Phase 0b slice: monorepo scaffold + @sh-mcp/shared core + integration packages (#2)
* Phase 0b slice: monorepo scaffold + shared core + integration packages
The 0a-INDEPENDENT code slice (one-shot via af-0b-package-slice workflow: Haiku
scaffold + Sonnet packages, Sonnet fix-to-green). Nothing deploys; no CDK/servers.
- Monorepo scaffold: npm workspaces, strict TS (NodeNext), vitest (80% gate),
eslint 9 flat config, prettier; ci.yaml/deploy.yaml callers (Node 24, enable-qemu).
- @sh-mcp/shared: transport-agnostic core — Scope/AuthContext/ToolDef, ToolRegistry,
redact()+maskValue() (PII), OpenAPI 3.1 generator. AUTH STUBBED behind an AuthProvider
interface (TODO auth-layer-0a); JWT/aud/client_id/JWKS/deny-list deferred per design.md §2.
- 9 integration packages (qbo, google-maps, internal-data, payments, knowledge-base,
gmail, calendar, tasks, reminders): tools against shared, external deps mocked behind
injected client interfaces; finance handlers call redact().
Verified green: tsc -b clean, vitest 245/245, eslint 0 errors. Auth mechanism intentionally
deferred until the 0a spike resolves it (G16/§0.4).
* Complete Cognito auth provider + Phase 1 build brief
Finish the WIP CognitoAuthProvider (client_id allow-list as audience
boundary, finance TTL ceiling, deny-list, scope-prefix stripping) with
its test suite, and check in docs/build-plan-phase-1.md so the Phase 1
work has its governing brief in-tree (design.md §2.5).
* ci: disable cdk synth for Phase 0b (no CDK app yet)
The reusable ci-typescript-cdk workflow defaults run-cdk-synth: true, but
the Phase 0b package scaffold has no cdk.json or stacks, so cdk synth fails
with '--app is required'. Disable it here; Phase 1 re-enables it with the
server CDK stubs.
2026-06-26 12:42:17 -04:00
|
|
|
import { defineConfig } from 'vitest/config';
|
|
|
|
|
|
|
|
|
|
export default defineConfig({
|
|
|
|
|
test: {
|
|
|
|
|
globals: true,
|
|
|
|
|
environment: 'node',
|
|
|
|
|
coverage: {
|
|
|
|
|
provider: 'v8',
|
|
|
|
|
reporter: ['text', 'json', 'html'],
|
|
|
|
|
include: ['packages/**/*.ts', 'servers/**/*.ts', 'jobs/**/*.ts', 'auth/**/*.ts'],
|
|
|
|
|
exclude: [
|
|
|
|
|
'node_modules/',
|
|
|
|
|
'dist/',
|
|
|
|
|
'**/*.d.ts',
|
|
|
|
|
'**/*.test.ts',
|
|
|
|
|
'**/*.spec.ts',
|
Add security-weighted test suite + coverage gate; wire tooling
Add tests for the highest-risk surface (build-plan §5, design.md §7.3):
tool-hiding, server-side scope enforcement (incl. forced hidden calls),
audience binding, input-schema validation, finance redaction on egress, audit
emission with hashed args, prompt-injection regression (tool output is data),
rate limiting, MCP conformance (in-memory transport round-trip), OpenAPI 3.1
validity, and local-auth safety. Add HTTP integration tests (supertest) for both
servers and per-package dev-client tests. 405 tests pass.
Wire the coverage gate into vitest.config.ts: 80% overall, with per-file
thresholds on the auth + dispatch crown jewels; exclude deferred real client
stubs, entrypoints, cdk apps, and aws-only config from the gate (documented).
Extend eslint flat config + add .prettierignore to cover servers/. Commit the
updated package-lock.json.
2026-06-24 20:42:41 -04:00
|
|
|
// Type-only module (no executable lines).
|
|
|
|
|
'**/types.ts',
|
|
|
|
|
// Barrel re-export files (no logic; re-exports only).
|
|
|
|
|
'**/index.ts',
|
|
|
|
|
// Real external-service client stubs are DEFERRED (build-plan §0/§4): they
|
|
|
|
|
// throw until the real AWS/Google/QBO integrations land in a later phase
|
|
|
|
|
// and are only reachable in SH_MCP_ENV=aws, which is out of scope here.
|
|
|
|
|
'packages/*/src/client.ts',
|
|
|
|
|
// Synth-only CDK apps (build-plan §6) — validated by `cdk synth`, not vitest.
|
|
|
|
|
'servers/*/cdk/**',
|
|
|
|
|
// Server config aws-branch + listener wiring (build-plan §2.2) — the aws
|
|
|
|
|
// path needs Cognito/SSM, out of scope for the local test surface.
|
|
|
|
|
'servers/*/src/config.ts',
|
Phase 0b slice: monorepo scaffold + @sh-mcp/shared core + integration packages (#2)
* Phase 0b slice: monorepo scaffold + shared core + integration packages
The 0a-INDEPENDENT code slice (one-shot via af-0b-package-slice workflow: Haiku
scaffold + Sonnet packages, Sonnet fix-to-green). Nothing deploys; no CDK/servers.
- Monorepo scaffold: npm workspaces, strict TS (NodeNext), vitest (80% gate),
eslint 9 flat config, prettier; ci.yaml/deploy.yaml callers (Node 24, enable-qemu).
- @sh-mcp/shared: transport-agnostic core — Scope/AuthContext/ToolDef, ToolRegistry,
redact()+maskValue() (PII), OpenAPI 3.1 generator. AUTH STUBBED behind an AuthProvider
interface (TODO auth-layer-0a); JWT/aud/client_id/JWKS/deny-list deferred per design.md §2.
- 9 integration packages (qbo, google-maps, internal-data, payments, knowledge-base,
gmail, calendar, tasks, reminders): tools against shared, external deps mocked behind
injected client interfaces; finance handlers call redact().
Verified green: tsc -b clean, vitest 245/245, eslint 0 errors. Auth mechanism intentionally
deferred until the 0a spike resolves it (G16/§0.4).
* Complete Cognito auth provider + Phase 1 build brief
Finish the WIP CognitoAuthProvider (client_id allow-list as audience
boundary, finance TTL ceiling, deny-list, scope-prefix stripping) with
its test suite, and check in docs/build-plan-phase-1.md so the Phase 1
work has its governing brief in-tree (design.md §2.5).
* ci: disable cdk synth for Phase 0b (no CDK app yet)
The reusable ci-typescript-cdk workflow defaults run-cdk-synth: true, but
the Phase 0b package scaffold has no cdk.json or stacks, so cdk synth fails
with '--app is required'. Disable it here; Phase 1 re-enables it with the
server CDK stubs.
2026-06-26 12:42:17 -04:00
|
|
|
],
|
|
|
|
|
thresholds: {
|
Add security-weighted test suite + coverage gate; wire tooling
Add tests for the highest-risk surface (build-plan §5, design.md §7.3):
tool-hiding, server-side scope enforcement (incl. forced hidden calls),
audience binding, input-schema validation, finance redaction on egress, audit
emission with hashed args, prompt-injection regression (tool output is data),
rate limiting, MCP conformance (in-memory transport round-trip), OpenAPI 3.1
validity, and local-auth safety. Add HTTP integration tests (supertest) for both
servers and per-package dev-client tests. 405 tests pass.
Wire the coverage gate into vitest.config.ts: 80% overall, with per-file
thresholds on the auth + dispatch crown jewels; exclude deferred real client
stubs, entrypoints, cdk apps, and aws-only config from the gate (documented).
Extend eslint flat config + add .prettierignore to cover servers/. Commit the
updated package-lock.json.
2026-06-24 20:42:41 -04:00
|
|
|
// Overall gate (build-plan §5 / design.md §7.3).
|
Phase 0b slice: monorepo scaffold + @sh-mcp/shared core + integration packages (#2)
* Phase 0b slice: monorepo scaffold + shared core + integration packages
The 0a-INDEPENDENT code slice (one-shot via af-0b-package-slice workflow: Haiku
scaffold + Sonnet packages, Sonnet fix-to-green). Nothing deploys; no CDK/servers.
- Monorepo scaffold: npm workspaces, strict TS (NodeNext), vitest (80% gate),
eslint 9 flat config, prettier; ci.yaml/deploy.yaml callers (Node 24, enable-qemu).
- @sh-mcp/shared: transport-agnostic core — Scope/AuthContext/ToolDef, ToolRegistry,
redact()+maskValue() (PII), OpenAPI 3.1 generator. AUTH STUBBED behind an AuthProvider
interface (TODO auth-layer-0a); JWT/aud/client_id/JWKS/deny-list deferred per design.md §2.
- 9 integration packages (qbo, google-maps, internal-data, payments, knowledge-base,
gmail, calendar, tasks, reminders): tools against shared, external deps mocked behind
injected client interfaces; finance handlers call redact().
Verified green: tsc -b clean, vitest 245/245, eslint 0 errors. Auth mechanism intentionally
deferred until the 0a spike resolves it (G16/§0.4).
* Complete Cognito auth provider + Phase 1 build brief
Finish the WIP CognitoAuthProvider (client_id allow-list as audience
boundary, finance TTL ceiling, deny-list, scope-prefix stripping) with
its test suite, and check in docs/build-plan-phase-1.md so the Phase 1
work has its governing brief in-tree (design.md §2.5).
* ci: disable cdk synth for Phase 0b (no CDK app yet)
The reusable ci-typescript-cdk workflow defaults run-cdk-synth: true, but
the Phase 0b package scaffold has no cdk.json or stacks, so cdk synth fails
with '--app is required'. Disable it here; Phase 1 re-enables it with the
server CDK stubs.
2026-06-26 12:42:17 -04:00
|
|
|
lines: 80,
|
|
|
|
|
functions: 80,
|
|
|
|
|
branches: 80,
|
|
|
|
|
statements: 80,
|
Add security-weighted test suite + coverage gate; wire tooling
Add tests for the highest-risk surface (build-plan §5, design.md §7.3):
tool-hiding, server-side scope enforcement (incl. forced hidden calls),
audience binding, input-schema validation, finance redaction on egress, audit
emission with hashed args, prompt-injection regression (tool output is data),
rate limiting, MCP conformance (in-memory transport round-trip), OpenAPI 3.1
validity, and local-auth safety. Add HTTP integration tests (supertest) for both
servers and per-package dev-client tests. 405 tests pass.
Wire the coverage gate into vitest.config.ts: 80% overall, with per-file
thresholds on the auth + dispatch crown jewels; exclude deferred real client
stubs, entrypoints, cdk apps, and aws-only config from the gate (documented).
Extend eslint flat config + add .prettierignore to cover servers/. Commit the
updated package-lock.json.
2026-06-24 20:42:41 -04:00
|
|
|
// 100% on the shared auth + scope-guard + dispatch modules — the
|
|
|
|
|
// highest-risk surface (build-plan §5). 'branches' is held slightly
|
|
|
|
|
// below 100 where a defensive guard is unreachable from the public API.
|
|
|
|
|
'packages/shared/src/auth.ts': {
|
|
|
|
|
lines: 100,
|
|
|
|
|
functions: 100,
|
|
|
|
|
statements: 100,
|
|
|
|
|
branches: 100,
|
|
|
|
|
},
|
|
|
|
|
'packages/shared/src/dispatch.ts': {
|
|
|
|
|
lines: 95,
|
|
|
|
|
functions: 100,
|
|
|
|
|
statements: 95,
|
|
|
|
|
branches: 85,
|
|
|
|
|
},
|
|
|
|
|
'packages/shared/src/cognito-auth.ts': {
|
|
|
|
|
lines: 95,
|
|
|
|
|
functions: 85,
|
|
|
|
|
statements: 95,
|
|
|
|
|
branches: 80,
|
|
|
|
|
},
|
Phase 0b slice: monorepo scaffold + @sh-mcp/shared core + integration packages (#2)
* Phase 0b slice: monorepo scaffold + shared core + integration packages
The 0a-INDEPENDENT code slice (one-shot via af-0b-package-slice workflow: Haiku
scaffold + Sonnet packages, Sonnet fix-to-green). Nothing deploys; no CDK/servers.
- Monorepo scaffold: npm workspaces, strict TS (NodeNext), vitest (80% gate),
eslint 9 flat config, prettier; ci.yaml/deploy.yaml callers (Node 24, enable-qemu).
- @sh-mcp/shared: transport-agnostic core — Scope/AuthContext/ToolDef, ToolRegistry,
redact()+maskValue() (PII), OpenAPI 3.1 generator. AUTH STUBBED behind an AuthProvider
interface (TODO auth-layer-0a); JWT/aud/client_id/JWKS/deny-list deferred per design.md §2.
- 9 integration packages (qbo, google-maps, internal-data, payments, knowledge-base,
gmail, calendar, tasks, reminders): tools against shared, external deps mocked behind
injected client interfaces; finance handlers call redact().
Verified green: tsc -b clean, vitest 245/245, eslint 0 errors. Auth mechanism intentionally
deferred until the 0a spike resolves it (G16/§0.4).
* Complete Cognito auth provider + Phase 1 build brief
Finish the WIP CognitoAuthProvider (client_id allow-list as audience
boundary, finance TTL ceiling, deny-list, scope-prefix stripping) with
its test suite, and check in docs/build-plan-phase-1.md so the Phase 1
work has its governing brief in-tree (design.md §2.5).
* ci: disable cdk synth for Phase 0b (no CDK app yet)
The reusable ci-typescript-cdk workflow defaults run-cdk-synth: true, but
the Phase 0b package scaffold has no cdk.json or stacks, so cdk synth fails
with '--app is required'. Disable it here; Phase 1 re-enables it with the
server CDK stubs.
2026-06-26 12:42:17 -04:00
|
|
|
},
|
|
|
|
|
},
|
|
|
|
|
},
|
|
|
|
|
});
|