1 Commits
Author SHA1 Message Date
Jason ZhouandClaude Opus 5 c122780255 test(e2e): prove failure capture against real providers, not stubs
The unit tests use a fake relay, so nothing until now had shown that a REAL
provider's error body survives the round trip — decode, redaction, truncation,
column, and back out through /admin/errors. This runs it end to end on the real
platform keys for a few tenths of a cent.

12/12, and two of the checks only mean something because they ran for real:

- tikhub answers this machine with a Cloudflare HTML block page, not JSON. That
  is exactly the CDN/WAF case the decode path was written for — the edge
  generates it and ignores the identity request. It stored at 2001 chars (the
  2000 cap plus the truncation marker) and decoded clean, no replacement
  characters. A stub would never have produced it.
- the leak check asserts all twenty real platform keys are absent from every
  captured row, and asserts separately that there WAS evidence to search, so it
  cannot pass vacuously. Keys are compared, never printed.

Also confirmed against a live upstream: a 200 stores nothing, /calls still does
not carry the columns, and the two spyfu/serpapi attempts were refused by treg
before relay (refused_by=request) — the required-param gate doing its job, and
correctly NOT captured.

The harness runs on its own port and its own database, deliberately not through
treg-dev-server: that script pkills every `python -m treg`, and another session
has one running against the main checkout. Its own stop had the same class of
bug and is fixed here — it matched an env var that never appears in argv, so it
silently killed nothing and left an orphan holding the deleted database open,
which surfaced as "attempt to write a readonly database". It kills by port now.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-17 16:13:16 +10:00