From 5d4e150873dff3ad37076d0a1094053e8ee915ac Mon Sep 17 00:00:00 2001 From: Neil <4138956+nwparker@users.noreply.github.com> Date: Thu, 3 Sep 2026 17:44:19 -0700 Subject: [PATCH] test(proxy): close the shorthand and chained-receiver holes in the fetch call-site audit The audit caught `net.request({ session: x })` and `ident.fetch(`, but not the two shapes a real regression is just as likely to take: the `{ url, session }` shorthand that both `net.request` overloads accept, and a receiver with no bare identifier (`session.fromPartition(...).fetch(`, `ctx.session.fetch(`). Rule 1 now also matches the shorthand key; rule 2 scans every `.fetch(` and excludes only a literal `net`/`globalThis`/`global` receiver. Audited counts are unchanged (2/2/1). --- .../proxy-guarded-fetch-call-site-audit.test.ts | 14 +++++++++++--- 1 file changed, 11 insertions(+), 3 deletions(-) diff --git a/src/main/proxy-guarded-fetch-call-site-audit.test.ts b/src/main/proxy-guarded-fetch-call-site-audit.test.ts index 6ed1e52fd8b..ab13e610fa3 100644 --- a/src/main/proxy-guarded-fetch-call-site-audit.test.ts +++ b/src/main/proxy-guarded-fetch-call-site-audit.test.ts @@ -24,9 +24,12 @@ const AUDITED_NON_NET_FETCH_CALLS = new Map([ ]) // `globalThis.fetch` / `global.fetch` belong to global-fetch-call-site-audit.test.ts. -const NON_NET_FETCH_CALL = /(? { it('keeps every non-default-session fetcher audited with its expected count', () => { const found = new Map() for (const { file, content } of sources) { - const hits = [...content.matchAll(NON_NET_FETCH_CALL)].length + const hits = [...content.matchAll(FETCH_CALL)].filter((match) => { + const receiver = RECEIVER_IDENTIFIER.exec(content.slice(0, match.index))?.[1] + // A chained (`session.fromPartition(...).fetch(`) or member (`ctx.session.fetch(`) + // receiver has no bare trailing identifier, and is never the default session. + return receiver === undefined || !DEFAULT_SESSION_RECEIVERS.has(receiver) + }).length if (hits > 0) { found.set(file, hits) }