Something went wrong. Try again.
This repository has no description
Something went wrong. Try again.
JavaScript
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162import assert from "node:assert/strict";import { test } from "node:test";import { build } from "esbuild";import { Miniflare, convertV4MiniflareOptions } from "miniflare";import { mkdtemp, rm } from "node:fs/promises";import { tmpdir } from "node:os";import { join } from "node:path";
test("native capability policy enforces owner decisions, persists defaults and records safe audit events", async () => { const bundle = await build({ entryPoints: ["tests/fixtures/capability-policy-worker.ts"], alias: { path: "node:path" }, bundle: true, write: false, format: "esm", platform: "neutral", conditions: ["workerd", "worker", "browser"], mainFields: ["module", "main"], external: ["cloudflare:*", "node:*"], }); const persistence = await mkdtemp(join(tmpdir(), "flarebot-policy-")); const options = { ...convertV4MiniflareOptions({ modules: true, script: bundle.outputFiles[0].text, compatibilityDate: "2026-09-04", compatibilityFlags: ["nodejs_compat"], durableObjects: { MODEL: { className: "CapabilityPolicyFixture", useSQLite: true }, }, }), resourcePersistencePath: persistence, }; let worker = new Miniflare(options); const call = async (action, value) => ( await worker.dispatchFetch("https://fixture.example", { method: "POST", body: JSON.stringify({ action, value }), }) ).json(); const reference = { source: { kind: "mcp", id: "private-server-id" }, id: "a".repeat(64), fingerprint: "b".repeat(64), }; let metadata = { ...reference, name: "private-tool-name", sourceName: "private-server-name", actionSummary: "private-action-summary", enabled: true, }; const run = (value) => call("execute", value ?? reference); try { await call("metadata", metadata); let config = await call("policy"); assert.equal(config.defaultPolicy, "ask"); assert.equal((await run()).decision, "ask"); assert.equal((await call("count")).executions, 0); assert.equal( (await run({ ...reference, approval: "allow" })).decision, "invalid", ); metadata = { ...metadata, approval: "never" }; await call("metadata", metadata); config = await call("configure", { ...config, defaultPolicy: "allow" }); assert.equal((await run()).decision, "never"); assert.equal((await call("count")).executions, 0); metadata = { ...metadata, approval: "allow" }; await call("metadata", metadata); assert.equal((await run()).ok, true); assert.equal((await call("count")).executions, 1); config = await call("configure", { ...config, sourceOverrides: [{ source: reference.source, policy: "ask" }], }); assert.equal( (await run()).decision, "ask", "broader source policy can require approval for an allowed tool", ); const stale = config; config = await call("configure", { ...config, sourceOverrides: [{ source: reference.source, policy: "never" }], }); assert.equal((await run()).decision, "never"); assert.equal( ( await call("configure", { ...stale, defaultPolicy: "allow", sourceOverrides: [{ source: reference.source, policy: "allow" }], sourceOverrides: [], }) ).ok, false, ); await worker.dispose(); worker = new Miniflare(options); assert.deepEqual(await call("policy"), config); assert.equal((await run()).decision, "never"); config = await call("configure", { ...config, sourceOverrides: [] }); metadata = { ...metadata, enabled: false }; await call("metadata", metadata); assert.equal((await run()).decision, "unavailable"); metadata = { ...metadata, enabled: true, fingerprint: "c".repeat(64) }; await call("metadata", metadata); assert.equal((await run()).decision, "unavailable"); assert.equal( ( await run({ ...reference, source: { kind: "skill", id: reference.source.id }, }) ).decision, "unavailable", ); assert.equal( (await call("count")).executions, 1, "denied and forged calls never invoke the operation", ); const diagnostics = await call("diagnostics"); const decisions = diagnostics.events.filter( (event) => event.kind === "approval", ); assert.ok( decisions.some((event) => event.details.approvalDecision === "allow"), ); assert.ok( decisions.some((event) => event.details.approvalDecision === "ask"), ); assert.ok( decisions.some((event) => event.details.approvalDecision === "never"), ); assert.ok( decisions.some( (event) => event.details.approvalDecision === "unavailable", ), ); assert.ok( decisions.every((event) => Number.isInteger(event.details.policyRevision), ), ); for (const sentinel of [ "private-server-id", "private-tool-name", "private-server-name", "private-action-summary", "private-conversation", "private-tool-call", ]) assert.ok(!JSON.stringify(diagnostics).includes(sentinel), sentinel); } finally { await worker.dispose(); await rm(persistence, { recursive: true, force: true }); }});