mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-08-13 04:06:59 +00:00
fix(blueprints): fail closed on marker ownership for apply and withdraw (#1694)
* fix(blueprints): fail closed on marker ownership for apply and withdraw Require a matching .blueprint.json under the stack lock, persist required_blueprint_id on deletion intents, remove the legacy remote apply fallback, and protect the marker in the file explorer. * fix(blueprints): add CodeQL path barriers on ownership probes Use the canonical resolve-and-startsWith sanitizer inline at the marker and stack-directory fs sinks so js/path-injection clears. * fix(blueprints): block delete on failed withdraw and defer marker write Refuse Blueprint DELETE when pre-delete withdraw does not complete, and write .blueprint.json only after a successful deploy so failed applies cannot orphan stacks or claim an unapplied revision. * test(blueprints): align lock-order assert with deferred marker write Update the per-stack lock ordering expectations to compose, cleanup, deploy, then marker after the partial-apply fix. * fix(deps): bump postcss past GHSA-r28c-9q8g-f849 for npm audit Raise the Vitest/Vite transitive postcss to 8.5.23 so Backend CI audit --audit-level=high passes.
This commit is contained in:
@@ -95,9 +95,10 @@ describe('FileSystemService stack methods', () => {
|
||||
expect(fileNames).toEqual(['.env', 'compose.yaml']);
|
||||
});
|
||||
|
||||
it('marks compose.yaml and .env as protected', async () => {
|
||||
it('marks compose.yaml, .env, and .blueprint.json as protected', async () => {
|
||||
await fs.writeFile(path.join(stackDir, 'compose.yaml'), '');
|
||||
await fs.writeFile(path.join(stackDir, '.env'), '');
|
||||
await fs.writeFile(path.join(stackDir, '.blueprint.json'), '{}');
|
||||
await fs.writeFile(path.join(stackDir, 'custom.conf'), '');
|
||||
|
||||
const service = FileSystemService.getInstance();
|
||||
@@ -106,6 +107,7 @@ describe('FileSystemService stack methods', () => {
|
||||
const byName = Object.fromEntries(entries.map(e => [e.name, e]));
|
||||
expect(byName['compose.yaml'].isProtected).toBe(true);
|
||||
expect(byName['.env'].isProtected).toBe(true);
|
||||
expect(byName['.blueprint.json'].isProtected).toBe(true);
|
||||
expect(byName['custom.conf'].isProtected).toBe(false);
|
||||
});
|
||||
|
||||
|
||||
Reference in New Issue
Block a user