Machine-produced by `pnpm run rescope-vendor --apply` plus the regeneration it prints: `pnpm install` for the lockfile, `pnpm run gen-third-party-notices`, `verify-translation-pairing --write` for the touched bilingual pairs, `gen-doc-graphs`, and one typert snapshot whose ids embed character offsets. `pnpm run rescope-vendor --check` verifies the result. Renames nine vendored packages (cordis, cosmokit, schemastery and the six @cordisjs plugins) and every reference that resolves them: manifest names and dependency keys, module specifiers including declare-module merges, cordis.yml plugin names, tsconfig paths, every Markdown fence, and `docs/` prose. Directory names, upstream versions, and dependency ranges are unchanged, so vendor/README.md still reads as an upstream snapshot; its manifest table gains an upstream-name column so THIRD_PARTY_NOTICES keeps MIT attribution pointed at each fork's origin. The tutorial tier follows the rename end to end: its yaml fences named plugins the Loader can no longer resolve, its `ts ignore-check` fences disagreed with the compiled fences beside them, and its prose quoted both. The contracts that told readers to keep upstream names — the root convention and the vendoring cookbook's tree comment and manifest invariant — now say to rescope instead. Two rules read `@deepseek-ai/` as "another workspace plugin": the client bundle purity gate now names the vendored libraries a browser bundle inlines, and the files where a bare `cordis` is an agent-preset id keep that product data.
54 lines
2.0 KiB
TypeScript
54 lines
2.0 KiB
TypeScript
import { describe, expect, it } from 'vitest'
|
|
import { Context, Service } from '@deepseek-ai/cordis'
|
|
import SessionStore, { type Session, type SessionEvent } from '@deepseek-ai/dsh-session'
|
|
import * as PermissionInvariant from '@deepseek-ai/dsh-permission/invariant'
|
|
import InvariantService from '@deepseek-ai/dsh-invariants'
|
|
|
|
class PermissionProbe extends Service {
|
|
readonly names = ['safe', 'trusted']
|
|
|
|
constructor(ctx: Context) {
|
|
super(ctx, 'permission')
|
|
}
|
|
}
|
|
|
|
async function setup(): Promise<Context> {
|
|
const ctx = new Context()
|
|
await ctx.plugin(SessionStore)
|
|
await ctx.plugin(PermissionProbe)
|
|
await ctx.plugin(InvariantService, { enabled: true })
|
|
await ctx.plugin(PermissionInvariant)
|
|
return ctx
|
|
}
|
|
|
|
function presetEvent(preset: string): SessionEvent {
|
|
return { type: 'permission/preset', seq: 0, time: 0, data: { preset } }
|
|
}
|
|
|
|
describe('permission invariants', () => {
|
|
it('accepts configured preset events and ignores other session data', async () => {
|
|
const ctx = await setup()
|
|
expect(() => { ctx.emit('session/event', {} as Session, presetEvent('safe')) }).not.toThrow()
|
|
expect(() => { ctx.emit('session/event', {} as Session, {
|
|
type: 'turn/end', seq: 0, time: 0, data: {},
|
|
} as SessionEvent) }).not.toThrow()
|
|
expect(() => { ctx.emit('tools/change') }).not.toThrow()
|
|
})
|
|
|
|
it('rejects a durable preset that the active table cannot resolve', async () => {
|
|
const ctx = await setup()
|
|
expect(() => { ctx.emit('session/event', {} as Session, presetEvent('missing')) })
|
|
.toThrow(/unknown preset "missing"/)
|
|
})
|
|
|
|
it('rejects an unknown preset already present on late registration', async () => {
|
|
const ctx = new Context()
|
|
await ctx.plugin(SessionStore)
|
|
await ctx.plugin(PermissionProbe)
|
|
ctx.sessions.create().append('permission/preset', { preset: 'missing' })
|
|
await ctx.plugin(InvariantService, { enabled: true })
|
|
|
|
await expect(ctx.plugin(PermissionInvariant).then(() => undefined)).rejects.toThrow(/unknown preset "missing"/)
|
|
})
|
|
})
|