Standalone per-card browser model/security/view modules for HUX-01..10 plus node+pytest suites that read the hux.v1 contract schemas directly. Reconciled drift found on integration: the activity model now accepts all 32 hux.event.v1 kinds (delegation.*, memory.suppressed, memory.retrieval_removed, budget.exhausted, side_effect.*), the autonomy model carries the external_side_effect capability, and the foundation boundary test now asserts the shipped static HUX surface exists on disk and that images never bake activated HUX_FLAGS. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BvMSXH8VH2tMWXanb8SJdf
95 lines
3.6 KiB
Python
95 lines
3.6 KiB
Python
"""Executable and static quality gates for isolated HUX-07 multimodal chat."""
|
|
|
|
from __future__ import annotations
|
|
|
|
import subprocess
|
|
from pathlib import Path
|
|
|
|
|
|
ROOT = Path(__file__).resolve().parents[2]
|
|
MULTIMODAL = ROOT / "dockerfiles" / "hermes-webui-hux" / "multimodal"
|
|
|
|
|
|
def test_hux_multimodal_model_node_suite_and_coverage():
|
|
result = subprocess.run(
|
|
[
|
|
"node",
|
|
"--test",
|
|
"--experimental-strip-types",
|
|
"--experimental-test-coverage",
|
|
"--test-coverage-lines=95",
|
|
"--test-coverage-functions=95",
|
|
"--test-coverage-branches=95",
|
|
"--test-coverage-include=dockerfiles/hermes-webui-hux/multimodal/model.ts",
|
|
"--test-coverage-include=dockerfiles/hermes-webui-hux/multimodal/security.ts",
|
|
"--test-coverage-include=dockerfiles/hermes-webui-hux/multimodal/endpoints.ts",
|
|
"testing/tests/test_hermes_hux_ui_multimodal.mjs",
|
|
],
|
|
cwd=ROOT,
|
|
check=False,
|
|
capture_output=True,
|
|
text=True,
|
|
timeout=30,
|
|
)
|
|
assert result.returncode == 0, result.stdout + result.stderr
|
|
|
|
|
|
def test_hux_multimodal_component_is_flagged_accessible_safe_and_inert():
|
|
component = (MULTIMODAL / "MultimodalChat.tsx").read_text(encoding="utf-8")
|
|
model = (MULTIMODAL / "model.ts").read_text(encoding="utf-8")
|
|
endpoints = (MULTIMODAL / "endpoints.ts").read_text(encoding="utf-8")
|
|
styles = (MULTIMODAL / "styles.css").read_text(encoding="utf-8")
|
|
assert "if (!enabled || !page) return null" in component
|
|
assert "multimodalEnabled(props.flags)" in component
|
|
for flag in (
|
|
"FOUNDATION_FLAG",
|
|
"PROJECTS_FLAG",
|
|
"ARTIFACTS_FLAG",
|
|
"AUTONOMY_FLAG",
|
|
"MULTIMODAL_FLAG",
|
|
):
|
|
assert flag in model
|
|
assert 'aria-label="Multimodal chat"' in component
|
|
assert 'aria-live="polite"' in component
|
|
assert 'aria-label="Live media permissions"' in component
|
|
assert "Ask to use" in component and "Ask before uploading" in component
|
|
assert "Create linked variant" in component
|
|
assert "Correct transcript" in component
|
|
assert "Content is not executed" in component
|
|
assert "dangerouslySetInnerHTML" not in component
|
|
assert "<iframe" not in component and "<object" not in component and "<embed" not in component
|
|
assert "getUserMedia" not in component and "getDisplayMedia" not in component
|
|
assert "fetch(" not in endpoints and "axios" not in endpoints
|
|
assert '"PATCH"' not in endpoints and '"DELETE"' not in endpoints
|
|
assert ".hux-multimodal" in styles
|
|
assert "body" not in styles and ":root" not in styles
|
|
assert "prefers-reduced-motion" in styles
|
|
|
|
|
|
def test_hux_multimodal_sources_are_bounded_and_isolated():
|
|
sources = sorted(MULTIMODAL.glob("*"))
|
|
assert {path.name for path in sources} == {
|
|
"MultimodalChat.tsx",
|
|
"endpoints.ts",
|
|
"index.ts",
|
|
"model.ts",
|
|
"security.ts",
|
|
"styles.css",
|
|
"types.ts",
|
|
}
|
|
for path in sources:
|
|
assert len(path.read_text(encoding="utf-8").splitlines()) <= 500
|
|
assert "dockerfiles/hermes-webui-hux/multimodal" not in (
|
|
ROOT / "dockerfiles" / "Dockerfile.hermes-agent"
|
|
).read_text(encoding="utf-8")
|
|
|
|
|
|
def test_hux_multimodal_forbids_inline_and_executable_media():
|
|
security = (MULTIMODAL / "security.ts").read_text(encoding="utf-8")
|
|
component = (MULTIMODAL / "MultimodalChat.tsx").read_text(encoding="utf-8")
|
|
assert "image/svg+xml" not in security
|
|
assert "text/html" not in security
|
|
assert "data:" not in component
|
|
assert "URL.createObjectURL" not in component
|
|
assert "blob:" in security
|