Commit Graph

24 Commits

Author SHA1 Message Date
Jakub Zych
0ac9dc45d0 fix(02): scan leftover passwords and redact secrets in diffs (WR-04)
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 14:43:01 +02:00
Jakub Zych
d3d202e0e2 fix(02): reject trailing JSON after the first decoded value (WR-03)
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 14:41:59 +02:00
Jakub Zych
5cb2defe0f fix(02): compare redirect Location headers during replay (WR-02)
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 14:41:39 +02:00
Jakub Zych
7e70afe819 fix(02): write fixtures exclusively and only on successful flush (WR-01)
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 14:41:18 +02:00
Jakub Zych
5994e671b3 fix(02): stop short ids rewriting pagination and IPv4 (CR-01)
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 14:39:45 +02:00
Jakub Zych
5ed920b7b1 test(02-05): cover proxy, scrub and CLI security boundaries
- Reject non-loopback bind/upstream, cap bodies, isolate concurrent sessions and refuse traversal
- Scrub JWT, inv_ tokens, cookies, client secrets and OAuth codes out of fixtures
- CLI discovery and replay errors exit nonzero without printing secrets

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 14:06:40 +02:00
Jakub Zych
59b5276cba test(02-05): lock down every response parity class with negative tests
- Record/replay baselines plus mutated fixtures for nil vs [], dates, tri-state bools, envelopes, money and ids
- Header, CSV/image byte, sidecar digest and two-flow continuation cases fail with path diagnostics
- Manifest coverage still reports later flows after a comparison failure

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 14:03:55 +02:00
Jakub Zych
7a6c669e3a fix(02-03): scrub PKCE and OAuth form fields by name
Value-based replace can miss a code_verifier when an authorization code is a substring of it, which 502'd MCP token capture.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 13:43:27 +02:00
Jakub Zych
2eb9b4b0c9 fix(02-03): surface reverse-proxy record failures in 502 bodies
Silent "upstream error" hid capture-rule failures during MCP token exchange.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 13:40:47 +02:00
Jakub Zych
8881df9f7a fix(02-03): capture OAuth code from JSON redirect URLs
Consent returns the callback URL in JSON, so replay can fill {{oauth:code}} from $.data.redirect_to before the token request.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 13:38:54 +02:00
Jakub Zych
22f02eed59 fix(02-03): mask OAuth client_id and unix issued_at
RFC 7591 registration returns a string client_id and unix client_id_issued_at; treating those as Carbon/integer foreign keys would fail PHP self-replay of MCP OAuth.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 13:36:30 +02:00
Jakub Zych
8f94b07986 fix(02-03): scrub PHP-escaped JSON secret values
PHP json_encode writes \/ so captured redirect URLs never matched the fixture body, leaving OAuth codes in client sessions.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 13:32:11 +02:00
Jakub Zych
0307510b22 fix(02-03): mask collection_key and checkpoint in JSON diffs
Album sync payloads hash the collection and stamp a checkpoint that
change across seed runs and must not fail PHP self-replay.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 13:03:38 +02:00
Jakub Zych
4c1259aafd fix(02-03): keep a recorded seed when --update recaptures routes
Re-running bootstrap against an already seeded PHP instance 409s.
Route --update must not recapture a complete seed fixture.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 13:00:44 +02:00
Jakub Zych
39ddf787ce fix(02-03): re-record on --update and honor case capture rules
Ordered PHP self-replay needs regenerated share tokens captured into
vars, and --update must overwrite already-recorded route fixtures.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 13:00:14 +02:00
Jakub Zych
5b947c7454 fix(02-03): treat null foreign keys as valid masked ids
PHP album payloads leave discogs_id null. The id mask required an
integer and failed PHP self-replay on otherwise identical bodies.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 12:52:06 +02:00
Jakub Zych
591a0d4681 fix(02-03): expand expected placeholders after replay capture
Unquoted numeric id placeholders made recorded JSON illegal to parse.
Replay now recaptures, persists vars, expands the expected body, and
diffs against the live response.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 12:51:24 +02:00
Jakub Zych
1ea3c59055 fix(02-03): scrub short captured ids only at token boundaries
Numeric seed ids like 1 were substring-replaced through /api/v1 paths
and 15-style JSON integers. Keep ReplaceAll for long secrets and isolate
short values so the corpus stays replayable.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 12:47:38 +02:00
Jakub Zych
4451c2f39f fix(02-03): resolve relative seed specs and skip only recorded seeds
Manifest seed paths are fixtures-relative. Skip re-hitting the backend
only when every seed step already has a recorded status so a hand-written
spec can be recorded in place.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 12:46:38 +02:00
Jakub Zych
24c1f43e84 feat(02-02): record manifest route cases and report coverage
Drive ordered route cases through RecordFlow, resume in batches of
15, and print recorded/passing/failing/unrecorded coverage.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 12:36:48 +02:00
Jakub Zych
aa165fe3d0 feat(02-02): capture, scrub, and strictly diff stateful flows
Resolve named placeholders from a private variable store, mask
dates and ids after shape checks, and keep comparing independent steps.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 12:32:49 +02:00
Jakub Zych
bb6a5a91c9 feat(02-02): capture named sessions through a loopback proxy
Record Nuxt/MCP traffic as ordered flows via parity:proxy, pin
loopback upstream, and refuse oversized or credential-shaped fixtures.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 12:27:57 +02:00
Jakub Zych
f669d056c9 feat(02-01): lock the one-route tide record and replay contract
- Reject unknown YAML fields, empty names, duplicate steps and unsafe sidecars
- Treat JSON key order as insignificant and fail missing keys and token types at $.path
- Bound request bodies and refuse oversized or malformed input before writing a fixture

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 12:21:34 +02:00
Jakub Zych
f6e1b892bc feat(02-01): record and replay one route through the summer CLI
- Add a generic tide flow schema with YAML fixture IO and HTTP record/replay
- Register parity:record and parity:replay on the bonfire summer tool
- Diff JSON scalars at $.path and non-JSON bodies at the changed byte offset

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 12:20:22 +02:00