import assert from 'node:assert/strict'; import test from 'node:test'; import { canEnterSelectedDomainRuntime, createDomainEntryTarget, projectDomainRuntimeBoundary } from './domain-entry-state.js'; const validRuntimePolicy = { allowedSessionScopes: ['domain:enter', 'knowledge:read'], forbiddenDataScopes: ['private:relationship-core'], manifestDigest: 'a'.repeat(64), permissionPolicyRef: 'policy://origin-domain/default', routeRef: 'domain-route://origin-domain/runtime', themeOwner: 'fifth-domain' as const, themePackageRef: 'theme://origin-domain/lake-reflects-stars', }; const ready = (domainId: string, nodeType: 'local-terminal' | 'cloud-resident' = 'local-terminal') => ({ blockers: [], domainId, nodeType, runtimePolicy: validRuntimePolicy, runtimeReady: true, stage: 'runtime-ready' as const, }); test('a generic login request does not silently target the Fifth Domain', () => { assert.equal(canEnterSelectedDomainRuntime(null, ready('DOM-FIFTH-0001')), false); assert.match(projectDomainRuntimeBoundary(null, ready('DOM-FIFTH-0001')), /先选择目标域/); }); test('the selected stable domain id must match the returned access evidence', () => { const fifth = createDomainEntryTarget('fifth', 'cloud-resident'); assert.equal(canEnterSelectedDomainRuntime(fifth, ready('DOMAIN-MAIN', 'cloud-resident')), false); assert.match(projectDomainRuntimeBoundary(fifth, ready('DOMAIN-MAIN', 'cloud-resident')), /另一个域/); }); test('enterprise vestibules cannot reuse the Fifth Domain renderer', () => { const main = createDomainEntryTarget('main'); assert.equal(main.domain.stableDomainId, 'DOMAIN-MAIN'); assert.equal(main.nodeType, 'local-terminal'); assert.equal(canEnterSelectedDomainRuntime(main, ready('DOMAIN-MAIN')), false); assert.match(projectDomainRuntimeBoundary(main, ready('DOMAIN-MAIN')), /独立运行端点与主题包尚未登记/); }); test('the Fifth Domain opens only with matching runtime-ready evidence', () => { const fifth = createDomainEntryTarget('fifth', 'cloud-resident'); assert.equal(canEnterSelectedDomainRuntime(fifth, ready('DOM-FIFTH-0001', 'cloud-resident')), true); assert.equal(canEnterSelectedDomainRuntime(fifth, ready('DOM-FIFTH-0001', 'local-terminal')), false); assert.match(projectDomainRuntimeBoundary(fifth, ready('DOM-FIFTH-0001', 'local-terminal')), /另一种节点类型/); assert.match(projectDomainRuntimeBoundary(fifth, ready('DOM-FIFTH-0001', 'cloud-resident')), /已经匹配/); }); test('the Fifth Domain stays closed without the exact verified runtime policy projection', () => { const fifth = createDomainEntryTarget('fifth'); const base = ready('DOM-FIFTH-0001'); assert.equal(canEnterSelectedDomainRuntime(fifth, { ...base, runtimePolicy: undefined }), false); assert.match(projectDomainRuntimeBoundary(fifth, { ...base, runtimePolicy: undefined }), /可信运行策略缺失或不匹配/); for (const runtimePolicy of [ { ...validRuntimePolicy, manifestDigest: 'not-a-digest' }, { ...validRuntimePolicy, themeOwner: 'domain-team' as const }, { ...validRuntimePolicy, themePackageRef: 'theme://enterprise/fifth-look' }, { ...validRuntimePolicy, routeRef: 'domain-route://enterprise/fifth' }, { ...validRuntimePolicy, allowedSessionScopes: ['knowledge:read'] }, ]) { assert.equal(canEnterSelectedDomainRuntime(fifth, { ...base, runtimePolicy }), false); } });