R-304 option C (hub half): recovery_older_package allowlisted and operator-only; design + row updated
gates / gates (push) Successful in 4m13s

Unreleased; ships with tomorrow's hub release.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-08 10:09:20 +02:00
parent 83e6167145
commit 5beedcce1a
7 changed files with 43 additions and 4 deletions
+3
View File
@@ -2169,6 +2169,9 @@ var allowedEventTypes = map[string]bool{
// R-243 — the hub raises these itself (monitor/offsite_escrow_pending.go); allowlisted like the line above.
"offsite_escrow_pending": true,
"offsite_escrow_pending_cleared": true,
// R-304 option C — controller (same day) sends it on an unlock that opens / may open an older package. Operator-only
// (notify.operatorOnlyEvents); NO customerMessages entry.
"recovery_older_package": true,
// controller v0.289.0 (decision 69): the customer-chosen deletion of set-aside history is deferred
// to the operator — the box's append-only key cannot delete. Operator-only (notify.operatorOnlyEvents).
"offbox_abandon_deferred": true,
@@ -0,0 +1,19 @@
package api
import (
"testing"
"gitea.dooplex.hu/admin/felhom-hub/internal/notify"
)
// R-304 option C (decision 183): the controller's recovery_older_package must be accepted (or POST /event 400s — R-77)
// and must reach only the operator. RED-PROOF: drop it from allowedEventTypes → "must be in allowedEventTypes".
func TestR304_RecoveryOlderPackageIsAllowlistedAndOperatorOnly(t *testing.T) {
et := "recovery_older_package"
if !allowedEventTypes[et] {
t.Fatalf("%s must be in allowedEventTypes — the controller's push would 400", et)
}
if !notify.IsOperatorOnly(et) {
t.Fatalf("%s must be operator-only — reopening old history is the operator's (R-312)", et)
}
}