test(authz): pin the GET-exemption set by membership, not by count (#11531) - #11580
Merged
diegosouzapw merged 2 commits intoAug 26, 2026
Conversation
…iegosouzapw#11531) diegosouzapw#11531 added `/api/tunnels/cloudflared` to `LOCAL_ONLY_API_GET_EXEMPTIONS` and shipped its own guard for it, but the diegosouzapw#5083 sibling asserts `LOCAL_ONLY_API_GET_EXEMPTIONS.size === 1` — so `Unit Tests fast-path` has been red on every branch since: ✖ LOCAL_ONLY_API_GET_EXEMPTIONS has exactly 1 entry actual: 2, expected: 1 The production side is correct and reviewed: GET on that path is tunnel status, and POST still spawns cloudflared and stays local-only (`route-guard-tunnel-processes-local-only.test.ts` proves both). The stale assertion is the defect, and a cardinality pin is the wrong shape for what it was guarding. It cannot say WHICH path appeared, and it cannot see a substitution at all — swapping `/api/system/version` for a spawn-capable route keeps the size at 1 and passes. Asserting the exact membership keeps the "must not grow by accident" guard, fails just as loudly on an addition, additionally catches a swap, and names the offending path in the diff. The two entries are listed with the reason each is safe for a read-only method.
This was referenced Aug 26, 2026
diegosouzapw
merged commit Aug 26, 2026
8cb2d0c
into
diegosouzapw:release/v3.8.51
10 of 16 checks passed
diegosouzapw
pushed a commit
that referenced
this pull request
Aug 26, 2026
Merged via /merge-batch (lote 2026-08-26 batch 2, v3.8.51). 7 conflitos, todos triviais/duplicados (mesmos base-reds já corrigidos por PRs paralelas mergeadas neste lote — #11580/#11582/#11583/#11585/#11588/#11589/#11590/#11591/#11609): mantida a versão já validada nesses casos. Validado: 68/68 testes passando. Obrigado por resolver os base-reds.
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…iegosouzapw#11531) (diegosouzapw#11580) Merged via /merge-batch (lote 2026-08-26, v3.8.51). Boarded no worktree combinado junto com outras ~30 PRs; validação única: typecheck/complexity/cognitive-complexity/changelog-integrity verdes, file-size rebaseado onde necessário (crescimento legítimo), lint com os mesmos 228 achados pré-existentes confirmados via sonda contra o tip puro (não introduzidos por este lote), e ~370 testes focados (unit + vitest) passando. Obrigado pela contribuição.
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…osouzapw#11608) Merged via /merge-batch (lote 2026-08-26 batch 2, v3.8.51). 7 conflitos, todos triviais/duplicados (mesmos base-reds já corrigidos por PRs paralelas mergeadas neste lote — diegosouzapw#11580/diegosouzapw#11582/diegosouzapw#11583/diegosouzapw#11585/diegosouzapw#11588/diegosouzapw#11589/diegosouzapw#11590/diegosouzapw#11591/diegosouzapw#11609): mantida a versão já validada nesses casos. Validado: 68/68 testes passando. Obrigado por resolver os base-reds.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The red test
Unit Tests fast-pathfails on every branch:#11531 (
e48ffd38d, yesterday)added
/api/tunnels/cloudflaredtoLOCAL_ONLY_API_GET_EXEMPTIONSand shippedtests/unit/authz/route-guard-tunnel-processes-local-only.test.tsalongside it. What itdid not touch was the #5083 sibling four directories over, which pins the set's
cardinality at 1.
This is the test that is wrong, not the code
Worth stating plainly, because "align the assertion to current behaviour" is usually how
a real defect gets buried. Here the production change is the reviewed one:
GET /api/tunnels/cloudflaredis tunnel status — no spawn.POSTon the same path still spawns cloudflared and stays local-only.route-guard-tunnel-processes-local-only.test.tsasserts both, and it passes today. Theexemption was deliberate; only the count in the older file rotted.
Why membership instead of a bigger number
Bumping
1to2would go green, but it would keep a guard that cannot do its job. Asizeassertion:actual: 2, expected: 1sends the next authorhunting for a diff the test already had in hand.
/api/system/versionfor a spawn-capableroute and the size stays 1 — a security-relevant edit passes silently.
Pinning the exact membership keeps the "must not grow by accident" property, fails just
as loudly on an addition, additionally catches the swap, and prints the offending path.
Both entries are now listed with the reason each is safe for a read-only method, so the
next person to add one is told what the bar is.
Verification
Three states, same file:
Whole directory, after the change:
The two remaining failures are
client-api-policy-fallbackandmanagement-policy,both failing in their
test.afterrmSyncof a tmpDATA_DIRwithEPERMon thisWindows host — identical on the unmodified base branch, unrelated to this change.
Test-only; no production code touched.