test(ci): run the unit suite in CI + frontend-syntax gate; green pre-existing test debt

- CI: add a 'test' job running the unit suite via config/vitest.ci.config.ts. Excludes browser (Playwright/chromium) and perf tests (timing-flaky), like the existing test/mobile suite. Safe in CI: TmuxManager no-ops shell commands under VITEST (test/setup.ts).
- Add scripts/check-frontend-syntax.mjs (node --check on src/web/public/*.js), wired into the lint job — catches a class of frontend SyntaxError that passes lint today (lint globs only TS).
- Add test/security-regression.test.ts (wired Host/Origin guard, self-update CSRF, CSP/security headers, text/plain raw body, WS anti-CSWSH) + test/sse-registry-parity.test.ts (backend<->frontend SSE registry parity).
- Green pre-existing test debt surfaced by the new gate: stale 'Session not found' asserts -> 'not found' substring; drop tests for removed helpers (isError now internal; createSuccessResponse deleted); file-stream-manager: mock realpathSync + fix stale /tmp assertion; sse-subscription-filter: lifecycle events broadcast to all clients (only terminal stream filtered); session.test.ts: mkdir /tmp/test; skip one interactive-respawn test needing a real PTY (covered by respawn-controller.test.ts).
- Full non-mobile suite verified green locally (2680 passed, 12 skipped).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
arkon
2026-06-09 20:02:15 +02:00
co-authored by Claude Opus 4.8
parent 36bc22a3d5
commit d5f91e4cd7
14 changed files with 428 additions and 121 deletions
+10 -12
View File
@@ -24,6 +24,10 @@ vi.mock('node:fs', async (importOriginal) => {
...orig,
existsSync: vi.fn(() => true),
statSync: vi.fn(() => ({ size: 1024 })),
// createStream re-resolves symlinks via realpathSync right before spawn (TOCTOU
// guard); the test fixtures are non-existent paths, so the real realpathSync would
// throw. Mock it as identity so the re-check passes.
realpathSync: vi.fn((p: string) => p),
};
});
@@ -92,11 +96,9 @@ describe('FileStreamManager', () => {
onError: vi.fn(),
});
expect(mockSpawn).toHaveBeenCalledWith(
'tail',
['-f', '-n', '50', expect.stringContaining('/var/log/app.log')],
{ stdio: ['ignore', 'pipe', 'pipe'] },
);
expect(mockSpawn).toHaveBeenCalledWith('tail', ['-f', '-n', '50', expect.stringContaining('/var/log/app.log')], {
stdio: ['ignore', 'pipe', 'pipe'],
});
});
it('should use custom lines parameter', async () => {
@@ -113,11 +115,7 @@ describe('FileStreamManager', () => {
onError: vi.fn(),
});
expect(mockSpawn).toHaveBeenCalledWith(
'tail',
['-f', '-n', '100', expect.any(String)],
expect.any(Object),
);
expect(mockSpawn).toHaveBeenCalledWith('tail', ['-f', '-n', '100', expect.any(String)], expect.any(Object));
});
it('should reject when file does not exist', async () => {
@@ -448,7 +446,7 @@ describe('FileStreamManager', () => {
expect(result.success).toBe(true);
});
it('should allow paths in /tmp', async () => {
it('should reject paths in /tmp (world-writable, intentionally excluded)', async () => {
const proc = createMockProcess();
mockSpawn.mockReturnValue(proc);
@@ -461,7 +459,7 @@ describe('FileStreamManager', () => {
onError: vi.fn(),
});
expect(result.success).toBe(true);
expect(result.success).toBe(false);
});
it('should handle stat errors gracefully', async () => {