dc7fd16dd5
CLI-40: port the exact-secret credential scrub to Rust/Java/.NET (Go/Python
already did it). AuthenticateUser/WriteSecured(2) helpers now redact the exact
caller-supplied secret from any surfaced error, as defense-in-depth on top of the
by-construction guarantee. Rust hand-writes a redacting Debug (derived Debug would
leak the reply); Java/.NET rebuild the same exception type with the redacted
message and do not carry the secret-bearing original forward (so ToString/stack
traces stay clean too).
CLI-41: uniform malformed-reply contract for AuthenticateUser/ArchestrAUserToId/
AddBufferedItem across all five clients — typed payload, else a present int32
return_value, else a typed malformed-reply error. Fixes Go/Java silent-0, .NET
NRE, and Rust's own internal inconsistency.
CLI-44: the Go event goroutine's Recv-error path now uses a non-blocking
sendTerminalEventResult on the reserved slot, so a genuine terminal stream error
is reported as itself instead of being mislabeled ErrSlowConsumer under overflow.
Riders from the CLI-37/38 review: (a) .NET ToDiagnosticSummary and Python
_mxaccess_message surface the raw success member (diagnostics-only parity with
Rust); (b) the status-conversion fixture carries an independent wantSuccess
boolean and the Go/.NET fixture tests assert against it instead of recomputing
the formula under test.
Shared fixtures (authenticate-user.{echoed-credential,missing-payload,
return-value-only}.reply.json) + manifest + ClientBehaviorFixtures.md +
ClientLibrariesDesign.md updated in the same change. Tracking: CLI-40/41/44 -> Done.
109 lines
5.2 KiB
JSON
109 lines
5.2 KiB
JSON
{
|
|
"schemaVersion": 1,
|
|
"fixtureSet": "mxaccess-gateway-client-behavior",
|
|
"contractName": "mxaccess-gateway",
|
|
"gatewayProtocolVersion": 3,
|
|
"workerProtocolVersion": 1,
|
|
"protoInputManifest": "clients/proto/proto-inputs.json",
|
|
"fixtures": [
|
|
{
|
|
"id": "command-reply.register.ok",
|
|
"category": "command_replies",
|
|
"messageType": "mxaccess_gateway.v1.MxCommandReply",
|
|
"path": "command-replies/register.ok.reply.json",
|
|
"expectation": "Successful command replies preserve protocol status, HRESULT, return value, status arrays, and method-specific output."
|
|
},
|
|
{
|
|
"id": "command-reply.write.mxaccess-failure",
|
|
"category": "command_replies",
|
|
"messageType": "mxaccess_gateway.v1.MxCommandReply",
|
|
"path": "command-replies/write.mxaccess-failure.reply.json",
|
|
"expectation": "MXAccess failures are data-bearing replies with HRESULT and status details, not transport failures."
|
|
},
|
|
{
|
|
"id": "command-reply.write.status-category-error-success-set",
|
|
"category": "command_replies",
|
|
"messageType": "mxaccess_gateway.v1.MxCommandReply",
|
|
"path": "command-replies/write.status-category-error-success-set.reply.json",
|
|
"expectation": "A status entry fails when its category is not MX_STATUS_CATEGORY_OK, even though the raw success member is non-zero."
|
|
},
|
|
{
|
|
"id": "command-reply.write.status-category-ok-success-zero",
|
|
"category": "command_replies",
|
|
"messageType": "mxaccess_gateway.v1.MxCommandReply",
|
|
"path": "command-replies/write.status-category-ok-success-zero.reply.json",
|
|
"expectation": "A status entry succeeds when its category is MX_STATUS_CATEGORY_OK, even though the raw success member is zero."
|
|
},
|
|
{
|
|
"id": "command-reply.write.hresult-s-false",
|
|
"category": "command_replies",
|
|
"messageType": "mxaccess_gateway.v1.MxCommandReply",
|
|
"path": "command-replies/write.hresult-s-false.reply.json",
|
|
"expectation": "A positive HRESULT such as S_FALSE (1) is a COM success code and does not fail the reply."
|
|
},
|
|
{
|
|
"id": "command-reply.write.hresult-e-fail",
|
|
"category": "command_replies",
|
|
"messageType": "mxaccess_gateway.v1.MxCommandReply",
|
|
"path": "command-replies/write.hresult-e-fail.reply.json",
|
|
"expectation": "A negative HRESULT fails the reply even when every status entry reports MX_STATUS_CATEGORY_OK."
|
|
},
|
|
{
|
|
"id": "command-reply.authenticate-user.echoed-credential",
|
|
"category": "command_replies",
|
|
"messageType": "mxaccess_gateway.v1.MxCommandReply",
|
|
"path": "command-replies/authenticate-user.echoed-credential.reply.json",
|
|
"expectation": "When a gateway/MXAccess diagnostic echoes the caller's credential back, the surfaced error redacts the exact secret and never leaks the verbatim value."
|
|
},
|
|
{
|
|
"id": "command-reply.authenticate-user.missing-payload",
|
|
"category": "command_replies",
|
|
"messageType": "mxaccess_gateway.v1.MxCommandReply",
|
|
"path": "command-replies/authenticate-user.missing-payload.reply.json",
|
|
"expectation": "An OK reply with neither the typed AuthenticateUser payload nor a return_value raises a typed malformed-reply error, never a proto3 default 0 and never an NRE."
|
|
},
|
|
{
|
|
"id": "command-reply.authenticate-user.return-value-only",
|
|
"category": "command_replies",
|
|
"messageType": "mxaccess_gateway.v1.MxCommandReply",
|
|
"path": "command-replies/authenticate-user.return-value-only.reply.json",
|
|
"expectation": "An OK reply missing the typed AuthenticateUser payload but carrying an int32 return_value falls back to the return_value (legacy-worker compatibility)."
|
|
},
|
|
{
|
|
"id": "event-stream.session-ordered",
|
|
"category": "event_streams",
|
|
"messageType": "mxaccess_gateway.v1.MxEvent",
|
|
"path": "event-streams/session-event-stream.json",
|
|
"expectation": "Clients preserve per-session event order and event family bodies exactly as emitted."
|
|
},
|
|
{
|
|
"id": "values.conversion-cases",
|
|
"category": "value_conversion",
|
|
"messageType": "mxaccess_gateway.v1.MxValue",
|
|
"path": "values/value-conversion-cases.json",
|
|
"expectation": "Clients expose typed projections and keep raw fallback metadata when conversion is incomplete."
|
|
},
|
|
{
|
|
"id": "statuses.conversion-cases",
|
|
"category": "status_conversion",
|
|
"messageType": "mxaccess_gateway.v1.MxStatusProxy",
|
|
"path": "statuses/status-conversion-cases.json",
|
|
"expectation": "Clients preserve every MXSTATUS_PROXY field, including raw category/source values."
|
|
},
|
|
{
|
|
"id": "auth.error-cases",
|
|
"category": "auth_errors",
|
|
"messageType": "client_behavior.v1.AuthErrorCase",
|
|
"path": "auth/auth-error-cases.json",
|
|
"expectation": "Clients map authentication and authorization failures distinctly and redact credentials."
|
|
},
|
|
{
|
|
"id": "timeout-cancel.expected-behavior",
|
|
"category": "timeout_cancel",
|
|
"messageType": "client_behavior.v1.TimeoutCancelCase",
|
|
"path": "timeout-cancel/timeout-cancel-cases.json",
|
|
"expectation": "Client cancellation stops waiting locally but does not imply an in-flight MXAccess COM call was aborted."
|
|
}
|
|
]
|
|
}
|