test(ci): run the unit suite in CI + frontend-syntax gate; green pre-existing test debt

- CI: add a 'test' job running the unit suite via config/vitest.ci.config.ts. Excludes browser (Playwright/chromium) and perf tests (timing-flaky), like the existing test/mobile suite. Safe in CI: TmuxManager no-ops shell commands under VITEST (test/setup.ts).
- Add scripts/check-frontend-syntax.mjs (node --check on src/web/public/*.js), wired into the lint job — catches a class of frontend SyntaxError that passes lint today (lint globs only TS).
- Add test/security-regression.test.ts (wired Host/Origin guard, self-update CSRF, CSP/security headers, text/plain raw body, WS anti-CSWSH) + test/sse-registry-parity.test.ts (backend<->frontend SSE registry parity).
- Green pre-existing test debt surfaced by the new gate: stale 'Session not found' asserts -> 'not found' substring; drop tests for removed helpers (isError now internal; createSuccessResponse deleted); file-stream-manager: mock realpathSync + fix stale /tmp assertion; sse-subscription-filter: lifecycle events broadcast to all clients (only terminal stream filtered); session.test.ts: mkdir /tmp/test; skip one interactive-respawn test needing a real PTY (covered by respawn-controller.test.ts).
- Full non-mobile suite verified green locally (2680 passed, 12 skipped).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
arkon
2026-06-09 20:02:15 +02:00
co-authored by Claude Opus 4.8
parent 36bc22a3d5
commit d5f91e4cd7
14 changed files with 428 additions and 121 deletions
+4 -33
View File
@@ -5,11 +5,7 @@
*/
import { describe, it, expect } from 'vitest';
import {
ApiErrorCode,
createErrorResponse,
createSuccessResponse,
} from '../src/types.js';
import { ApiErrorCode, createErrorResponse } from '../src/types.js';
describe('API Response Structures', () => {
describe('SessionState Structure', () => {
@@ -480,34 +476,9 @@ describe('API Response Structures', () => {
});
describe('Response Validation', () => {
describe('SessionResponse', () => {
it('should have success property', () => {
const response = createSuccessResponse({ id: 'session-1' });
expect(response).toHaveProperty('success');
expect(response.success).toBe(true);
});
it('should have data property on success', () => {
const response = createSuccessResponse({ id: 'session-1', status: 'idle' });
expect(response).toHaveProperty('data');
expect(response.data?.id).toBe('session-1');
});
});
describe('QuickStartResponse', () => {
it('should include session and case info on success', () => {
const response = createSuccessResponse({
sessionId: 'session-1',
casePath: '/path/to/case',
caseName: 'test-case',
});
expect(response.success).toBe(true);
expect(response.data?.sessionId).toBeDefined();
expect(response.data?.casePath).toBeDefined();
expect(response.data?.caseName).toBeDefined();
});
});
// (SessionResponse / QuickStartResponse success-envelope tests removed — the
// createSuccessResponse helper they exercised no longer exists. Error-envelope
// coverage remains below.)
describe('Error Responses', () => {
it('should include error code', () => {