ( ds : Record < string , unknown > ) => DatasourceSchema . safeParse ( ds ) ;
805805 const refusalOf = ( ds : Record < string , unknown > ) => {
@@ -828,7 +828,7 @@ describe('datasource — bound credentialsRef + user-less mongo url refused (#90
828828 expect ( issue ! . message ) . toContain ( 'silent no-op' ) ;
829829 } ) ;
830830
831- it ( 'judges a legacy `driver: mongo` row identically (alias-resolved, like the #9040 read path)' , ( ) => {
831+ it ( 'judges a legacy `driver: mongo` row identically (alias-resolved, like the passthrough read- path redaction )' , ( ) => {
832832 const issue = refusalOf ( {
833833 name : 'events' ,
834834 driver : 'mongo' ,
@@ -848,7 +848,7 @@ describe('datasource — bound credentialsRef + user-less mongo url refused (#90
848848 expect ( issue ) . toBeDefined ( ) ;
849849 } ) ;
850850
851- it ( 'accepts the blessed shape byte-identically: bare-username URL + bound secret (#8155) ' , ( ) => {
851+ it ( 'accepts the blessed shape byte-identically: bare-username URL + bound secret, what the stored-credential remedy prescribes ' , ( ) => {
852852 const ds = {
853853 name : 'events' ,
854854 driver : 'mongodb' ,
@@ -892,7 +892,7 @@ describe('datasource — bound credentialsRef + user-less mongo url refused (#90
892892 }
893893 } ) ;
894894
895- it ( 'the COMPOSED branch is #9147\'s arm, never this one — a composed config reports neither #9041 nor a `config.url` path' , ( ) => {
895+ it ( 'the COMPOSED branch belongs to the no-username arm, never this one — a composed config reports neither the user-less URL refusal nor a `config.url` path' , ( ) => {
896896 // With no `url` the discrete `username` is live and the factory
897897 // interpolates the bound secret into the URI it composes (the branch
898898 // beside commit 90a12fb18's DSN one), so a composed config that NAMES a
@@ -955,7 +955,7 @@ describe('datasource — bound credentialsRef + user-less mongo url refused (#90
955955 expect ( result . error ! . issues . some ( ( i ) => i . message . includes ( "the URL's own userinfo" ) ) ) . toBe ( false ) ;
956956 } ) ;
957957
958- it ( 'composes with the #9040 passthrough refusal — one artefact, both findings, own paths' , ( ) => {
958+ it ( 'composes with the options- passthrough credential refusal — one artefact, both findings, own paths' , ( ) => {
959959 // The PM-mechanism composition pin: the datasource-level commit d491625c1 refinement
960960 // and the config-level commit 24206416a `credentialFreeMongoOptions` judge the same
961961 // artefact independently — an input violating both reports both.
@@ -992,7 +992,7 @@ describe('datasource — bound credentialsRef + user-less mongo url refused (#90
992992 expect ( result . success , JSON . stringify ( result . error ?. issues ) ) . toBe ( true ) ;
993993 } ) ;
994994
995- it ( 'composes with the #8082 userinfo refusal the other way: a password-bearing URL has a USER' , ( ) => {
995+ it ( 'composes with the URL userinfo refusal the other way: a password-bearing URL has a USER' , ( ) => {
996996 // `user:password@host` violates #8082, but its userinfo NAMES a user — so
997997 // this refusal correctly stays out and the author gets exactly the #8082
998998 // prescription (bind the secret), not a contradictory second message.
@@ -1030,7 +1030,7 @@ describe('datasource — bound credentialsRef + user-less mongo url refused (#90
10301030 * schema refusal is wrapped uniformly by the publish door (metadata-protocol's
10311031 * `422 INVALID_METADATA`, whose `issues[]` carry these codes verbatim).
10321032 */
1033- describe ( 'datasource — bound credentialsRef + composed mongo config naming no username refused (#9147) ' , ( ) => {
1033+ describe ( 'datasource — bound credentialsRef + composed mongo config naming no username refused' , ( ) => {
10341034 const BOUND = { credentialsRef : 'sys_secret:01J9ZK4T2N' } as const ;
10351035 /** The composed branch's minimum viable target — no `url`, so the URI is built. */
10361036 const COMPOSED = { database : 'events' , host : 'mongo.internal' } as const ;
@@ -1067,7 +1067,7 @@ describe('datasource — bound credentialsRef + composed mongo config naming no
10671067 expect ( issue ! . message ) . not . toContain ( 'add the username to the URL' ) ;
10681068 } ) ;
10691069
1070- it ( 'judges a legacy `driver: mongo` row identically (alias-resolved, like #9041 and the #9040 read path)' , ( ) => {
1070+ it ( 'judges a legacy `driver: mongo` row identically (alias-resolved, like the user-less URL arm and the passthrough read path)' , ( ) => {
10711071 expect ( refusalOf ( {
10721072 name : 'events' ,
10731073 driver : 'mongo' ,
@@ -1092,7 +1092,7 @@ describe('datasource — bound credentialsRef + composed mongo config naming no
10921092 } ) ) . toBeDefined ( ) ;
10931093 } ) ;
10941094
1095- it ( 'an empty `config.url` routes HERE, not to #9041 — the arms split on the factory\'s own branch test' , ( ) => {
1095+ it ( 'an empty `config.url` routes HERE, not to the user-less URL arm — the arms split on the factory\'s own branch test' , ( ) => {
10961096 const result = parse ( {
10971097 name : 'events' ,
10981098 driver : 'mongodb' ,
@@ -1119,7 +1119,7 @@ describe('datasource — bound credentialsRef + composed mongo config naming no
11191119 expect ( DatasourceSchema . parse ( ds ) ) . toEqual ( result . data ) ;
11201120 } ) ;
11211121
1122- it ( 'near-miss ① `url` present naming NO user — exactly ONE refusal fires, and it is #9041 \'s' , ( ) => {
1122+ it ( 'near-miss ① `url` present naming NO user — exactly ONE refusal fires, and it is the user-less URL arm \'s' , ( ) => {
11231123 // The arms partition the input: the author must never receive two messages
11241124 // prescribing different fixes for one datasource.
11251125 const result = parse ( {
@@ -1133,7 +1133,7 @@ describe('datasource — bound credentialsRef + composed mongo config naming no
11331133 expect ( result . error ! . issues . some ( ( i ) => i . message . includes ( "add `username` to `config`" ) ) ) . toBe ( false ) ;
11341134 } ) ;
11351135
1136- it ( 'near-miss ② a discrete `username` present — the branch where the bound secret is LIVE (#8696) ' , ( ) => {
1136+ it ( 'near-miss ② a discrete `username` present — the branch where the bound secret is LIVE' , ( ) => {
11371137 const ds = {
11381138 name : 'events' ,
11391139 driver : 'mongodb' ,
@@ -1192,7 +1192,7 @@ describe('datasource — bound credentialsRef + composed mongo config naming no
11921192 expect ( result . error ! . issues . some ( ( i ) => i . message . includes ( "add `username` to `config`" ) ) ) . toBe ( false ) ;
11931193 } ) ;
11941194
1195- it ( 'composes with the #9040 passthrough refusal — one artefact, both findings, own paths' , ( ) => {
1195+ it ( 'composes with the options- passthrough credential refusal — one artefact, both findings, own paths' , ( ) => {
11961196 const result = parse ( {
11971197 name : 'events' ,
11981198 driver : 'mongodb' ,
0 commit comments