mirror of
https://github.com/wu736139669/hapi.git
synced 2026-10-10 19:42:21 +00:00
* feat(a2a): P3 AGENT_NOTIFY_SUMMARY → work-graph status ingest Land A0 events/event_links substrate (aligned with #1374 contracts) plus thin P3 ingest so opt-in notify footers become durable work_ad rows. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(a2a): address #1467 cold pass-1 Majors on notify ingest Populate expires_at from message ts+TTL, persist message timestamps on insert, pin append-only ledger survival, and defer project column to P4. * test(hub): cover notify ingest via syncEngine message-received Pins the display-never-gates-capture invariant on the real handleRealtimeEvent wiring path (cold pass-1 minor 12). * fix(a2a): address #1467 Sol cold Majors on notify ingest Support AGY agy_message text extraction, bind audit principal to session id, map stalled→blocked (never self-stale), and cap work-graph POST bodies. * fix(a2a): validate work-graph creates at store insert (Sol S4) Notify ingest built WorkGraphEventCreate and inserted without schema bounds; oversized footer summaries could land past HTTP Zod limits. Validate WorkGraphEventCreateSchema in insertWorkGraphEvent, clamp untrusted notify strings at elevation, and regress 2049-char summaries. * fix(a2a): reject fractional work-graph list limit Bot Minor: limit=1.5 passed Number.isFinite and hit SQLite LIMIT as a non-integer, surfacing as 500. Require Number.isInteger before query. * fix(a2a): keep notify elevation inside payload budget Drop duplicated notify_summary nesting that could exceed the 32 KiB payload_json cap after per-field clamps, and measure the cap in UTF-8 bytes via TextEncoder instead of UTF-16 string.length. * fix(a2a): clamp notify footer fields by UTF-8 bytes Per-field string.length clamps still let CJK footers exceed the UTF-8 payload_json budget and silent-drop elevation. Truncate action/project/ agent/summary (and tags) to the ledger byte caps before insert. * fix(a2a): clamp notify payload fields by JSON-escaped UTF-8 Raw UTF-8 clamps still let backslash-heavy footers expand past the payload_json budget after JSON.stringify. Budget the escaped form so elevation inserts instead of silent-dropping. --------- Co-authored-by: Cursor <cursoragent@cursor.com>
97 lines
3.3 KiB
TypeScript
97 lines
3.3 KiB
TypeScript
import { describe, expect, it } from 'bun:test'
|
|
import {
|
|
WORK_GRAPH_MAX_PAYLOAD_JSON_BYTES,
|
|
WorkGraphEventCreateSchema,
|
|
WorkGraphPrincipalSchema,
|
|
isPrincipalAccountable,
|
|
principalMatchesAuthenticatedOwner
|
|
} from './workGraph'
|
|
|
|
describe('WorkGraphPrincipalSchema', () => {
|
|
it('accepts human principal without on_behalf_of', () => {
|
|
const parsed = WorkGraphPrincipalSchema.safeParse({ kind: 'human', id: '42' })
|
|
expect(parsed.success).toBe(true)
|
|
})
|
|
|
|
it('rejects agent without on_behalf_of', () => {
|
|
const parsed = WorkGraphPrincipalSchema.safeParse({ kind: 'agent', id: 'session-1' })
|
|
expect(parsed.success).toBe(false)
|
|
})
|
|
|
|
it('accepts agent with human owner', () => {
|
|
const parsed = WorkGraphPrincipalSchema.safeParse({
|
|
kind: 'agent',
|
|
id: 'session-1',
|
|
on_behalf_of: '42'
|
|
})
|
|
expect(parsed.success).toBe(true)
|
|
})
|
|
})
|
|
|
|
describe('principal accountability helpers', () => {
|
|
it('refuses non-human with empty owner', () => {
|
|
expect(isPrincipalAccountable({
|
|
kind: 'service',
|
|
id: 'ci',
|
|
on_behalf_of: ' '
|
|
})).toBe(false)
|
|
})
|
|
|
|
it('requires human id to match authenticated owner', () => {
|
|
expect(principalMatchesAuthenticatedOwner({ kind: 'human', id: '1' }, 1)).toBe(true)
|
|
expect(principalMatchesAuthenticatedOwner({ kind: 'human', id: '2' }, 1)).toBe(false)
|
|
})
|
|
|
|
it('requires agent on_behalf_of to match authenticated owner', () => {
|
|
expect(principalMatchesAuthenticatedOwner({
|
|
kind: 'agent',
|
|
id: 'worker',
|
|
on_behalf_of: '1'
|
|
}, 1)).toBe(true)
|
|
expect(principalMatchesAuthenticatedOwner({
|
|
kind: 'agent',
|
|
id: 'worker',
|
|
on_behalf_of: '99'
|
|
}, 1)).toBe(false)
|
|
})
|
|
})
|
|
|
|
describe('WorkGraphEventCreateSchema bounds', () => {
|
|
const base = {
|
|
source_kind: 'session',
|
|
source_ref: 'sess-1',
|
|
event_type: 'work_ad',
|
|
principal: { kind: 'human' as const, id: '1' }
|
|
}
|
|
|
|
it('rejects oversized payload_json', () => {
|
|
const parsed = WorkGraphEventCreateSchema.safeParse({
|
|
...base,
|
|
payload_json: { blob: 'x'.repeat(WORK_GRAPH_MAX_PAYLOAD_JSON_BYTES) }
|
|
})
|
|
expect(parsed.success).toBe(false)
|
|
})
|
|
|
|
it('rejects payload_json that fits UTF-16 length but exceeds UTF-8 bytes', () => {
|
|
// CJK is 1 UTF-16 code unit / 3 UTF-8 bytes. ~12k chars stays under
|
|
// string.length of 32 KiB but over UTF-8 byte budget.
|
|
const cjk = '\u4e2d'.repeat(12_000)
|
|
const json = JSON.stringify({ blob: cjk })
|
|
expect(json.length).toBeLessThanOrEqual(WORK_GRAPH_MAX_PAYLOAD_JSON_BYTES)
|
|
expect(new TextEncoder().encode(json).byteLength).toBeGreaterThan(WORK_GRAPH_MAX_PAYLOAD_JSON_BYTES)
|
|
const parsed = WorkGraphEventCreateSchema.safeParse({
|
|
...base,
|
|
payload_json: { blob: cjk }
|
|
})
|
|
expect(parsed.success).toBe(false)
|
|
})
|
|
|
|
it('rejects too many tags', () => {
|
|
const parsed = WorkGraphEventCreateSchema.safeParse({
|
|
...base,
|
|
tags: Array.from({ length: 33 }, (_, i) => `t${i}`)
|
|
})
|
|
expect(parsed.success).toBe(false)
|
|
})
|
|
})
|