import assert from 'node:assert/strict' import test from 'node:test' import { validateDeploymentSource } from './deployment-source-guard.mjs' const policy = { schema: 'hololake.source-route-policy/v1', routes: [ { distribution: 'personal', repository_id: 'REPO-008', channel_id: 'HLP-CHANNEL-0001', source_node: 'JD-FD-PRIMARY', source_owner_id: 'ICE-GL∞', allowed_authorizers: ['ICE-GL∞'], allowed_personas: ['ICE-GL-ZY001'], allowed_execution_runtimes: ['SYS-GLW-ZY-EXEC-0001'], allowed_targets: ['JD-FD-PRIMARY'], deployment_enabled: true, }, { distribution: 'team', repository_id: null, channel_id: null, source_node: 'AW-GZ-001', allowed_personas: [], allowed_targets: ['AW-GZ-001'], deployment_enabled: false, }, { distribution: 'public-module', repository_id: null, channel_id: null, source_node: null, allowed_personas: [], allowed_targets: [], deployment_enabled: false, }, ], } test('allows Ice Shuo authorization plus Zhuyuan main control to package the personal distribution', () => { assert.deepEqual(validateDeploymentSource(policy, { distribution: 'personal', repositoryId: 'REPO-008', channelId: 'HLP-CHANNEL-0001', sourceOwnerId: 'ICE-GL∞', authorizerId: 'ICE-GL∞', personaId: 'ICE-GL-ZY001', executionRuntimeId: 'SYS-GLW-ZY-EXEC-0001', target: 'JD-FD-PRIMARY', }), { ok: true }) }) test('rejects a team persona using Ice Shuo personal source', () => { assert.deepEqual(validateDeploymentSource(policy, { distribution: 'personal', repositoryId: 'REPO-008', channelId: 'HLP-CHANNEL-0001', sourceOwnerId: 'ICE-GL∞', authorizerId: 'ICE-GL∞', personaId: 'AGE-TEAM-001', executionRuntimeId: 'SYS-GLW-ZY-EXEC-0001', target: 'JD-FD-PRIMARY', }), { ok: false, reason: 'deployment_persona_not_allowed' }) }) test('blocks team deployment until its enterprise repository route is registered', () => { assert.deepEqual(validateDeploymentSource(policy, { distribution: 'team', repositoryId: 'REPO-008', channelId: 'HLP-CHANNEL-0001', sourceOwnerId: 'ICE-GL∞', authorizerId: 'ICE-GL∞', personaId: 'AGE-TEAM-001', executionRuntimeId: 'SYS-GLW-ZY-EXEC-0001', target: 'AW-GZ-001', }), { ok: false, reason: 'deployment_source_route_inactive' }) }) test('public modules are reusable source and never an application deployment target', () => { assert.deepEqual(validateDeploymentSource(policy, { distribution: 'public-module', repositoryId: 'REPO-008', channelId: 'HLP-CHANNEL-0001', sourceOwnerId: 'ICE-GL∞', authorizerId: 'ICE-GL∞', personaId: 'ICE-GL-ZY001', executionRuntimeId: 'SYS-GLW-ZY-EXEC-0001', target: 'JD-FD-PRIMARY', }), { ok: false, reason: 'deployment_source_route_inactive' }) }) test('rejects a human identity presented as the executing persona', () => { assert.deepEqual(validateDeploymentSource(policy, { distribution: 'personal', repositoryId: 'REPO-008', channelId: 'HLP-CHANNEL-0001', sourceOwnerId: 'ICE-GL∞', authorizerId: 'ICE-GL∞', personaId: 'ICE-GL∞', executionRuntimeId: 'SYS-GLW-ZY-EXEC-0001', target: 'JD-FD-PRIMARY', }), { ok: false, reason: 'deployment_persona_not_allowed' }) })