mirror of
https://github.com/Sea-Haven-Industries/sh-mcp.git
synced 2026-10-07 10:28:57 +00:00
Add tests for the highest-risk surface (build-plan §5, design.md §7.3): tool-hiding, server-side scope enforcement (incl. forced hidden calls), audience binding, input-schema validation, finance redaction on egress, audit emission with hashed args, prompt-injection regression (tool output is data), rate limiting, MCP conformance (in-memory transport round-trip), OpenAPI 3.1 validity, and local-auth safety. Add HTTP integration tests (supertest) for both servers and per-package dev-client tests. 405 tests pass. Wire the coverage gate into vitest.config.ts: 80% overall, with per-file thresholds on the auth + dispatch crown jewels; exclude deferred real client stubs, entrypoints, cdk apps, and aws-only config from the gate (documented). Extend eslint flat config + add .prettierignore to cover servers/. Commit the updated package-lock.json.
12 lines
272 B
Text
12 lines
272 B
Text
# Build + dependency output
|
|
**/dist/**
|
|
**/node_modules/**
|
|
**/cdk.out/**
|
|
**/coverage/**
|
|
package-lock.json
|
|
|
|
# Source-of-truth docs are authored by hand; do not reflow prose / tables.
|
|
docs/**
|
|
|
|
# HTML test fixtures are fixed inputs; keep them byte-stable.
|
|
**/test/fixtures/**
|