* ✨ Enable closed schemas for RPC methods
* 🐛 Fix duplicate make-dummy-request test helper definition
The branch added a variadic DummyRequest/make-dummy-request pair but
left the pre-existing single-arg definition in place. Because it was
loaded last, zero-arg (make-dummy-request) calls added by
prepare-rpc-params and rpc-nitrate-test threw ArityException, which
broke 384 tests and caused 14 downstream assertion failures.
Remove the stale duplicate so the variadic definition is the only
one, and drop the now-unused yrq alias and duplicate yres alias.
AI-assisted-by: deepseek-v4.1-flash
* ✨ Add focused tests for make-dummy-request helper
Pin the call contract of make-dummy-request, which the suite uses
in three styles: no arguments, a single options map, and keyword
arguments. The helper's redefinition shadowing in 8ca95adb98 was
only caught by a full-suite run with hundreds of unrelated errors;
these tests fail locally in a focused --focus run.
Cover the zero-arg defaults, map and keyword overrides, the
:body-bytes -> ByteArrayInputStream wrapping, :body-stream
precedence, and cookie readback. Also clarify the docstring to
list all supported call styles.
AI-assisted-by: deepseek-v4.1-flash
* 🚑 Prevent RPC client params from overriding auth context
Strip qualified keys from decoded request params before merging
them with the server-built auth context, so transit bodies can
no longer override ::profile-id, ::auth-type or ::token-perms.
Adds a regression test proving the override and the fix.
AI-assisted-by: muse-spark-1.3-contributor
* 📚 Merge backend subtleties memories under generic name
Rename rpc-db-worker-subtleties to subtleties and fold in
http-storage-filedata-subtleties, so the name no longer
enumerates topics. Update all mem: references accordingly.
AI-assisted-by: muse-spark-1.3-contributor
* ✨ Add realistic tests for RPC auth override
Cover the transit wire vector and the real wrapped :get-profile
method with two database profiles, proving a session cannot read
another profile by smuggling :app.rpc/profile-id in the body.
AI-assisted-by: muse-spark-1.3-contributor
* ✨ Add e2e test for RPC auth context override
Parametrize rpcPost with contentType, accept and query so e2e
can send hand-written transit bodies without new dependencies.
The new test proves a transit-smuggled :app.rpc/profile-id no
longer overrides the session in get-profile. Also fix the demo
email assertion in auth-flow to the current uuid format.
AI-assisted-by: muse-spark-1.3-contributor
Add end-to-end HTTP tests under backend/test/e2e/ using Node.js built-in
test runner (node:test) and native fetch. Tests run through the devenv
nginx proxy on port 3450.
Test suites (19 tests total):
- auth-flow: demo profile creation, login, session cookies, access tokens
- export-binfile: file creation, export to asset URL via SSE
- asset-download: download with cookie/token auth, 401 without auth,
S3 redirect behavior, full export-to-download flow
Key findings documented in tests:
- nginx @handle_redirect intercepts backend 307 and proxies to S3 directly,
stripping the client Authorization header (bug does not reproduce in devenv)
- SSE end event uses ~#uri tagged format for URLs
- Unauthenticated RPC returns uuid/zero profile (not null)
AI-assisted-by: mimo-v2.5-pro
Signed-off-by: Andrey Antukh <niwi@niwi.nz>