Files
hapi/shared/src/workGraph.test.ts
T
ad12eeb5d6 feat(a2a): P3 AGENT_NOTIFY_SUMMARY → work-graph status ingest (#1467)
* feat(a2a): P3 AGENT_NOTIFY_SUMMARY → work-graph status ingest

Land A0 events/event_links substrate (aligned with #1374 contracts) plus
thin P3 ingest so opt-in notify footers become durable work_ad rows.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(a2a): address #1467 cold pass-1 Majors on notify ingest

Populate expires_at from message ts+TTL, persist message timestamps on
insert, pin append-only ledger survival, and defer project column to P4.

* test(hub): cover notify ingest via syncEngine message-received

Pins the display-never-gates-capture invariant on the real handleRealtimeEvent
wiring path (cold pass-1 minor 12).

* fix(a2a): address #1467 Sol cold Majors on notify ingest

Support AGY agy_message text extraction, bind audit principal to session id,
map stalled→blocked (never self-stale), and cap work-graph POST bodies.

* fix(a2a): validate work-graph creates at store insert (Sol S4)

Notify ingest built WorkGraphEventCreate and inserted without schema
bounds; oversized footer summaries could land past HTTP Zod limits.
Validate WorkGraphEventCreateSchema in insertWorkGraphEvent, clamp
untrusted notify strings at elevation, and regress 2049-char summaries.

* fix(a2a): reject fractional work-graph list limit

Bot Minor: limit=1.5 passed Number.isFinite and hit SQLite LIMIT as a
non-integer, surfacing as 500. Require Number.isInteger before query.

* fix(a2a): keep notify elevation inside payload budget

Drop duplicated notify_summary nesting that could exceed the 32 KiB
payload_json cap after per-field clamps, and measure the cap in UTF-8
bytes via TextEncoder instead of UTF-16 string.length.

* fix(a2a): clamp notify footer fields by UTF-8 bytes

Per-field string.length clamps still let CJK footers exceed the UTF-8
payload_json budget and silent-drop elevation. Truncate action/project/
agent/summary (and tags) to the ledger byte caps before insert.

* fix(a2a): clamp notify payload fields by JSON-escaped UTF-8

Raw UTF-8 clamps still let backslash-heavy footers expand past the
payload_json budget after JSON.stringify. Budget the escaped form so
elevation inserts instead of silent-dropping.

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-10 10:49:52 +08:00

97 lines
3.3 KiB
TypeScript

import { describe, expect, it } from 'bun:test'
import {
WORK_GRAPH_MAX_PAYLOAD_JSON_BYTES,
WorkGraphEventCreateSchema,
WorkGraphPrincipalSchema,
isPrincipalAccountable,
principalMatchesAuthenticatedOwner
} from './workGraph'
describe('WorkGraphPrincipalSchema', () => {
it('accepts human principal without on_behalf_of', () => {
const parsed = WorkGraphPrincipalSchema.safeParse({ kind: 'human', id: '42' })
expect(parsed.success).toBe(true)
})
it('rejects agent without on_behalf_of', () => {
const parsed = WorkGraphPrincipalSchema.safeParse({ kind: 'agent', id: 'session-1' })
expect(parsed.success).toBe(false)
})
it('accepts agent with human owner', () => {
const parsed = WorkGraphPrincipalSchema.safeParse({
kind: 'agent',
id: 'session-1',
on_behalf_of: '42'
})
expect(parsed.success).toBe(true)
})
})
describe('principal accountability helpers', () => {
it('refuses non-human with empty owner', () => {
expect(isPrincipalAccountable({
kind: 'service',
id: 'ci',
on_behalf_of: ' '
})).toBe(false)
})
it('requires human id to match authenticated owner', () => {
expect(principalMatchesAuthenticatedOwner({ kind: 'human', id: '1' }, 1)).toBe(true)
expect(principalMatchesAuthenticatedOwner({ kind: 'human', id: '2' }, 1)).toBe(false)
})
it('requires agent on_behalf_of to match authenticated owner', () => {
expect(principalMatchesAuthenticatedOwner({
kind: 'agent',
id: 'worker',
on_behalf_of: '1'
}, 1)).toBe(true)
expect(principalMatchesAuthenticatedOwner({
kind: 'agent',
id: 'worker',
on_behalf_of: '99'
}, 1)).toBe(false)
})
})
describe('WorkGraphEventCreateSchema bounds', () => {
const base = {
source_kind: 'session',
source_ref: 'sess-1',
event_type: 'work_ad',
principal: { kind: 'human' as const, id: '1' }
}
it('rejects oversized payload_json', () => {
const parsed = WorkGraphEventCreateSchema.safeParse({
...base,
payload_json: { blob: 'x'.repeat(WORK_GRAPH_MAX_PAYLOAD_JSON_BYTES) }
})
expect(parsed.success).toBe(false)
})
it('rejects payload_json that fits UTF-16 length but exceeds UTF-8 bytes', () => {
// CJK is 1 UTF-16 code unit / 3 UTF-8 bytes. ~12k chars stays under
// string.length of 32 KiB but over UTF-8 byte budget.
const cjk = '\u4e2d'.repeat(12_000)
const json = JSON.stringify({ blob: cjk })
expect(json.length).toBeLessThanOrEqual(WORK_GRAPH_MAX_PAYLOAD_JSON_BYTES)
expect(new TextEncoder().encode(json).byteLength).toBeGreaterThan(WORK_GRAPH_MAX_PAYLOAD_JSON_BYTES)
const parsed = WorkGraphEventCreateSchema.safeParse({
...base,
payload_json: { blob: cjk }
})
expect(parsed.success).toBe(false)
})
it('rejects too many tags', () => {
const parsed = WorkGraphEventCreateSchema.safeParse({
...base,
tags: Array.from({ length: 33 }, (_, i) => `t${i}`)
})
expect(parsed.success).toBe(false)
})
})