Schemas for the whole v1 surface: 38 methods, 9 events, 25 named types and the
JSON-RPC envelope, with x-privileged / x-transports / x-deadlineMs / x-errors
annotations that both generators emit as data rather than prose.
Four generators over one IR (contracts/codegen/schema_ir.py), so the C++ structs,
the TypeScript types and the OpenRPC document cannot disagree about what the
contract says:
gen_cpp.py -> core/generated/velox_proto.{hpp,cpp}
gen_ts.py -> extension/src/shared/protocol/
gen_openrpc.py -> contracts/openrpc.json
gen_cpp_conformance.py -> tests/conformance/cpp/fixture_dispatcher.hpp
Inbound parsing never throws: parse<T>() returns std::expected<T, ParseError> and
nlohmann's throwing ADL from_json is deliberately not emitted. Schema constraints
(minimum, maxLength, pattern, ...) become real runtime checks in both languages —
the daemon does not trust the extension and the extension does not trust the
daemon.
59 golden fixtures: a success case per method, 12 error cases, 9 events. Replayed
by tests/conformance/ against both the generated C++ and a live server over both
transports. tools/mockd serves the same fixtures with unhappy-path flags so the
GUI and EXT lanes never wait for veloxd.
run.sh also proves capture.offer fails open: with a daemon answering slower than
750 ms the client gives up and lets Firefox take the download.
core/generated/ is libveloxproto, a separate target from libveloxcore, which
still never sees JSON — see docs/adr/0009.
Co-Authored-By: Claude Opus 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_012fgjnqFCS5h5L7gZTZo3rV
31 lines
838 B
JSON
31 lines
838 B
JSON
{
|
|
"name": "settings.set \u2014 a privileged method called over the WebSocket transport",
|
|
"description": "The extension may request a download; it may not reconfigure the daemon. Letting it write saveTo.allowedRoots would defeat every path check in the project.",
|
|
"transport": "ws",
|
|
"request": {
|
|
"jsonrpc": "2.0",
|
|
"id": 103,
|
|
"method": "settings.set",
|
|
"params": {
|
|
"values": {
|
|
"saveTo.allowedRoots": [
|
|
"/"
|
|
]
|
|
}
|
|
}
|
|
},
|
|
"response": {
|
|
"jsonrpc": "2.0",
|
|
"id": 103,
|
|
"error": {
|
|
"code": -32003,
|
|
"message": "method is not permitted on this transport"
|
|
}
|
|
},
|
|
"assertions": [
|
|
"the check happens before params are even parsed",
|
|
"every method with x-privileged true behaves identically here",
|
|
"nothing is written and no event is emitted"
|
|
]
|
|
}
|