fix(web-search): harden client response boundary
This commit is contained in:
@@ -0,0 +1,105 @@
|
||||
# Task: REV-01 Client WebSearchClient remediation
|
||||
|
||||
## Identity
|
||||
|
||||
- Task ID: 20260901-web-search-rev01-client-remediation-e4a7c9b2
|
||||
- Mode: Feature
|
||||
- Branch: codex/20260901-web-search-rev01-client-remediation-e4a7c9b2-web-search-rev01-client-remediation
|
||||
- Worktree: D:\Datas\OthersProjects\makelore-web-search-rev01-client-remediation-e4a7c9b2
|
||||
- Base commit: 4a1e5d31213191a0102eab9278dd9887ba8738f4
|
||||
- Owner: web-search-rev01-client-remediation
|
||||
- Status: Ready for Integration
|
||||
|
||||
## Scope
|
||||
|
||||
- Remediate the four accepted REV-01 Client Spec-axis findings from the exact
|
||||
coordinator frontier `4a1e5d31213191a0102eab9278dd9887ba8738f4`.
|
||||
- Ownership is limited to `electron/services/web-search-client.ts`, its
|
||||
focused Web Search client tests, and this task record. No Server,
|
||||
composition, Pi, Package Store, Renderer, or shared product-scope changes.
|
||||
- Preserve the fixed typed route, trusted admission, same logical-operation
|
||||
replay, closed capability envelope, and external PostgreSQL/live OpenAI/
|
||||
production-activation holds.
|
||||
|
||||
## Intent And Constraints
|
||||
|
||||
- Project Context Loaded:
|
||||
- Task ID: `20260901-web-search-rev01-client-remediation-e4a7c9b2`
|
||||
- Mode: Feature
|
||||
- Branch: `codex/20260901-web-search-rev01-client-remediation-e4a7c9b2-web-search-rev01-client-remediation`
|
||||
- Worktree: `D:\Datas\OthersProjects\makelore-web-search-rev01-client-remediation-e4a7c9b2`
|
||||
- Base commit: `4a1e5d31213191a0102eab9278dd9887ba8738f4`
|
||||
- Other active local tasks: client coordinator, MLW-01/02/03 source tasks,
|
||||
and the read-only REV-01 client/server review tasks. Their records were
|
||||
inspected for scope; no product writer overlaps this remediation.
|
||||
- Overlap/semantic assessment: the four findings are confined to the
|
||||
WebSearchClient response boundary and have one authorized owner. No
|
||||
semantic conflict with server DTO, composition, or Package Store scope.
|
||||
- Read: client `AGENTS.md`; complete `maintain-project-docs`, `implement-spec`,
|
||||
and `tdd` skills; project entry files; client architecture/domain/decision,
|
||||
evidence/reflection/commitment/stale indexes; the Web Search design and
|
||||
implementation Spec; REV-01 client Spec and Standards task records.
|
||||
- Concurrent Task Gate: Passed. `check_project_docs.py` passed; task_context
|
||||
created the isolated worktree and `status --json` matches this task ID,
|
||||
owner, worktree, branch, and exact base.
|
||||
- Planning Gate: Passed. The fixed client review identified exactly four
|
||||
actionable response-boundary findings; the current plan remains within the
|
||||
accepted ownership and does not alter the frozen contract.
|
||||
- Implementation plan:
|
||||
1. Add public-seam tests that fail for status/body precedence, streamed
|
||||
response bounds, closed status/receipt/result pairings, and source URL
|
||||
validation.
|
||||
2. Make the smallest WebSearchClient changes to pass each red test: status
|
||||
first with bounded Retry-After, chunked streaming cap, closed receipt and
|
||||
result invariants, and absolute HTTP(S) URL validation without userinfo.
|
||||
3. Run focused and adjacent tests, typecheck, lint, diff/doc gates; then
|
||||
update this record and create one source commit only after a clean handoff.
|
||||
|
||||
## Outcome
|
||||
|
||||
- Implemented the four accepted WebSearchClient response-boundary fixes:
|
||||
HTTP-status-first 429 handling with bounded Retry-After, a true streamed
|
||||
response cap, closed search/billing/error pairings, and safe bounded source
|
||||
URLs. No file outside the owned client service/test/task-record scope was
|
||||
changed.
|
||||
|
||||
## Verification
|
||||
|
||||
- Concurrent/Planning gates passed.
|
||||
- TDD RED: the new focused suite exposed 8 failures in 16 tests for unsafe
|
||||
URLs, 429 body precedence, chunked buffering, malformed receipts/pairings,
|
||||
and the now-invalid failed-without-error fixture.
|
||||
- TDD GREEN: `pnpm exec vitest run tests/unit/web-search-client.test.ts`
|
||||
passed 16/16.
|
||||
- Adjacent: `pnpm exec vitest run tests/unit/web-search-client.test.ts
|
||||
tests/unit/web-search-plugin-adapter.test.ts` passed 27/27.
|
||||
- `pnpm run typecheck` passed; owned-file ESLint passed with zero errors.
|
||||
- Full `pnpm test` passed: 214 files, 1,759 tests passed, 2 skipped; the
|
||||
pressure suite passed 1/1. Full `pnpm run lint:check` passed with zero
|
||||
errors and five pre-existing warnings outside this task's ownership.
|
||||
- Task-aware doc drift and source diff checks passed; the final source commit
|
||||
and clean `task_context` handoff are recorded below.
|
||||
|
||||
## Handoff
|
||||
|
||||
- Source commit: the final task `HEAD` handed off to the coordinator; its
|
||||
sole parent is the exact coordinator frontier
|
||||
`4a1e5d31213191a0102eab9278dd9887ba8738f4`.
|
||||
- `task_context complete` passed with `READY_FOR_INTEGRATION`; this source
|
||||
commit is the sole integration candidate.
|
||||
|
||||
## Follow-ups
|
||||
|
||||
- Coordinator must integrate only the final source commit and trigger a fresh
|
||||
fixed-range Standards/Spec review.
|
||||
|
||||
## Promotion Candidates
|
||||
|
||||
- Target: client integration coordinator and fresh REV-01 review checkpoint.
|
||||
Proposal: preserve HTTP-status-first semantics, enforce a real 1 MiB stream
|
||||
cap, reject incoherent closed receipts/results, and reject unsafe source URLs.
|
||||
Evidence: REV-01 Client Spec findings and new public-seam regressions.
|
||||
Future impact: prevents malformed responses from overriding server status,
|
||||
unbounded chunked buffering, ungrounded success results, or provider URL
|
||||
leakage. Semantic conflicts: none; human confirmation: not required for this
|
||||
in-scope remediation.
|
||||
Reference in New Issue
Block a user