From b364b8179bc3593533e017328ea8fbf7f7d4bc69 Mon Sep 17 00:00:00 2001 From: Claude Date: Mon, 5 Oct 2026 01:07:47 +0000 Subject: [PATCH] test(spec): security, ai, identity, integration, migrations, marketplace, meta-spelling and studio test titles state each cited decision in words instead of a tracker number (stage 14) The eight small directories under packages/spec/src: 89 test titles and declared test strings that carried 94 tracker ids now state what the cited record decided, in words, or drop a number the title already explains. Text only: no assertion, identifier, test count or code comment changes. The two build-progress assertion needles that pin the source docblock's own carrier names stay. Claude-Session: https://claude.ai/code/session_01T9u38rswFp5Rw8DswRUReJ Co-authored-by: Claude --- packages/spec/src/ai/agent.test.ts | 2 +- packages/spec/src/ai/conversation.test.ts | 4 ++-- packages/spec/src/ai/knowledge-source.test.ts | 6 +++--- ...skill-trigger-condition-value-shape.test.ts | 12 ++++++------ packages/spec/src/ai/skill.test.ts | 2 +- .../spec/src/ai/solution-blueprint.test.ts | 2 +- ...confirmation-prescription-tense.pin.test.ts | 2 +- packages/spec/src/ai/tool.test.ts | 2 +- .../src/identity/api-key-retirement.test.ts | 4 ++-- packages/spec/src/identity/identity.test.ts | 4 ++-- .../spec/src/identity/organization.test.ts | 10 +++++----- .../platform-admin-capabilities.test.ts | 6 +++--- .../position-delegatable-enforcer.pin.test.ts | 2 +- packages/spec/src/identity/position.test.ts | 4 ++-- .../integration/connector-author-shape.test.ts | 8 ++++---- .../connector-provider-errors.test.ts | 2 +- .../src/integration/connector-provider.test.ts | 2 +- .../spec/src/integration/connector.test.ts | 16 ++++++++-------- .../src/marketplace/package-namespace.test.ts | 2 +- .../marketplace/template-manifest-id.test.ts | 4 ++-- .../manifest-collection-spelling.test.ts | 4 ++-- .../spec/src/migrations/migrations.test.ts | 16 ++++++++-------- .../spec-changes-surface-scope.test.ts | 2 +- packages/spec/src/security/explain.test.ts | 14 +++++++------- .../spec/src/security/high-privilege.test.ts | 4 ++-- packages/spec/src/security/permission.test.ts | 18 +++++++++--------- .../rls-predicate-grammar-docs.pin.test.ts | 2 +- packages/spec/src/security/rls.test.ts | 6 +++--- packages/spec/src/security/sharing.test.ts | 4 ++-- .../spec/src/security/tenancy-posture.test.ts | 4 ++-- .../src/security/tenant-layer0-verdict.test.ts | 4 ++-- .../studio/action-location-retirement.test.ts | 2 +- packages/spec/src/studio/flow-builder.test.ts | 2 +- 33 files changed, 89 insertions(+), 89 deletions(-) diff --git a/packages/spec/src/ai/agent.test.ts b/packages/spec/src/ai/agent.test.ts index 35920b85dc4..5224c1799bc 100644 --- a/packages/spec/src/ai/agent.test.ts +++ b/packages/spec/src/ai/agent.test.ts @@ -71,7 +71,7 @@ describe('AIModelConfigSchema', () => { }); }); -describe('agent.tools retirement (ADR-0064 / #3820, tombstoned in #3894)', () => { +describe('agent.tools retirement (ADR-0064) — tombstoned; tools move into skills', () => { it('REJECTS a legacy inline tools array, with the fix in the message', () => { // Tombstoned, not deleted: AgentSchema is `strictObject`, so a plain // deletion would reject the key with a generic unknown-key error. diff --git a/packages/spec/src/ai/conversation.test.ts b/packages/spec/src/ai/conversation.test.ts index 67a38a4ee0c..1ca3ef626f7 100644 --- a/packages/spec/src/ai/conversation.test.ts +++ b/packages/spec/src/ai/conversation.test.ts @@ -291,7 +291,7 @@ describe('ConversationSessionSchema', () => { it('should accept full session with messages', () => { const session = { id: 'session-1', - name: 'Support Chat - Case #123', + name: 'Support Chat - Case', context: { sessionId: 'session-1', userId: 'user-1', @@ -590,7 +590,7 @@ describe('Real-World Conversation Examples', () => { // `ConversationAnalytics` is runtime-emitted, so the silent-strip alternative // is the real hazard: this shape is not strict, and a producer still writing // `duration` would have lost the one measurement on the row with no error at all. -describe('ConversationAnalytics.duration carries its unit (#15680)', () => { +describe('ConversationAnalytics.duration carries its unit', () => { const base = { sessionId: 'session-1', totalMessages: 10, diff --git a/packages/spec/src/ai/knowledge-source.test.ts b/packages/spec/src/ai/knowledge-source.test.ts index ca1523985e2..c7cf09cf6b7 100644 --- a/packages/spec/src/ai/knowledge-source.test.ts +++ b/packages/spec/src/ai/knowledge-source.test.ts @@ -48,7 +48,7 @@ const SOURCE: KnowledgeSource = { const CRON_5_FIELD = '0 3 * * *'; -describe('KnowledgeRefreshPolicySchema.cron — the typed cron slot (#14825)', () => { +describe('KnowledgeRefreshPolicySchema.cron — the typed cron slot', () => { it('positive control: a 5-field cron on a full knowledge source parses and normalizes to the cron envelope', () => { const r = KnowledgeSourceSchema.safeParse({ ...SOURCE, refresh: { cron: CRON_5_FIELD } }); expect(r.success, r.success ? '' : JSON.stringify(r.error.issues)).toBe(true); @@ -94,8 +94,8 @@ describe('KnowledgeRefreshPolicySchema.cron — the typed cron slot (#14825)', ( }); it.each([ - ['a dialect the protocol does not declare (`js`, retired at #3278, ADR-0058 addendum)', 'js'], - ['a declared dialect that is not this slot\'s (`cel`, #15028)', 'cel'], + ['a dialect the protocol does not declare (`js`, a retired expression dialect, ADR-0058 addendum)', 'js'], + ['a declared dialect that is not this slot\'s (`cel`)', 'cel'], ])('refuses an envelope naming %s with ONE `invalid_union` at `cron` whose message is the cron dialect-only sentence', (_label, dialect) => { const r = KnowledgeRefreshPolicySchema.safeParse({ cron: { dialect, source: 'x' } }); expect(r.success).toBe(false); diff --git a/packages/spec/src/ai/skill-trigger-condition-value-shape.test.ts b/packages/spec/src/ai/skill-trigger-condition-value-shape.test.ts index 9c8a88f8c48..9ef0561865c 100644 --- a/packages/spec/src/ai/skill-trigger-condition-value-shape.test.ts +++ b/packages/spec/src/ai/skill-trigger-condition-value-shape.test.ts @@ -44,7 +44,7 @@ function valueIssue(result: ReturnType) { return issues[0]!; } -describe('#7113 — the reported shape is refused at authoring time', () => { +describe('a set operator carrying a scalar is refused at authoring time', () => { it('refuses the card example: a set operator carrying a scalar', () => { const result = parse({ field: 'userRole', operator: 'in', value: 'admin' }); const issue = valueIssue(result); @@ -72,7 +72,7 @@ describe('#7113 — the reported shape is refused at authoring time', () => { }); }); -describe('#7113 — list operators require an array', () => { +describe('list operators require an array', () => { it.each(SKILL_TRIGGER_LIST_VALUE_OPERATORS)('%s refuses a scalar', (operator) => { const issue = valueIssue(parse({ field: 'objectName', operator, value: 'lead' })); expect(issue.code).toBe('custom'); @@ -109,7 +109,7 @@ describe('#7113 — list operators require an array', () => { }); }); -describe('#7113 — identity operators require a string', () => { +describe('identity operators require a string', () => { it.each(SKILL_TRIGGER_SCALAR_VALUE_OPERATORS)('%s refuses an array', (operator) => { const issue = valueIssue(parse({ field: 'objectName', operator, value: ['lead'] })); expect(issue.code).toBe('custom'); @@ -127,7 +127,7 @@ describe('#7113 — identity operators require a string', () => { }); }); -describe('#7113 — `contains` keeps BOTH shapes (#5685: no stricter than the runtime)', () => { +describe('`contains` keeps BOTH shapes — no stricter than the runtime', () => { it('accepts a string comparand — the substring branch', () => { expect(parse({ field: 'viewName', operator: 'contains', value: 'kanban' }).success).toBe(true); }); @@ -147,7 +147,7 @@ describe('#7113 — `contains` keeps BOTH shapes (#5685: no stricter than the ru }); }); -describe('#7113 — the exported vocabularies are the contract, not a copy', () => { +describe('the exported vocabularies are the contract, not a copy', () => { it('the two vocabularies are disjoint and both subsets of the operator enum', () => { const all = [ ...SKILL_TRIGGER_LIST_VALUE_OPERATORS, @@ -172,7 +172,7 @@ describe('#7113 — the exported vocabularies are the contract, not a copy', () }); }); -describe('#7113 — the refinement does not disturb the carrier', () => { +describe('the value-shape refinement does not disturb the carrier', () => { it('an unrelated operator/value pair still parses through Skill.triggerConditions', () => { const skill = SkillSchema.parse({ name: 'order_management', diff --git a/packages/spec/src/ai/skill.test.ts b/packages/spec/src/ai/skill.test.ts index b0835ea87b5..e0325a06fbe 100644 --- a/packages/spec/src/ai/skill.test.ts +++ b/packages/spec/src/ai/skill.test.ts @@ -192,7 +192,7 @@ describe('defineSkill', () => { }); }); -describe('#3896 close-out — retired `triggerPhrases`', () => { +describe('retired `triggerPhrases` — phrases never routed a skill; triggerConditions do', () => { it('REJECTS the retired key with the routing prescription', () => { let message = ''; try { diff --git a/packages/spec/src/ai/solution-blueprint.test.ts b/packages/spec/src/ai/solution-blueprint.test.ts index e63bde02f5f..5b2fd2a4e10 100644 --- a/packages/spec/src/ai/solution-blueprint.test.ts +++ b/packages/spec/src/ai/solution-blueprint.test.ts @@ -671,7 +671,7 @@ describe('strict mirror ↔ lenient schema — key parity', () => { // because the model happened to retry with a repaired blueprint the user never // saw. Two declarations of one contract, disagreeing about values. // --------------------------------------------------------------------------- -describe('strict mirror ↔ lenient schema — VALUE parity (cloud#1967)', () => { +describe('strict mirror ↔ lenient schema — VALUE parity', () => { /** The regex a zod string leaf enforces, or null when it enforces none. */ const patternOf = (schema: any): string | null => { const checks = schema?.def?.checks; diff --git a/packages/spec/src/ai/tool-confirmation-prescription-tense.pin.test.ts b/packages/spec/src/ai/tool-confirmation-prescription-tense.pin.test.ts index 224366b540a..452d7937b2f 100644 --- a/packages/spec/src/ai/tool-confirmation-prescription-tense.pin.test.ts +++ b/packages/spec/src/ai/tool-confirmation-prescription-tense.pin.test.ts @@ -142,7 +142,7 @@ function aiDoorBody(): string { return source.slice(start, end === -1 ? source.length : end); } -describe('[#17487] the confirmation-gate prescriptions match the door that runs', () => { +describe('the confirmation-gate prescriptions match the door that runs', () => { it('anchors on real text in all three carriers', () => { // Anti-vacuity for every assertion below: an empty carrier would pass // "carries no denial" by reading nothing. diff --git a/packages/spec/src/ai/tool.test.ts b/packages/spec/src/ai/tool.test.ts index ec3b621b9ab..ef62ccc5168 100644 --- a/packages/spec/src/ai/tool.test.ts +++ b/packages/spec/src/ai/tool.test.ts @@ -250,7 +250,7 @@ describe('defineTool', () => { expect(message).not.toContain('Did you mean'); }); - it('emission order: which key is wrong → the fix → the history, last (#5955)', () => { + it('emission order: which key is wrong → the fix → the history, last', () => { // The template's ordering contract, asserted on this surface because the // fold is what brings this surface under it. `history` sat in the middle // until #5955 and pushed the fix past ~character 220 on the single-line diff --git a/packages/spec/src/identity/api-key-retirement.test.ts b/packages/spec/src/identity/api-key-retirement.test.ts index 7b60ded3497..e959a93ad14 100644 --- a/packages/spec/src/identity/api-key-retirement.test.ts +++ b/packages/spec/src/identity/api-key-retirement.test.ts @@ -52,7 +52,7 @@ import { // // Form follows #4988 / #5055 / #8075: resolved symbol identity over every // public entry via the build-time `export-origins/` artifact. -describe('[#8715] identity/ ApiKeySchema retirement', () => { +describe('identity/ ApiKeySchema retirement', () => { /** The 3 names the retired def exported (1 schema const + 2 types). */ const RETIRED_NAMES = ['ApiKeySchema', 'ApiKey', 'ApiKeyParsed'] as const; @@ -79,7 +79,7 @@ describe('[#8715] identity/ ApiKeySchema retirement', () => { // ── ABSENCE (every entry, not just ./identity) ──────────────────────── for (const name of RETIRED_NAMES) { - expect(holdersOf(name), `${name} must have zero holders after #8715`).toEqual([]); + expect(holdersOf(name), `${name} must have zero holders after the ApiKeySchema retirement`).toEqual([]); } // ── SURVIVAL ────────────────────────────────────────────────────────── diff --git a/packages/spec/src/identity/identity.test.ts b/packages/spec/src/identity/identity.test.ts index a50cf9a42f5..c7e0ce86139 100644 --- a/packages/spec/src/identity/identity.test.ts +++ b/packages/spec/src/identity/identity.test.ts @@ -85,7 +85,7 @@ describe('UserSchema', () => { * drop of `.url()` (which would start admitting `''` and `'not-a-url'`) goes * red here rather than passing as "still accepts null". */ -describe('[#18509] UserSchema.image accept set', () => { +describe('UserSchema.image accept set — null, the shape better-auth serves', () => { const base = { id: 'user_123', email: 'test@example.com', @@ -199,7 +199,7 @@ describe('AccountSchema', () => { }); }); -describe('Session is not declared here (#4641)', () => { +describe('Session is not declared here', () => { // Pin: this module no longer declares the bare `SessionSchema` name. The pin is // compile-time (`typeof import` is type-level only — no runtime barrel load): // if the name is re-added here, the conditional type flips to `true` and the diff --git a/packages/spec/src/identity/organization.test.ts b/packages/spec/src/identity/organization.test.ts index 5608b5a56f0..e87c0d3ad69 100644 --- a/packages/spec/src/identity/organization.test.ts +++ b/packages/spec/src/identity/organization.test.ts @@ -129,7 +129,7 @@ describe('OrganizationSchema', () => { * The whole accept set is pinned, not just the row that moved — see the sibling * block in `identity.test.ts` for why. */ -describe('[#18509] OrganizationSchema.logo accept set', () => { +describe('OrganizationSchema.logo accept set — null, the shape better-auth serves', () => { const base = { id: 'org_123', name: 'Acme Corporation', @@ -198,7 +198,7 @@ describe('[#18509] OrganizationSchema.logo accept set', () => { * "accepts the served body" and "stopped checking" are otherwise the same * green. */ - it('[#18728] accepts a served read-route body WHOLE — updatedAt absent, metadata decoded', () => { + it('accepts a served read-route body WHOLE — updatedAt absent, metadata decoded', () => { const served = { id: 'org_123', name: 'Acme Corporation', @@ -213,7 +213,7 @@ describe('[#18509] OrganizationSchema.logo accept set', () => { expect(result.success).toBe(true); }); - it('[#18728] accepts the same body with metadata OMITTED — an unset column', () => { + it('accepts the same body with metadata OMITTED — an unset column', () => { const { metadata: _unset, ...withoutMetadata } = { id: 'org_123', name: 'Acme Corporation', @@ -226,7 +226,7 @@ describe('[#18509] OrganizationSchema.logo accept set', () => { expect(result.success).toBe(true); }); - it('⭐ [#18728] still REFUSES metadata as null or as the stored JSON text', () => { + it('⭐ still REFUSES metadata as null or as the stored JSON text', () => { // The producer omits an unset column and decodes a set one, so neither of // these is a shape any route sends. They must stay refused: if either ever // parses, the producer has regressed or this schema has been loosened to @@ -245,7 +245,7 @@ describe('[#18509] OrganizationSchema.logo accept set', () => { } }); - it('⭐ [#18728] `.optional()` widened updatedAt by ABSENCE only — a present value is still a datetime', () => { + it('⭐ `.optional()` widened updatedAt by ABSENCE only — a present value is still a datetime', () => { const result = OrganizationSchema.safeParse({ id: 'org_123', name: 'Acme Corporation', diff --git a/packages/spec/src/identity/platform-admin-capabilities.test.ts b/packages/spec/src/identity/platform-admin-capabilities.test.ts index 7f7fdd52a59..402c6518e5a 100644 --- a/packages/spec/src/identity/platform-admin-capabilities.test.ts +++ b/packages/spec/src/identity/platform-admin-capabilities.test.ts @@ -7,7 +7,7 @@ import { ADMIN_FULL_ACCESS, ADMIN_FULL_ACCESS_CAPABILITIES } from './eval-user.z import { PermissionSetSchema } from '../security/permission.zod'; import { PLATFORM_CAPABILITIES, PLATFORM_CAPABILITY_NAMES } from '../security/capabilities'; -describe('ADMIN_FULL_ACCESS_CAPABILITIES (#11965, Choice 6A)', () => { +describe('ADMIN_FULL_ACCESS_CAPABILITIES — the one platform-admin list plugin-security imports', () => { it('carries exactly the two capability-bearing fields — name/label stay with the declaring package', () => { // The export is the capability CONTENT, not a permission set. `name` / // `label` (or any other authored field) creeping in here would make the @@ -31,7 +31,7 @@ describe('ADMIN_FULL_ACCESS_CAPABILITIES (#11965, Choice 6A)', () => { expect(parsed.objects['*'].modifyAllRecords).toBe(true); }); - it('the wildcard grants NO export — #8681 ruling pinned at the declaration\'s new home', () => { + it('the wildcard grants NO export — export stays an opt-in axis, pinned at the declaration\'s new home', () => { // [#3544/#8681] export is an OPT-IN axis, deliberately absent from the // super-user wildcard (maintainer ruling 2026-08-15). Moving the // declaration into spec must not resurrect it. @@ -40,7 +40,7 @@ describe('ADMIN_FULL_ACCESS_CAPABILITIES (#11965, Choice 6A)', () => { expect(parsed.objects['*'].allowExport).not.toBe(true); }); - it('[#21260] carries the compliance ledger’s audit capability, declared org-scoped', () => { + it('carries the compliance ledger’s audit capability, declared org-scoped', () => { // Ruling B on #21175: platform administrators hold it by default, through // this grant (and the config-derived envelope core builds from this same // list). The other shipped sets withhold it, pinned on the seeded sets in diff --git a/packages/spec/src/identity/position-delegatable-enforcer.pin.test.ts b/packages/spec/src/identity/position-delegatable-enforcer.pin.test.ts index 82228571c9f..bf694fad326 100644 --- a/packages/spec/src/identity/position-delegatable-enforcer.pin.test.ts +++ b/packages/spec/src/identity/position-delegatable-enforcer.pin.test.ts @@ -101,7 +101,7 @@ function unbackedRuleIds(prose: string, backed: Set): string[] { return [...new Set(named.filter((id) => !backed.has(id)))]; } -describe('`delegatable` JSDoc names only enforcers that exist (#6628)', () => { +describe('`delegatable` JSDoc names only enforcers that exist', () => { it('reads a real rule table off `packages/lint`', () => { const ids = declaredSecurityRuleIds(); // A floor, not an exact count — new security rules are expected. Its only diff --git a/packages/spec/src/identity/position.test.ts b/packages/spec/src/identity/position.test.ts index a6b1061395c..3ce598e9d56 100644 --- a/packages/spec/src/identity/position.test.ts +++ b/packages/spec/src/identity/position.test.ts @@ -232,7 +232,7 @@ describe('PositionSchema', () => { // ADR-0010 protection envelope the #4071 ledger flagged as the known sibling // gap (applyProtection stamps EVERY registered metadata type; position could // not represent the stamp). -describe('unknown keys are rejected, not stripped (#4001)', () => { +describe('unknown keys are rejected, not stripped', () => { const unknownKeyIssue = (value: unknown) => { const result = PositionSchema.safeParse(value); expect(result.success).toBe(false); @@ -253,7 +253,7 @@ describe('unknown keys are rejected, not stripped (#4001)', () => { .toContain('FLAT'); }); - it('points `permissions` at permission-set bindings (#9885, ADR-0049 retirement)', () => { + it('points `permissions` at permission-set bindings (ADR-0049 retirement)', () => { // The sys_position row column of the same name was retired (no producer, // no reader); this guidance is the live-authoring half of the // prescription — the migrate-meta half is the semantic entry diff --git a/packages/spec/src/integration/connector-author-shape.test.ts b/packages/spec/src/integration/connector-author-shape.test.ts index 78e1bd61be9..ca1f3a335a0 100644 --- a/packages/spec/src/integration/connector-author-shape.test.ts +++ b/packages/spec/src/integration/connector-author-shape.test.ts @@ -150,7 +150,7 @@ function typescriptBlocks(markdown: string): string[] { */ const ELISION = /\.\.\.\s*[,}\]]/; -describe('[#5515] SYNC_ARCHITECTURE.md L3 connector examples compile', () => { +describe('SYNC_ARCHITECTURE.md L3 connector examples compile', () => { const markdown = readFileSync(SYNC_ARCHITECTURE, 'utf8'); const allBlocks = typescriptBlocks(markdown); const connectorBlocks = allBlocks.filter((b) => b.includes('Connector')); @@ -214,7 +214,7 @@ describe('[#5515] SYNC_ARCHITECTURE.md L3 connector examples compile', () => { }); }); -describe('[#5515] the spellings the example used to carry are rejected', () => { +describe('the spellings the example used to carry are rejected', () => { // Reverse verification, direction stated BEFORE running: each probe below // restores one retired key into an otherwise-valid literal, and each must go // RED with a named diagnostic. Not "some diagnostic" — a bare non-empty check @@ -290,7 +290,7 @@ describe('[#5515] the spellings the example used to carry are rejected', () => { }); }); -describe('[#5515] the schema rejects them at RUNTIME too, and how it says so', () => { +describe('the schema rejects them at RUNTIME too, and how it says so', () => { // The compile probes above guard the TYPE surface. These guard the PARSE // surface, and they are not redundant with it: what an author is told when // they get it wrong is the difference between a fixable mistake and a @@ -337,7 +337,7 @@ describe('[#5515] the schema rejects them at RUNTIME too, and how it says so', ( }); }); -describe('[#5515] the bare `Connector` is the author shape; `ConnectorParsed` is the parse result', () => { +describe('the bare `Connector` is the author shape; `ConnectorParsed` is the parse result', () => { // The fourth diagnostic, pinned as an ANNOTATION fact rather than fixed by // renaming this file's aliases. Direction stated before running: the SAME // literal is green under the bare `Connector` and red under `ConnectorParsed`, diff --git a/packages/spec/src/integration/connector-provider-errors.test.ts b/packages/spec/src/integration/connector-provider-errors.test.ts index 304550a9d36..3b683590158 100644 --- a/packages/spec/src/integration/connector-provider-errors.test.ts +++ b/packages/spec/src/integration/connector-provider-errors.test.ts @@ -10,7 +10,7 @@ import { isConnectorUpstreamUnavailable, } from './connector-provider-errors'; -describe('#3017 — connector provider upstream-unavailable classification', () => { +describe('connector provider upstream-unavailable classification — an unreachable upstream degrades instead of aborting boot', () => { it('the error carries the marker code, a stable name, and the cause', () => { const cause = new Error('connect ECONNREFUSED 127.0.0.1:9999'); const err = new ConnectorUpstreamUnavailableError('mcp server unreachable', { cause }); diff --git a/packages/spec/src/integration/connector-provider.test.ts b/packages/spec/src/integration/connector-provider.test.ts index 483871ed6d4..335ee01eafc 100644 --- a/packages/spec/src/integration/connector-provider.test.ts +++ b/packages/spec/src/integration/connector-provider.test.ts @@ -88,7 +88,7 @@ describe('ADR-0097 connector schema evolution', () => { ).not.toThrow(); }); - it('rejects inline `authentication` secrets on a catalog descriptor (#7990)', () => { + it('rejects inline `authentication` secrets on a catalog descriptor', () => { const result = DeclarativeConnectorEntrySchema.safeParse({ name: 'legacy', label: 'Legacy', diff --git a/packages/spec/src/integration/connector.test.ts b/packages/spec/src/integration/connector.test.ts index 0a3648b6ea6..d8beb8d0afa 100644 --- a/packages/spec/src/integration/connector.test.ts +++ b/packages/spec/src/integration/connector.test.ts @@ -241,7 +241,7 @@ describe('RetryConfigSchema', () => { // Connector Action Effect (#4395) // ============================================================================ -describe('ConnectorActionSchema.effect (#4395)', () => { +describe('ConnectorActionSchema.effect — declares whether an action reads or writes', () => { it('declares exactly read | write — the two countable answers', () => { expect(ConnectorActionEffectSchema.options).toEqual(['read', 'write']); }); @@ -389,7 +389,7 @@ describe('ConnectorSchema', () => { // tempting wrong fix — pointing `connector.rateLimitConfig` at the shared inbound // schema — would throttle the opposite direction, so the absence assertions below // are as load-bearing as the presence ones. -describe('[#4911] `./integration` no longer publishes an outbound rate-limit shape', () => { +describe('`./integration` no longer publishes an outbound rate-limit shape', () => { it('every retired name is absent from the entry — no alias, no re-export', async () => { const integrationEntry = await import('./index'); @@ -591,7 +591,7 @@ describe('[#4911] `./integration` no longer publishes an outbound rate-limit sha // declarations remain, and the pins below now hold the base against the import // mapping alone — plus the fact that the connector name is GONE rather than // folded into either survivor. -describe('[#4703] FieldMapping no longer names three declarations', () => { +describe('FieldMapping no longer names three declarations', () => { it('each entry exposes exactly one field-mapping name, and not the others’', async () => { const integrationEntry = await import('./index'); const dataEntry = await import('../data/index'); @@ -843,7 +843,7 @@ const STAMPED_CONNECTOR = { ...STAMPED_ENVELOPE, } as const; -describe('ADR-0010 protection envelope (#6362)', () => { +describe('ADR-0010 protection envelope — preserved, never silently stripped', () => { it('ConnectorSchema PRESERVES every stamped envelope key through a parse', () => { const parsed = ConnectorSchema.parse(STAMPED_CONNECTOR); @@ -990,7 +990,7 @@ const AUTHORED_ERROR_MAPPING = { const ERROR_MAPPING_PRESCRIPTION = /`connector\.errorMapping`.*was removed.*17/s; -describe('[#14676] connector.errorMapping retirement', () => { +describe('connector.errorMapping retirement', () => { it('REJECTS an authored `errorMapping` at path `errorMapping`, carrying the prescription', () => { const result = ConnectorSchema.safeParse({ ...ERROR_MAPPING_WELL_FORMED, @@ -1138,7 +1138,7 @@ describe('[#14676] connector.errorMapping retirement', () => { }); }); -describe('[#14676] integration/ErrorMappingConfig + ErrorMappingRule + ConnectorErrorCategory def retirement', () => { +describe('integration/ErrorMappingConfig + ErrorMappingRule + ConnectorErrorCategory def retirement', () => { /** The 7 names the three retired defs exported (3 schema consts + 4 types). */ const RETIRED_NAMES = [ 'ErrorMappingConfigSchema', @@ -1160,7 +1160,7 @@ describe('[#14676] integration/ErrorMappingConfig + ErrorMappingRule + Connector // ── ABSENCE (every entry, not just ./integration) ───────────────────── for (const name of RETIRED_NAMES) { - expect(holdersOf(name), `${name} must have zero holders after #14676`).toEqual([]); + expect(holdersOf(name), `${name} must have zero holders after the errorMapping retirement`).toEqual([]); } // ── SURVIVAL ────────────────────────────────────────────────────────── @@ -1192,7 +1192,7 @@ describe('[#14676] integration/ErrorMappingConfig + ErrorMappingRule + Connector }); }); -describe('[#14676] ADR-0087 registration', () => { +describe('the errorMapping retirement is registered under ADR-0087', () => { it('declares both carrier keys and the three removed defs under major 18, with the D2 conversion in the step-18 chain', () => { expect(RETIRED_KEYS_BY_MAJOR[18]).toContain('integration/Connector:errorMapping'); expect(RETIRED_KEYS_BY_MAJOR[18]).toContain('integration/DeclarativeConnectorEntry:errorMapping'); diff --git a/packages/spec/src/marketplace/package-namespace.test.ts b/packages/spec/src/marketplace/package-namespace.test.ts index 7611e5c2cf1..bc7ae29630b 100644 --- a/packages/spec/src/marketplace/package-namespace.test.ts +++ b/packages/spec/src/marketplace/package-namespace.test.ts @@ -182,7 +182,7 @@ describe('two gates, one vocabulary (§A.7)', () => { }); }); -describe('TemplateManifestSchema declares namespace as a scaffold-only extra (#6861)', () => { +describe('TemplateManifestSchema declares namespace as a scaffold-only extra', () => { /** A template manifest that is valid except for whatever a case changes. */ function templateManifest(overrides: Record = {}) { return { diff --git a/packages/spec/src/marketplace/template-manifest-id.test.ts b/packages/spec/src/marketplace/template-manifest-id.test.ts index d66e76bd637..00955de711b 100644 --- a/packages/spec/src/marketplace/template-manifest-id.test.ts +++ b/packages/spec/src/marketplace/template-manifest-id.test.ts @@ -44,7 +44,7 @@ function createRequest(overrides: Record = {}) { }; } -describe('TemplateManifestSchema relaxes manifestId to optional (#7319)', () => { +describe('TemplateManifestSchema relaxes manifestId to optional', () => { it('parses a manifest that declares no manifestId — the shipped shape', () => { const result = TemplateManifestSchema.safeParse(templateManifest()); expect(result.success).toBe(true); @@ -77,7 +77,7 @@ describe('TemplateManifestSchema relaxes manifestId to optional (#7319)', () => }); }); -describe('CreatePackageRequestSchema keeps manifestId REQUIRED (#7319)', () => { +describe('CreatePackageRequestSchema keeps manifestId REQUIRED', () => { it('rejects a publish request with no manifestId', () => { const { manifestId: _dropped, ...withoutId } = createRequest(); const result = CreatePackageRequestSchema.safeParse(withoutId); diff --git a/packages/spec/src/meta-spelling/manifest-collection-spelling.test.ts b/packages/spec/src/meta-spelling/manifest-collection-spelling.test.ts index b02f481ab7f..3996ef43c34 100644 --- a/packages/spec/src/meta-spelling/manifest-collection-spelling.test.ts +++ b/packages/spec/src/meta-spelling/manifest-collection-spelling.test.ts @@ -30,7 +30,7 @@ import { META_URL_TO_SINGULAR, } from './index'; -describe('#11503 — the manifest-collection vocabulary is the SAME contract on both entries', () => { +describe('the manifest-collection vocabulary is the SAME contract on both entries', () => { it('`/meta-spelling` and `/shared` hand out identical bindings (one declaration, two entries)', async () => { const shared = await import('../shared/metadata-collection.zod'); expect(shared.PLURAL_TO_SINGULAR).toBe(PLURAL_TO_SINGULAR); @@ -47,7 +47,7 @@ describe('#11503 — the manifest-collection vocabulary is the SAME contract on }); }); -describe('#8424 — widening the entry did not merge the two spelling contracts', () => { +describe('widening the entry did not merge the two spelling contracts', () => { it('keeps the manifest map and the URL map distinct symbols', () => { expect(PLURAL_TO_SINGULAR).not.toBe(META_URL_TO_SINGULAR); }); diff --git a/packages/spec/src/migrations/migrations.test.ts b/packages/spec/src/migrations/migrations.test.ts index 472ab0ab2b1..fae59edd3c4 100644 --- a/packages/spec/src/migrations/migrations.test.ts +++ b/packages/spec/src/migrations/migrations.test.ts @@ -219,7 +219,7 @@ describe('migration chain (ADR-0087 D3)', () => { // projection of it (ADR-0087 D4, `gen:upgrade-guide`), so this string IS the // page an author upgrading 16 → 17 reads. A stale present-tense claim here is // published advice, which is why it gets pinned like a prescription. - describe('protocol-17 rationale — the app-area section states the CURRENT fact (#5337)', () => { + describe('protocol-17 rationale — the app-area section states the CURRENT fact', () => { const rationale17 = () => MIGRATIONS_BY_MAJOR[17]!.rationale; it('does not repeat the retired "the server does not walk `areas`" claim', () => { @@ -255,7 +255,7 @@ describe('migration chain (ADR-0087 D3)', () => { expect(r).toMatch(/no gate of its own/); }); - it('keeps `visible` client-side only — the half #4722 did NOT change', () => { + it('keeps `visible` client-side only — the half the server-side item gate did NOT change', () => { // The newly tempting false belief is "areas are gated now, so `visible` // is fine". `visible` (CEL) is still evaluated in the browser at every // level, so it hides an entry that has already been served. @@ -265,7 +265,7 @@ describe('migration chain (ADR-0087 D3)', () => { expect(r).toMatch(/never in `visible`/); }); - it('still carries the #4651 history the step exists to explain', () => { + it('still carries the area-gate removal history the step exists to explain', () => { // The first half is a record of the state AT the retirement and of why // route B (remove) beat route A (enforce). Correcting the caveat must not // erase it — an upgrading author needs to know the keys were fail-open, @@ -290,13 +290,13 @@ describe('migration chain (ADR-0087 D3)', () => { // barrel, two hops an import-statement-level scan cannot see (the third miss // of that class, after #4667 / #4709). The RETIREMENT is untouched; only the // sentence that justified it moves. - describe('protocol-17 #5015 entry — stops republishing #4610\'s falsified evidence (#5781)', () => { + describe('protocol-17 NotificationAction / EmbedConfig entry — stops republishing the falsified zero-consumer claim', () => { const entry = () => MIGRATIONS_BY_MAJOR[17]!.semantic.find( (s) => s.id === 'ui-notification-action-embed-config-retired', ); - it('finds the entry, and it still explains the #4610 orphaning (anti-vacuity)', () => { + it('finds the entry, and it still explains the dual-source orphaning (anti-vacuity)', () => { expect(entry()).toBeDefined(); // The orphaning is stated in words, not by tracker number: the reason is // printed to the author by `os migrate meta`. @@ -330,7 +330,7 @@ describe('migration chain (ADR-0087 D3)', () => { // "warned about by NEITHER channel — check those by hand" false in the // direction that costs a reader work. #6749 fixed the TSDoc half; this is the // registry channel it explicitly excluded (#6844). - describe('protocol-17 #5561 entry — supportsPause is enforced now, so stop asking for a hand-audit (#6844)', () => { + describe('protocol-17 resumeAuthority default-flip entry — supportsPause is enforced now, so stop asking for a hand-audit', () => { const entry = () => MIGRATIONS_BY_MAJOR[17]!.semantic.find( (s) => s.id === 'action-descriptor-resume-authority-default-flip', @@ -452,7 +452,7 @@ describe('migration chain (ADR-0087 D3)', () => { // the two, a 17 → 18 replay ended `schemaValid: false` and `os migrate meta` // closed with "resolve the manual changes above" over a list that named // neither element. This block pins the instruction back into the list. - describe('protocol-18 #17594 entry — the chain NAMES the bare node it leaves standing', () => { + describe('protocol-18 element:filter / element:form entry — the chain NAMES the bare node it leaves standing', () => { /** A page authored against 17, carrying both retired elements. */ const authored = () => ({ pages: [ @@ -552,7 +552,7 @@ describe('migration chain (ADR-0087 D3)', () => { // any major the floor move dropped gets a refusal, not a silent no-op // chain. The refusal names the floor and the other path, which is the // whole prescription those consumers have. - it('every major the #19056 floor move dropped is refused, by name', () => { + it('every major the floor move to 16 dropped is refused, by name', () => { for (const from of [10, 11, 12, 13, 14, 15]) { let thrown: unknown; try { diff --git a/packages/spec/src/migrations/spec-changes-surface-scope.test.ts b/packages/spec/src/migrations/spec-changes-surface-scope.test.ts index 124949134de..47426e62eca 100644 --- a/packages/spec/src/migrations/spec-changes-surface-scope.test.ts +++ b/packages/spec/src/migrations/spec-changes-surface-scope.test.ts @@ -44,7 +44,7 @@ const ONE_RELEASE_SLICE = { }; const SCOPE = { fromVersion: '17.3.0', toVersion: '17.4.0' }; -describe('aggregate export arrays declare the range they really cover (#18978)', () => { +describe('aggregate export arrays declare the range they really cover', () => { it('carries the published-version pair the diff was taken between', () => { const aggregate = composeSpecChanges(MIGRATION_SUPPORT_FLOOR, PROTOCOL_MAJOR, { ...ONE_RELEASE_SLICE, diff --git a/packages/spec/src/security/explain.test.ts b/packages/spec/src/security/explain.test.ts index 5183e7e83aa..6860880ddc0 100644 --- a/packages/spec/src/security/explain.test.ts +++ b/packages/spec/src/security/explain.test.ts @@ -195,7 +195,7 @@ describe('ExplainRequestSchema — the request contract', () => { expect(recordLevel.recordId).toBe('lr_42'); }); - it('[#8326] recordIds round-trips a batch; singular and object-level requests are untouched by its presence in the schema', () => { + it('recordIds round-trips a batch; singular and object-level requests are untouched by its presence in the schema', () => { const batch = ExplainRequestSchema.parse({ object: 'leave_request', operation: 'update', recordIds: ['lr_1', 'lr_2'] }); expect(batch.recordIds).toEqual(['lr_1', 'lr_2']); expect(batch.recordId).toBeUndefined(); @@ -204,7 +204,7 @@ describe('ExplainRequestSchema — the request contract', () => { expect(singular.recordIds).toBeUndefined(); }); - it('[#8326] the cap is 200: exactly 200 ids parse, 201 are refused (never truncated)', () => { + it('the cap is 200: exactly 200 ids parse, 201 are refused (never truncated)', () => { const ids = (n: number) => Array.from({ length: n }, (_, i) => `r_${i}`); expect(ExplainRequestSchema.parse({ object: 'x', operation: 'read', recordIds: ids(200) }).recordIds).toHaveLength(200); expect(EXPLAIN_BATCH_MAX_RECORD_IDS).toBe(200); @@ -212,11 +212,11 @@ describe('ExplainRequestSchema — the request contract', () => { expect(over.success).toBe(false); }); - it('[#8326] an empty recordIds array is refused — send at least one id or omit the field', () => { + it('an empty recordIds array is refused — send at least one id or omit the field', () => { expect(ExplainRequestSchema.safeParse({ object: 'x', operation: 'read', recordIds: [] }).success).toBe(false); }); - it('[#8326] recordId + recordIds together is a loud refusal, never a silent precedence', () => { + it('recordId + recordIds together is a loud refusal, never a silent precedence', () => { const both = ExplainRequestSchema.safeParse({ object: 'x', operation: 'read', recordId: 'r_1', recordIds: ['r_1', 'r_2'], }); @@ -224,7 +224,7 @@ describe('ExplainRequestSchema — the request contract', () => { expect(JSON.stringify(both.success ? [] : both.error.issues)).toContain('mutually exclusive'); }); - it('[#8326] non-string members are refused by the element schema', () => { + it('non-string members are refused by the element schema', () => { expect(ExplainRequestSchema.safeParse({ object: 'x', operation: 'read', recordIds: [42] }).success).toBe(false); }); }); @@ -301,7 +301,7 @@ describe('ExplainDecisionSchema — the full decision report L3 consumes', () => expect(parsed.layers[1].record?.outcome).toBe('excluded'); }); - it('[#8326] round-trips a batch decision — records[] carries the same verdict shape as record', () => { + it('round-trips a batch decision — records[] carries the same verdict shape as record', () => { const parsed = ExplainDecisionSchema.parse({ allowed: true, object: 'leave_request', operation: 'update', principal: { userId: 'u2' }, @@ -410,7 +410,7 @@ describe('AccessMatrix schemas — the authoring-time companion', () => { }); }); - it('[#16870] the AUTHORING accept set refuses the very pair this snapshot shape tolerates', () => { + it('the AUTHORING accept set refuses a readScope beside viewAllRecords, the pair this snapshot shape tolerates', () => { // The boundary, asserted rather than described. If a later change makes // the authoring schema accept the pair again, this fails here too — the // snapshot tolerance above is only defensible while the door upstream of diff --git a/packages/spec/src/security/high-privilege.test.ts b/packages/spec/src/security/high-privilege.test.ts index 68dcb027e55..2631d2db3c7 100644 --- a/packages/spec/src/security/high-privilege.test.ts +++ b/packages/spec/src/security/high-privilege.test.ts @@ -27,7 +27,7 @@ const PLATFORM_TOKEN = 'manage_users'; */ const DOTTED_PLATFORM_TOKEN = 'setup.access'; -describe('describeHighPrivilegeBits — app-declared capability vs platform system permission (#17189)', () => { +describe('describeHighPrivilegeBits — an app-declared capability is not a platform system permission', () => { it('pins the platform names this suite reasons about (else the floor tests nothing)', () => { expect(PLATFORM_CAPABILITY_NAMES.has(PLATFORM_TOKEN)).toBe(true); expect(PLATFORM_CAPABILITY_NAMES.has(DOTTED_PLATFORM_TOKEN)).toBe(true); @@ -105,7 +105,7 @@ describe('describeHighPrivilegeBits — app-declared capability vs platform syst ).toMatch(/system permissions/); }); - it('[#21260] puts the ledger audit capability on the floor with no list of its own: an app cannot launder it onto an anchor', () => { + it('puts the ledger audit capability on the floor with no list of its own: an app cannot launder it onto an anchor', () => { // It unlocks the ledger rows the parent-record read gate otherwise // withholds, so it must never reach `everyone` / `guest` wholesale. The // floor is `PLATFORM_CAPABILITY_NAMES` itself, so declaring it there is the diff --git a/packages/spec/src/security/permission.test.ts b/packages/spec/src/security/permission.test.ts index 631b0d55e94..00f7d01ef9a 100644 --- a/packages/spec/src/security/permission.test.ts +++ b/packages/spec/src/security/permission.test.ts @@ -117,7 +117,7 @@ describe('ObjectPermissionSchema', () => { expect(result.modifyAllRecords).toBe(false); }); - it('allowExport is optional with no default — unset stays undefined (#3544)', () => { + it('allowExport is optional with no default — unset stays undefined', () => { // Deliberately NOT defaulted: unset = inherit read (backward-compatible // opt-out), so adding the key changes nothing for existing permission sets. const result = ObjectPermissionSchema.parse({}); @@ -170,7 +170,7 @@ describe('ObjectPermissionSchema', () => { }); }); -describe('[#16870] a depth axis beside the super-user bit that short-circuits it is REFUSED', () => { +describe('a depth axis beside the super-user bit that short-circuits it is REFUSED', () => { // The defect: `PermissionEvaluator.getEffectiveScope` answers `org` on the // super-user bit BEFORE it consults the depth key, and `getDeclaredScope` // (the ADR-0090 D10 delegated-path input) carries the identical @@ -275,7 +275,7 @@ describe('[#16870] a depth axis beside the super-user bit that short-circuits it }); }); -describe('allowRestore / allowPurge are RETIRED (#12497, ADR-0049)', () => { +describe('allowRestore / allowPurge are RETIRED (ADR-0049)', () => { // Removed by the 2026-08-26 maintainer ruling accepting #1883's // recommendation B: the `restore`/`purge` ObjectQL operations the bits // claimed to gate have never existed (no destructive lifecycle verb in the @@ -305,7 +305,7 @@ describe('allowRestore / allowPurge are RETIRED (#12497, ADR-0049)', () => { } }); - it('[#12840] the refusal is the tombstone byte-for-byte — guidance text, expected: never, located path', () => { + it('the refusal is the tombstone byte-for-byte — guidance text, expected: never, located path', () => { // The #12497 refusal shape was measured as // `{ expected: 'never', code: 'invalid_type', path: […, key], message: }`. // The residue stage must not touch it: a non-default value never enters @@ -352,7 +352,7 @@ describe('allowRestore / allowPurge are RETIRED (#12497, ADR-0049)', () => { }); }); -describe('[#12840] the RETIRED DEFAULT parses as inert residue and strips (class rule)', () => { +describe('the RETIRED DEFAULT parses as inert residue and strips (class rule)', () => { // Maintainer ruling 2026-08-28, recorded on objectstack-ai/cloud#1685: a // retired key that had a schema default is refused only when it carries a // NON-default value. The published `@objectstack/spec` 17.x still emitted @@ -418,7 +418,7 @@ describe('[#12840] the RETIRED DEFAULT parses as inert residue and strips (class } }); - it('[#17425] the only post-parse observation left: an EXPLICIT `undefined` survives as an own key', () => { + it('the only post-parse observation left: an EXPLICIT `undefined` survives as an own key', () => { // The consumer-facing claim this pins (prose on `ObjectPermissionSchema`): // on data that came from JSON no post-parse guard can ever fire — `false` // strips and every other JSON value throws, so the key is always @@ -542,7 +542,7 @@ describe('[#12840] the RETIRED DEFAULT parses as inert residue and strips (class }); }); -describe('EffectiveObjectPermissionSchema (#3391 response-side)', () => { +describe('EffectiveObjectPermissionSchema (response side: the server-resolved operations the UI renders)', () => { it('carries every ObjectPermission field plus optional apiOperations', () => { const parsed = EffectiveObjectPermissionSchema.parse({ allowRead: true, @@ -990,7 +990,7 @@ describe('PermissionSetSchema - tabPermissions', () => { // or restriction was in place that the runtime never saw (the ADR-0049 // asymmetry at the capability container itself). Strictness plus the shared // `strictUnknownKeyError` factory turns that into a loud, fixable error. -describe('unknown keys are rejected, not stripped (#4001)', () => { +describe('unknown keys are rejected, not stripped', () => { const unknownKeyIssue = (schema: { safeParse: (v: unknown) => any }, value: unknown) => { const result = schema.safeParse(value); expect(result.success).toBe(false); @@ -1117,7 +1117,7 @@ describe('unknown keys are rejected, not stripped (#4001)', () => { * bypass would be the opposite lie, since on the common owner-bearing object it * does exactly what it says. */ -describe('[#6698] modifyAllRecords declares its bypass AND the limit of that bypass', () => { +describe('modifyAllRecords declares its bypass AND the limit of that bypass', () => { const description = ObjectPermissionSchema.shape.modifyAllRecords.description ?? ''; /** Idioms that SCOPE the bypass to the objects record sharing enforces on. */ diff --git a/packages/spec/src/security/rls-predicate-grammar-docs.pin.test.ts b/packages/spec/src/security/rls-predicate-grammar-docs.pin.test.ts index a6d6d968a74..e01d01da08d 100644 --- a/packages/spec/src/security/rls-predicate-grammar-docs.pin.test.ts +++ b/packages/spec/src/security/rls-predicate-grammar-docs.pin.test.ts @@ -112,7 +112,7 @@ const FACES: ReadonlyArray = [ ['.describe()', describeFace()], ]; -describe('[#6919] rls.zod.ts states one predicate grammar on all three faces', () => { +describe('rls.zod.ts states one predicate grammar on all three faces', () => { it('finds all three faces at all (anti-vacuity)', () => { // Every assertion below is a search over a string. An empty haystack would // make the negative ones pass forever the day someone moves a block. diff --git a/packages/spec/src/security/rls.test.ts b/packages/spec/src/security/rls.test.ts index 48ae9650de0..ec3358eef77 100644 --- a/packages/spec/src/security/rls.test.ts +++ b/packages/spec/src/security/rls.test.ts @@ -167,7 +167,7 @@ describe('Row-Level Security (RLS) Protocol', () => { expect(result.positions).toEqual(['sales_rep', 'sales_manager']); }); - it('refuses the retired `tags` at its path, with the prescription (#20321)', () => { + it('refuses the retired `tags` at its path, with the prescription', () => { // This case used to pin `tags` round-tripping; that branch is retired // (ADR-0049 enforce-or-remove — nothing ever read a policy's tags). The // full pin set, door by door, is `rls-tags-retirement.test.ts`. @@ -519,7 +519,7 @@ describe('Row-Level Security (RLS) Protocol', () => { // #4001 step 2 — the authorable RLS policy is `.strict()`: an undeclared key // used to be dropped by zod's default `.strip`, so a row-level restriction the // author wrote was never compiled into the filter and nothing failed. -describe('unknown keys are rejected, not stripped (#4001)', () => { +describe('unknown keys are rejected, not stripped', () => { const policy = { name: 'p', object: 'account', operation: 'select' as const, using: 'owner_id == current_user.id', @@ -701,7 +701,7 @@ describe('RowLevelSecurityPolicySchema — a check on a policy that writes no ro // so the non-empty check is what makes this pin fail on an emptied string // rather than only on changed wording. // --------------------------------------------------------------------------- -describe('RowLevelSecurityPolicySchema.using — the published description (#6762)', () => { +describe('RowLevelSecurityPolicySchema.using — the published description advertises what the compiler lowers', () => { const description = RowLevelSecurityPolicySchema.shape.using.description ?? ''; it('is present and non-empty, so the generated reference row is not blank', () => { diff --git a/packages/spec/src/security/sharing.test.ts b/packages/spec/src/security/sharing.test.ts index d3ef84c1b16..14ab4bdde09 100644 --- a/packages/spec/src/security/sharing.test.ts +++ b/packages/spec/src/security/sharing.test.ts @@ -421,7 +421,7 @@ describe('SharingRuleSchema', () => { // key used to be dropped silently, so a share the author intended was never // materialised — the same trap class this file's own history (#3896, #3865) // keeps closing. -describe('unknown keys are rejected, not stripped (#4001)', () => { +describe('unknown keys are rejected, not stripped', () => { const rule = { name: 'r', type: 'criteria' as const, object: 'task', condition: 'record.status == "open"', @@ -472,7 +472,7 @@ describe('unknown keys are rejected, not stripped (#4001)', () => { // parses, what is refused, and where the refusal points. The runtime semantics // (per-record expansion, `multiple: true` honoured, empty column ⇒ nobody, // re-materialisation on the record's own write) are the executor's, #15072. -describe("sharedWith.type: 'field' — the record-relative recipient (#14103)", () => { +describe("sharedWith.type: 'field' — the record-relative recipient", () => { const rule = (sharedWith: unknown) => ({ name: 'assignees_can_read', object: 'duly_assignment', diff --git a/packages/spec/src/security/tenancy-posture.test.ts b/packages/spec/src/security/tenancy-posture.test.ts index 937b9c88e91..687b91a5910 100644 --- a/packages/spec/src/security/tenancy-posture.test.ts +++ b/packages/spec/src/security/tenancy-posture.test.ts @@ -18,7 +18,7 @@ import { type OrgScopingEntitlement, } from './tenancy-posture'; -describe('[#12699] PlatformGlobalObjectsSchema', () => { +describe('PlatformGlobalObjectsSchema — the objects a deployment exempts from the Layer 0 wall', () => { it('accepts exact object machine names', () => { const parsed = PlatformGlobalObjectsSchema.safeParse([ 'sys_setting', @@ -47,7 +47,7 @@ describe('[#12699] PlatformGlobalObjectsSchema', () => { }); }); -describe('[#12699] OrgScopingEntitlementSchema', () => { +describe('OrgScopingEntitlementSchema — the deployment facts Layer 0 arming reads', () => { it('accepts a full declaration', () => { const declaration: OrgScopingEntitlement = { supportedPostures: ['isolated'], diff --git a/packages/spec/src/security/tenant-layer0-verdict.test.ts b/packages/spec/src/security/tenant-layer0-verdict.test.ts index 59a0b49b39a..8115a0d4dc0 100644 --- a/packages/spec/src/security/tenant-layer0-verdict.test.ts +++ b/packages/spec/src/security/tenant-layer0-verdict.test.ts @@ -13,7 +13,7 @@ import { describe, it, expect } from 'vitest'; import { TenantLayer0VerdictSchema } from './tenant-layer0-verdict'; -describe('[#15813] TenantLayer0VerdictSchema — the four verdicts', () => { +describe('TenantLayer0VerdictSchema — the four verdicts the wall records on an operation', () => { it.each([ ['none', { kind: 'none' }], ['organization', { kind: 'organization', organizationId: 'org_acme' }], @@ -27,7 +27,7 @@ describe('[#15813] TenantLayer0VerdictSchema — the four verdicts', () => { }); }); -describe('[#15813] TenantLayer0VerdictSchema — junk is refused, never read as an organization', () => { +describe('TenantLayer0VerdictSchema — junk is refused, never read as an organization', () => { it.each([ ['an unknown kind', { kind: 'organisation', organizationId: 'org_acme' }], ['an empty organization id', { kind: 'organization', organizationId: '' }], diff --git a/packages/spec/src/studio/action-location-retirement.test.ts b/packages/spec/src/studio/action-location-retirement.test.ts index 6b3f69994ce..f83e7ce06fa 100644 --- a/packages/spec/src/studio/action-location-retirement.test.ts +++ b/packages/spec/src/studio/action-location-retirement.test.ts @@ -38,7 +38,7 @@ import { // anti-vacuity guards; sabotage-verified in the PR (re-exporting the ui enum // from ./studio under the bare name — green to the dual-source gate, a lie to // authors — and resurrecting the old 3-value const each turn it red). -describe('[#4737] studio ActionLocation dual-source retirement', () => { +describe('studio ActionLocation dual-source retirement', () => { it('resolves the export surface: one owner per name, across every public entry', () => { // Anti-vacuity: the baseline must cover the real surface. (This used to // enumerate package.json's exports map and build its own `ts.createProgram` diff --git a/packages/spec/src/studio/flow-builder.test.ts b/packages/spec/src/studio/flow-builder.test.ts index 4466618d6ff..1c789ff2f12 100644 --- a/packages/spec/src/studio/flow-builder.test.ts +++ b/packages/spec/src/studio/flow-builder.test.ts @@ -218,7 +218,7 @@ describe('FlowBuilderConfigSchema', () => { expect(config.undoLimit).toBe(100); }); - it('answers `snap.grid` with `gridSize`, and the advice actually parses (#5481)', () => { + it('answers `snap.grid` with `gridSize`, and the advice actually parses', () => { // A `grid_: 'showGrid'` entry used to sit after `grid: 'gridSize'` in this // table; `aliasProbe` strips `_`, so the two shared one index and the later // one won. An author writing `grid: 24` — the pixel pitch — was pointed at