hololake-system-architecture/product-source/guanghu-knowledge-base/src/domain-entry-state.test.ts

66 lines
3.4 KiB
TypeScript

import assert from 'node:assert/strict';
import test from 'node:test';
import { canEnterSelectedDomainRuntime, createDomainEntryTarget, projectDomainRuntimeBoundary } from './domain-entry-state.js';
const validRuntimePolicy = {
allowedSessionScopes: ['domain:enter', 'knowledge:read'],
forbiddenDataScopes: ['private:relationship-core'],
manifestDigest: 'a'.repeat(64),
permissionPolicyRef: 'policy://origin-domain/default',
routeRef: 'domain-route://origin-domain/runtime',
themeOwner: 'fifth-domain' as const,
themePackageRef: 'theme://origin-domain/lake-reflects-stars',
};
const ready = (domainId: string, nodeType: 'local-terminal' | 'cloud-resident' = 'local-terminal') => ({
blockers: [],
domainId,
nodeType,
runtimePolicy: validRuntimePolicy,
runtimeReady: true,
stage: 'runtime-ready' as const,
});
test('a generic login request does not silently target the Fifth Domain', () => {
assert.equal(canEnterSelectedDomainRuntime(null, ready('DOM-FIFTH-0001')), false);
assert.match(projectDomainRuntimeBoundary(null, ready('DOM-FIFTH-0001')), /先选择目标域/);
});
test('the selected stable domain id must match the returned access evidence', () => {
const fifth = createDomainEntryTarget('fifth', 'cloud-resident');
assert.equal(canEnterSelectedDomainRuntime(fifth, ready('DOMAIN-MAIN', 'cloud-resident')), false);
assert.match(projectDomainRuntimeBoundary(fifth, ready('DOMAIN-MAIN', 'cloud-resident')), /另一个域/);
});
test('enterprise vestibules cannot reuse the Fifth Domain renderer', () => {
const main = createDomainEntryTarget('main');
assert.equal(main.domain.stableDomainId, 'DOMAIN-MAIN');
assert.equal(main.nodeType, 'local-terminal');
assert.equal(canEnterSelectedDomainRuntime(main, ready('DOMAIN-MAIN')), false);
assert.match(projectDomainRuntimeBoundary(main, ready('DOMAIN-MAIN')), /独立运行端点与主题包尚未登记/);
});
test('the Fifth Domain opens only with matching runtime-ready evidence', () => {
const fifth = createDomainEntryTarget('fifth', 'cloud-resident');
assert.equal(canEnterSelectedDomainRuntime(fifth, ready('DOM-FIFTH-0001', 'cloud-resident')), true);
assert.equal(canEnterSelectedDomainRuntime(fifth, ready('DOM-FIFTH-0001', 'local-terminal')), false);
assert.match(projectDomainRuntimeBoundary(fifth, ready('DOM-FIFTH-0001', 'local-terminal')), /另一种节点类型/);
assert.match(projectDomainRuntimeBoundary(fifth, ready('DOM-FIFTH-0001', 'cloud-resident')), /已经匹配/);
});
test('the Fifth Domain stays closed without the exact verified runtime policy projection', () => {
const fifth = createDomainEntryTarget('fifth');
const base = ready('DOM-FIFTH-0001');
assert.equal(canEnterSelectedDomainRuntime(fifth, { ...base, runtimePolicy: undefined }), false);
assert.match(projectDomainRuntimeBoundary(fifth, { ...base, runtimePolicy: undefined }), /可信运行策略缺失或不匹配/);
for (const runtimePolicy of [
{ ...validRuntimePolicy, manifestDigest: 'not-a-digest' },
{ ...validRuntimePolicy, themeOwner: 'domain-team' as const },
{ ...validRuntimePolicy, themePackageRef: 'theme://enterprise/fifth-look' },
{ ...validRuntimePolicy, routeRef: 'domain-route://enterprise/fifth' },
{ ...validRuntimePolicy, allowedSessionScopes: ['knowledge:read'] },
]) {
assert.equal(canEnterSelectedDomainRuntime(fifth, { ...base, runtimePolicy }), false);
}
});