feat(02-01): lock the one-route tide record and replay contract

- Reject unknown YAML fields, empty names, duplicate steps and unsafe sidecars
- Treat JSON key order as insignificant and fail missing keys and token types at $.path
- Bound request bodies and refuse oversized or malformed input before writing a fixture

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Jakub Zych
2026-09-17 12:21:34 +02:00
parent f6e1b892bc
commit f669d056c9
3 changed files with 155 additions and 0 deletions

View File

@@ -57,6 +57,9 @@ func doStep(ctx context.Context, client *http.Client, target string, req Request
if err != nil {
return Response{}, err
}
if int64(len(req.Body)) > limit {
return Response{}, fmt.Errorf("%w: request body exceeds %d bytes", errTruncated, limit)
}
var body io.Reader
if req.Body != "" {
body = strings.NewReader(string(req.Body))