Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
65 changes: 65 additions & 0 deletions packages/rest/src/rest-approvals-wire-codes.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -28,13 +28,20 @@
* route. The derivation mirrors the production template exactly
* (single-occurrence `.replace('-', '_')` included), so a route name the
* template would mangle into an invalid code also fails here.
* [#14573] The file has since become the home for the approvals door's
* live-emission pins generally, not only the #8885 population: the
* `FORBIDDEN` → 403 case below pins a row that is registered vocabulary and
* whose emission was — contrary to that card's premise — already observed
* elsewhere. See its own comment for where, and why it is pinned here too.
*
* 3. The union stays CLOSED — the control case in
* `rest-field-visibility-fault-envelope.test.ts` covers this file too (same
* schema instance); membership green here is evidence, not vacuity.
*/

import { describe, it, expect, vi } from 'vitest';
import { ApiErrorSchema } from '@objectstack/spec/api';
import { BUILTIN_OPERATION_MESSAGES } from '@objectstack/spec/system';
// `.js` on purpose — NodeNext resolution requires the extension (#7248).
import { RestServer } from './rest-server.js';

Expand DownExpand Up@@ -115,6 +122,64 @@ describe('approvals wire codes are registered vocabulary (#8885)', () => {
).toBe(true);
});

// [#14573] The `FORBIDDEN` → 403 row is the one EVERY authorisation
// refusal rides: recall by a non-submitter, decide by a non-approver,
// reassign / remind / sendBack / resubmit by the wrong actor, and
// `resolveActor`'s impersonation refusals all reach this table through
// the same single row.
//
// ⚠️ THIS IS A SECOND PIN, NOT THE FIRST — read this before adding a
// third. #14573 was filed and triaged on the reading that the row had NO
// live-emission pin, and that reading is WRONG: §7 of
// `rest-data-door-code-prefix.test.ts` ("[#13095] the approvals door
// strips the code it answers") already drives the REAL approve route with
// a `FORBIDDEN: …` throw and already asserts 403, `code: 'FORBIDDEN'` and
// the strip. Measured, not read: deleting the row from `rest-server.ts`
// reds THREE cases — this one and both of §7's. What was true is narrower
// than the card: the file that OWNS the approvals wire-code contract did
// not pin the row, so a reader auditing wire codes here saw a gap that a
// strip-contract file was silently covering. That is the gap this case
// closes, and naming §7 here is half the fix — an unlabelled duplicate is
// what got the card mis-filed in the first place.
//
// The service suites (`recall-refusal-user-copy.test.ts`,
// `approval-revise.test.ts`) are NOT pins on this row: they assert the
// `FORBIDDEN:` MESSAGE PREFIX at the throw site, a different fact from
// what the route answers.
//
// Losing the row FAILS CLOSED, which is why this is a contract pin and not
// a security one: `handleApprovalError` returns false on no match, the
// caller rethrows, and the terminal catch answers 500
// `APPROVAL_RECALL_FAILED`. The caller is still refused — at the wrong
// status, with the wrong code, and (because that arm forwards
// `String(error?.message ?? error)` verbatim) with the raw `FORBIDDEN: `
// token the [#13095] anchored strip exists to remove. Two contract
// properties ride this one row, so the third assertion below is NOT
// redundant with the first two: it is what catches the degraded shape's
// unstripped message. (Ablation: all three reds read
// `expected 500 to be 403`.)
it('recall by a non-submitter answers 403 FORBIDDEN, prefix stripped — the row every authorisation refusal rides', async () => {
// The message the real service throws: `approval-service.ts`'s recall
// non-submitter branch is `FORBIDDEN: ${userFacingRefusal(...)}`.
// Read from the catalog rather than transcribed so a [#11993] copy
// edit cannot red this pin for a reason that is not the wire contract
// — the same construction `approval-revise.test.ts` uses.
const refusal = BUILTIN_OPERATION_MESSAGES.en.approval_recall_not_submitter;
const rest = boot({
recall: vi.fn().mockRejectedValue(new Error(`FORBIDDEN: ${refusal}`)),
});
const answer = await drive(rest, 'POST', `${REQ}/recall`);
expect(answer.status).toBe(403);
expect(answer.body?.code).toBe('FORBIDDEN');
// [#13095] Exactly the `FORBIDDEN:` this row just answered comes off,
// and the user-facing sentence reaches the wire whole.
expect(answer.body?.error).toBe(refusal);
expect(
ApiErrorSchema.safeParse({ code: answer.body?.code, message: answer.body?.error }).success,
'FORBIDDEN must be in StandardErrorCode ∪ ERROR_CODE_LEDGER',
).toBe(true);
});

// [#13182] `READ_BACK_FAILED` is a NAMED wire row (the RESUME_FAILED
// precedent: a genuine server-side inconsistency, but named): the write is
// recorded and NOT rolled back, the read-back is org-filtered, and the
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all \u003cpre\u003e\u003ccode\u003e blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks"); } } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); } })(); (function(){ try { var __m = "github.com"; var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
65 changes: 65 additions & 0 deletions packages/rest/src/rest-approvals-wire-codes.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -28,13 +28,20 @@
* route. The derivation mirrors the production template exactly
* (single-occurrence `.replace('-', '_')` included), so a route name the
* template would mangle into an invalid code also fails here.
* [#14573] The file has since become the home for the approvals door's
* live-emission pins generally, not only the #8885 population: the
* `FORBIDDEN` → 403 case below pins a row that is registered vocabulary and
* whose emission was — contrary to that card's premise — already observed
* elsewhere. See its own comment for where, and why it is pinned here too.
*
* 3. The union stays CLOSED — the control case in
* `rest-field-visibility-fault-envelope.test.ts` covers this file too (same
* schema instance); membership green here is evidence, not vacuity.
*/

import { describe, it, expect, vi } from 'vitest';
import { ApiErrorSchema } from '@objectstack/spec/api';
import { BUILTIN_OPERATION_MESSAGES } from '@objectstack/spec/system';
// `.js` on purpose — NodeNext resolution requires the extension (#7248).
import { RestServer } from './rest-server.js';

Expand DownExpand Up@@ -115,6 +122,64 @@ describe('approvals wire codes are registered vocabulary (#8885)', () => {
).toBe(true);
});

// [#14573] The `FORBIDDEN` → 403 row is the one EVERY authorisation
// refusal rides: recall by a non-submitter, decide by a non-approver,
// reassign / remind / sendBack / resubmit by the wrong actor, and
// `resolveActor`'s impersonation refusals all reach this table through
// the same single row.
//
// ⚠️ THIS IS A SECOND PIN, NOT THE FIRST — read this before adding a
// third. #14573 was filed and triaged on the reading that the row had NO
// live-emission pin, and that reading is WRONG: §7 of
// `rest-data-door-code-prefix.test.ts` ("[#13095] the approvals door
// strips the code it answers") already drives the REAL approve route with
// a `FORBIDDEN: …` throw and already asserts 403, `code: 'FORBIDDEN'` and
// the strip. Measured, not read: deleting the row from `rest-server.ts`
// reds THREE cases — this one and both of §7's. What was true is narrower
// than the card: the file that OWNS the approvals wire-code contract did
// not pin the row, so a reader auditing wire codes here saw a gap that a
// strip-contract file was silently covering. That is the gap this case
// closes, and naming §7 here is half the fix — an unlabelled duplicate is
// what got the card mis-filed in the first place.
//
// The service suites (`recall-refusal-user-copy.test.ts`,
// `approval-revise.test.ts`) are NOT pins on this row: they assert the
// `FORBIDDEN:` MESSAGE PREFIX at the throw site, a different fact from
// what the route answers.
//
// Losing the row FAILS CLOSED, which is why this is a contract pin and not
// a security one: `handleApprovalError` returns false on no match, the
// caller rethrows, and the terminal catch answers 500
// `APPROVAL_RECALL_FAILED`. The caller is still refused — at the wrong
// status, with the wrong code, and (because that arm forwards
// `String(error?.message ?? error)` verbatim) with the raw `FORBIDDEN: `
// token the [#13095] anchored strip exists to remove. Two contract
// properties ride this one row, so the third assertion below is NOT
// redundant with the first two: it is what catches the degraded shape's
// unstripped message. (Ablation: all three reds read
// `expected 500 to be 403`.)
it('recall by a non-submitter answers 403 FORBIDDEN, prefix stripped — the row every authorisation refusal rides', async () => {
// The message the real service throws: `approval-service.ts`'s recall
// non-submitter branch is `FORBIDDEN: ${userFacingRefusal(...)}`.
// Read from the catalog rather than transcribed so a [#11993] copy
// edit cannot red this pin for a reason that is not the wire contract
// — the same construction `approval-revise.test.ts` uses.
const refusal = BUILTIN_OPERATION_MESSAGES.en.approval_recall_not_submitter;
const rest = boot({
recall: vi.fn().mockRejectedValue(new Error(`FORBIDDEN: ${refusal}`)),
});
const answer = await drive(rest, 'POST', `${REQ}/recall`);
expect(answer.status).toBe(403);
expect(answer.body?.code).toBe('FORBIDDEN');
// [#13095] Exactly the `FORBIDDEN:` this row just answered comes off,
// and the user-facing sentence reaches the wire whole.
expect(answer.body?.error).toBe(refusal);
expect(
ApiErrorSchema.safeParse({ code: answer.body?.code, message: answer.body?.error }).success,
'FORBIDDEN must be in StandardErrorCode ∪ ERROR_CODE_LEDGER',
).toBe(true);
});

// [#13182] `READ_BACK_FAILED` is a NAMED wire row (the RESUME_FAILED
// precedent: a genuine server-side inconsistency, but named): the write is
// recorded and NOT rolled back, the read-back is org-filtered, and the
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
65 changes: 65 additions & 0 deletions packages/rest/src/rest-approvals-wire-codes.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -28,13 +28,20 @@
* route. The derivation mirrors the production template exactly
* (single-occurrence `.replace('-', '_')` included), so a route name the
* template would mangle into an invalid code also fails here.
* [#14573] The file has since become the home for the approvals door's
* live-emission pins generally, not only the #8885 population: the
* `FORBIDDEN` → 403 case below pins a row that is registered vocabulary and
* whose emission was — contrary to that card's premise — already observed
* elsewhere. See its own comment for where, and why it is pinned here too.
*
* 3. The union stays CLOSED — the control case in
* `rest-field-visibility-fault-envelope.test.ts` covers this file too (same
* schema instance); membership green here is evidence, not vacuity.
*/

import { describe, it, expect, vi } from 'vitest';
import { ApiErrorSchema } from '@objectstack/spec/api';
import { BUILTIN_OPERATION_MESSAGES } from '@objectstack/spec/system';
// `.js` on purpose — NodeNext resolution requires the extension (#7248).
import { RestServer } from './rest-server.js';

Expand DownExpand Up@@ -115,6 +122,64 @@ describe('approvals wire codes are registered vocabulary (#8885)', () => {
).toBe(true);
});

// [#14573] The `FORBIDDEN` → 403 row is the one EVERY authorisation
// refusal rides: recall by a non-submitter, decide by a non-approver,
// reassign / remind / sendBack / resubmit by the wrong actor, and
// `resolveActor`'s impersonation refusals all reach this table through
// the same single row.
//
// ⚠️ THIS IS A SECOND PIN, NOT THE FIRST — read this before adding a
// third. #14573 was filed and triaged on the reading that the row had NO
// live-emission pin, and that reading is WRONG: §7 of
// `rest-data-door-code-prefix.test.ts` ("[#13095] the approvals door
// strips the code it answers") already drives the REAL approve route with
// a `FORBIDDEN: …` throw and already asserts 403, `code: 'FORBIDDEN'` and
// the strip. Measured, not read: deleting the row from `rest-server.ts`
// reds THREE cases — this one and both of §7's. What was true is narrower
// than the card: the file that OWNS the approvals wire-code contract did
// not pin the row, so a reader auditing wire codes here saw a gap that a
// strip-contract file was silently covering. That is the gap this case
// closes, and naming §7 here is half the fix — an unlabelled duplicate is
// what got the card mis-filed in the first place.
//
// The service suites (`recall-refusal-user-copy.test.ts`,
// `approval-revise.test.ts`) are NOT pins on this row: they assert the
// `FORBIDDEN:` MESSAGE PREFIX at the throw site, a different fact from
// what the route answers.
//
// Losing the row FAILS CLOSED, which is why this is a contract pin and not
// a security one: `handleApprovalError` returns false on no match, the
// caller rethrows, and the terminal catch answers 500
// `APPROVAL_RECALL_FAILED`. The caller is still refused — at the wrong
// status, with the wrong code, and (because that arm forwards
// `String(error?.message ?? error)` verbatim) with the raw `FORBIDDEN: `
// token the [#13095] anchored strip exists to remove. Two contract
// properties ride this one row, so the third assertion below is NOT
// redundant with the first two: it is what catches the degraded shape's
// unstripped message. (Ablation: all three reds read
// `expected 500 to be 403`.)
it('recall by a non-submitter answers 403 FORBIDDEN, prefix stripped — the row every authorisation refusal rides', async () => {
// The message the real service throws: `approval-service.ts`'s recall
// non-submitter branch is `FORBIDDEN: ${userFacingRefusal(...)}`.
// Read from the catalog rather than transcribed so a [#11993] copy
// edit cannot red this pin for a reason that is not the wire contract
// — the same construction `approval-revise.test.ts` uses.
const refusal = BUILTIN_OPERATION_MESSAGES.en.approval_recall_not_submitter;
const rest = boot({
recall: vi.fn().mockRejectedValue(new Error(`FORBIDDEN: ${refusal}`)),
});
const answer = await drive(rest, 'POST', `${REQ}/recall`);
expect(answer.status).toBe(403);
expect(answer.body?.code).toBe('FORBIDDEN');
// [#13095] Exactly the `FORBIDDEN:` this row just answered comes off,
// and the user-facing sentence reaches the wire whole.
expect(answer.body?.error).toBe(refusal);
expect(
ApiErrorSchema.safeParse({ code: answer.body?.code, message: answer.body?.error }).success,
'FORBIDDEN must be in StandardErrorCode ∪ ERROR_CODE_LEDGER',
).toBe(true);
});

// [#13182] `READ_BACK_FAILED` is a NAMED wire row (the RESUME_FAILED
// precedent: a genuine server-side inconsistency, but named): the write is
// recorded and NOT rolled back, the read-back is org-filtered, and the
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length \u003e 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
65 changes: 65 additions & 0 deletions packages/rest/src/rest-approvals-wire-codes.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -28,13 +28,20 @@
* route. The derivation mirrors the production template exactly
* (single-occurrence `.replace('-', '_')` included), so a route name the
* template would mangle into an invalid code also fails here.
* [#14573] The file has since become the home for the approvals door's
* live-emission pins generally, not only the #8885 population: the
* `FORBIDDEN` → 403 case below pins a row that is registered vocabulary and
* whose emission was — contrary to that card's premise — already observed
* elsewhere. See its own comment for where, and why it is pinned here too.
*
* 3. The union stays CLOSED — the control case in
* `rest-field-visibility-fault-envelope.test.ts` covers this file too (same
* schema instance); membership green here is evidence, not vacuity.
*/

import { describe, it, expect, vi } from 'vitest';
import { ApiErrorSchema } from '@objectstack/spec/api';
import { BUILTIN_OPERATION_MESSAGES } from '@objectstack/spec/system';
// `.js` on purpose — NodeNext resolution requires the extension (#7248).
import { RestServer } from './rest-server.js';

Expand DownExpand Up@@ -115,6 +122,64 @@ describe('approvals wire codes are registered vocabulary (#8885)', () => {
).toBe(true);
});

// [#14573] The `FORBIDDEN` → 403 row is the one EVERY authorisation
// refusal rides: recall by a non-submitter, decide by a non-approver,
// reassign / remind / sendBack / resubmit by the wrong actor, and
// `resolveActor`'s impersonation refusals all reach this table through
// the same single row.
//
// ⚠️ THIS IS A SECOND PIN, NOT THE FIRST — read this before adding a
// third. #14573 was filed and triaged on the reading that the row had NO
// live-emission pin, and that reading is WRONG: §7 of
// `rest-data-door-code-prefix.test.ts` ("[#13095] the approvals door
// strips the code it answers") already drives the REAL approve route with
// a `FORBIDDEN: …` throw and already asserts 403, `code: 'FORBIDDEN'` and
// the strip. Measured, not read: deleting the row from `rest-server.ts`
// reds THREE cases — this one and both of §7's. What was true is narrower
// than the card: the file that OWNS the approvals wire-code contract did
// not pin the row, so a reader auditing wire codes here saw a gap that a
// strip-contract file was silently covering. That is the gap this case
// closes, and naming §7 here is half the fix — an unlabelled duplicate is
// what got the card mis-filed in the first place.
//
// The service suites (`recall-refusal-user-copy.test.ts`,
// `approval-revise.test.ts`) are NOT pins on this row: they assert the
// `FORBIDDEN:` MESSAGE PREFIX at the throw site, a different fact from
// what the route answers.
//
// Losing the row FAILS CLOSED, which is why this is a contract pin and not
// a security one: `handleApprovalError` returns false on no match, the
// caller rethrows, and the terminal catch answers 500
// `APPROVAL_RECALL_FAILED`. The caller is still refused — at the wrong
// status, with the wrong code, and (because that arm forwards
// `String(error?.message ?? error)` verbatim) with the raw `FORBIDDEN: `
// token the [#13095] anchored strip exists to remove. Two contract
// properties ride this one row, so the third assertion below is NOT
// redundant with the first two: it is what catches the degraded shape's
// unstripped message. (Ablation: all three reds read
// `expected 500 to be 403`.)
it('recall by a non-submitter answers 403 FORBIDDEN, prefix stripped — the row every authorisation refusal rides', async () => {
// The message the real service throws: `approval-service.ts`'s recall
// non-submitter branch is `FORBIDDEN: ${userFacingRefusal(...)}`.
// Read from the catalog rather than transcribed so a [#11993] copy
// edit cannot red this pin for a reason that is not the wire contract
// — the same construction `approval-revise.test.ts` uses.
const refusal = BUILTIN_OPERATION_MESSAGES.en.approval_recall_not_submitter;
const rest = boot({
recall: vi.fn().mockRejectedValue(new Error(`FORBIDDEN: ${refusal}`)),
});
const answer = await drive(rest, 'POST', `${REQ}/recall`);
expect(answer.status).toBe(403);
expect(answer.body?.code).toBe('FORBIDDEN');
// [#13095] Exactly the `FORBIDDEN:` this row just answered comes off,
// and the user-facing sentence reaches the wire whole.
expect(answer.body?.error).toBe(refusal);
expect(
ApiErrorSchema.safeParse({ code: answer.body?.code, message: answer.body?.error }).success,
'FORBIDDEN must be in StandardErrorCode ∪ ERROR_CODE_LEDGER',
).toBe(true);
});

// [#13182] `READ_BACK_FAILED` is a NAMED wire row (the RESUME_FAILED
// precedent: a genuine server-side inconsistency, but named): the write is
// recorded and NOT rolled back, the read-back is org-filtered, and the
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
65 changes: 65 additions & 0 deletions packages/rest/src/rest-approvals-wire-codes.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -28,13 +28,20 @@
* route. The derivation mirrors the production template exactly
* (single-occurrence `.replace('-', '_')` included), so a route name the
* template would mangle into an invalid code also fails here.
* [#14573] The file has since become the home for the approvals door's
* live-emission pins generally, not only the #8885 population: the
* `FORBIDDEN` → 403 case below pins a row that is registered vocabulary and
* whose emission was — contrary to that card's premise — already observed
* elsewhere. See its own comment for where, and why it is pinned here too.
*
* 3. The union stays CLOSED — the control case in
* `rest-field-visibility-fault-envelope.test.ts` covers this file too (same
* schema instance); membership green here is evidence, not vacuity.
*/

import { describe, it, expect, vi } from 'vitest';
import { ApiErrorSchema } from '@objectstack/spec/api';
import { BUILTIN_OPERATION_MESSAGES } from '@objectstack/spec/system';
// `.js` on purpose — NodeNext resolution requires the extension (#7248).
import { RestServer } from './rest-server.js';

Expand DownExpand Up@@ -115,6 +122,64 @@ describe('approvals wire codes are registered vocabulary (#8885)', () => {
).toBe(true);
});

// [#14573] The `FORBIDDEN` → 403 row is the one EVERY authorisation
// refusal rides: recall by a non-submitter, decide by a non-approver,
// reassign / remind / sendBack / resubmit by the wrong actor, and
// `resolveActor`'s impersonation refusals all reach this table through
// the same single row.
//
// ⚠️ THIS IS A SECOND PIN, NOT THE FIRST — read this before adding a
// third. #14573 was filed and triaged on the reading that the row had NO
// live-emission pin, and that reading is WRONG: §7 of
// `rest-data-door-code-prefix.test.ts` ("[#13095] the approvals door
// strips the code it answers") already drives the REAL approve route with
// a `FORBIDDEN: …` throw and already asserts 403, `code: 'FORBIDDEN'` and
// the strip. Measured, not read: deleting the row from `rest-server.ts`
// reds THREE cases — this one and both of §7's. What was true is narrower
// than the card: the file that OWNS the approvals wire-code contract did
// not pin the row, so a reader auditing wire codes here saw a gap that a
// strip-contract file was silently covering. That is the gap this case
// closes, and naming §7 here is half the fix — an unlabelled duplicate is
// what got the card mis-filed in the first place.
//
// The service suites (`recall-refusal-user-copy.test.ts`,
// `approval-revise.test.ts`) are NOT pins on this row: they assert the
// `FORBIDDEN:` MESSAGE PREFIX at the throw site, a different fact from
// what the route answers.
//
// Losing the row FAILS CLOSED, which is why this is a contract pin and not
// a security one: `handleApprovalError` returns false on no match, the
// caller rethrows, and the terminal catch answers 500
// `APPROVAL_RECALL_FAILED`. The caller is still refused — at the wrong
// status, with the wrong code, and (because that arm forwards
// `String(error?.message ?? error)` verbatim) with the raw `FORBIDDEN: `
// token the [#13095] anchored strip exists to remove. Two contract
// properties ride this one row, so the third assertion below is NOT
// redundant with the first two: it is what catches the degraded shape's
// unstripped message. (Ablation: all three reds read
// `expected 500 to be 403`.)
it('recall by a non-submitter answers 403 FORBIDDEN, prefix stripped — the row every authorisation refusal rides', async () => {
// The message the real service throws: `approval-service.ts`'s recall
// non-submitter branch is `FORBIDDEN: ${userFacingRefusal(...)}`.
// Read from the catalog rather than transcribed so a [#11993] copy
// edit cannot red this pin for a reason that is not the wire contract
// — the same construction `approval-revise.test.ts` uses.
const refusal = BUILTIN_OPERATION_MESSAGES.en.approval_recall_not_submitter;
const rest = boot({
recall: vi.fn().mockRejectedValue(new Error(`FORBIDDEN: ${refusal}`)),
});
const answer = await drive(rest, 'POST', `${REQ}/recall`);
expect(answer.status).toBe(403);
expect(answer.body?.code).toBe('FORBIDDEN');
// [#13095] Exactly the `FORBIDDEN:` this row just answered comes off,
// and the user-facing sentence reaches the wire whole.
expect(answer.body?.error).toBe(refusal);
expect(
ApiErrorSchema.safeParse({ code: answer.body?.code, message: answer.body?.error }).success,
'FORBIDDEN must be in StandardErrorCode ∪ ERROR_CODE_LEDGER',
).toBe(true);
});

// [#13182] `READ_BACK_FAILED` is a NAMED wire row (the RESUME_FAILED
// precedent: a genuine server-side inconsistency, but named): the write is
// recorded and NOT rolled back, the read-back is org-filtered, and the
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
65 changes: 65 additions & 0 deletions packages/rest/src/rest-approvals-wire-codes.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -28,13 +28,20 @@
* route. The derivation mirrors the production template exactly
* (single-occurrence `.replace('-', '_')` included), so a route name the
* template would mangle into an invalid code also fails here.
* [#14573] The file has since become the home for the approvals door's
* live-emission pins generally, not only the #8885 population: the
* `FORBIDDEN` → 403 case below pins a row that is registered vocabulary and
* whose emission was — contrary to that card's premise — already observed
* elsewhere. See its own comment for where, and why it is pinned here too.
*
* 3. The union stays CLOSED — the control case in
* `rest-field-visibility-fault-envelope.test.ts` covers this file too (same
* schema instance); membership green here is evidence, not vacuity.
*/

import { describe, it, expect, vi } from 'vitest';
import { ApiErrorSchema } from '@objectstack/spec/api';
import { BUILTIN_OPERATION_MESSAGES } from '@objectstack/spec/system';
// `.js` on purpose — NodeNext resolution requires the extension (#7248).
import { RestServer } from './rest-server.js';

Expand DownExpand Up@@ -115,6 +122,64 @@ describe('approvals wire codes are registered vocabulary (#8885)', () => {
).toBe(true);
});

// [#14573] The `FORBIDDEN` → 403 row is the one EVERY authorisation
// refusal rides: recall by a non-submitter, decide by a non-approver,
// reassign / remind / sendBack / resubmit by the wrong actor, and
// `resolveActor`'s impersonation refusals all reach this table through
// the same single row.
//
// ⚠️ THIS IS A SECOND PIN, NOT THE FIRST — read this before adding a
// third. #14573 was filed and triaged on the reading that the row had NO
// live-emission pin, and that reading is WRONG: §7 of
// `rest-data-door-code-prefix.test.ts` ("[#13095] the approvals door
// strips the code it answers") already drives the REAL approve route with
// a `FORBIDDEN: …` throw and already asserts 403, `code: 'FORBIDDEN'` and
// the strip. Measured, not read: deleting the row from `rest-server.ts`
// reds THREE cases — this one and both of §7's. What was true is narrower
// than the card: the file that OWNS the approvals wire-code contract did
// not pin the row, so a reader auditing wire codes here saw a gap that a
// strip-contract file was silently covering. That is the gap this case
// closes, and naming §7 here is half the fix — an unlabelled duplicate is
// what got the card mis-filed in the first place.
//
// The service suites (`recall-refusal-user-copy.test.ts`,
// `approval-revise.test.ts`) are NOT pins on this row: they assert the
// `FORBIDDEN:` MESSAGE PREFIX at the throw site, a different fact from
// what the route answers.
//
// Losing the row FAILS CLOSED, which is why this is a contract pin and not
// a security one: `handleApprovalError` returns false on no match, the
// caller rethrows, and the terminal catch answers 500
// `APPROVAL_RECALL_FAILED`. The caller is still refused — at the wrong
// status, with the wrong code, and (because that arm forwards
// `String(error?.message ?? error)` verbatim) with the raw `FORBIDDEN: `
// token the [#13095] anchored strip exists to remove. Two contract
// properties ride this one row, so the third assertion below is NOT
// redundant with the first two: it is what catches the degraded shape's
// unstripped message. (Ablation: all three reds read
// `expected 500 to be 403`.)
it('recall by a non-submitter answers 403 FORBIDDEN, prefix stripped — the row every authorisation refusal rides', async () => {
// The message the real service throws: `approval-service.ts`'s recall
// non-submitter branch is `FORBIDDEN: ${userFacingRefusal(...)}`.
// Read from the catalog rather than transcribed so a [#11993] copy
// edit cannot red this pin for a reason that is not the wire contract
// — the same construction `approval-revise.test.ts` uses.
const refusal = BUILTIN_OPERATION_MESSAGES.en.approval_recall_not_submitter;
const rest = boot({
recall: vi.fn().mockRejectedValue(new Error(`FORBIDDEN: ${refusal}`)),
});
const answer = await drive(rest, 'POST', `${REQ}/recall`);
expect(answer.status).toBe(403);
expect(answer.body?.code).toBe('FORBIDDEN');
// [#13095] Exactly the `FORBIDDEN:` this row just answered comes off,
// and the user-facing sentence reaches the wire whole.
expect(answer.body?.error).toBe(refusal);
expect(
ApiErrorSchema.safeParse({ code: answer.body?.code, message: answer.body?.error }).success,
'FORBIDDEN must be in StandardErrorCode ∪ ERROR_CODE_LEDGER',
).toBe(true);
});

// [#13182] `READ_BACK_FAILED` is a NAMED wire row (the RESUME_FAILED
// precedent: a genuine server-side inconsistency, but named): the write is
// recorded and NOT rolled back, the read-back is org-filtered, and the
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
65 changes: 65 additions & 0 deletions packages/rest/src/rest-approvals-wire-codes.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -28,13 +28,20 @@
* route. The derivation mirrors the production template exactly
* (single-occurrence `.replace('-', '_')` included), so a route name the
* template would mangle into an invalid code also fails here.
* [#14573] The file has since become the home for the approvals door's
* live-emission pins generally, not only the #8885 population: the
* `FORBIDDEN` → 403 case below pins a row that is registered vocabulary and
* whose emission was — contrary to that card's premise — already observed
* elsewhere. See its own comment for where, and why it is pinned here too.
*
* 3. The union stays CLOSED — the control case in
* `rest-field-visibility-fault-envelope.test.ts` covers this file too (same
* schema instance); membership green here is evidence, not vacuity.
*/

import { describe, it, expect, vi } from 'vitest';
import { ApiErrorSchema } from '@objectstack/spec/api';
import { BUILTIN_OPERATION_MESSAGES } from '@objectstack/spec/system';
// `.js` on purpose — NodeNext resolution requires the extension (#7248).
import { RestServer } from './rest-server.js';

Expand DownExpand Up@@ -115,6 +122,64 @@ describe('approvals wire codes are registered vocabulary (#8885)', () => {
).toBe(true);
});

// [#14573] The `FORBIDDEN` → 403 row is the one EVERY authorisation
// refusal rides: recall by a non-submitter, decide by a non-approver,
// reassign / remind / sendBack / resubmit by the wrong actor, and
// `resolveActor`'s impersonation refusals all reach this table through
// the same single row.
//
// ⚠️ THIS IS A SECOND PIN, NOT THE FIRST — read this before adding a
// third. #14573 was filed and triaged on the reading that the row had NO
// live-emission pin, and that reading is WRONG: §7 of
// `rest-data-door-code-prefix.test.ts` ("[#13095] the approvals door
// strips the code it answers") already drives the REAL approve route with
// a `FORBIDDEN: …` throw and already asserts 403, `code: 'FORBIDDEN'` and
// the strip. Measured, not read: deleting the row from `rest-server.ts`
// reds THREE cases — this one and both of §7's. What was true is narrower
// than the card: the file that OWNS the approvals wire-code contract did
// not pin the row, so a reader auditing wire codes here saw a gap that a
// strip-contract file was silently covering. That is the gap this case
// closes, and naming §7 here is half the fix — an unlabelled duplicate is
// what got the card mis-filed in the first place.
//
// The service suites (`recall-refusal-user-copy.test.ts`,
// `approval-revise.test.ts`) are NOT pins on this row: they assert the
// `FORBIDDEN:` MESSAGE PREFIX at the throw site, a different fact from
// what the route answers.
//
// Losing the row FAILS CLOSED, which is why this is a contract pin and not
// a security one: `handleApprovalError` returns false on no match, the
// caller rethrows, and the terminal catch answers 500
// `APPROVAL_RECALL_FAILED`. The caller is still refused — at the wrong
// status, with the wrong code, and (because that arm forwards
// `String(error?.message ?? error)` verbatim) with the raw `FORBIDDEN: `
// token the [#13095] anchored strip exists to remove. Two contract
// properties ride this one row, so the third assertion below is NOT
// redundant with the first two: it is what catches the degraded shape's
// unstripped message. (Ablation: all three reds read
// `expected 500 to be 403`.)
it('recall by a non-submitter answers 403 FORBIDDEN, prefix stripped — the row every authorisation refusal rides', async () => {
// The message the real service throws: `approval-service.ts`'s recall
// non-submitter branch is `FORBIDDEN: ${userFacingRefusal(...)}`.
// Read from the catalog rather than transcribed so a [#11993] copy
// edit cannot red this pin for a reason that is not the wire contract
// — the same construction `approval-revise.test.ts` uses.
const refusal = BUILTIN_OPERATION_MESSAGES.en.approval_recall_not_submitter;
const rest = boot({
recall: vi.fn().mockRejectedValue(new Error(`FORBIDDEN: ${refusal}`)),
});
const answer = await drive(rest, 'POST', `${REQ}/recall`);
expect(answer.status).toBe(403);
expect(answer.body?.code).toBe('FORBIDDEN');
// [#13095] Exactly the `FORBIDDEN:` this row just answered comes off,
// and the user-facing sentence reaches the wire whole.
expect(answer.body?.error).toBe(refusal);
expect(
ApiErrorSchema.safeParse({ code: answer.body?.code, message: answer.body?.error }).success,
'FORBIDDEN must be in StandardErrorCode ∪ ERROR_CODE_LEDGER',
).toBe(true);
});

// [#13182] `READ_BACK_FAILED` is a NAMED wire row (the RESUME_FAILED
// precedent: a genuine server-side inconsistency, but named): the write is
// recorded and NOT rolled back, the read-back is org-filtered, and the
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
65 changes: 65 additions & 0 deletions packages/rest/src/rest-approvals-wire-codes.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -28,13 +28,20 @@
* route. The derivation mirrors the production template exactly
* (single-occurrence `.replace('-', '_')` included), so a route name the
* template would mangle into an invalid code also fails here.
* [#14573] The file has since become the home for the approvals door's
* live-emission pins generally, not only the #8885 population: the
* `FORBIDDEN` → 403 case below pins a row that is registered vocabulary and
* whose emission was — contrary to that card's premise — already observed
* elsewhere. See its own comment for where, and why it is pinned here too.
*
* 3. The union stays CLOSED — the control case in
* `rest-field-visibility-fault-envelope.test.ts` covers this file too (same
* schema instance); membership green here is evidence, not vacuity.
*/

import { describe, it, expect, vi } from 'vitest';
import { ApiErrorSchema } from '@objectstack/spec/api';
import { BUILTIN_OPERATION_MESSAGES } from '@objectstack/spec/system';
// `.js` on purpose — NodeNext resolution requires the extension (#7248).
import { RestServer } from './rest-server.js';

Expand DownExpand Up@@ -115,6 +122,64 @@ describe('approvals wire codes are registered vocabulary (#8885)', () => {
).toBe(true);
});

// [#14573] The `FORBIDDEN` → 403 row is the one EVERY authorisation
// refusal rides: recall by a non-submitter, decide by a non-approver,
// reassign / remind / sendBack / resubmit by the wrong actor, and
// `resolveActor`'s impersonation refusals all reach this table through
// the same single row.
//
// ⚠️ THIS IS A SECOND PIN, NOT THE FIRST — read this before adding a
// third. #14573 was filed and triaged on the reading that the row had NO
// live-emission pin, and that reading is WRONG: §7 of
// `rest-data-door-code-prefix.test.ts` ("[#13095] the approvals door
// strips the code it answers") already drives the REAL approve route with
// a `FORBIDDEN: …` throw and already asserts 403, `code: 'FORBIDDEN'` and
// the strip. Measured, not read: deleting the row from `rest-server.ts`
// reds THREE cases — this one and both of §7's. What was true is narrower
// than the card: the file that OWNS the approvals wire-code contract did
// not pin the row, so a reader auditing wire codes here saw a gap that a
// strip-contract file was silently covering. That is the gap this case
// closes, and naming §7 here is half the fix — an unlabelled duplicate is
// what got the card mis-filed in the first place.
//
// The service suites (`recall-refusal-user-copy.test.ts`,
// `approval-revise.test.ts`) are NOT pins on this row: they assert the
// `FORBIDDEN:` MESSAGE PREFIX at the throw site, a different fact from
// what the route answers.
//
// Losing the row FAILS CLOSED, which is why this is a contract pin and not
// a security one: `handleApprovalError` returns false on no match, the
// caller rethrows, and the terminal catch answers 500
// `APPROVAL_RECALL_FAILED`. The caller is still refused — at the wrong
// status, with the wrong code, and (because that arm forwards
// `String(error?.message ?? error)` verbatim) with the raw `FORBIDDEN: `
// token the [#13095] anchored strip exists to remove. Two contract
// properties ride this one row, so the third assertion below is NOT
// redundant with the first two: it is what catches the degraded shape's
// unstripped message. (Ablation: all three reds read
// `expected 500 to be 403`.)
it('recall by a non-submitter answers 403 FORBIDDEN, prefix stripped — the row every authorisation refusal rides', async () => {
// The message the real service throws: `approval-service.ts`'s recall
// non-submitter branch is `FORBIDDEN: ${userFacingRefusal(...)}`.
// Read from the catalog rather than transcribed so a [#11993] copy
// edit cannot red this pin for a reason that is not the wire contract
// — the same construction `approval-revise.test.ts` uses.
const refusal = BUILTIN_OPERATION_MESSAGES.en.approval_recall_not_submitter;
const rest = boot({
recall: vi.fn().mockRejectedValue(new Error(`FORBIDDEN: ${refusal}`)),
});
const answer = await drive(rest, 'POST', `${REQ}/recall`);
expect(answer.status).toBe(403);
expect(answer.body?.code).toBe('FORBIDDEN');
// [#13095] Exactly the `FORBIDDEN:` this row just answered comes off,
// and the user-facing sentence reaches the wire whole.
expect(answer.body?.error).toBe(refusal);
expect(
ApiErrorSchema.safeParse({ code: answer.body?.code, message: answer.body?.error }).success,
'FORBIDDEN must be in StandardErrorCode ∪ ERROR_CODE_LEDGER',
).toBe(true);
});

// [#13182] `READ_BACK_FAILED` is a NAMED wire row (the RESUME_FAILED
// precedent: a genuine server-side inconsistency, but named): the write is
// recorded and NOT rolled back, the read-back is org-filtered, and the
Expand Down
Loading