import test from 'node:test'; import assert from 'node:assert/strict'; import { mkdtempSync, rmSync } from 'node:fs'; import { tmpdir } from 'node:os'; import { join } from 'node:path'; import { Store } from '../src/store.mjs'; import { Broker } from '../src/broker.mjs'; const businesses = { demo: { id: 'demo', human: 'jason', arbiters: { technical: 'cto', delivery: 'pm' }, roles: { coder: { authority: { withinRole: ['message.send'], crossRole: ['task.scope.change'] } }, cto: { authority: { withinRole: [], crossRole: [] } }, pm: { authority: { withinRole: [], crossRole: [] } }, }, }, }; function fixture(t, gatedMessages = false) { const root = mkdtempSync(join(tmpdir(), 'bus-once-')); let store, b, cap, human; const policy = structuredClone(businesses); if (gatedMessages) policy.demo.roles.coder.authority.withinRole = []; const call = (c, verb, args = {}) => b.request(c, { verb, args }); const bind = (run) => b.bindLaunch({ business: 'demo', role: 'coder', run, harness: 'pi', address: run }); function open() { store = new Store(root); b = new Broker({ store, businesses: policy }); cap = bind('run1'); human = b.bindHuman({ business: 'demo', human: 'jason', via: 'cli', outsideAgent: true }); } open(); call(cap, 'role.claim'); t.after(() => { store.close(); rmSync(root, { recursive: true, force: true }); }); function approve(action = 'deploy', domain = 'delivery', target = 'release1') { const d = call(cap, 'decision.raise', { action, domain, target, question: 'Allow?', options: [ { key: 'yes', text: 'Yes' }, { key: 'no', text: 'No' }, ], recommendation: 'no', blocking: false, }); if (d.route_to === 'human') call(human, 'decision.resolve', { id: d.id, choice: 'yes' }); else { const c = b.bindLaunch({ business: 'demo', role: 'cto', run: 'cto1', harness: 'pi', address: 'cto1' }); call(c, 'role.claim'); call(c, 'decision.resolve', { id: d.id, choice: 'yes' }); } return d; } return { get b() { return b; }, get store() { return store; }, get cap() { return cap; }, call, bind, approve, use(d, c = cap) { return b.authorize(c, d.action, { decision: d.id, target: d.authorization.target }); }, setPolicy(withinRole, crossRole) { policy.demo.roles.coder.authority = { withinRole, crossRole }; }, narrowToCross(action) { policy.demo.roles.coder.authority.crossRole.push(action); }, reopen() { store.close(); open(); }, count(d) { return store.get( "SELECT count(*) AS n FROM events WHERE kind='action.allowed' AND json_extract(body,'$.decision')=? AND json_extract(body,'$.operation') IS NOT 'decision.raise'", d.id, ).n; }, }; } test('gated approval authorizes once, survives store reopen, and fresh approval works', (t) => { const f = fixture(t), d = f.approve(); assert.equal(f.use(d).class, 'gated'); assert.equal(f.count(d), 1); assert.throws(() => f.use(d), /decision-consumed/); assert.equal(f.count(d), 1); f.reopen(); assert.throws(() => f.use(d), /decision-consumed/); const fresh = f.approve(); f.use(fresh); assert.equal(f.count(fresh), 1); }); test('another run cannot consume an approval; a failed check leaves it usable', (t) => { const f = fixture(t), d = f.approve(), other = f.bind('run2'); f.call(f.cap, 'role.release'); f.call(other, 'role.claim'); assert.throws(() => f.use(d, other), /decision-mismatch/); assert.equal(f.count(d), 0); f.call(other, 'role.release'); f.call(f.cap, 'role.claim'); assert.throws( () => f.b.authorize(f.cap, 'deploy', { decision: d.id, target: 'other' }), /decision-mismatch/, ); f.use(d); assert.equal(f.count(d), 1); }); test('two scheduled callers have exactly one grant and one consumed refusal', async (t) => { const f = fixture(t), d = f.approve(); const results = await Promise.allSettled([ Promise.resolve().then(() => f.use(d)), Promise.resolve().then(() => f.use(d)), ]); assert.equal(results.filter((r) => r.status === 'fulfilled').length, 1); assert.equal(results.find((r) => r.status === 'rejected').reason.code, 'decision-consumed'); assert.equal(f.count(d), 1); }); test('failed commit rolls consumption back; cross-role consumes and within-role stays reusable', (t) => { const f = fixture(t), d = f.approve(), transaction = f.store.transaction.bind(f.store); f.store.transaction = (fn) => transaction(() => { fn(); throw Error('fixture rollback'); }); assert.throws(() => f.use(d), /fixture rollback/); f.store.transaction = transaction; assert.equal(f.count(d), 0); f.use(d); const cross = f.approve('task.scope.change', 'technical'); f.use(cross); assert.throws(() => f.use(cross), /decision-consumed/); f.reopen(); assert.throws(() => f.use(cross), /decision-consumed/); assert.equal(f.count(cross), 1); for (let n = 0; n < 2; n++) assert.equal(f.b.authorize(f.cap, 'message.send').class, 'within-role'); const within = f.call(f.cap, 'decision.raise', { action: 'message.send', question: 'Send?', options: [ { key: 'yes', text: 'Yes' }, { key: 'no', text: 'No' }, ], recommendation: 'yes', choice: 'yes', blocking: false, }); assert.equal(within.route_to, 'coder'); f.use(within); assert.throws(() => f.use(within), /decision-consumed/); assert.equal(f.count(within), 1); }); for (const [from, to] of [ ['gated', 'cross-role'], ['cross-role', 'gated'], ['gated', 'within-role'], ['cross-role', 'within-role'], ['within-role', 'gated'], ['within-role', 'cross-role'], ]) { test(`class drift ${from} to ${to} refuses before consumption`, (t) => { const f = fixture(t), action = 'task.priority.change'; f.setPolicy(from === 'within-role' ? [action] : [], from === 'cross-role' ? [action] : []); f.reopen(); let d; if (from === 'within-role') d = f.call(f.cap, 'decision.raise', { action, target: 'release1', question: 'Allow?', options: [ { key: 'yes', text: 'Yes' }, { key: 'no', text: 'No' }, ], recommendation: 'yes', choice: 'yes', blocking: false, }); else d = f.approve(action, 'technical'); f.setPolicy(to === 'within-role' ? [action] : [], to === 'cross-role' ? [action] : []); f.reopen(); assert.throws(() => f.use(d), /decision-mismatch/); assert.equal(f.count(d), 0); }); } test('message.send consumes approval and prevents a later send or authorize', (t) => { const f = fixture(t, true), d = f.approve('message.send', 'delivery', 'pm'); // Invalid effect must roll the consumption insert back with the message. assert.throws(() => f.call(f.cap, 'message.send', { to: 'pm', body: '', decision: d.id }), /invalid/); assert.equal(f.count(d), 0); f.call(f.cap, 'message.send', { to: 'pm', body: 'once', decision: d.id }); assert.equal(f.count(d), 1); assert.throws( () => f.call(f.cap, 'message.send', { to: 'pm', body: 'twice', decision: d.id }), /decision-consumed/, ); assert.throws(() => f.use(d), /decision-consumed/); assert.equal(f.store.get('SELECT count(*) AS n FROM messages').n, 1); const fresh = f.approve('message.send', 'delivery', 'pm'); f.use(fresh); assert.throws( () => f.call(f.cap, 'message.send', { to: 'pm', body: 'after authorize', decision: fresh.id }), /decision-consumed/, ); }); test('role.revoke consumes approval and prevents a later revoke or authorize', (t) => { const f = fixture(t), pm = f.b.bindLaunch({ business: 'demo', role: 'pm', run: 'pm1', harness: 'pi', address: 'pm1' }); f.call(pm, 'role.claim'); const d = f.approve('role.revoke', 'delivery', 'pm'); f.call(f.cap, 'role.revoke', { role: 'pm', decision: d.id }); assert.equal(f.count(d), 1); assert.throws(() => f.call(f.cap, 'role.revoke', { role: 'pm', decision: d.id }), /decision-consumed/); assert.throws(() => f.use(d), /decision-consumed/); assert.equal(f.store.get("SELECT count(*) AS n FROM role_claims WHERE op='revoke'").n, 1); const next = f.b.bindLaunch({ business: 'demo', role: 'pm', run: 'pm2', harness: 'pi', address: 'pm2' }); f.call(next, 'role.claim'); const fresh = f.approve('role.revoke', 'delivery', 'pm'); f.use(fresh); assert.throws(() => f.call(f.cap, 'role.revoke', { role: 'pm', decision: fresh.id }), /decision-consumed/); });