test(contracts): tests mirror tui_gateway/; the runtime-artifact spoof test asserts the new 4000
tests/contracts -> tests/tui_gateway/contracts (tree-layout rule: tests mirror a source package). test_rpc_params_cannot_spoof_runtime_artifacts: forged owner_transport / owner_session_record / owner_token keys are now refused at the wire (4000 + key path) instead of silently dropped before the handler; the invariant (no steer reaches the agent) is unchanged and asserted directly.
This commit is contained in:
@@ -1,6 +1,6 @@
|
||||
// GENERATED by scripts/gen_gateway_contracts.py from tui_gateway/contracts — DO NOT EDIT.
|
||||
// Regenerate: .venv/bin/python scripts/gen_gateway_contracts.py
|
||||
// tests/contracts/test_generated.py fails when this file is stale.
|
||||
// tests/tui_gateway/contracts/test_generated.py fails when this file is stale.
|
||||
/* eslint-disable */
|
||||
// ── Types ──
|
||||
/** Any method the desktop may route to a named profile (``requestGatewayForProfile`` adds ``profile``). */
|
||||
|
||||
@@ -6,7 +6,7 @@
|
||||
* `./gateway-contract.generated.ts` carries `RpcMethods` (client→server method → params/result),
|
||||
* `ServerRequestMap` (server→client request → params/result), `GatewayEventMap` (notification
|
||||
* type → payload) and every value shape. `scripts/gen_gateway_contracts.py` regenerates it and
|
||||
* `tests/contracts/test_generated.py` fails when the committed file is stale, so a field the
|
||||
* `tests/tui_gateway/contracts/test_generated.py` fails when the committed file is stale, so a field the
|
||||
* backend stops sending fails `tsc` here instead of drifting.
|
||||
*
|
||||
* This module adds only what the wire does not carry: the client-local synthetic events the TUI
|
||||
|
||||
Reference in New Issue
Block a user