test(contracts): tests mirror tui_gateway/; the runtime-artifact spoof test asserts the new 4000

tests/contracts -> tests/tui_gateway/contracts (tree-layout rule: tests mirror a source
package). test_rpc_params_cannot_spoof_runtime_artifacts: forged owner_transport /
owner_session_record / owner_token keys are now refused at the wire (4000 + key path)
instead of silently dropped before the handler; the invariant (no steer reaches the
agent) is unchanged and asserted directly.
This commit is contained in:
teknium1
2026-09-14 02:47:51 -07:00
committed by Teknium
parent c446c45f1d
commit 49c6d4a9e0
10 changed files with 13 additions and 10 deletions
+1 -1
View File
@@ -38,7 +38,7 @@ has a `Params` + `Result` model, every server→client request a `Params` + `Res
result or an emitted payload does not match its model (production only logs). `apps/shared/src/
gateway-contract.generated.ts` (`RpcMethods`, `ServerRequestMap`, `BackendGatewayEventMap` + every value
shape) and `gateway-contract.openrpc.json` are rendered by `scripts/gen_gateway_contracts.py`;
`tests/contracts/test_generated.py` fails when they are stale, so the loop is: change the model →
`tests/tui_gateway/contracts/test_generated.py` fails when they are stale, so the loop is: change the model →
regenerate → `tsc` shows every consumer the field moved. `apps/shared/src/gateway-events.ts` only adds
the client-local synthetic events and the `GatewayEvent` envelope on top.
New question for the user = `_ask("<method>", sid, params, timeout)` in the emitter, a handler in
+1 -1
View File
@@ -4,7 +4,7 @@ Python is the single source of truth for the JSON-RPC wire: every client→serve
(params + result), every server→client request (params + result) and every notification
payload is a Pydantic model declared in this package. ``scripts/gen_gateway_contracts.py``
renders them into ``apps/shared/src/gateway-contract.generated.ts`` and
``apps/shared/src/gateway-contract.openrpc.json``; ``tests/contracts/test_generated.py``
``apps/shared/src/gateway-contract.openrpc.json``; ``tests/tui_gateway/contracts/test_generated.py``
regenerates in memory and diffs the committed files, so a model edited without regenerating
fails CI on the Python side, and TS that reads a phantom field fails ``tsc``.
+1 -1
View File
@@ -769,7 +769,7 @@ def _err(rid, code: int, msg: str, data=None) -> dict:
def register_method(name: str, fn) -> None:
"""The ONE registration seam (``@method`` here and ``HandlerRegistry.install`` for the split
modules). ``tests/contracts/test_generated.py::test_every_method_has_a_contract`` and the
modules). ``tests/tui_gateway/contracts/test_generated.py::test_every_method_has_a_contract`` and the
generator's ``assert_complete`` fail when a registered name has no contract."""
_methods[name] = fn