Files
openclaude/tests/sdk/permissions.test.ts
T
60c76b6599 feat: SDK Runtime — Query Engine, Sessions, and Build Pipeline (#984)
* feat(sdk): add SDK foundation — type declarations, errors, and utilities

Adds standalone SDK building blocks with no SDK source dependencies:
- sdk.d.ts: ambient type declarations for SDK bundle
- coreSchemas.ts + coreTypes.generated.ts: Zod schemas and generated types
- errors.ts: SDK-specific error classes
- validation.ts: input validation utilities
- messageFilters.ts: extracted message filter logic
- handlePromptSubmit.ts: imports from messageFilters
- 16 generated-types tests

* fix(sdk): narrow assertFunction type from broad Function to callable signature

Code review finding: assertFunction used `asserts value is Function` which
accepts any function-like value without narrowing. Changed to
`(...args: any[]) => any` for better type safety.

* fix(sdk): update sdk.d.ts header — manually maintained, not generated

Reviewer noted the header said "Generated from index.ts" but no generator
produces this file. Updated to "Manually maintained — keep in sync with
index.ts". Drift detection added in validate-externals.ts (PR 3).

* fix(sdk): align sdk.d.ts types with canonical coreTypes.generated.ts

Tighten SDK public type contract to resolve reviewer blockers:

- PermissionResult: unknown[] → precise 6-shape discriminated union
  (addRules/replaceRules/removeRules/setMode/addDirectories/removeDirectories)
- SDKSessionInfo: snake_case → camelCase (sessionId, lastModified, etc.)
- ForkSessionResult: session_id → sessionId
- SDKPermissionRequestMessage: uuid + session_id now required
- SDKPermissionTimeoutMessage: added uuid + session_id
- SessionMessage: parent_uuid → parentUuid
- SDKMessage/SDKUserMessage/SDKResultMessage: replaced loose inline
  definitions with re-exports from coreTypes.generated.ts

* feat(sdk): wire existing code modules + SDK shared utilities

Modifies core modules for SDK integration:
- QueryEngine, tools, state, commands: SDK type hooks
- SDK shared utilities (shared.ts, permissions.ts)
- 21 SDK tests (shared-utils, permissions)

Stack: main ← pr1-foundation ← pr2-sdk-core

* feat(sdk): add snake_case ↔ camelCase key mapping utilities

casing.ts provides recursive key transformation for the SDK boundary
layer. Internal runtime uses snake_case; public API exposes camelCase.
Will be used by shared.ts, sessions.ts, query.ts at export boundaries.

* test(sdk): add tests for snake_case ↔ camelCase mapping utilities

Covers snakeToCamel, camelToSnake, mapKeysToCamel, mapKeysToSnake
including nested objects, arrays, null/undefined, and round-trips.

* feat(sdk): add SDK runtime — query engine, sessions, build pipeline

Completes the SDK implementation:
- SDK build target (dist/sdk.mjs) with TUI dependency stubbing
- External dependency lists (scripts/externals.ts)
- SDK type generation from Zod schemas (scripts/generate-sdk-types.ts)
- External validation (scripts/validate-externals.ts)
- SDK source: index, query, v2, sessions modules
- agentSdkTypes: re-exports SDK functions (query, createSession, etc.)
- 136 SDK tests + 7 build scanner tests

Stack: main ← pr1-foundation ← pr2-sdk-core ← pr3-sdk-runtime

* fix(sdk): align internal SDK types with camelCase public contract

shared.ts: SDKSessionInfo, ForkSessionResult, SessionMessage fields
now use camelCase matching sdk.d.ts. SDKPermissionRequestMessage and
SDKPermissionTimeoutMessage gain required uuid + session_id fields.

permissions.ts: onPermissionRequest/onTimeout callbacks now include
uuid and session_id in emitted messages.

* fix(sdk): update runtime modules to use camelCase field names

sessions.ts: toSDKSessionInfo outputs camelCase keys, entryToSessionMessage
uses parentUuid, forkSession returns sessionId.

query.ts: reads sessionId from listSessions/forkSession results
instead of snake_case session_id.

* fix(test): update session tests to use camelCase field names

session_id → sessionId in forkSession result assertions and
getSessionMessages calls.

* fix(sdk): prevent permission timeout race condition with once-only resolve wrapper

Add createOnceOnlyResolve utility to prevent double-resolution of promises
when timeout and host response happen simultaneously. This ensures
deterministic behavior in the permission handling flow.

* fix(sdk): improve race condition test robustness

* fix(sdk): handle consecutive underscores in snakeToCamel conversion

Changes:
- Use _+([a-z]) regex to match multiple consecutive underscores before letters
- Add lookahead (?=. ) to preserve underscore-letter pairs at string end
- Handle dunder names (__proto__, __typename) by stripping wrapper and capitalizing
- Add tests for consecutive underscores and trailing underscore preservation

* fix(sdk): include original error message in permission callback denial

When a canUseTool callback throws an error, the catch block now
includes the original error message in the denial message, making
debugging easier for SDK consumers.

* feat(sdk): add optional timeout to env mutex for deadlock prevention

Add timeout parameter to acquireEnvMutex() to prevent infinite waits
in deadlock scenarios. The timeout is optional and defaults to no timeout
(wait forever) for backward compatibility.

Returns a MutexAcquireResult object with acquired status and optional
timeout reason for failed acquisitions.

* fix(sdk): remove timed-out callback from mutex queue to prevent deadlock

* test(sdk): add missing error path and timeout scenario tests

Add tests for timeout scenarios when host doesn't respond to permission
requests, fallback behavior when no onPermissionRequest callback, and
MCP connection edge cases for undefined/empty config.

* fix(sdk): address code review issues - race conditions, validation, error handling

- Add createPermissionTarget() factory that applies onceOnlyResolve at
  registration time, fixing race condition where timeout and host response
  could both try to resolve the same promise
- Add try-catch to releaseEnvMutex() to prevent permanent lock if callback throws
- Extract DEFAULT_PERMISSION_TIMEOUT_MS constant (30 seconds)
- Add MCP config validation rejecting null, non-objects, and arrays
- Preserve error stack traces in MCP connection failures
- Add runtime validation to mapMessageToSDK for null/non-object/invalid type
- Update tests to use createPermissionTarget and add validation tests

* fix(sdk): syntax fixes and MCP connection error handling

- Remove extra closing parenthesis in permissions.ts
- Remove extra closing braces in shared.ts type definitions
- Wrap MCP connection in try/catch to continue without MCP tools on failure

* fix(sdk): syntax fixes, MCP error handling, and logic clarity

- Remove extra closing parenthesis in permissions.ts
- Remove extra closing braces in shared.ts type definitions
- Wrap MCP connection in try/catch to continue without MCP tools on failure
- Clarify thinkingConfig logic: use ?? true instead of !== false
- Add explanatory comment about thinkingEnabled default behavior
- Apply createOnceOnlyResolve wrapper in QueryImpl.registerPendingPermission

* fix(sdk): comprehensive error handling and resource cleanup

- Add try-catch around injectAgents() to gracefully handle plugin agent
  tool validation failures (prevents test crashes from unknown 'LS' tool)
- Add console.warn logging to agent loading/injection catch blocks for
  debugging visibility (matches v2.ts pattern)
- Add pendingPermissionPrompts.clear() to close() and interrupt() methods
  in both query.ts and v2.ts to prevent memory accumulation
- Add close() method to SDKSession interface and SDKSessionImpl
- Wrap MCP connection in query.ts with try-catch (matches v2.ts behavior)
- Add timeoutQueue cleanup in finally blocks (query.ts + v2.ts)
- Remove error.stack from MCP error messages to prevent internal path leak

All 208 SDK tests pass. TypeScript errors are pre-existing.

* fix(sdk): address code review non-blocking issues

- Add SDKAgentLoadFailureMessage type for agent load failure events
- Emit agent definition/injection failures to SDK message stream
- Add tool name to permission timeout denial message
- Replace 'as any' casts with proper typed state access
- Fix supportedCommands to use correct mcp.commands/plugins.commands paths
- Update test for correct AppState structure

* fix(sdk): address code review blocking and non-blocking issues

Blocking Issues Fixed:
- MCP cleanup missing on session/query close - now disconnects MCP clients
  to prevent resource leaks in long-running processes with multiple sessions
- Engine reference not cleared on close - now sets _engine = null to prevent
  memory leaks
- Added MCP cleanup tests (9 new tests covering cleanup scenarios)

Non-Blocking Issues Fixed:
- Removed redundant catch block that just rethrew errors (query.ts)
- Fixed inconsistent timeout denial message format (permissions.ts)
- Fixed hardcoded tool name 'Bash' in test (permissions.test.ts)
- Exported PermissionResolveDecision type for SDK consumers (index.ts)

All 217 SDK tests pass.

* fix(sdk): address code review type consistency issues

- Add close() method to SDKSession interface (documented but missing from type)
- Fix SDKSessionInfo, ForkSessionResult, SessionMessage field naming:
  snake_case → camelCase to match sdk.d.ts public contract and implementation
- Add uuid and session_id to SDKPermissionTimeoutMessage for correlation
- Fix JSDoc comment in forkSession to use sessionId (not session_id)

These changes align internal types (shared.ts) with the public SDK contract
(sdk.d.ts) and actual implementation output. The merge from origin/main
introduced snake_case types that mismatched camelCase implementation and tests.

* fix: restore openclaude.json comment in REPL.tsx

Merge 0f3aa7a incorrectly took main's side for this comment, reverting
PR2 fix c725c48. Project has migrated to ~/.openclaude.json, not ~/.claude.json.

This is the only PR2 fix lost during merge - all other PR2 fixes
(permissions.ts race conditions, state.ts parentSessionId, etc.)
are preserved in PR3 via subsequent fix commits.

* fix(sdk): add missing type declarations to sdk.d.ts

Add SDKAgentLoadFailureMessage and PermissionResolveDecision to sdk.d.ts
to resolve type declaration drift detected by build validation.

- SDKAgentLoadFailureMessage: Agent loading failure notification
  (stage: definitions/injection, error_message)
- PermissionResolveDecision: SDK-specific permission resolution result
  (allow with updatedInput, deny with message + decisionReason)

Build validation now passes: 56 exports match between index.ts and sdk.d.ts.

* fix(sdk): resource leak and null safety in close/interrupt paths

- unstable_v2_prompt: wrap session in try/finally to guarantee
  session.close() on both success and error paths, preventing
  MCP connection and engine resource leaks
- QueryImpl.interrupt(): add null guard on _engine so calling
  interrupt() after close() is a safe no-op instead of throwing
- SDKSessionImpl.interrupt(): add matching null guard for v2
  sessions, consistent with the Query fix
- QueryImpl.close(): call this.interrupt() before cleanup to
  properly stop in-flight engine operations, matching v2's close()
  pattern and ensuring engine.interrupt() runs before nulling

* fix(sdk): abort AbortController in SDKSessionImpl.close() to prevent resource leak

SDKSessionImpl.close() was not aborting the AbortController, unlike
QueryImpl.close() which does. This meant in-flight HTTP requests and
async operations could continue running after session closure.

- Store AbortController reference via _abortController field + late-bind setter
- Abort and null the controller in close(), mirroring QueryImpl pattern
- Also null _appStateStore in close() to release state snapshots
- Wire abortController through createEngineFromOptions return value

* fix(sdk): index ALL entries in byUuid for compact preserved segment

The byUuid map must index system compact_boundary entries, not just
user/assistant. When anchorUuid === boundary.uuid, the relink walk
needs to find the boundary in byUuid.

Changes:
- query.ts: Index ALL non-sidechain entries (user, assistant, system)
- v2.ts: Same fix — index ALL entries, leaf selection user/assistant only
- Add regression test: boundary.uuid as anchorUuid scenario

Test verifies preserved messages kept, stale pre-compact dropped,
post-boundary chain intact when anchorUuid points to boundary itself.

* fix(sdk): complete preserved segment handling for compact resumes

Multiple fixes for compact-aware transcript loading:

1. Index ALL entries in byUuid (including system compact_boundary)
   - Needed when anchorUuid === boundary.uuid

2. Keep anchorUuid when pruning preserved segment entries
   - The anchor is the parent of preserved head after relink
   - Deleting it breaks the conversation chain

3. Filter system entries from final messages
   - compact_boundary is metadata, shouldn't pass to engine

4. Fix test timestamp format (ISO 8601 requires 2-digit hours)
   - '2025-01-04T0:00:00Z' → '2025-01-04T00:00:00Z'

5. Update test expectations for anchor inclusion
   - When anchor is a stale entry, it appears in messages
   - preserved(4) + anchor(1) + post(4) = 9 max

All 224 SDK tests pass.

* fix(sdk): MCP type:sdk tools properly convert SdkMcpToolDefinition to Tool

- Import MCPTool base from tools/MCPTool/MCPTool.js
- Spread MCPTool properties for proper Tool interface compliance
- Add tools field to SdkMcpSdkConfig type declaration
- Add regression tests for type:sdk tools wiring

Fix ensures in-process SDK tools match Tool interface expected
by QueryEngine and permission handlers.

* test(sdk): strengthen preserved segment and MCP tools tests

Preserved segment test improvements:
- Fix content extraction (access message.content, not message)
- Add exact count assert: messages.length === 6
- Add exact content asserts: preserved turn 1/2, post-boundary present
- Assert no stale, no system entries in final messages

MCP tools test additions:
- Direct test of connectSdkMcpServers() function
- Assert clients.length === 0 (in-process, no MCP connections)
- Assert tools.length === 1 with proper name/description
- Verify handler works via direct call (not via Tool.call which needs context)

* fix(sdk): published types complete, init errors fatal, permission session IDs

Three fixes for SDK production readiness:

1. HIGH: Published SDK types incomplete
   - Add coreTypes.generated.d.ts to package.json "files" array
   - sdk.d.ts re-exports from ./sdk/coreTypes.generated.js which was missing
   - TypeScript consumers would get module resolution errors

2. MEDIUM: query() swallows real init() failures
   - Add _engineWasInjected field to track pre-injected vs fresh engine
   - Check _engineWasInjected, not _engine !== null (always true after setEngine)
   - Auth/config/init errors now properly fatal for normal query() calls

3. MEDIUM: SDK permission events lose real session id
   - Pass sessionId to createExternalCanUseTool() in both query.ts and v2.ts
   - Permission_request/timeout messages now have correct session_id
   - Hosts can correlate permission callbacks to sessions

Test result: 225 pass, 0 fail

* fix(sdk): complete package types + dynamic permission session_id

Two fixes for SDK production readiness:

1. Published SDK types now include actual definitions
   - Replace 215-byte wrapper with 63KB coreTypes.generated.ts
   - TypeScript consumers get full type definitions (SDKMessage, etc.)
   - npm pack now includes real generated types

2. Permission event session_id dynamic for all query() paths
   - createExternalCanUseTool accepts string | (() => string | undefined)
   - query.ts passes () => queryImpl.sessionId getter
   - Fresh/fork/continue queries emit correct session_id at event time
   - V2 passes static sessionId (stable at creation/resume)
   - Add 4 tests: static sessionId, getter resolution, undefined fallback, timeout

Test result: 229 pass, 0 fail

* fix(sdk): fix sdk.d.ts for real TypeScript consumer compilation

Two issues prevented external consumers from compiling against packed SDK types:

1. SDKRateLimitError used constructor parameter properties (readonly resetsAt,
   readonly rateLimitType) which are invalid in .d.ts declarations — moved to
   class properties with separate constructor signature.

2. Re-exported SDKMessage/SDKUserMessage/SDKResultMessage were not imported
   into local scope — added import type alongside export type so TypeScript
   can resolve them for use in other declarations within the same file.

Added package-consumer-types.test.ts that compiles a real temp project against
the SDK types with skipLibCheck:false, catching both regressions.

* fix(sdk): eliminate React/Ink imports from SDK bundle

SDK bundle leaked React/Ink imports via tool UI modules, keybindings,
react-compiler-runtime, and spawnMultiAgent's static React import.

Changes:
- Stub root ink.js barrel, tool UI.js, keybindings/, react-compiler-runtime,
  It2SetupPrompt, and React hook files in SDK build
- Add local no-op stub for react/jsx-dev-runtime (jsxDEV returns null)
- Convert spawnMultiAgent's static React/It2SetupPrompt imports to dynamic
  await import() — spawnTeammate logic stays fully intact
- Add post-build leakage validation (fails on from "react"/"ink"/jsx-dev-runtime)
- Remove react/jsx-dev-runtime from SDK externals (now handled by build plugin)

* fix(sdk): wire disallowedTools through permission context

QueryOptions.disallowedTools was declared but never used. buildPermissionContext()
now passes it to alwaysDenyRules.cliArg so getTools() filters denied tools from
the model-visible list. Also added to V2 SDKSessionOptions for API consistency.

* fix(sdk): defer permission warning to execution time

createDefaultCanUseTool() warned at construction time even when the caller
provided canUseTool/onPermissionRequest. Move warning to first actual default
denial so valid SDK consumers never see false warnings. Add tests for
disallowedTools filtering, tool exclusion, and warning timing.

* refactor(sdk): extract transcript helpers + fix permission typing

- Extract shared transcript utilities to transcript.ts
  (parseJsonlEntries, findLastCompactBoundary, applyPreservedSegmentRelinks,
  buildConversationChain, stripExtraFields) deduplicating query.ts and v2.ts

- Add PermissionTarget interface to hide internal pendingPermissionPrompts
  map from createExternalCanUseTool, with deletePendingPermission and
  denyPendingPermission methods on QueryImpl and SDKSessionImpl

- Fix sessionId stability: preserve constructor UUID for fresh queries
  when continue:true finds no existing sessions, and when explicit
  sessionId does not resolve to a valid transcript file

- Add getMcpClients/setMcpClients to QueryEngine for SDK cleanup access

* fix(sdk): resolve remaining TypeScript errors in SDK modules

- Fix PermissionDecision type compatibility: import from types/permissions
  and cast PermissionResolveDecision to PermissionDecision properly

- Fix AsyncIterator/AsyncGenerator: async generators must return
  AsyncGenerator (which implements AsyncIterable), not AsyncIterator

- Fix Map method callable errors: cast additionalWorkingDirectories
  to Map<string, unknown> before calling .set() and .keys()

- Fix ApiKeySource type: map internal ApiKeySource to SDK's narrower
  type using conversion function, spread info before apiKeySource
  to avoid override

- Fix MCP config scope type: cast 'session' scope to ScopedMcpServerConfig
  for connectToServer compatibility

- Add PermissionMode import and cast for decisionReason.mode

- Deny pending permissions in interrupt(): resolve all pending promises
  with deny before clearing the map (both query.ts and v2.ts)

* fix(sdk): correct init skip logic and test mocks

- query.ts: skip init() entirely for injected engines (mocks, SDK host
  overrides) instead of calling init() and swallowing errors. Pass
  { injected: false } from query() factory to distinguish real engine
  from test mocks.
- mock-engine.ts: add getMcpClients() and setMcpClients() methods to
  match QueryEngine API added in this PR.
- permissions.test.ts: use filterToolsByDenyRules instead of getTools
  for disallowedTools tests, with proper base tool fixtures.

* fix: address code review feedback for exports and build script

package.json exports (Breaking Change Mitigation):
- Add "./package.json": "./package.json" for tool compatibility
- Add "./dist/cli.mjs": "./dist/cli.mjs" for CLI bundle access
- Keep ./sdk as sole library entrypoint
- Root import intentionally blocked (CLI-first package, no main field)

build.ts (Bug Fix):
- Add | undefined to result/sdkResult type declarations
- Add optional chaining: result?.success, sdkResult?.success
- Prevents TypeError masking actual build errors when Bun.build throws

tests/sdk/package-consumer-types.test.ts:
- Update simulated exports to match real package.json
- Add tests verifying exports map structure and file existence

---------

Co-authored-by: Ali Alakbarli <ali.alakbarli@users.noreply.github.com>
2026-05-04 20:56:30 +08:00

876 lines
29 KiB
TypeScript

import { describe, test, expect, vi } from 'bun:test'
import {
buildPermissionContext,
connectSdkMcpServers,
createDefaultCanUseTool,
createExternalCanUseTool,
createOnceOnlyResolve,
createPermissionTarget,
NO_SESSION_PLACEHOLDER,
} from '../../src/entrypoints/sdk/permissions.js'
import type { PermissionResolveDecision } from '../../src/entrypoints/sdk/permissions.js'
import { getEmptyToolPermissionContext } from '../../src/Tool.js'
import { filterToolsByDenyRules } from '../../src/tools.js'
describe('buildPermissionContext', () => {
test('returns default mode when no permissionMode specified', () => {
const ctx = buildPermissionContext({ cwd: '/tmp' })
expect(ctx.mode).toBe('default')
})
test('maps plan mode correctly', () => {
const ctx = buildPermissionContext({ cwd: '/tmp', permissionMode: 'plan' })
expect(ctx.mode).toBe('plan')
})
test('maps auto-accept to acceptEdits', () => {
const ctx = buildPermissionContext({ cwd: '/tmp', permissionMode: 'auto-accept' })
expect(ctx.mode).toBe('acceptEdits')
})
test('maps acceptEdits mode', () => {
const ctx = buildPermissionContext({ cwd: '/tmp', permissionMode: 'acceptEdits' })
expect(ctx.mode).toBe('acceptEdits')
})
test('maps bypass-permissions mode', () => {
const ctx = buildPermissionContext({ cwd: '/tmp', permissionMode: 'bypass-permissions' })
expect(ctx.mode).toBe('bypassPermissions')
expect(ctx.isBypassPermissionsModeAvailable).toBe(true)
})
test('maps bypassPermissions mode', () => {
const ctx = buildPermissionContext({ cwd: '/tmp', permissionMode: 'bypassPermissions' })
expect(ctx.mode).toBe('bypassPermissions')
expect(ctx.isBypassPermissionsModeAvailable).toBe(true)
})
test('default mode does not have bypass available', () => {
const ctx = buildPermissionContext({ cwd: '/tmp' })
expect(ctx.isBypassPermissionsModeAvailable).toBe(false)
})
test('allowDangerouslySkipPermissions sets bypass flag', () => {
const ctx = buildPermissionContext({
cwd: '/tmp',
allowDangerouslySkipPermissions: true,
})
expect(ctx.isBypassPermissionsModeAvailable).toBe(true)
})
test('additionalDirectories are added to context', () => {
const ctx = buildPermissionContext({
cwd: '/tmp',
additionalDirectories: ['/dir1', '/dir2'],
})
expect(ctx.additionalWorkingDirectories.has('/dir1')).toBe(true)
expect(ctx.additionalWorkingDirectories.has('/dir2')).toBe(true)
})
test('empty additionalDirectories does nothing', () => {
const ctx = buildPermissionContext({ cwd: '/tmp', additionalDirectories: [] })
expect(ctx.additionalWorkingDirectories.size).toBe(0)
})
test('disallowedTools sets alwaysDenyRules.cliArg', () => {
const ctx = buildPermissionContext({ cwd: '/tmp', disallowedTools: ['Bash', 'Edit'] })
expect(ctx.alwaysDenyRules.cliArg).toEqual(['Bash', 'Edit'])
})
test('disallowedTools defaults to empty array', () => {
const ctx = buildPermissionContext({ cwd: '/tmp' })
expect(ctx.alwaysDenyRules.cliArg).toEqual([])
})
})
describe('disallowedTools tool filtering', () => {
const baseTools = [{ name: 'Bash' }, { name: 'Read' }]
test('Bash is excluded from the tool list when disallowed', () => {
const ctx = buildPermissionContext({ cwd: '/tmp', disallowedTools: ['Bash'] })
const tools = filterToolsByDenyRules(baseTools, ctx)
expect(tools.some(t => t.name === 'Bash')).toBe(false)
})
test('disallowedTools does not affect other tools', () => {
const ctx = buildPermissionContext({ cwd: '/tmp', disallowedTools: ['Bash'] })
const tools = filterToolsByDenyRules(baseTools, ctx)
// Read tool should still be present
expect(tools.some(t => t.name === 'Read')).toBe(true)
})
test('empty disallowedTools includes the tool list', () => {
const ctx = buildPermissionContext({ cwd: '/tmp' })
const tools = filterToolsByDenyRules(baseTools, ctx)
expect(tools.some(t => t.name === 'Bash')).toBe(true)
})
})
describe('createDefaultCanUseTool', () => {
test('denies all tool uses', async () => {
const ctx = getEmptyToolPermissionContext()
const canUseTool = createDefaultCanUseTool(ctx)
const result = await canUseTool(
{ name: 'TestTool' } as any,
{ command: 'rm -rf /' },
{} as any,
{} as any,
undefined,
undefined,
)
expect(result.behavior).toBe('deny')
})
test('honors forceDecision when provided', async () => {
const ctx = getEmptyToolPermissionContext()
const canUseTool = createDefaultCanUseTool(ctx)
const forced = { behavior: 'allow' as const }
const result = await canUseTool(
{ name: 'Bash' } as any,
{},
{} as any,
{} as any,
undefined,
forced,
)
expect(result.behavior).toBe('allow')
})
test('warning not emitted at construction time', () => {
const ctx = getEmptyToolPermissionContext()
const logger = { warn: vi.fn() }
// Creating the default canUseTool should NOT emit a warning at construction time.
// The warning is deferred to execution time (when a tool is actually denied).
createDefaultCanUseTool(ctx, logger)
expect(logger.warn).not.toHaveBeenCalled()
})
test('no warning when forceDecision is provided', async () => {
const ctx = getEmptyToolPermissionContext()
const logger = { warn: vi.fn() }
const canUseTool = createDefaultCanUseTool(ctx, logger)
await canUseTool(
{ name: 'Bash' } as any,
{},
{} as any,
{} as any,
undefined,
{ behavior: 'allow' as const },
)
expect(logger.warn).not.toHaveBeenCalled()
})
})
describe('createExternalCanUseTool synchronous host response', () => {
test('synchronous host response from onPermissionRequest is received', async () => {
// Regression test: onPermissionRequest must fire AFTER registerPendingPermission
// so a host that responds synchronously finds the entry in the map.
const permissionTarget = createPermissionTarget()
const onPermissionRequest = vi.fn((message: any) => {
// Simulate a host that resolves synchronously from the callback
const pending = permissionTarget.pendingPermissionPrompts.get(message.tool_use_id)
expect(pending).toBeDefined() // Must be registered before this callback fires
pending!.resolve({ behavior: 'allow' as const })
})
const canUseTool = createExternalCanUseTool(
undefined,
async () => ({ behavior: 'deny' as const, message: 'fallback' }),
permissionTarget,
onPermissionRequest,
undefined,
50, // short timeout — should NOT fire since host responds immediately
)
const result = await canUseTool(
{ name: 'TestTool' } as any,
{},
{} as any,
{} as any,
'sync-response-id',
undefined,
)
expect(result.behavior).toBe('allow')
expect(onPermissionRequest).toHaveBeenCalledTimes(1)
})
test('permission request message includes uuid and session_id matching schema', async () => {
// Regression test: permission_request must match SDKMessageSchema contract
// which requires uuid and session_id fields (not optional).
const permissionTarget = createPermissionTarget()
const onPermissionRequest = vi.fn((message: any) => {
// Verify message shape matches generated schema requirements
expect(message.type).toBe('permission_request')
expect(message.request_id).toBeDefined()
expect(message.tool_name).toBe('TestTool')
expect(message.tool_use_id).toBe('shape-test-id')
expect(message.input).toBeDefined()
expect(message.uuid).toBeDefined() // Required by schema
expect(message.session_id).toBeDefined() // Required by schema
// Resolve to complete the test
const pending = permissionTarget.pendingPermissionPrompts.get(message.tool_use_id)
pending!.resolve({ behavior: 'allow' as const })
})
const canUseTool = createExternalCanUseTool(
undefined,
async () => ({ behavior: 'deny' as const, message: 'fallback' }),
permissionTarget,
onPermissionRequest,
undefined,
50,
'test-session-123', // Provide session_id
)
const result = await canUseTool(
{ name: 'TestTool' } as any,
{},
{} as any,
{} as any,
'shape-test-id',
undefined,
)
expect(result.behavior).toBe('allow')
expect(onPermissionRequest).toHaveBeenCalledTimes(1)
// Verify session_id was passed through
expect(onPermissionRequest.mock.calls[0][0].session_id).toBe('test-session-123')
})
test('permission request uses no-session placeholder when sessionId not provided', async () => {
// When createExternalCanUseTool is called without sessionId,
// the permission request should emit 'no-session' placeholder
// to explicitly indicate standalone permission prompt context.
const permissionTarget = createPermissionTarget()
const onPermissionRequest = vi.fn((message: any) => {
expect(message.session_id).toBe(NO_SESSION_PLACEHOLDER)
const pending = permissionTarget.pendingPermissionPrompts.get(message.tool_use_id)
pending!.resolve({ behavior: 'allow' as const })
})
// Note: sessionId parameter intentionally omitted
const canUseTool = createExternalCanUseTool(
undefined,
async () => ({ behavior: 'deny' as const, message: 'fallback' }),
permissionTarget,
onPermissionRequest,
undefined,
50,
// sessionId undefined - should use placeholder
)
const result = await canUseTool(
{ name: 'TestTool' } as any,
{},
{} as any,
{} as any,
'no-session-test-id',
undefined,
)
expect(result.behavior).toBe('allow')
expect(onPermissionRequest).toHaveBeenCalledTimes(1)
})
})
describe('createExternalCanUseTool race condition', () => {
test('handles simultaneous timeout and response correctly', async () => {
// Use createPermissionTarget which applies onceOnlyResolve at registration
const permissionTarget = createPermissionTarget()
const onPermissionRequest = vi.fn()
const onTimeout = vi.fn()
// Timeout set to 50ms with 25ms wait to trigger race condition reliably
// This gives enough time for the test to be stable on slower systems
// while still being fast enough to test the race condition scenario
const timeoutMs = 50
const canUseTool = createExternalCanUseTool(
undefined,
async () => ({ behavior: 'deny' as const, message: 'fallback' }),
permissionTarget,
onPermissionRequest,
onTimeout,
timeoutMs,
)
const toolUseID = 'test-tool-use-id'
// Start the canUseTool call
const resultPromise = canUseTool(
{ name: 'TestTool' } as any,
{},
{} as any,
{} as any,
toolUseID,
undefined,
)
// Simulate host responding right at timeout threshold
// This creates the race condition scenario where both timeout and host
// try to resolve the same promise - but onceOnlyResolve ensures only one wins
await new Promise(r => setTimeout(r, 25))
const pending = permissionTarget.pendingPermissionPrompts.get(toolUseID)
if (pending) {
// This will race with the timeout handler's resolve call
pending.resolve({ behavior: 'allow' as const })
}
// Wait for result - should NOT throw "promise already resolved" error
// Explicitly wrap in try-catch to verify no error is thrown during race condition
let result: PermissionResolveDecision
let errorThrown: Error | null = null
try {
result = await resultPromise
} catch (e) {
errorThrown = e as Error
throw new Error(`Expected no error during race condition, but got: ${errorThrown.message}`)
}
// Explicitly verify no error was thrown
expect(errorThrown).toBeNull()
// Result should be deterministic - either allow or deny, but no error
expect(['allow', 'deny']).toContain(result!.behavior)
})
test('once-only resolve wrapper prevents double resolution', async () => {
// Use createPermissionTarget which applies onceOnlyResolve at registration
const permissionTarget = createPermissionTarget()
const onPermissionRequest = vi.fn()
const onTimeout = vi.fn()
const canUseTool = createExternalCanUseTool(
undefined,
async () => ({ behavior: 'deny' as const, message: 'fallback' }),
permissionTarget,
onPermissionRequest,
onTimeout,
50, // 50ms timeout
)
const toolUseID = 'test-tool-use-id-race'
// Start the canUseTool call
const resultPromise = canUseTool(
{ name: 'TestTool' } as any,
{},
{} as any,
{} as any,
toolUseID,
undefined,
)
// Respond immediately after starting to simulate very fast host response
// This tests that the first response wins, not the timeout
const pending = permissionTarget.pendingPermissionPrompts.get(toolUseID)
if (pending) {
pending.resolve({ behavior: 'allow' as const, updatedInput: { test: true } })
}
// Wait for result
const result = await resultPromise
// Host response should win over timeout since it came first
expect(result.behavior).toBe('allow')
expect(onTimeout).not.toHaveBeenCalled()
})
test('host response after timeout is safely ignored (no double-resolve)', async () => {
const permissionTarget = createPermissionTarget()
const onPermissionRequest = vi.fn()
const onTimeout = vi.fn()
const canUseTool = createExternalCanUseTool(
undefined,
async () => ({ behavior: 'deny' as const, message: 'fallback' }),
permissionTarget,
onPermissionRequest,
onTimeout,
50, // 50ms timeout
)
const toolUseID = 'test-timeout-then-late-response'
// Start the canUseTool call — this registers a pending permission
const resultPromise = canUseTool(
{ name: 'TestTool' } as any,
{},
{} as any,
{} as any,
toolUseID,
undefined,
)
// Grab a reference to the resolve BEFORE timeout fires — simulates host
// capturing the callback while the permission prompt is still pending
const staleResolve = permissionTarget.pendingPermissionPrompts.get(toolUseID)
expect(staleResolve).toBeDefined()
// Wait LONGER than the 50ms timeout — timeout fires first, resolves with deny
const result = await resultPromise
// Timeout should have denied
expect(result.behavior).toBe('deny')
expect(onTimeout).toHaveBeenCalledTimes(1)
// Map entry cleaned up by timeout handler — no leaked listener
expect(permissionTarget.pendingPermissionPrompts.has(toolUseID)).toBe(false)
// NOW the host responds late through the stale reference it captured earlier.
// This is the critical scenario: host calls resolve({allow}) AFTER timeout
// already resolved with {deny}. onceOnlyResolve must silently ignore this.
// Wrap in try/catch to explicitly verify no error from double-resolve attempt.
let lateResponseError: Error | null = null
try {
staleResolve!.resolve({ behavior: 'allow' as const, updatedInput: { injected: true } })
} catch (e) {
lateResponseError = e as Error
}
// No error thrown — onceOnlyResolve silently swallowed the second resolve
expect(lateResponseError).toBeNull()
// Result stays 'deny' — timeout decision is immutable
expect(result.behavior).toBe('deny')
expect((result as any).updatedInput).toBeUndefined()
})
})
describe('createOnceOnlyResolve', () => {
test('only resolves once when called multiple times', () => {
let resolvedValue: string | undefined
let callCount = 0
const resolve = (value: string) => {
callCount++
resolvedValue = value
}
const onceOnlyResolve = createOnceOnlyResolve(resolve)
// First call should resolve
onceOnlyResolve('first')
expect(resolvedValue).toBe('first')
expect(callCount).toBe(1)
// Second call should be ignored
onceOnlyResolve('second')
expect(resolvedValue).toBe('first') // Still 'first', not 'second'
expect(callCount).toBe(1) // Still 1, not incremented
// Third call should also be ignored
onceOnlyResolve('third')
expect(resolvedValue).toBe('first')
expect(callCount).toBe(1)
})
test('works with Promise resolution', async () => {
let resolveFunc: (value: string) => void
const promise = new Promise<string>(resolve => {
resolveFunc = resolve
})
const onceOnlyResolve = createOnceOnlyResolve(resolveFunc!)
// Resolve twice rapidly
onceOnlyResolve('first')
onceOnlyResolve('second')
// Promise should resolve with 'first' only
const result = await promise
expect(result).toBe('first')
})
test('handles undefined and null values', () => {
let resolvedValue: string | null | undefined = 'initial'
const resolve = (value: string | null | undefined) => {
resolvedValue = value
}
const onceOnlyResolve = createOnceOnlyResolve(resolve)
onceOnlyResolve(undefined)
expect(resolvedValue).toBeUndefined()
onceOnlyResolve('should not change')
expect(resolvedValue).toBeUndefined() // Still undefined
onceOnlyResolve(null)
expect(resolvedValue).toBeUndefined() // Still undefined
})
test('timeout-deny-then-host-allow: raw resolve called exactly once', () => {
// This directly proves onceOnlyResolve prevents the raw resolve from being
// called a second time — the exact scenario the reviewer asked about:
// timeout fires first (deny), then host responds (allow) — raw resolve
// must only execute once.
let rawCallCount = 0
let rawResolvedValue: PermissionResolveDecision | undefined
const rawResolve = (value: PermissionResolveDecision) => {
rawCallCount++
rawResolvedValue = value
}
const wrapped = createOnceOnlyResolve(rawResolve)
// Step 1: Timeout fires first — resolves with deny
wrapped({ behavior: 'deny', message: 'Permission resolution timed out' })
expect(rawCallCount).toBe(1)
expect(rawResolvedValue!.behavior).toBe('deny')
// Step 2: Host responds late with allow — must be ignored
wrapped({ behavior: 'allow' as const, updatedInput: { injected: true } })
expect(rawCallCount).toBe(1) // NOT 2 — second call was a no-op
expect(rawResolvedValue!.behavior).toBe('deny') // Unchanged
expect((rawResolvedValue as any).updatedInput).toBeUndefined()
})
})
describe('createPermissionTarget', () => {
test('creates permission target with wrapped resolve', () => {
const target = createPermissionTarget()
expect(target.pendingPermissionPrompts).toBeDefined()
expect(target.registerPendingPermission).toBeDefined()
})
test('registerPendingPermission stores wrapped resolve', async () => {
const target = createPermissionTarget()
const toolUseId = 'test-id'
// Register should create a promise
const promise = target.registerPendingPermission(toolUseId)
// The resolve should be stored in the map
const pending = target.pendingPermissionPrompts.get(toolUseId)
expect(pending).toBeDefined()
// Calling resolve twice should only resolve once (onceOnlyResolve behavior)
pending!.resolve({ behavior: 'allow' as const })
pending!.resolve({ behavior: 'deny' as const, message: 'should not happen', decisionReason: { type: 'mode', mode: 'default' } })
// Promise should resolve with 'allow' (first call)
const result = await promise
expect(result.behavior).toBe('allow')
})
})
describe('createExternalCanUseTool error handling', () => {
test('includes original error message in denial', async () => {
const userFn = async () => {
throw new Error('Custom error from callback')
}
const permissionTarget = {
registerPendingPermission: async () => ({ behavior: 'deny' as const }),
pendingPermissionPrompts: new Map(),
}
const canUseTool = createExternalCanUseTool(
userFn,
async () => ({ behavior: 'deny' as const, message: 'fallback' }),
permissionTarget,
)
const result = await canUseTool(
{ name: 'TestTool' } as any,
{},
{} as any,
{} as any,
'test-id',
undefined,
)
expect(result.behavior).toBe('deny')
expect(result.message).toContain('Custom error from callback')
})
test('throwing onPermissionRequest cleans up pending resolver and denies', async () => {
// Regression test: After registerPendingPermission was moved before onPermissionRequest,
// a throwing host callback leaves a pending resolver behind in pendingPermissionPrompts.
// The callback should be wrapped so the pending entry is deleted and the flow denies cleanly.
const permissionTarget = createPermissionTarget()
const throwingCallback = vi.fn(() => {
throw new Error('host boom')
})
const canUseTool = createExternalCanUseTool(
undefined,
async () => ({ behavior: 'deny' as const, message: 'fallback' }),
permissionTarget,
throwingCallback,
undefined,
50,
)
const result = await canUseTool(
{ name: 'TestTool' } as any,
{},
{} as any,
{} as any,
'throw-id',
undefined,
)
// Should deny with error message, NOT throw
expect(result.behavior).toBe('deny')
expect(result.message).toContain('host boom')
expect(throwingCallback).toHaveBeenCalledTimes(1)
// Critical: pending resolver must be cleaned up, not leaked
expect(permissionTarget.pendingPermissionPrompts.has('throw-id')).toBe(false)
})
})
describe('createExternalCanUseTool warning suppression', () => {
test('fallback warning not emitted when userFn allows tool', async () => {
const ctx = getEmptyToolPermissionContext()
const logger = { warn: vi.fn() }
const fallback = createDefaultCanUseTool(ctx, logger)
const userFn = vi.fn(async () => ({ behavior: 'allow' as const }))
const permissionTarget = createPermissionTarget()
const canUseTool = createExternalCanUseTool(
userFn,
fallback,
permissionTarget,
)
await canUseTool({ name: 'TestTool' } as any, {}, {} as any, {} as any, 'test-id', undefined)
// User callback allowed the tool — default fallback warning should NOT fire
expect(logger.warn).not.toHaveBeenCalled()
})
test('fallback warning not emitted when onPermissionRequest resolves', async () => {
const ctx = getEmptyToolPermissionContext()
const logger = { warn: vi.fn() }
const fallback = createDefaultCanUseTool(ctx, logger)
const permissionTarget = createPermissionTarget()
const onPermissionRequest = vi.fn((message: any) => {
const pending = permissionTarget.pendingPermissionPrompts.get(message.tool_use_id)
pending!.resolve({ behavior: 'allow' as const })
})
const canUseTool = createExternalCanUseTool(
undefined,
fallback,
permissionTarget,
onPermissionRequest,
undefined,
50,
)
await canUseTool({ name: 'TestTool' } as any, {}, {} as any, {} as any, 'test-id', undefined)
// onPermissionRequest resolved — default fallback warning should NOT fire
expect(logger.warn).not.toHaveBeenCalled()
})
})
describe('createExternalCanUseTool timeout scenarios', () => {
test('emits timeout message when host does not respond', async () => {
// Use createPermissionTarget which applies onceOnlyResolve at registration
const permissionTarget = createPermissionTarget()
const onPermissionRequest = vi.fn()
const onTimeout = vi.fn()
const canUseTool = createExternalCanUseTool(
undefined,
async () => ({ behavior: 'deny' as const, message: 'fallback' }),
permissionTarget,
onPermissionRequest,
onTimeout,
50, // 50ms timeout for fast test
)
const result = await canUseTool(
{ name: 'TestTool' } as any,
{},
{} as any,
{} as any,
'test-id',
undefined,
)
expect(result.behavior).toBe('deny')
// When timeout occurs, the implementation calls onTimeout and falls through to fallback
expect(result.message).toBe('fallback')
expect(onTimeout).toHaveBeenCalled()
expect(onTimeout.mock.calls[0][0].type).toBe('permission_timeout')
expect(onTimeout.mock.calls[0][0].tool_name).toBe('TestTool')
expect(onTimeout.mock.calls[0][0].timed_out_after_ms).toBe(50)
})
test('fallback is used when no onPermissionRequest callback', async () => {
const permissionTarget = createPermissionTarget()
const canUseTool = createExternalCanUseTool(
undefined,
async () => ({ behavior: 'deny' as const, message: 'fallback denial' }),
permissionTarget,
// No onPermissionRequest callback
)
const result = await canUseTool(
{ name: 'TestTool' } as any,
{},
{} as any,
{} as any,
'test-id',
undefined,
)
expect(result.behavior).toBe('deny')
expect(result.message).toBe('fallback denial')
})
})
describe('connectSdkMcpServers error handling', () => {
test('returns empty arrays for undefined config', async () => {
const result = await connectSdkMcpServers(undefined)
expect(result.clients).toEqual([])
expect(result.tools).toEqual([])
})
test('returns empty arrays for empty config', async () => {
const result = await connectSdkMcpServers({})
expect(result.clients).toEqual([])
expect(result.tools).toEqual([])
})
})
describe('permission session_id dynamic resolution', () => {
test('static sessionId is used in permission_request', async () => {
const permissionTarget = createPermissionTarget()
let capturedSessionId: string | undefined
const onPermissionRequest = vi.fn((message: any) => {
capturedSessionId = message.session_id
const pending = permissionTarget.pendingPermissionPrompts.get(message.tool_use_id)
pending!.resolve({ behavior: 'allow' as const })
})
const canUseTool = createExternalCanUseTool(
undefined,
async () => ({ behavior: 'deny' as const, message: 'fallback' }),
permissionTarget,
onPermissionRequest,
undefined,
50,
'static-session-123', // Static value
)
await canUseTool({ name: 'TestTool' } as any, {}, {} as any, {} as any, 'test-id', undefined)
expect(capturedSessionId).toBe('static-session-123')
})
test('getter function resolves sessionId at event time', async () => {
const permissionTarget = createPermissionTarget()
let currentSessionId = 'initial-session'
let capturedSessionId: string | undefined
const onPermissionRequest = vi.fn((message: any) => {
capturedSessionId = message.session_id
const pending = permissionTarget.pendingPermissionPrompts.get(message.tool_use_id)
pending!.resolve({ behavior: 'allow' as const })
})
// Pass getter that returns current value at call time
const canUseTool = createExternalCanUseTool(
undefined,
async () => ({ behavior: 'deny' as const, message: 'fallback' }),
permissionTarget,
onPermissionRequest,
undefined,
50,
() => currentSessionId, // Dynamic getter
)
// Change sessionId BEFORE the permission request is emitted
currentSessionId = 'updated-session'
await canUseTool({ name: 'TestTool' } as any, {}, {} as any, {} as any, 'test-id', undefined)
// Should use the value at event emission time, not initial value
expect(capturedSessionId).toBe('updated-session')
})
test('getter returning undefined falls back to no-session placeholder', async () => {
const permissionTarget = createPermissionTarget()
let capturedSessionId: string | undefined
const onPermissionRequest = vi.fn((message: any) => {
capturedSessionId = message.session_id
const pending = permissionTarget.pendingPermissionPrompts.get(message.tool_use_id)
pending!.resolve({ behavior: 'allow' as const })
})
const canUseTool = createExternalCanUseTool(
undefined,
async () => ({ behavior: 'deny' as const, message: 'fallback' }),
permissionTarget,
onPermissionRequest,
undefined,
50,
() => undefined, // Getter returns undefined
)
await canUseTool({ name: 'TestTool' } as any, {}, {} as any, {} as any, 'test-id', undefined)
expect(capturedSessionId).toBe(NO_SESSION_PLACEHOLDER)
})
test('permission_timeout also uses dynamic sessionId', async () => {
const permissionTarget = createPermissionTarget()
let currentSessionId = 'timeout-session' // Set before call
let capturedTimeoutSessionId: string | undefined
const onPermissionRequest = vi.fn((message: any) => {
// Don't resolve - let it timeout
})
const onTimeout = vi.fn((message: any) => {
capturedTimeoutSessionId = message.session_id
})
const canUseTool = createExternalCanUseTool(
undefined,
async () => ({ behavior: 'deny' as const, message: 'fallback' }),
permissionTarget,
onPermissionRequest, // Required for timeout logic to run
onTimeout,
20, // Short timeout
() => currentSessionId,
)
await canUseTool({ name: 'TestTool' } as any, {}, {} as any, {} as any, 'test-id', undefined)
// Timeout message should use dynamic sessionId
expect(capturedTimeoutSessionId).toBe('timeout-session')
})
})