You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Follow-ups to #257: suggestion-hides-unapproved edge, hiddenChannels privacy test, cache-copy and TTL test gaps #276
hide only names whose proposal has ever been approved (needs history);
or document the trade-off.
Test gap: the cache-safety copy in hideRevoked on the default path.TestRevokedFilterDoesNotMutateCacheAndKeepsEncrypted only covers ?includeEncrypted=true, where the slice is already copied. Add the default request, where hideRevoked receives GetChannels' cached slice. The mutant that drops the copy must fail.
Test gap (privacy-relevant): the EXISTS (… transmissions …) clause. Without it, hiddenChannels on the public /api/channels would list proposals that have no traffic, including pending suggestions, which are otherwise admin-only. Add a test that a pending suggestion without traffic never appears in hiddenChannels. Mutant G1 must fail.
Test gap: invalidateApiCache('/channels') in refreshChannelList. The harness api() has no TTL cache, so mutant F3 survives. The same gap exists for onApproved. Add a harness with a TTL cache, or an E2E that revokes and checks the list without waiting 15 s.
Docs:hiddenChannels is global, not per region, and another open tab keeps its old hidden set until it reloads. That also applies after a re-approval. Add one sentence about it.
Follow-ups from pve-agent3's round-2 review of #257 (#251, merged as
c6b356de). Details and evidence are in the review comment on #257.hashChannels/channelKeysby a hot reload, or a name past the 4096-name cap ofbuiltin-channels.json. After fix(channels): hide revoked shared channels from the channel list (#251) #257, an anonymous suggestion for that name (pending) hides it. Decide on one of these and lock it with a test:hideRevokedon the default path.TestRevokedFilterDoesNotMutateCacheAndKeepsEncryptedonly covers?includeEncrypted=true, where the slice is already copied. Add the default request, wherehideRevokedreceivesGetChannels' cached slice. The mutant that drops the copy must fail.EXISTS (… transmissions …)clause. Without it,hiddenChannelson the public/api/channelswould list proposals that have no traffic, including pending suggestions, which are otherwise admin-only. Add a test that a pending suggestion without traffic never appears inhiddenChannels. Mutant G1 must fail.invalidateApiCache('/channels')inrefreshChannelList. The harnessapi()has no TTL cache, so mutant F3 survives. The same gap exists foronApproved. Add a harness with a TTL cache, or an E2E that revokes and checks the list without waiting 15 s.hiddenChannelsis global, not per region, and another open tab keeps its old hidden set until it reloads. That also applies after a re-approval. Add one sentence about it.