Formatting

This commit is contained in:
2026-08-03 03:40:57 +00:00
parent 97d4422b8f
commit c9845d0f28
6 changed files with 214 additions and 246 deletions
+3 -3
View File
@@ -158,8 +158,7 @@ export class DataRoute implements RouteModule {
oc.columns([ 'resource_id', 'public_key' ]).doUpdateSet({
blob,
timestamp,
}),
)
}))
.execute();
}
});
@@ -276,7 +275,8 @@ export class DataRoute implements RouteModule {
const signature = hexToBin(signatureHex);
// Create a SHA-256 hash of the payload.
const messageHash = createHash('sha256').update(payload).digest();
const messageHash = createHash('sha256').update(payload)
.digest();
// Low-S normalization rejects malleable signature encodings.
return secp256k1.verifySignatureDERLowS(signature, publicKey, messageHash);
+4 -5
View File
@@ -20,7 +20,8 @@ const WS_ROUTE = '/ws';
// Strict validation prevents legacy or protocol-specific fields reaching routes.
const wsRequestSchema = z
.object({
id: z.string().min(1).optional(),
id: z.string().min(1)
.optional(),
path: z.string().min(1),
body: z.unknown().optional(),
})
@@ -178,13 +179,11 @@ export class WsTransportRouter implements UpgradeTransportRouter {
* @param error - Failure to normalize into the public error shape.
*/
private sendError(ws: WSContext, requestId: string | undefined, error: unknown): void {
ws.send(
toExtendedJson({
ws.send(toExtendedJson({
...(requestId === undefined ? {} : { id: requestId }),
type: 'error',
...normalizePublicError(error),
}),
);
}));
}
/**
+31 -48
View File
@@ -1,24 +1,24 @@
import { describe, expect, it, vi } from "vitest";
import { describe, expect, it, vi } from 'vitest';
import { DataRoute } from "../../source/routes/resources.js";
import { UnauthorizedError } from "../../source/errors/index.js";
import { type BaseBroadcaster } from "../../source/services/broadcaster.js";
import { ApplicationRouteStream } from "../../source/services/route-stream.js";
import { Database } from "../../source/services/storage/database.js";
import { TestConnection } from "../helpers/test-connection.js";
import { HTTP_STATUS_CODE_NOT_ACCEPTED } from "../../source/constants.js";
import { DataRoute } from '../../source/routes/resources.ts';
import { UnauthorizedError } from '../../source/errors/index.ts';
import { type BaseBroadcaster } from '../../source/services/broadcaster.ts';
import { ApplicationRouteStream } from '../../source/services/route-stream.ts';
import type { Database } from '../../source/services/storage/database.ts';
import { TestConnection } from '../helpers/test-connection.ts';
import { HTTP_STATUS_CODE_NOT_ACCEPTED } from '../../source/constants.ts';
function createBroadcasterStub() {
const createBroadcasterStub = (): BaseBroadcaster => {
return {
subscribe: vi.fn(),
unsubscribe: vi.fn().mockResolvedValue(undefined),
publish: vi.fn(),
sendEvent: vi.fn(),
} as unknown as BaseBroadcaster;
}
};
describe("DataRoute subscriptions", () => {
it("subscribes to future resource changes until removal", async () => {
describe('DataRoute subscriptions', (): void => {
it('subscribes to future resource changes until removal', async (): Promise<void> => {
let resolveRemoved: () => void = () => undefined;
const removed = new Promise<void>((resolve) => {
resolveRemoved = resolve;
@@ -32,30 +32,22 @@ describe("DataRoute subscriptions", () => {
vi.mocked(broadcaster.subscribe).mockReturnValue(removed);
const connection = new TestConnection(true, false);
const stream = new ApplicationRouteStream(connection, {
resourceId: ["a", "b"],
resourceId: [ 'a', 'b' ],
});
const route = new DataRoute(storage, broadcaster, 0);
const execution = route.subscribeData(stream);
expect(broadcaster.subscribe).toHaveBeenCalledWith(
stream,
["resource:a", "resource:b"],
);
expect(broadcaster.subscribe).toHaveBeenCalledWith(stream, [ 'resource:a', 'resource:b' ]);
expect(storage.db.transaction).not.toHaveBeenCalled();
expect(connection.messages).toEqual([]);
await expect(
Promise.race([
execution.then(() => "settled"),
Promise.resolve("pending"),
]),
).resolves.toBe("pending");
await expect(Promise.race([ execution.then(() => 'settled'), Promise.resolve('pending') ])).resolves.toBe('pending');
resolveRemoved();
await execution;
});
it("unsubscribes a bidirectional connection and acknowledges the request", async () => {
it('unsubscribes a bidirectional connection and acknowledges the request', async (): Promise<void> => {
const storage = {
db: {
transaction: vi.fn(),
@@ -63,29 +55,23 @@ describe("DataRoute subscriptions", () => {
} as unknown as Database;
const broadcaster = createBroadcasterStub();
const connection = new TestConnection(true, true);
const stream = new ApplicationRouteStream(
connection,
{ resourceId: ["a"] },
"unsubscribe-1",
);
const stream = new ApplicationRouteStream(connection, { resourceId: [ 'a' ] }, 'unsubscribe-1');
const route = new DataRoute(storage, broadcaster, 0);
await route.unsubscribeData(stream);
expect(broadcaster.unsubscribe).toHaveBeenCalledWith(stream, [
"resource:a",
]);
expect(broadcaster.unsubscribe).toHaveBeenCalledWith(stream, [ 'resource:a' ]);
expect(connection.messages).toEqual([
{
id: "unsubscribe-1",
type: "response",
id: 'unsubscribe-1',
type: 'response',
statusCode: 200,
body: {},
},
]);
});
it("rejects selective unsubscribe on a one-way connection", async () => {
it('rejects selective unsubscribe on a one-way connection', async (): Promise<void> => {
const storage = {
db: {
transaction: vi.fn(),
@@ -93,7 +79,7 @@ describe("DataRoute subscriptions", () => {
} as unknown as Database;
const broadcaster = createBroadcasterStub();
const stream = new ApplicationRouteStream(new TestConnection(true, false), {
resourceId: ["a"],
resourceId: [ 'a' ],
});
const route = new DataRoute(storage, broadcaster, 0);
@@ -102,19 +88,18 @@ describe("DataRoute subscriptions", () => {
});
});
describe("DataRoute resource write auth", () => {
it("rejects an invalid resource signature before writing the batch", async () => {
describe('DataRoute resource write auth', (): void => {
it('rejects an invalid resource signature before writing the batch', async (): Promise<void> => {
const storage = {
db: {
transaction: vi.fn(),
},
} as unknown as Database;
const broadcaster = createBroadcasterStub()
const broadcaster = createBroadcasterStub();
const route = new DataRoute(storage, broadcaster, 0);
await expect(
route.writeData({
await expect(route.writeData({
connection: new TestConnection(true, true),
streaming: true,
bidirectional: true,
@@ -122,19 +107,17 @@ describe("DataRoute resource write auth", () => {
body: {
resources: [
{
id: "resource-a",
publicKey: "not-a-public-key",
id: 'resource-a',
publicKey: 'not-a-public-key',
timestamp: Date.now(),
signature: "not-a-signature",
signature: 'not-a-signature',
value: new Uint8Array([ 1, 2, 3 ]),
},
],
},
} as unknown as ApplicationRouteStream),
).rejects.toBeInstanceOf(UnauthorizedError);
} as unknown as ApplicationRouteStream)).rejects.toBeInstanceOf(UnauthorizedError);
expect(storage.db.transaction).not.toHaveBeenCalled()
expect(storage.db.transaction).not.toHaveBeenCalled();
expect(broadcaster.publish).not.toHaveBeenCalled();
});
});
+16 -20
View File
@@ -1,34 +1,32 @@
import { describe, expect, it, vi } from "vitest";
import { describe, expect, it, vi } from 'vitest';
import { HonoSSEStream } from "../../../source/services/stream/hono-sse-stream.js";
import { HttpRequestStream } from "../../../source/services/stream/http-request-stream.js";
import { WSStream } from "../../../source/services/stream/ws-stream.js";
import { HonoSSEStream } from '../../../source/services/stream/hono-sse-stream.ts';
import { HttpRequestStream } from '../../../source/services/stream/http-request-stream.ts';
import { WSStream } from '../../../source/services/stream/ws-stream.ts';
describe("stream lifecycle observers", () => {
it("buffers exactly one normal HTTP response", async () => {
describe('stream lifecycle observers', (): void => {
it('buffers exactly one normal HTTP response', async (): Promise<void> => {
const stream = new HttpRequestStream();
await stream.send({
type: "response",
type: 'response',
statusCode: 200,
body: { ok: true },
});
expect(stream.getResponse()).toEqual({
type: "response",
type: 'response',
statusCode: 200,
body: { ok: true },
});
await expect(
stream.send({
type: "response",
await expect(stream.send({
type: 'response',
statusCode: 200,
body: { second: true },
}),
).rejects.toThrow("only send one response");
})).rejects.toThrow('only send one response');
});
it("notifies WebSocket observers registered after remote closure", () => {
it('notifies WebSocket observers registered after remote closure', (): void => {
const stream = new WSStream({
send: vi.fn(),
close: vi.fn(),
@@ -42,19 +40,17 @@ describe("stream lifecycle observers", () => {
expect(onClose).toHaveBeenCalledOnce();
});
it("notifies SSE observers registered after local closure", () => {
it('notifies SSE observers registered after local closure', async (): Promise<void> => {
const streamApi = {
writeSSE: vi.fn(),
close: vi.fn(),
};
const stream = new HonoSSEStream(
streamApi as unknown as ConstructorParameters<typeof HonoSSEStream>[0],
);
const stream = new HonoSSEStream(streamApi as unknown as ConstructorParameters<typeof HonoSSEStream>[0]);
const onClose = vi.fn();
stream.close();
await stream.close();
stream.onClose(onClose);
stream.close();
await stream.close();
expect(streamApi.close).toHaveBeenCalledOnce();
expect(onClose).toHaveBeenCalledOnce();
+25 -35
View File
@@ -1,53 +1,43 @@
import { describe, expect, it } from "vitest";
import { z } from "zod";
import { WebSocketServer } from "ws";
import { describe, expect, it } from 'vitest';
import { z } from 'zod';
import type { WebSocketServer } from 'ws';
import { ApplicationRouter } from "../../../source/services/router.js";
import {
WsTransportRouter,
} from "../../../source/services/transport/ws-transport.js";
import { Logger } from "../../../source/utils/logger.js";
import { toExtendedJson } from "@xo-cash/utils";
import { ApplicationRouter } from '../../../source/services/router.ts';
import { WsTransportRouter } from '../../../source/services/transport/ws-transport.ts';
import { Logger } from '../../../source/utils/logger.ts';
import { toExtendedJson } from '@xo-cash/utils';
describe("WebSocket request decoding", () => {
it("decodes the minimal route-agnostic envelope and Extended JSON body", async () => {
await expect(
WsTransportRouter.decodeWebSocketRequest(
toExtendedJson({
id: "request-1",
path: "/data/write",
describe('WebSocket request decoding', (): void => {
it('decodes the minimal route-agnostic envelope and Extended JSON body', async (): Promise<void> => {
await expect(WsTransportRouter.decodeWebSocketRequest(toExtendedJson({
id: 'request-1',
path: '/data/write',
body: { value: new Uint8Array([ 1, 2, 3 ]) },
}),
),
).resolves.toEqual({
requestId: "request-1",
path: "/data/write",
}))).resolves.toEqual({
requestId: 'request-1',
path: '/data/write',
body: { value: new Uint8Array([ 1, 2, 3 ]) },
});
});
it.each([
"{}",
'{"path":42}',
'{"path":"/data/get","id":1}',
'{"path":"/data/get","method":"POST"}',
])("rejects an invalid envelope: %s", async (payload) => {
await expect(WsTransportRouter.decodeWebSocketRequest(payload)).rejects.toBeInstanceOf(
z.ZodError,
it.each([ '{}', '{"path":42}', '{"path":"/data/get","id":1}', '{"path":"/data/get","method":"POST"}' ])(
'rejects an invalid envelope: %s',
async (payload) => {
await expect(WsTransportRouter.decodeWebSocketRequest(payload)).rejects.toBeInstanceOf(z.ZodError);
},
);
});
it("rejects malformed JSON", async () => {
await expect(WsTransportRouter.decodeWebSocketRequest("{")).rejects.toMatchObject({
it('rejects malformed JSON', async (): Promise<void> => {
await expect(WsTransportRouter.decodeWebSocketRequest('{')).rejects.toMatchObject({
statusCode: 400,
message: "Invalid JSON in WebSocket message",
message: 'Invalid JSON in WebSocket message',
});
});
});
describe("WsTransportRouter payload limits", () => {
describe('WsTransportRouter payload limits', (): void => {
it("configures Hono's ws server with the requested maxPayload", async () => {
const debug = new Logger("ws-transport-test");
const debug = new Logger('ws-transport-test');
const router = await ApplicationRouter.create([]);
const transport = new WsTransportRouter(router, debug, 1024);
const wsServer = transport.websocketServer as unknown as WebSocketServer;