* test(#177): add DispatchEvent factory failing tests Red tests for makeDispatchEvent shape, traceId UUID v4, uniqueness, parentTraceId-always-undefined (P1.3), args redaction toggle, ISO 8601 timestamp, and all result variant passthrough. * feat(#177): introduce DispatchEvent factory makeDispatchEvent produces an immutable event record per dispatch: - traceId: crypto.randomUUID() (UUID v4) - parentTraceId: always undefined (P1.4 wires composer) - command, result, timestamp (ISO 8601) - args only included when includeArgs === true (default: omitted) * test(#177): add arg redaction policy failing tests Red tests for shouldIncludeArgs (GSD_AUDIT_ARGS env gating) and redactEvent (strips args from frozen events, preserves all other fields, returns a new object, never mutates the source). * feat(#177): introduce arg redaction policy shouldIncludeArgs(): only GSD_AUDIT_ARGS==='1' opts in; all other values (unset, '', '0', 'true') default to omitting args. redactEvent(event): returns a shallow copy of the event, dropping the args field unless opted in. Never mutates the (frozen) source event. * test(#177): add DispatchLogger interface failing tests Red tests covering: - no-op logger: silent on all events, never throws - default logger: silent on ok, one flattened JSON line to stderr on error - default logger: audit file creation + append-only + redaction + config gate - GSD_AUDIT env var and config.audit.enabled config gate - GSD_AUDIT_ARGS opt-in for args inclusion All tests use real fs under os.tmpdir() — no mocked appendFileSync. * feat(#177): introduce DispatchLogger with default and no-op implementations createNoOpLogger(): silent on all events — Hub default when no logger injected. createDefaultLogger({ cwd, config }): - Silent on ok result - Flattened JSON line to stderr on error: { kind, traceId, ...typedPayload } - Append-only audit at .planning/.gsd-trace.jsonl when GSD_AUDIT=1 or config.audit.enabled - Args redacted by default; GSD_AUDIT_ARGS=1 opts in - Logger errors caught internally; never break dispatch callers * test(#177): add Hub+logger integration failing tests Red tests verifying: - onEvent called exactly once per dispatch (ok, error, handler-throw, unknown) - DispatchEvent shape: traceId uniqueness, command, result.kind, parentTraceId - Logger errors contained (dispatch still returns Result, warn line to stderr) - Hub defaults to no-op when no logger injected - End-to-end with createDefaultLogger: silent on success, stderr on error, audit file * feat(#177): wire DispatchLogger into CommandRoutingHub Add optional logger param to createHub({ ..., logger }). Defaults to createNoOpLogger() — silent, no behaviour change for callers that don't inject a logger. After every dispatch (success and error): - Normalises HubResult { ok } to DispatchEvent { kind: 'ok'|error-kind } - Calls makeDispatchEvent({ command, args, result }) to mint the event - Calls logger.onEvent(event) exactly once - Wraps in try/catch: logger errors emit { level:'warn', source:'DispatchLogger' } to stderr but never propagate to dispatch callers * chore(#177): gitignore .planning/.gsd-trace.jsonl audit file The audit trail is local-only, append-only, and must never be committed. Slotted under the existing "Local scratch + Claude-test artifacts" block. * docs(#177): document GSD_AUDIT, GSD_AUDIT_ARGS, config.audit.enabled New ## Observability section at end of CONFIGURATION.md covering: - Default silent/stderr behaviour overview - Stderr error JSON format - Audit file opt-in (env var and config key) - Args redaction policy and GSD_AUDIT_ARGS opt-in Also slots GSD_AUDIT and GSD_AUDIT_ARGS into the existing ## Environment Variables table (alphabetical order). * chore(#177): add changeset for observability seam type: Added — new DispatchLogger seam with default silent/stderr/audit behaviour.
151 lines
4.4 KiB
JavaScript
151 lines
4.4 KiB
JavaScript
'use strict';
|
|
|
|
/**
|
|
* Tests for arg redaction policy (issue #177).
|
|
*
|
|
* Redaction decides whether args appear in emitted events based on
|
|
* the GSD_AUDIT_ARGS env var. Tests use real env manipulation and
|
|
* restore state in afterEach. No mocks.
|
|
*/
|
|
|
|
const { describe, test, beforeEach, afterEach } = require('node:test');
|
|
const assert = require('node:assert/strict');
|
|
|
|
const {
|
|
shouldIncludeArgs,
|
|
redactEvent,
|
|
} = require('../../get-shit-done/bin/lib/observability/redaction.cjs');
|
|
|
|
describe('shouldIncludeArgs', () => {
|
|
let originalEnv;
|
|
|
|
beforeEach(() => {
|
|
originalEnv = process.env.GSD_AUDIT_ARGS;
|
|
delete process.env.GSD_AUDIT_ARGS;
|
|
});
|
|
|
|
afterEach(() => {
|
|
if (originalEnv === undefined) {
|
|
delete process.env.GSD_AUDIT_ARGS;
|
|
} else {
|
|
process.env.GSD_AUDIT_ARGS = originalEnv;
|
|
}
|
|
});
|
|
|
|
test('returns false when GSD_AUDIT_ARGS is not set', () => {
|
|
assert.strictEqual(shouldIncludeArgs(), false);
|
|
});
|
|
|
|
test('returns false when GSD_AUDIT_ARGS is empty string', () => {
|
|
process.env.GSD_AUDIT_ARGS = '';
|
|
assert.strictEqual(shouldIncludeArgs(), false);
|
|
});
|
|
|
|
test('returns false when GSD_AUDIT_ARGS is "0"', () => {
|
|
process.env.GSD_AUDIT_ARGS = '0';
|
|
assert.strictEqual(shouldIncludeArgs(), false);
|
|
});
|
|
|
|
test('returns true when GSD_AUDIT_ARGS is "1"', () => {
|
|
process.env.GSD_AUDIT_ARGS = '1';
|
|
assert.strictEqual(shouldIncludeArgs(), true);
|
|
});
|
|
|
|
test('returns false for any other non-1 value', () => {
|
|
process.env.GSD_AUDIT_ARGS = 'yes';
|
|
assert.strictEqual(shouldIncludeArgs(), false);
|
|
|
|
process.env.GSD_AUDIT_ARGS = 'true';
|
|
assert.strictEqual(shouldIncludeArgs(), false);
|
|
});
|
|
});
|
|
|
|
describe('redactEvent', () => {
|
|
let originalEnv;
|
|
|
|
beforeEach(() => {
|
|
originalEnv = process.env.GSD_AUDIT_ARGS;
|
|
delete process.env.GSD_AUDIT_ARGS;
|
|
});
|
|
|
|
afterEach(() => {
|
|
if (originalEnv === undefined) {
|
|
delete process.env.GSD_AUDIT_ARGS;
|
|
} else {
|
|
process.env.GSD_AUDIT_ARGS = originalEnv;
|
|
}
|
|
});
|
|
|
|
test('strips args from event when GSD_AUDIT_ARGS is not set', () => {
|
|
const event = Object.freeze({
|
|
traceId: 'abc',
|
|
command: 'plan',
|
|
args: ['--foo', 'bar'],
|
|
result: { kind: 'ok', data: null },
|
|
timestamp: new Date().toISOString(),
|
|
});
|
|
const redacted = redactEvent(event);
|
|
assert.ok(!('args' in redacted), 'args must be absent after redaction');
|
|
assert.equal(redacted.command, 'plan');
|
|
assert.equal(redacted.traceId, 'abc');
|
|
});
|
|
|
|
test('preserves all other fields after redaction', () => {
|
|
const event = Object.freeze({
|
|
traceId: 'xyz',
|
|
parentTraceId: undefined,
|
|
command: 'discuss',
|
|
args: ['--mode', 'fast'],
|
|
result: { kind: 'HandlerRefusal', reason: 'nope' },
|
|
timestamp: '2026-01-01T00:00:00.000Z',
|
|
});
|
|
const redacted = redactEvent(event);
|
|
assert.equal(redacted.traceId, 'xyz');
|
|
assert.equal(redacted.command, 'discuss');
|
|
assert.equal(redacted.timestamp, '2026-01-01T00:00:00.000Z');
|
|
assert.deepStrictEqual(redacted.result, { kind: 'HandlerRefusal', reason: 'nope' });
|
|
});
|
|
|
|
test('includes args when GSD_AUDIT_ARGS=1', () => {
|
|
process.env.GSD_AUDIT_ARGS = '1';
|
|
const event = Object.freeze({
|
|
traceId: 'abc',
|
|
command: 'plan',
|
|
args: ['--foo', 'bar'],
|
|
result: { kind: 'ok', data: null },
|
|
timestamp: new Date().toISOString(),
|
|
});
|
|
const redacted = redactEvent(event);
|
|
assert.ok('args' in redacted, 'args must be present when GSD_AUDIT_ARGS=1');
|
|
assert.deepStrictEqual(redacted.args, ['--foo', 'bar']);
|
|
});
|
|
|
|
test('event without args field stays without args after redaction', () => {
|
|
const event = Object.freeze({
|
|
traceId: 'abc',
|
|
command: 'plan',
|
|
result: { kind: 'ok', data: null },
|
|
timestamp: new Date().toISOString(),
|
|
});
|
|
const redacted = redactEvent(event);
|
|
assert.ok(!('args' in redacted), 'args should not appear if original event had none');
|
|
});
|
|
|
|
test('returns a new object, not a mutation of the original frozen event', () => {
|
|
const event = Object.freeze({
|
|
traceId: 'abc',
|
|
command: 'plan',
|
|
args: ['secret'],
|
|
result: { kind: 'ok', data: null },
|
|
timestamp: new Date().toISOString(),
|
|
});
|
|
const redacted = redactEvent(event);
|
|
// Original must still have args
|
|
assert.ok('args' in event);
|
|
// Redacted must not have args
|
|
assert.ok(!('args' in redacted));
|
|
// They must be different object references
|
|
assert.ok(redacted !== event);
|
|
});
|
|
});
|