mirror of
https://github.com/garrytan/gbrain.git
synced 2026-07-27 22:15:33 +00:00
test(e2e): update multi-source-bug-class validateSourceId expectations for strict regex
The v0.32.8 test pinned the OLD permissive ^[a-z0-9_-]+$ behavior including the underscored case 'jarvis_memory'. The v0.38 wave (this PR's E2 + codex P1-D) tightens validateSourceId to the strict kebab regex shared with sources-ops. 'jarvis_memory' now lives in the rejected set, not the allowed set. Updated the test to assert the new contract: - Replaced 'jarvis_memory' allowed case with 'jarvis-memory' (kebab) - Added 'a' (single-char) to allowed cases - Added 'jarvis_memory', 'snake_case', '-leading', 'trailing-', and a 33-char string to the rejected cases — the v0.38 strict-regex additions Comment explains the contract shift so future readers don't see the test as flapping intent. Found by running the main E2E suite — the test file is in the canonical e2e set and would have failed CI otherwise. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.7
parent
c7ed9b9904
commit
c835f93fee
@@ -156,12 +156,20 @@ describe('multi-source bug class', () => {
|
|||||||
});
|
});
|
||||||
|
|
||||||
test('validateSourceId rejects path traversal (F6)', () => {
|
test('validateSourceId rejects path traversal (F6)', () => {
|
||||||
// Allowed
|
// v0.38 (codex P1-D + eng E2): regex TIGHTENED from permissive
|
||||||
|
// ^[a-z0-9_-]+$ to strict kebab ^[a-z0-9](?:[a-z0-9-]{0,30}[a-z0-9])?$.
|
||||||
|
// Underscores no longer allowed at the path-safety gate (matches
|
||||||
|
// what sources-ops always rejected at creation time). 'jarvis_memory'
|
||||||
|
// was a v0.32.8 permissive-regex test case; now lives in the
|
||||||
|
// rejected set. Path-traversal rejection unchanged.
|
||||||
|
//
|
||||||
|
// Allowed (strict kebab):
|
||||||
expect(() => validateSourceId('default')).not.toThrow();
|
expect(() => validateSourceId('default')).not.toThrow();
|
||||||
expect(() => validateSourceId('media-corpus')).not.toThrow();
|
expect(() => validateSourceId('media-corpus')).not.toThrow();
|
||||||
expect(() => validateSourceId('jarvis_memory')).not.toThrow();
|
expect(() => validateSourceId('jarvis-memory')).not.toThrow();
|
||||||
expect(() => validateSourceId('abc123')).not.toThrow();
|
expect(() => validateSourceId('abc123')).not.toThrow();
|
||||||
// Rejected
|
expect(() => validateSourceId('a')).not.toThrow();
|
||||||
|
// Rejected — path traversal / unsafe chars:
|
||||||
expect(() => validateSourceId('..')).toThrow();
|
expect(() => validateSourceId('..')).toThrow();
|
||||||
expect(() => validateSourceId('../etc')).toThrow();
|
expect(() => validateSourceId('../etc')).toThrow();
|
||||||
expect(() => validateSourceId('foo/bar')).toThrow();
|
expect(() => validateSourceId('foo/bar')).toThrow();
|
||||||
@@ -169,6 +177,13 @@ describe('multi-source bug class', () => {
|
|||||||
expect(() => validateSourceId('Default')).toThrow(); // uppercase
|
expect(() => validateSourceId('Default')).toThrow(); // uppercase
|
||||||
expect(() => validateSourceId('.hidden')).toThrow();
|
expect(() => validateSourceId('.hidden')).toThrow();
|
||||||
expect(() => validateSourceId('')).toThrow();
|
expect(() => validateSourceId('')).toThrow();
|
||||||
|
// Rejected — strict regex additions (v0.38):
|
||||||
|
expect(() => validateSourceId('jarvis_memory')).toThrow(); // underscores
|
||||||
|
expect(() => validateSourceId('snake_case')).toThrow();
|
||||||
|
expect(() => validateSourceId('-leading')).toThrow(); // edge hyphen
|
||||||
|
expect(() => validateSourceId('trailing-')).toThrow();
|
||||||
|
const tooLong = 'a' + 'b'.repeat(31) + 'c'; // 33 chars
|
||||||
|
expect(() => validateSourceId(tooLong)).toThrow();
|
||||||
});
|
});
|
||||||
|
|
||||||
test('reverse-write disk layout uses .sources/<id>/<slug>.md for non-default (F6)', () => {
|
test('reverse-write disk layout uses .sources/<id>/<slug>.md for non-default (F6)', () => {
|
||||||
|
|||||||
Reference in New Issue
Block a user