diff --git a/src/__tests__/scan.test.js b/src/__tests__/scan.test.js index f25ddd1..bd0bde6 100644 --- a/src/__tests__/scan.test.js +++ b/src/__tests__/scan.test.js @@ -135,6 +135,22 @@ describe('runScan — missing blob reporting and cross-check', () => { expect(result.trustworthy).toBe(false); expect(result.errors.some((e) => e.step === 'listMissingBlobs')).toBe(true); }); + + test('listMissingBlobs is called WITHOUT a repo param (authenticated-session endpoint)', async () => { + const calls = []; + const api = makeApi({ held: [BLOB1], collections: [], pdsMissing: [] }); + const orig = api.listMissingBlobs; + api.listMissingBlobs = async (params) => { + calls.push(params); + return orig(params); + }; + await runScan({ did: DID, ...api }); + expect(calls.length).toBeGreaterThan(0); + for (const c of calls) { + expect(c).not.toHaveProperty('repo'); + expect(c).toHaveProperty('limit'); + } + }); }); describe('runScan — fail-closed invariants', () => { diff --git a/src/lib/scan.js b/src/lib/scan.js index fd556c3..7c70b88 100644 --- a/src/lib/scan.js +++ b/src/lib/scan.js @@ -35,7 +35,8 @@ export const DEFAULT_LIST_RECORDS_LIMIT = 100; * @param {Function} opts.listBlobs async ({did, limit, cursor}) => {data:{cids:[],cursor}} * @param {Function} opts.describeRepo async ({repo}) => {data:{collections:[]}} * @param {Function} opts.listRecords async ({repo, collection, limit, cursor}) => {data:{records:[],cursor}} - * @param {Function} opts.listMissingBlobs async ({repo, limit, cursor}) => {data:{blobs:[],cursor}} + * @param {Function} opts.listMissingBlobs async ({limit, cursor}) => {data:{blobs:[],cursor}} + * NOTE: takes only limit/cursor (operates on authenticated repo) * @param {string} opts.did * @param {Object} [opts.onProgress] optional {onHeld, onCollection, onRecord, onMissing} callbacks * @returns {Promise} @@ -152,11 +153,13 @@ export async function runScan({ missing.sort((a, b) => a.cid.localeCompare(b.cid)); // 5. Cross-check missing against listMissingBlobs (PDS's own accounting) + // NOTE: listMissingBlobs takes ONLY limit/cursor — it operates on the + // authenticated session's repo. Passing `repo` is an invalid parameter. const pdsMissing = new Set(); try { let cursor; do { - const res = await listMissingBlobs({ repo: did, limit: 500, cursor }); + const res = await listMissingBlobs({ limit: 500, cursor }); const blobs = res?.data?.blobs; if (Array.isArray(blobs)) { for (const b of blobs) {