Files
msd-core/tests/milestone-audit.test.cjs
Tom Boucher f0a20e4dd7 feat: open artifact audit gate for milestone close and phase verify (#2157, #2158) (#2160)
* feat(2158): add audit.cjs open artifact scanner with security-hardened path handling

- Scans 8 .planning/ artifact categories for unresolved state
- Debug sessions, quick tasks, threads, todos, seeds, UAT gaps, verification gaps, CONTEXT open questions
- requireSafePath with allowAbsolute:true on all file reads
- sanitizeForDisplay on all output strings
- Graceful per-category error handling, never throws
- formatAuditReport returns human-readable report with emoji indicators

* feat(2158): add audit-open CLI command to gsd-tools.cjs + Deferred Items to state template

- Add audit-open [--json] case to switch router
- Add audit-open entry to header comment block
- Add Deferred Items section to state.md template for milestone carry-forward

* feat(2157): add phase artifact scan step to verify-work workflow

- scan_phase_artifacts step runs audit-open --json after UAT completion
- Surfaces UAT gaps, VERIFICATION gaps, and CONTEXT open questions for current phase
- Prompts user to confirm or decline before marking phase verified
- Records acknowledged gaps in VERIFICATION.md Acknowledged Gaps section
- SECURITY note: file paths validated, content truncated and sanitized before display

* feat(2158): add pre-close artifact audit gate to complete-milestone workflow

- pre_close_artifact_audit step runs before verify_readiness
- Displays full audit report when open items exist
- Three-way choice: Resolve, Acknowledge all, or Cancel
- Acknowledge path writes deferred items table to STATE.md
- Records deferred count in MILESTONES.md entry
- Adds three new success criteria checklist items
- SECURITY note on sanitizing all STATE.md writes

* test(2157,2158): add milestone audit gate tests

- 6 tests for audit.cjs: structured result, graceful missing dirs, open debug detection,
  resolved session exclusion, formatAuditReport header, all-clear message
- 3 tests for complete-milestone.md: pre_close_artifact_audit step, Deferred Items,
  security note presence
- 2 tests for verify-work.md: scan_phase_artifacts step, user prompt for gaps
- 1 test for state.md template: Deferred Items section
2026-04-12 10:06:42 -04:00

146 lines
5.4 KiB
JavaScript

'use strict';
const { describe, test, beforeEach, afterEach } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('fs');
const path = require('path');
const { createTempProject, cleanup } = require('./helpers.cjs');
describe('audit.cjs module (#2158)', () => {
let tmpDir;
beforeEach(() => {
tmpDir = createTempProject('audit-test');
});
afterEach(() => {
cleanup(tmpDir);
});
test('auditOpenArtifacts returns structured result with counts', () => {
const { auditOpenArtifacts } = require('../get-shit-done/bin/lib/audit.cjs');
const result = auditOpenArtifacts(tmpDir);
assert.ok(typeof result === 'object', 'result must be object');
assert.ok(typeof result.counts === 'object', 'result must have counts');
assert.ok(typeof result.counts.total === 'number', 'counts.total must be number');
assert.ok(typeof result.has_open_items === 'boolean', 'has_open_items must be boolean');
});
test('auditOpenArtifacts handles missing planning directories gracefully', () => {
const { auditOpenArtifacts } = require('../get-shit-done/bin/lib/audit.cjs');
// tmpDir has .planning/ but no debug/ or threads/ subdirs
const result = auditOpenArtifacts(tmpDir);
assert.strictEqual(result.counts.total, 0, 'empty project should have 0 open items');
assert.strictEqual(result.has_open_items, false);
});
test('auditOpenArtifacts detects open debug sessions', () => {
const { auditOpenArtifacts } = require('../get-shit-done/bin/lib/audit.cjs');
// Create a fake debug session
const debugDir = path.join(tmpDir, '.planning', 'debug');
fs.mkdirSync(debugDir, { recursive: true });
fs.writeFileSync(path.join(debugDir, 'test-bug.md'), [
'---',
'status: investigating',
'trigger: login fails',
'updated: 2026-04-10',
'---',
'# Debug: test-bug',
].join('\n'));
const result = auditOpenArtifacts(tmpDir);
assert.strictEqual(result.counts.debug_sessions, 1);
assert.ok(result.has_open_items);
});
test('auditOpenArtifacts ignores resolved debug sessions', () => {
const { auditOpenArtifacts } = require('../get-shit-done/bin/lib/audit.cjs');
const resolvedDir = path.join(tmpDir, '.planning', 'debug', 'resolved');
fs.mkdirSync(resolvedDir, { recursive: true });
fs.writeFileSync(path.join(resolvedDir, 'old-bug.md'), [
'---',
'status: resolved',
'---',
'# Resolved',
].join('\n'));
const result = auditOpenArtifacts(tmpDir);
assert.strictEqual(result.counts.debug_sessions, 0);
});
test('formatAuditReport returns string with header', () => {
const { auditOpenArtifacts, formatAuditReport } = require('../get-shit-done/bin/lib/audit.cjs');
const result = auditOpenArtifacts(tmpDir);
const report = formatAuditReport(result);
assert.ok(typeof report === 'string');
assert.ok(report.includes('Artifact Audit') || report.includes('artifact audit') || report.includes('All artifact'));
});
test('formatAuditReport shows all clear when no open items', () => {
const { auditOpenArtifacts, formatAuditReport } = require('../get-shit-done/bin/lib/audit.cjs');
const result = auditOpenArtifacts(tmpDir);
const report = formatAuditReport(result);
assert.ok(report.includes('clear') || report.includes('0 items') || report.includes('no open'),
'clean report should indicate all clear');
});
});
describe('complete-milestone workflow has pre-close audit gate (#2158)', () => {
const completeMilestoneContent = fs.readFileSync(
path.join(__dirname, '..', 'get-shit-done', 'workflows', 'complete-milestone.md'),
'utf8'
);
test('complete-milestone has pre_close_artifact_audit step', () => {
assert.ok(
completeMilestoneContent.includes('pre_close_artifact_audit') ||
completeMilestoneContent.includes('audit-open'),
'missing pre-close audit gate'
);
});
test('complete-milestone surfaces deferred items to STATE.md', () => {
assert.ok(completeMilestoneContent.includes('Deferred Items'),
'missing Deferred Items carry-forward logic');
});
test('complete-milestone has security note for audit output', () => {
assert.ok(
completeMilestoneContent.includes('sanitiz') || completeMilestoneContent.includes('SECURITY'),
'missing security note in milestone audit gate'
);
});
});
describe('verify-work workflow has phase artifact check (#2157)', () => {
const verifyWorkContent = fs.readFileSync(
path.join(__dirname, '..', 'get-shit-done', 'workflows', 'verify-work.md'),
'utf8'
);
test('verify-work has scan_phase_artifacts step', () => {
assert.ok(
verifyWorkContent.includes('scan_phase_artifacts') || verifyWorkContent.includes('audit-open'),
'missing phase artifact scan step'
);
});
test('verify-work prompts user on open UAT gaps', () => {
assert.ok(
verifyWorkContent.includes('gaps') && verifyWorkContent.includes('Proceed'),
'missing user prompt for open gaps'
);
});
});
describe('state.md template has Deferred Items section (#2158)', () => {
const stateTemplate = fs.readFileSync(
path.join(__dirname, '..', 'get-shit-done', 'templates', 'state.md'),
'utf8'
);
test('state.md template includes Deferred Items section', () => {
assert.ok(stateTemplate.includes('Deferred Items'),
'state.md template missing Deferred Items section');
});
});