Skip to content

test: cover user aggregate API routing and recent schema sync contracts - #882

Closed
cursor[bot] wants to merge 1 commit into
mainfrom
cursor/bc-3b520d41-1522-4ab0-b75d-9274a458f5a9-28d2
Closed

cursor[bot] wants to merge 1 commit into
mainfrom
cursor/bc-3b520d41-1522-4ab0-b75d-9274a458f5a9-28d2

Conversation

@cursor

@cursor cursor Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Description

Regression test coverage for recently merged production changes with meaningful business risk and no dedicated tests.

Risky behavior now covered

  1. User get aggregate API (fix: route user get through the aggregate API #876) — GET /ng/api/user/{userId} returns 405 on ng-manager (surfaced as 500). The fix routes through GET /ng/api/user/aggregate/{userId}. Tests lock the endpoint spec and registry.dispatch path so a revert re-breaks user lookups.

  2. HttpStepInfo authentication conditionals (chore: auto-sync harness schemas #869) — Schema sync added if/then required-field branches for Basic, BearerToken, and ApiKey auth types. Contract tests assert each branch requires the correct spec fields in v0 pipeline and template bundles.

  3. UnifiedStageNodeV1 permissions (chore: auto-sync harness schemas #864) — v1 pipeline/template stages gained a permissions object for scoped stage RBAC. Contract tests assert the field exists with the expected description.

  4. Istio-only K8s traffic routing (chore: auto-sync harness schemas #874) — Upstream removed SMI provider support and consolidated IstioProviderSpec (gateways/hosts/delegateService). Contract tests assert istio is the sole provider enum value and SMI/rootService are absent.

Test files added/updated

  • Added: tests/registry/access-control.test.ts (11 tests)
  • Updated: tests/schemas/schema-bundle-contract.test.ts (+3 contract tests)

Why these tests materially reduce regression risk

  • User aggregate routing is a silent production failure — agents calling harness_get(resource_type="user") would hit a disallowed endpoint without these guards.
  • Schema bundle contracts catch auto-sync regressions before agents build invalid pipeline YAML from stale or truncated schema definitions.
  • All tests are deterministic, mock-based, and independent of Harness credentials.

Type of Change

  • Bug fix
  • New feature
  • Refactor
  • Documentation
  • Other — regression test coverage

Checklist

  • pnpm test passes (28/28 targeted tests)
  • pnpm typecheck passes
  • pnpm build passes
  • pnpm standards:check passes
  • pnpm docs:check passes

Validation

pnpm test tests/registry/access-control.test.ts tests/schemas/schema-bundle-contract.test.ts
# 28 passed
Open in Web View Automation 

Add regression tests for access_control user get/list aggregate endpoints
(#876) and schema bundle contracts for HttpStepInfo auth conditionals (#869),
UnifiedStageNodeV1 permissions (#864), and Istio-only traffic routing (#874).

Co-authored-by: Rohan Gupta <thisrohangupta@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants