docs(desktop): preflight comments describe the OAuth-only branch; scope assertion via objectContaining

This commit is contained in:
kshitijk4poor
2026-09-15 16:01:27 +05:30
committed by kshitij
parent 2821cb2d8c
commit e112da7578
2 changed files with 10 additions and 14 deletions

View File

@@ -418,15 +418,10 @@ describe('selectConnection', () => {
// Auth is refreshed externally; the very next click must work with the
// same module and warm socket, without a cached failed readiness result.
await selectConnection('homelab', { profile: 'scout' })
expect(api.mock.calls).toEqual(
Array.from({ length: 3 }, () => [
{
connectionId: 'homelab',
profile: 'scout',
path: '/api/profiles',
timeoutMs: 60_000
}
])
expect(api.mock.calls.map(call => (call as unknown[])[0])).toEqual(
Array.from({ length: 3 }, () =>
expect.objectContaining({ connectionId: 'homelab', profile: 'scout', path: '/api/profiles' })
)
)
expect(openGatewayAgent.mock.calls).toEqual(Array.from({ length: 3 }, () => ['homelab', 'scout']))
expect(ensureGatewayAgent).toHaveBeenCalledTimes(1)

View File

@@ -243,8 +243,9 @@ export async function initializeConnectionsRegistry(): Promise<DesktopConnection
* never probes or opens remote gateways.
*
* Two phases, same commit contract as a Settings → Gateway apply (softSwitch):
* 1. Prove target socket/REST readiness WITHOUT activating it. The previous
* source stays fully bound and painted, so a dead target loses nothing.
* 1. Dial the target — and for OAuth remotes prove a protected REST read —
* WITHOUT activating it. The previous source stays fully bound and
* painted, so a dead target loses nothing.
* 2. Commit: beginGatewaySwitch() — barrier up, machine-context reset,
* session bindings wiped — then activate the already-open socket. The
* wipe runs inside the activation's serialized section, synchronously
@@ -355,9 +356,9 @@ export async function selectConnection(connectionId: string, options: SelectConn
targetConnection.authMode === 'oauth' &&
(targetConnection.kind === 'remote' || targetConnection.kind === 'cloud')
) {
// Retained sockets can outlive cookie/native OAuth REST auth. Prove a
// protected read on the destination before wiping. Keep the exact
// failure for caller UX (network failures must not become sign-in errors).
// Retained sockets can outlive cookie/native OAuth REST auth. Prove the
// cheapest protected read the target always serves before wiping. Keep
// the exact failure for caller UX (network failures are not sign-in errors).
await withTimeout(
getProfiles({ connectionId, profile: targetProfile }),
SWITCH_DIAL_TIMEOUT_MS,