Files
orca/mobile/src/tasks/setup-hook-trust.test.ts
Neil 77f23b013f refactor(shared): drop the shared/types barrel and import from the real modules (#14447)
#14397 split `shared/types.ts` into 46 per-domain modules but kept the path as
a re-export barrel so the import sites did not have to change. This removes
the barrel: every consumer now imports from the module that actually declares
the type, and `src/shared/types.ts` is deleted.

Barrels hide where a type lives, make every consumer look like it depends on
the whole domain, and let an unrelated edit invalidate a module that ~2,000
files transitively import.

2,323 import declarations across 2,321 files. Rewritten mechanically: each
specifier was resolved to an absolute path via the TypeScript AST and
recomputed, rather than string-substituted, so alias forms (`@/../../shared/
types`) and per-specifier `type` modifiers survive.

Four cases the mechanical pass had to handle, each found by a gate rather than
by reading the diff:

- Modules inside `src/shared` import the barrel as `./types`, not
  `shared/types`. A pre-filter on the latter string skipped 176 of them and
  left imports dangling at a deleted file, which surfaced as confusing
  `Property 'x' is optional in type 'Repo' but required in Pick<Repo, ...>`
  errors rather than "module not found".
- The barrel RENAMED one type on the way through
  (`WorkspaceSource as WorkspaceCreateTelemetrySource`), so the original name
  in the owning module has to be re-aliased at each consumer.
- Three test files put `;(globalThis as ...)` on the line after the import.
  TypeScript parses that `;` as the import statement's terminator, so
  replacing through `statement.getEnd()` deletes it and breaks ASI. The
  rewrite now stops at the module specifier.
- A file that already imported directly from a module got a SECOND import
  from it, because the barrel re-exported those same names — which trips
  `import/no-duplicates` under `--deny-warnings`. A post-pass merges
  declarations sharing a specifier and type-only-ness; the `import type` plus
  `import` pair from one module is left alone, since that form is allowed.

Splitting one barrel import into several genuinely adds lines, which pushed
`terminal-layout-pty-ownership.ts` to 301 counted lines: its 107-character
import must wrap, and neither local type collapses onto one line (101 and 116
characters). Rather than contort a type declaration to fit a line budget,
`collectLeafIds` and `pruneLeaves` move to `terminal-pane-layout-tree.ts` —
they are pure structural operations on the layout tree and independent of PTY
ownership. `visible-worktrees.ts` similarly loses its own mini-barrel
re-export of `isDefaultBranchWorkspace`, with the four real consumers
repointed at the declaring module. No `max-lines` bypass added.

Verified: cold `tsc --noEmit` green on node, cli, and web (buildinfo deleted
first — these projects are `composite: true` and reuse stale caches); the full
`pnpm lint` green, not just bare oxlint — the narrower local check is what let
the duplicate imports reach CI; max-lines ratchet OK at 344.
2026-08-13 22:48:24 -07:00

113 lines
3.3 KiB
TypeScript

import { describe, expect, it } from 'vitest'
import {
isSetupHookTrusted,
normalizeSetupHookTrust,
persistSetupHookTrustApproval,
trustedOrcaHooksWithSetupApproval,
wasSetupHookPreviouslyApproved
} from './setup-hook-trust'
import type { PersistedTrustedOrcaHooks } from '../../../src/shared/orca-yaml-hook-types'
import type { RpcClient } from '../transport/rpc-client'
describe('setup hook trust', () => {
it('trusts a setup script only when the approved hash matches', () => {
const trust: PersistedTrustedOrcaHooks = {
'repo-1': { setup: { contentHash: 'hash-1', approvedAt: 1000 } }
}
expect(isSetupHookTrusted(trust, 'repo-1', 'hash-1')).toBe(true)
expect(isSetupHookTrusted(trust, 'repo-1', 'hash-2')).toBe(false)
})
it('treats an always-trusted repo as trusted for changed setup scripts', () => {
const trust: PersistedTrustedOrcaHooks = {
'repo-1': { all: { approvedAt: 1000 } }
}
expect(isSetupHookTrusted(trust, 'repo-1', 'new-hash')).toBe(true)
})
it('preserves unrelated trust entries when approving setup', () => {
const trust: PersistedTrustedOrcaHooks = {
'repo-1': {
archive: { contentHash: 'archive-hash', approvedAt: 1000 }
}
}
expect(
trustedOrcaHooksWithSetupApproval({
trust,
repoId: 'repo-1',
contentHash: 'setup-hash',
alwaysTrust: false,
approvedAt: 2000
})
).toEqual({
'repo-1': {
archive: { contentHash: 'archive-hash', approvedAt: 1000 },
setup: { contentHash: 'setup-hash', approvedAt: 2000 }
}
})
})
it('records always-trust without dropping existing script approvals', () => {
const trust: PersistedTrustedOrcaHooks = {
'repo-1': {
setup: { contentHash: 'setup-hash', approvedAt: 1000 }
}
}
expect(
trustedOrcaHooksWithSetupApproval({
trust,
repoId: 'repo-1',
contentHash: 'ignored-for-all',
alwaysTrust: true,
approvedAt: 2000
})
).toEqual({
'repo-1': {
setup: { contentHash: 'setup-hash', approvedAt: 1000 },
all: { approvedAt: 2000 }
}
})
})
it('persists and returns the approved trust state', async () => {
let persisted: unknown
const client = {
sendRequest: async (_method: string, params: unknown) => {
persisted = params
return { ok: true, result: null }
}
} as unknown as RpcClient
const next = await persistSetupHookTrustApproval({
client,
trust: {},
repoId: 'repo-1',
contentHash: 'setup-hash',
alwaysTrust: false
})
expect(persisted).toEqual({ trustedOrcaHooks: next })
expect(isSetupHookTrusted(next, 'repo-1', 'setup-hash')).toBe(true)
})
it('detects previous setup approval and ignores incomplete trust payloads', () => {
expect(
wasSetupHookPreviouslyApproved(
{ 'repo-1': { setup: { contentHash: 'hash-1', approvedAt: 1000 } } },
'repo-1'
)
).toBe(true)
expect(normalizeSetupHookTrust({ contentHash: 'hash-1', scriptContent: '' })).toBe(null)
expect(
normalizeSetupHookTrust({ contentHash: 'hash-1', scriptContent: 'pnpm install' })
).toEqual({
contentHash: 'hash-1',
scriptContent: 'pnpm install'
})
})
})