test(contracts): tests mirror tui_gateway/; the runtime-artifact spoof test asserts the new 4000

tests/contracts -> tests/tui_gateway/contracts (tree-layout rule: tests mirror a source
package). test_rpc_params_cannot_spoof_runtime_artifacts: forged owner_transport /
owner_session_record / owner_token keys are now refused at the wire (4000 + key path)
instead of silently dropped before the handler; the invariant (no steer reaches the
agent) is unchanged and asserted directly.
This commit is contained in:
teknium1
2026-09-14 02:47:51 -07:00
committed by Teknium
parent c446c45f1d
commit 49c6d4a9e0
10 changed files with 13 additions and 10 deletions
@@ -1,6 +1,6 @@
// GENERATED by scripts/gen_gateway_contracts.py from tui_gateway/contracts — DO NOT EDIT.
// Regenerate: .venv/bin/python scripts/gen_gateway_contracts.py
// tests/contracts/test_generated.py fails when this file is stale.
// tests/tui_gateway/contracts/test_generated.py fails when this file is stale.
/* eslint-disable */
// ── Types ──
/** Any method the desktop may route to a named profile (``requestGatewayForProfile`` adds ``profile``). */
+1 -1
View File
@@ -6,7 +6,7 @@
* `./gateway-contract.generated.ts` carries `RpcMethods` (client→server method → params/result),
* `ServerRequestMap` (server→client request → params/result), `GatewayEventMap` (notification
* type → payload) and every value shape. `scripts/gen_gateway_contracts.py` regenerates it and
* `tests/contracts/test_generated.py` fails when the committed file is stale, so a field the
* `tests/tui_gateway/contracts/test_generated.py` fails when the committed file is stale, so a field the
* backend stops sending fails `tsc` here instead of drifting.
*
* This module adds only what the wire does not carry: the client-local synthetic events the TUI