66 lines
3.4 KiB
TypeScript
66 lines
3.4 KiB
TypeScript
import assert from 'node:assert/strict';
|
|
import test from 'node:test';
|
|
import { canEnterSelectedDomainRuntime, createDomainEntryTarget, projectDomainRuntimeBoundary } from './domain-entry-state.js';
|
|
|
|
const validRuntimePolicy = {
|
|
allowedSessionScopes: ['domain:enter', 'knowledge:read'],
|
|
forbiddenDataScopes: ['private:relationship-core'],
|
|
manifestDigest: 'a'.repeat(64),
|
|
permissionPolicyRef: 'policy://origin-domain/default',
|
|
routeRef: 'domain-route://origin-domain/runtime',
|
|
themeOwner: 'fifth-domain' as const,
|
|
themePackageRef: 'theme://origin-domain/lake-reflects-stars',
|
|
};
|
|
|
|
const ready = (domainId: string, nodeType: 'local-terminal' | 'cloud-resident' = 'local-terminal') => ({
|
|
blockers: [],
|
|
domainId,
|
|
nodeType,
|
|
runtimePolicy: validRuntimePolicy,
|
|
runtimeReady: true,
|
|
stage: 'runtime-ready' as const,
|
|
});
|
|
|
|
test('a generic login request does not silently target the Fifth Domain', () => {
|
|
assert.equal(canEnterSelectedDomainRuntime(null, ready('DOM-FIFTH-0001')), false);
|
|
assert.match(projectDomainRuntimeBoundary(null, ready('DOM-FIFTH-0001')), /先选择目标域/);
|
|
});
|
|
|
|
test('the selected stable domain id must match the returned access evidence', () => {
|
|
const fifth = createDomainEntryTarget('fifth', 'cloud-resident');
|
|
assert.equal(canEnterSelectedDomainRuntime(fifth, ready('DOMAIN-MAIN', 'cloud-resident')), false);
|
|
assert.match(projectDomainRuntimeBoundary(fifth, ready('DOMAIN-MAIN', 'cloud-resident')), /另一个域/);
|
|
});
|
|
|
|
test('enterprise vestibules cannot reuse the Fifth Domain renderer', () => {
|
|
const main = createDomainEntryTarget('main');
|
|
assert.equal(main.domain.stableDomainId, 'DOMAIN-MAIN');
|
|
assert.equal(main.nodeType, 'local-terminal');
|
|
assert.equal(canEnterSelectedDomainRuntime(main, ready('DOMAIN-MAIN')), false);
|
|
assert.match(projectDomainRuntimeBoundary(main, ready('DOMAIN-MAIN')), /独立运行端点与主题包尚未登记/);
|
|
});
|
|
|
|
test('the Fifth Domain opens only with matching runtime-ready evidence', () => {
|
|
const fifth = createDomainEntryTarget('fifth', 'cloud-resident');
|
|
assert.equal(canEnterSelectedDomainRuntime(fifth, ready('DOM-FIFTH-0001', 'cloud-resident')), true);
|
|
assert.equal(canEnterSelectedDomainRuntime(fifth, ready('DOM-FIFTH-0001', 'local-terminal')), false);
|
|
assert.match(projectDomainRuntimeBoundary(fifth, ready('DOM-FIFTH-0001', 'local-terminal')), /另一种节点类型/);
|
|
assert.match(projectDomainRuntimeBoundary(fifth, ready('DOM-FIFTH-0001', 'cloud-resident')), /已经匹配/);
|
|
});
|
|
|
|
test('the Fifth Domain stays closed without the exact verified runtime policy projection', () => {
|
|
const fifth = createDomainEntryTarget('fifth');
|
|
const base = ready('DOM-FIFTH-0001');
|
|
assert.equal(canEnterSelectedDomainRuntime(fifth, { ...base, runtimePolicy: undefined }), false);
|
|
assert.match(projectDomainRuntimeBoundary(fifth, { ...base, runtimePolicy: undefined }), /可信运行策略缺失或不匹配/);
|
|
|
|
for (const runtimePolicy of [
|
|
{ ...validRuntimePolicy, manifestDigest: 'not-a-digest' },
|
|
{ ...validRuntimePolicy, themeOwner: 'domain-team' as const },
|
|
{ ...validRuntimePolicy, themePackageRef: 'theme://enterprise/fifth-look' },
|
|
{ ...validRuntimePolicy, routeRef: 'domain-route://enterprise/fifth' },
|
|
{ ...validRuntimePolicy, allowedSessionScopes: ['knowledge:read'] },
|
|
]) {
|
|
assert.equal(canEnterSelectedDomainRuntime(fifth, { ...base, runtimePolicy }), false);
|
|
}
|
|
});
|