Repository navigation
Stateful handler verification matrix and gaps in fixtures suggest; composition-fit discovery fixes (#1136, #1137) - #1142
Merged
Merged
Conversation
… and let the planner find mcp Running the bounded authoring tools against a real composed application (#1137) showed four places where the answer existed only in prose, or not at all. Each edit is tied to one observed miss. - plan-feature named nothing for an MCP goal: the mcp extension's authoring surfaces carried no goal words. `servers` and `mount` now do. - The mcp mount said "add auth: true" without saying what that admits. With the bundled auth extension a request without the site's own Origin is refused 403, there is no OAuth or bearer authorization, and a handler is not told who called. The surface description, README, llms.txt and TOOLING say so. - The auth surfaces now say what the mount leaves out (admin console, API keys, OAuth/OIDC), that its database may be the owner's own, and that the session cookie is the only credential the gate admits. - A Better Auth plugin that adds columns refused to activate on the bundled SQLite file with advice that cannot help (`urlcode-auth migrate` does not read host.mjs). The refusal and the README now name the owner database. - docs search matched a catalog add-on on its name and description only, so `oauth` or `postgres` named no add-on in a site that installs none. It now also reads the authoring contract. - TOOLING described review as scanning a "source graph". It reads only the module each route names; an imported module is not scanned. - The planner's durable-collection outline states the bundled store's scope (flat scalar records, one SQLite database, one serving process). test/account-composition.test.ts is the executable composition: sign-up, sign-in, sign-out revocation, an admin-plugin suspension refused to non-administrators, the headless and bearer refusals on an auth: true MCP mount, the handler context keys and the plugin-schema refusal. No runtime behavior changes apart from the refusal message and the wider catalog match. Refs #1137. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…rios and untested gaps (#1136) Routes that run project code and can hold state have guarantees the YAML does not state. This makes those gaps actionable without inferring them. - fixtures suggest / MCP suggest_fixtures: when a function or middleware route with no extension accepts a write method or streams, the result carries verificationGaps: seven fixed rows, status "untested", saying which a steps fixture can check and which need an ordinary test. YAML only: no handler source, fixture or test result is read, nothing is imported, and no row is derived from a route name or description. Absent when no route qualifies. - examples/stateful-verification: one synthetic trusted handler with every row as a check. Fixtures cover revocation at event and byte capacity, derived credentials, restart and idempotent replay; tests/in-flight.test.mjs (plain node:test against startServer) covers a read pending at revocation, concurrent publishes, failed cleanup and owned processes. Six deliberate defects each fail exactly the checks written for them. - docs: the matrix and the fixture-versus-ordinary-test boundary in READINESS, the authoring rule in AI-AUTHORING, the output contract in TOOLING. No fixture syntax is added. The package size budget in scripts/package-audit.ts is exceeded by this change and is left for the coordinator to re-measure. Refs #1136 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Measured on the merged branch (Node 26): 1133642 packed, 4444006 unpacked, 571 entries. Budgets: 1111 KiB packed, 4348 KiB unpacked, 576 entries. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
jimhoyd
enabled auto-merge (squash)
October 4, 2026 01:10
… so the orphan check holds on Windows CI (verify windows-latest, 24, 3) failed "defect orphan-process fails exactly the checks written for it": with the defect on, no check failed. Windows ends a Node process's non-detached children with it (libuv's kill-on-close job object), so the tool process the defect leaves behind was already gone and the check could not see an orphan. The job now starts its tool detached (windowsHide), as tool runners commonly do, so the orphan exists on every platform unless the handler ends it. Refs #1136. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem and change
#1136: make stateful custom-handler verification gaps actionable
What fixtures can express today. No fixture syntax was added, and
schemas/requests.schema.jsonis unchanged.Reference scenarios.
examples/stateful-verification/is a synthetic "channel" handler:tests/in-flight.test.mjsis a plainnode:testfor the scenarios fixtures can't express.test/stateful-verification.test.tsasserts exactly which checks each one fails.Guidance.
docs/READINESS.mdhas a new "Stateful handler verification" section: the matrix, "untested is not passed", and the boundary between fixtures and ordinary tests. AI-AUTHORING and TOOLING point to it.Tooling.
urlcode fixtures suggest, MCPsuggest_fixturesand the SDK addverificationGapswhen a route qualifies:functionormiddleware, noextension, and a write method orstream: true.statusis alwaysuntested. It never claims coverage, reads no handler source and runs no project code; a test asserts this.#1137: composition discovery against a real application
The assessment result is on the issue. These changes are each tied to an observed discovery miss:
plan-featurenow namesmcpfor a remote-MCP goal; before, it returned nothing. The durable-collection note states the store's scope.oauth,bearer tokenandpostgresname the add-on.reviewreads only a route's entry module.test/account-composition.test.tshas four tests with negative authorization cases, plus one test each infeature-planandreview.Gaps reproduced and filed, not fixed here: #1139, #1140, #1141.
Verification
npm run verifyexits 0 on this exact tree.npm run test:packageexits 0: "46 packaged example commands ran from consumer copies; Packed installation and starter/cookbook checks passed".Core package budget, from the merged measurement:
Limitations
Closes #1136
Closes #1137
🤖 Generated with Claude Code