Something went wrong. Try again.
This repository has no description
Something went wrong. Try again.
JavaScript
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263import assert from "node:assert/strict";import { test } from "node:test";import { build } from "esbuild";import { Miniflare, convertV4MiniflareOptions } from "miniflare";import { mkdtemp, rm } from "node:fs/promises";import { tmpdir } from "node:os";import { join } from "node:path";
test( "native durable capability approvals persist, bind one execution, and recheck current authority", { timeout: 120_000 }, async () => { const bundle = await build({ entryPoints: ["tests/fixtures/capability-approval-worker.ts"], alias: { path: "node:path", crypto: "node:crypto", async_hooks: "node:async_hooks", }, target: "es2022", bundle: true, write: false, format: "esm", platform: "neutral", conditions: ["workerd", "worker", "browser"], mainFields: ["module", "main"], external: ["cloudflare:*", "node:*"], }); const persistence = await mkdtemp(join(tmpdir(), "flarebot-approval-")); const options = { ...convertV4MiniflareOptions({ modules: true, script: bundle.outputFiles[0].text, compatibilityDate: "2026-09-04", compatibilityFlags: ["nodejs_compat"], durableObjects: { MODEL: { className: "CapabilityApprovalFixture", useSQLite: true }, }, }), resourcePersistencePath: persistence, }; let worker = new Miniflare(options); const call = async (name, action, value) => { const response = await worker.dispatchFetch( `https://fixture.example/${name}`, { method: "POST", body: JSON.stringify({ action, value }) }, ); assert.equal(response.status, 200); return response.json(); }; const pause = async ( name, input = { note: "Review this exact note <script>owner-only</script>" }, expectedExecutions = 0, ) => { const submitted = await call(name, "submit", input); assert.ok(!submitted.error, JSON.stringify(submitted)); const pending = await call(name, "pending"); assert.equal( pending.length, 1, JSON.stringify(await call(name, "snapshot")), ); assert.deepEqual(pending[0].arguments, input); assert.match(pending[0].summary, /send_note.*Fixture notes.*Send a note/); assert.equal( (await call(name, "snapshot")).executions, expectedExecutions, ); return pending[0]; }; const decide = (name, pending, decision = "approve") => call(name, "decide", { executionId: pending.executionId, decision }); try { for (const decision of ["approve", "deny"]) { const name = `registry-${decision}`; const request = await pause(name); const activity = (snapshot) => snapshot.activities.find( (item) => item.toolCallId === request.toolCallId, ); assert.equal(activity(await call(name, "snapshot")).status, "pending"); await decide(name, request, decision); const snapshot = await call(name, "snapshot"); assert.equal(snapshot.executions, decision === "approve" ? 1 : 0); assert.equal( activity(snapshot).status, decision === "approve" ? "succeeded" : "cancelled", ); assert.equal( activity(snapshot).approvalDecision, decision === "approve" ? "approved" : "denied", ); } const pending = await pause("persist"); assert.deepEqual( await call("persist", "pending"), [pending], "a fresh request sees the same native durable approval", ); await worker.dispose(); worker = new Miniflare(options); let snapshot = await call("persist", "snapshot"); assert.equal( snapshot.activities.find( (activity) => activity.toolCallId === pending.toolCallId, )?.status, "pending", "startup restores durable pending activity before any approval-list request", ); assert.deepEqual( await call("persist", "pending"), [pending], "pending input and identity survive a full native worker restart", ); assert.deepEqual(await decide("persist", pending), { resolved: true }); assert.deepEqual(await decide("persist", pending), { resolved: false }); assert.deepEqual(await call("persist", "pending"), []); snapshot = await call("persist", "snapshot"); assert.equal(snapshot.executions, 1); assert.equal( snapshot.activities.find( (activity) => activity.toolCallId === pending.toolCallId, )?.status, "succeeded", ); assert.ok(JSON.stringify(snapshot.messages).includes('"delivered":true')); assert.equal( snapshot.activities.find( (item) => item.toolCallId === pending.toolCallId, )?.approvalDecision, "approved", ); assert.match( snapshot.activities.find( (item) => item.toolCallId === pending.toolCallId, )?.outputSummary, /^Owner approved once\. /, ); const second = await pause( "persist", { note: "A second call needs a separate decision" }, 1, ); assert.notEqual(second.toolCallId, pending.toolCallId); assert.notEqual(second.executionId, pending.executionId); await decide("persist", second, "deny"); assert.equal((await call("persist", "snapshot")).executions, 1);
const raced = await pause("concurrent"); assert.deepEqual( await decide("other-conversation", raced), { resolved: false }, "a decision cannot cross the native conversation boundary", ); const decisions = await Promise.all([ decide("concurrent", raced), decide("concurrent", raced), ]); assert.equal(decisions.filter((result) => result.resolved).length, 1); assert.equal((await call("concurrent", "snapshot")).executions, 1);
const denied = await pause("denied"); assert.deepEqual(await decide("denied", denied, "deny"), { resolved: true, }); assert.deepEqual(await decide("denied", denied), { resolved: false }); snapshot = await call("denied", "snapshot"); assert.equal(snapshot.executions, 0); const deniedActivity = snapshot.activities.find( (activity) => activity.toolCallId === denied.toolCallId, ); assert.equal(deniedActivity?.status, "cancelled"); assert.equal(deniedActivity?.reason, "approval-denied"); assert.equal(deniedActivity?.approvalDecision, "denied"); assert.equal(deniedActivity?.outputSummary, "Owner denied this action"); const rejectedPart = snapshot.messages .flatMap((message) => message.parts) .find((part) => part.toolCallId === denied.toolCallId); assert.equal(rejectedPart?.output?.status, "rejected"); assert.equal(rejectedPart?.output?.reason, "Owner denied this action"); assert.ok( JSON.stringify(snapshot.messages).includes("Owner denied this action"), );
for (const [name, action, value] of [ ["policy-never", "policy", "never"], ["disabled", "metadata", { enabled: false }], ["changed", "metadata", { fingerprint: "c".repeat(64) }], ]) { const request = await pause(name); await call(name, action, value); await decide(name, request); assert.equal( (await call(name, "snapshot")).executions, 0, `${name} must be checked again at approval execution`, ); assert.deepEqual(await call(name, "pending"), []); assert.equal( (await call(name, "snapshot")).activities.find( (item) => item.toolCallId === request.toolCallId, )?.status, "failed", ); }
const raw = await pause("raw-approval"); await call("raw-approval", "rawApprove", raw.executionId); assert.equal( (await call("raw-approval", "snapshot")).executions, 0, "an inherited SDK approval method does not carry the owner's bound grant", ); const forged = await pause("forged-decision"); assert.ok( ( await call("forged-decision", "decide", { executionId: forged.executionId, decision: "approve", approvedOnce: true, }) ).error, ); assert.equal((await call("forged-decision", "snapshot")).executions, 0); assert.deepEqual(await call("forged-decision", "pending"), [forged]); await call("forged-input", "submit", { note: "forged", approvedOnce: true, }); assert.equal((await call("forged-input", "snapshot")).executions, 0); assert.deepEqual(await call("forged-input", "pending"), []); for (const [name, note] of [ ["oversized-ascii", "x".repeat(65_536)], ["oversized-unicode", "🦊".repeat(17_000)], ]) { await call(name, "submit", { note }); assert.equal((await call(name, "snapshot")).executions, 0); assert.deepEqual( await call(name, "pending"), [], "unreviewable arguments cannot create a durable approval", ); } await call("allowed", "policy", "allow"); await call("allowed", "submit", { note: "Explicit owner policy permits this call", }); assert.equal((await call("allowed", "snapshot")).executions, 1); assert.deepEqual(await call("allowed", "pending"), []); await call("prohibited", "policy", "never"); await call("prohibited", "submit", { note: "Policy must prevent the pause too", }); assert.equal((await call("prohibited", "snapshot")).executions, 0); assert.deepEqual(await call("prohibited", "pending"), []); } finally { await worker.dispose(); await rm(persistence, { recursive: true, force: true }); } },);