import assert from "node:assert/strict"; import { createHash } from "node:crypto"; import { mkdtemp, mkdir, readFile, rm, writeFile } from "node:fs/promises"; import { tmpdir } from "node:os"; import { join } from "node:path"; import test from "node:test"; import { isValidTid } from "@atproto/syntax"; import { Hono } from "hono"; import { KnowledgeVideo } from "./components/knowledge-entry.tsx"; import { nextStandardSiteRkey, shouldValidateStandardSiteWrite, } from "./knowledge-atproto.ts"; import { knowledgeContentDigest, knowledgeHref, knowledgeRoute, loadKnowledgeGraph, parseKnowledgeDocument, } from "./knowledge.ts"; import { canonicalizeTrailingSlash } from "./trailing-slash.ts"; function draftSource(slug: string, route?: string): string { return `--- title: ${slug} slug: ${slug} ${route ? `route: ${route}\n` : ""}summary: A public test entry. kind: concept status: evolving claimMode: factual confidence: high topics: [] related: [] sources: - title: Example url: https://example.com/ aiAssisted: true generatedBy: Co updated: 2026-07-21T00:00:00.000Z reviewStatus: draft --- A public test entry with a [source](https://example.com/). `; } test("allocates lexicon-valid TID keys for new Standard.site records", () => { const first = nextStandardSiteRkey(); const second = nextStandardSiteRkey(); assert.equal(isValidTid(first), true); assert.equal(isValidTid(second), true); assert.notEqual(first, second); }); test("limits legacy record-key compatibility to existing document updates", () => { assert.equal(shouldValidateStandardSiteWrite({ collection: "site.standard.document", action: "update", rkey: "knowledge-now", }), false); assert.equal(shouldValidateStandardSiteWrite({ collection: "site.standard.document", action: "create", rkey: "knowledge-new-entry", }), true); assert.equal(shouldValidateStandardSiteWrite({ collection: "site.standard.document", action: "update", rkey: nextStandardSiteRkey(), }), true); assert.equal(shouldValidateStandardSiteWrite({ collection: "site.standard.publication", action: "update", rkey: "legacy-publication-key", }), true); }); test("uses a nested route without changing the stable slug", () => { const entry = parseKnowledgeDocument( draftSource("gemini-model-series", "language-models/gemini"), "gemini-model-series.md", true, ); assert.equal(knowledgeRoute(entry), "language-models/gemini"); assert.equal(knowledgeHref(entry), "/knowledge/language-models/gemini"); assert.equal(entry.slug, "gemini-model-series"); }); test("binds a route change into the reviewed content digest", () => { const flat = parseKnowledgeDocument(draftSource("gemini-model-series"), "flat.md", true); const nested = parseKnowledgeDocument( draftSource("gemini-model-series", "language-models/gemini"), "nested.md", true, ); assert.notEqual(knowledgeContentDigest(flat), knowledgeContentDigest(nested)); }); test("binds an optional YouTube video into the reviewed content digest", () => { const withoutVideo = parseKnowledgeDocument( draftSource("office-hours"), "without-video.md", true, ); const withVideo = parseKnowledgeDocument( draftSource("office-hours").replace( "aiAssisted: true", "youtubeVideoId: JiOmNrmY_Ys\naiAssisted: true", ), "with-video.md", true, ); assert.equal(withVideo.youtubeVideoId, "JiOmNrmY_Ys"); assert.notEqual(knowledgeContentDigest(withoutVideo), knowledgeContentDigest(withVideo)); }); test("rejects malformed YouTube video identifiers", () => { const source = draftSource("unsafe-video").replace( "aiAssisted: true", "youtubeVideoId: 'JiOmNrmY_Ys?autoplay=1'\naiAssisted: true", ); assert.throws( () => parseKnowledgeDocument(source, "unsafe-video.md", true), /YouTube video ID must be exactly 11 URL-safe characters/, ); }); test("renders YouTube videos through a fixed privacy-enhanced embed host", async () => { const html = await KnowledgeVideo({ videoId: "JiOmNrmY_Ys", title: "Office Hours", }).toString(); assert.match(html, /src="https:\/\/www\.youtube-nocookie\.com\/embed\/JiOmNrmY_Ys"/); assert.match(html, /href="https:\/\/www\.youtube\.com\/watch\?v=JiOmNrmY_Ys"/); assert.match(html, /loading="lazy"/); assert.doesNotMatch(html, / { assert.throws(() => parseKnowledgeDocument( draftSource("gemini-model-series", "/language-models/Gemini"), "invalid-route.md", true, )); }); test("rejects public source URLs with non-HTTP or backslash-normalized authority", () => { const javascriptSource = draftSource("unsafe-source").replace( "url: https://example.com/", "url: 'javascript:alert(1)'", ); assert.throws( () => parseKnowledgeDocument(javascriptSource, "unsafe-source.md", true), /public source URL must use HTTP\(S\)/, ); const backslashSource = draftSource("unsafe-source").replace( "url: https://example.com/", "url: 'https:\\\\evil.example/path'", ); assert.throws( () => parseKnowledgeDocument(backslashSource, "unsafe-source.md", true), /public source URL must use HTTP\(S\)/, ); }); test("Tinker technical-publication provenance is route-scoped and never claims exact Cameron review", async () => { const expectedPublishedAt: Record = { "tinker-curriculum": "2026-07-26T03:56:24.425Z", "tinker-curriculum-task-set-01": "2026-07-26T03:56:24.975Z", }; for (const slug of Object.keys(expectedPublishedAt)) { const documentPath = join(process.cwd(), "knowledge", "published", `${slug}.md`); const entry = parseKnowledgeDocument(await readFile(documentPath, "utf8"), `${slug}.md`, false); const authorization = entry.publicationAuthorization; assert.equal(entry.reviewBasis, "technical-publication-authorization"); assert.equal(entry.reviewedBy, undefined); assert.equal(entry.reviewedAt, undefined); assert.equal(entry.implementationReviewedBy, "Co"); assert.equal(authorization?.authorizedBy, "Cameron"); assert.equal(authorization?.exactRenderReviewed, false); assert.equal(authorization?.route, knowledgeRoute(entry)); assert.equal(entry.publishedAt?.toISOString(), expectedPublishedAt[slug]); const receiptBytes = await readFile(join(process.cwd(), authorization!.receiptPath)); const digest = `sha256:${createHash("sha256").update(receiptBytes).digest("hex")}`; assert.equal(authorization?.receiptDigest, digest); assert.equal(entry.reviewReceiptDigest, digest); } }); test("technical authorization rejects exact-review fields", async () => { const path = join(process.cwd(), "knowledge", "published", "tinker-curriculum.md"); const source = (await readFile(path, "utf8")).replace( "reviewBasis: technical-publication-authorization\n", "reviewBasis: technical-publication-authorization\nreviewedBy: Cameron\n", ); assert.throws( () => parseKnowledgeDocument(source, "misrepresented-review.md", false), /must not be represented as exact review/, ); }); test("captures multiple knowledge path segments in Hono", async () => { const app = new Hono(); app.get("/knowledge/:route{.+}", (context) => context.text(context.req.param("route"))); const response = await app.request("/knowledge/language-models/gemini"); assert.equal(response.status, 200); assert.equal(await response.text(), "language-models/gemini"); }); test("redirects trailing slashes to canonical Knowledge URLs", async () => { const app = new Hono(); app.use(canonicalizeTrailingSlash); app.get("/knowledge", (context) => context.text("knowledge")); app.get("/knowledge/:route{.+}", (context) => context.text(context.req.param("route"))); const landing = await app.request("https://cameron.stream/knowledge/?view=map"); assert.equal(landing.status, 301); assert.equal(landing.headers.get("location"), "/knowledge?view=map"); const entry = await app.request("https://cameron.stream/knowledge/agent-memory/"); assert.equal(entry.status, 301); assert.equal(entry.headers.get("location"), "/knowledge/agent-memory"); const head = await app.request("https://cameron.stream/knowledge/", { method: "HEAD" }); assert.equal(head.status, 301); assert.equal(head.headers.get("location"), "/knowledge"); }); test("indexes canonical nested routes and rejects route collisions", async () => { const root = await mkdtemp(join(tmpdir(), "knowledge-routes-")); try { await mkdir(join(root, "staged")); await writeFile( join(root, "staged", "gemini-model-series.md"), draftSource("gemini-model-series", "language-models/gemini"), ); await writeFile( join(root, "staged", "gemini-alias.md"), draftSource("gemini-alias", "language-models/gemini"), ); const graph = await loadKnowledgeGraph({ root, includeDrafts: true }); assert.equal(graph.byRoute.get("language-models/gemini")?.slug, "gemini-alias"); assert.ok(graph.errors.includes( "duplicate route language-models/gemini (gemini-alias, gemini-model-series)", )); } finally { await rm(root, { recursive: true, force: true }); } });