Files
msd-core/sdk/scripts/gen-secrets.mjs
Tom Boucher dde56a1b77 chore: enforce sdk/dist freshness in gen-*.mjs + add staleness guard helper (#169)
* feat: add requireFreshDist helper for gen-*.mjs scripts

Adds sdk/scripts/_gen-helpers.mjs exporting requireFreshDist(distPath, tsSourcePath).
Performs a synchronous mtime check before any generator reads sdk/dist/ — if
the dist file is missing or older than its TS source, exits 1 with a clear
actionable error naming both paths, both mtimes, and the npm run build:sdk hint.

Single source of truth so all 9 generators import one function rather than
duplicating the logic. See issue #168.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* feat: enforce dist freshness in all 9 gen-*.mjs generators

Each generator now calls requireFreshDist() before reading sdk/dist/.
If the dist artifact is missing or stale relative to its TS source,
the generator exits 1 with a clear error instead of silently emitting
stale CJS output.

Addresses the PR #154 incident where an agent edited a TS source,
regenerated the CJS without rebuilding, and silently overwrote a fix.
gen-configuration.mjs also had its existing throw-on-missing guard
replaced with requireFreshDist() which additionally catches staleness.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* test: add staleness-check regression for gen-*.mjs

tests/gen-staleness-check.test.cjs covers three cases for all 9 generators:
- exits 1 with "does not exist" + build hint when dist file is absent
- exits 1 with stale-dist error (paths + mtimes) when TS source is newer than dist
- exits 0 when dist is newer than TS source (skipped if sdk/dist not built)

Uses child_process.spawnSync to exercise the real gen-*.mjs entry path.
27/27 passing locally with sdk/dist present.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(gen-staleness-check): isolate dist-mutation tests with GSD_REPO_ROOT temp dirs

Subtests A and B in gen-staleness-check.test.cjs were renaming/creating real
sdk/dist files in the live repo tree while the suite ran at --test-concurrency=4.
Other parallel test processes (e.g. frontmatter-cli.test.cjs) spawned subprocesses
that attempted dynamic ESM import of sdk/dist/query/schema-detect.js while it was
temporarily absent, producing unhandled ENOENT failures unrelated to the staleness
guard logic under test.

Fix: add a GSD_REPO_ROOT env override to _gen-helpers.mjs so requireFreshDist()
resolves dist/ts paths against the provided root instead of the repo root derived
from import.meta.url. The test creates an isolated tmpdir tree per subtest (with
the real TS source copied in) and passes GSD_REPO_ROOT=<tmpdir> to the generator
subprocess, so no real dist files are ever touched during subtests A or B.

Subtest C (exits 0 on fresh dist) still uses the real repo tree because it needs
actual compiled output to exercise the generator end-to-end, but only sets the TS
source mtime (safe under concurrency) — it does not remove or rename any dist file.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 19:33:54 -04:00

92 lines
2.7 KiB
JavaScript

#!/usr/bin/env node
/**
* Generator for the Secrets CJS artifact.
*
* Reads the compiled ESM output from sdk/dist/query/secrets.js,
* extracts function source via Function.prototype.toString() for exports,
* then emits get-shit-done/bin/lib/secrets.generated.cjs.
*
* Run: cd sdk && npm run gen:secrets
* Freshness check: node sdk/scripts/check-secrets-fresh.mjs
*/
import { writeFile } from 'node:fs/promises';
import { fileURLToPath } from 'node:url';
import { requireFreshDist } from './_gen-helpers.mjs';
requireFreshDist('sdk/dist/query/secrets.js', 'sdk/src/query/secrets.ts');
export const BANNER = `'use strict';
/**
* GENERATED FILE — DO NOT EDIT.
*
* Source: sdk/src/query/secrets.ts
* Regenerate: cd sdk && npm run gen:secrets
*
* Secrets handling — masking convention for API keys and other
* credentials managed via /gsd-settings-integrations.
* This module does not read the filesystem.
*/
`;
export async function buildSecretsCjs() {
// Load the compiled ESM module to get exports via Function.prototype.toString()
const distUrl = new URL('../dist/query/secrets.js', import.meta.url);
const {
SECRET_CONFIG_KEYS,
isSecretKey,
maskSecret,
maskIfSecret,
} = await import(distUrl.href);
// Get exported function bodies via Function.prototype.toString()
const isSecretKeyBody = isSecretKey.toString();
const maskSecretBody = maskSecret.toString();
const maskIfSecretBody = maskIfSecret.toString();
// SECRET_CONFIG_KEYS is a Set — reconstruct it as a constant declaration
const secretKeys = [...SECRET_CONFIG_KEYS];
const secretKeysLiteral = secretKeys.map(k => ` '${k}',`).join('\n');
const parts = [
BANNER.trimEnd(),
'',
'const SECRET_CONFIG_KEYS = new Set([',
secretKeysLiteral,
']);',
'',
isSecretKeyBody,
'',
maskSecretBody,
'',
maskIfSecretBody,
'',
'module.exports = { SECRET_CONFIG_KEYS, isSecretKey, maskSecret, maskIfSecret };',
'',
];
return parts.join('\n');
}
async function main() {
const content = await buildSecretsCjs();
const outPath = fileURLToPath(
new URL('../../get-shit-done/bin/lib/secrets.generated.cjs', import.meta.url),
);
await writeFile(outPath, content, 'utf-8');
console.log(`Written: ${outPath}`);
}
// Only run main() when this file is the entry point, not when imported.
// process.argv[1] is already an absolute filesystem path on every platform Node
// supports; comparing directly avoids the Windows URL-parsing bug where
// `C:\\…\\gen-*.mjs` is misread as scheme "c:" by `new URL(...)`.
if (fileURLToPath(import.meta.url) === process.argv[1]) {
main().catch((err) => {
console.error(err);
process.exit(1);
});
}