test(telegram): pin that the route uses the service's shape answer, and name the hex arm honestly (TASK-159 follow-up) - #1939
Merged
Conversation
…nd name the hex arm honestly (TASK-159 follow-up) Vera's 74641 review of #1937 left two items; both are here rather than in a moved head, so her clearance of `3cde635f` stood. (a) `draws its width from the same constant as the minter` survived every constant mutation, because hex of N bytes is always 2N characters — it claimed a derivation it cannot witness. Renamed to what it pins and given the assertion that makes the title true: the minted code matches `^[0-9a-f]+$`. The derivation claim is carried by `accepts what the minter produces and refuses one character either side`, and the arm now says so. (b) The route-side witness pinned WHERE the shape answer comes from, not that the answer is USED: a belt-and-braces drift — ask the service and then also apply a local regex — stayed green. New arm mocks `isConnectCodeShape` to admit a malformed code and asserts the lookup proceeds, so re-checking the code in the route reddens.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Both items from Vera's review of #1937 (74641), as a follow-up cut from the merged main (
1defa900) rather than a moved head — so her clearance of3cde635fstood and she was owed no re-gate. Test-only, two files.(a) An arm that claimed a derivation it cannot witness
draws its width from the same constant as the minterassertedmintConnectCode().connectCodehasCONNECT_CODE_BYTES * 2characters — true by construction, because hex of N bytes is always 2N characters. It survived every constant mutation (20 bytes, 3 bytes, the{32}drift), so a reader would think the derivation is witnessed twice when it is witnessed once.Renamed to what it pins, with the assertion that makes the title true:
The hex assertion is exactly what Vera's mutation (
toString('hex')→toString('base64')) reddens; the comment records that the derivation claim belongs toaccepts what the minter produces and refuses one character either side.(b) The route asked the service but did not have to use its answer
The #1937 arm asserted
isConnectCodeShapewas called with the normalised code. A belt-and-braces drift — call the service, then also apply a local regex — stayed green. New arm:Mocking the service to admit a malformed code must let the lookup proceed. Re-checking the code in the route refuses instead and reddens — measured as M1 below.
Ledger — 3 mutations, baseline and restore 25/25
lets the service answer decide…, alonemints hex…arm,accepts what the minter produces…, and the pre-existing literal pin on minted outputNo survivors. The control is deliberate: an arm that mocks the predicate can pass because the route never consults it, so M3 shows the path it gates is live.
Scope
telegramConnectCode.test.js+3/−2;telegram.webhook.connectCode.test.js+13.import/extensionspair on the suite'srequires is ambient — 9 such diagnostics in that file for the same shape).Gate: Vera.