aaronsb_obsidian-mcp-plugin/tests
Aaron Bockelie 8bb580cc56 fix: .mcpignore semantics, TLS 1.3 startup, rename extension (#250, #252, #253)
Bundles the three reported bugs plus an unreported under-blocking bug found
while writing the tests for #250, and adds the coverage tooling that would
have caught all four.

#250 — .mcpignore negation was inverted
The parser stripped the leading '!' before Minimatch saw it, so .negate was
always false and the branch reading it was dead code. '!folder/*' compiled
into a positive exclusion: negation did not merely fail, it inverted.

Under-blocking (found while testing the above, not reported)
Patterns were handed to Minimatch raw, so two gitignore rules were never
implemented: a slash-less pattern matches at any depth ('*.secret' must hide
'a/b/creds.secret'), and a directory match covers its contents ('private/'
must hide 'private/notes.md'). No consumer of isExcluded() checks ancestors —
every caller passes a full file path — so nothing compensated downstream. The
plugin's own shipped .mcpignore template promises both behaviours, so a user
following it believed private files were hidden while they were being served
to the model. Patterns are now translated into the globs that implement
gitignore semantics, and negation is interpreted here rather than by Minimatch.

#252 — min TLS 1.3 crashed the server
secureProtocol mapped 1.3 to 'TLSv1_3_method', which OpenSSL never shipped, so
context creation threw "Unknown method: TLSv1_3_method". Switched to minVersion,
which also fixes a second latent bug: secureProtocol PINS one version, so
"minimum TLS 1.2" was silently refusing TLS 1.3 clients. The setting now
behaves as the floor it is labelled.

#253 — rename dropped the extension
'newName' was concatenated onto the source directory verbatim, so renaming
'note.md' to 'renamed' produced an extension-less file that drops out of
markdown views. The source extension is now carried over when newName omits
one, before the overwrite guard so it checks the right path.

Coverage + test contract
All four bugs shipped through code paths with zero coverage. Adds `make
coverage` / `coverage-map` / `coverage-gate`, a ratcheting coverageThreshold
(security boundary held to a far higher floor than global, since a hole there
leaks vault content), and tests/test-contract.test.ts enforcing that a green
run means something: no .only, no .skip, every file asserts, no tautologies.
The contract immediately caught an `expect(true).toBe(true)` placeholder in the
path-validator suite, now replaced with real assertions.

BREAKING (.mcpignore, both intended):
- The double-'!' workaround for #250 now correctly parses as a double negation
  (net exclude) and will stop working.
- A bare '*' now excludes at every depth, per gitignore, rather than top-level
  only. This is what makes the '*' + '!keep/**' whitelist idiom work.
2026-07-13 17:46:50 -05:00
..
__mocks__ fix: .mcpignore semantics, TLS 1.3 startup, rename extension (#250, #252, #253) 2026-07-13 17:46:50 -05:00
fixtures harden(bases): runtime-computed-member escape test + scope scanner claim 2026-05-16 23:03:43 -05:00
security fix: .mcpignore semantics, TLS 1.3 startup, rename extension (#250, #252, #253) 2026-07-13 17:46:50 -05:00
validation test: Add comprehensive unit tests for input validation 2025-12-03 12:55:01 -06:00
bases-expression-evaluator.test.ts feat(bases): replace new Function with expression-eval (ADR-201) 2026-05-16 22:57:43 -05:00
bases-yaml.test.ts test(bases): address #182 review — accurate date-safety rationale + explicit divergences 2026-05-16 14:20:23 -05:00
bridge-bootstrap.test.ts refactor(bridge): bridge-owned autostart opt-out; address #247 review 2026-06-24 10:06:39 -05:00
bridge-self-heal.test.ts refactor(bridge): bridge-owned autostart opt-out; address #247 review 2026-06-24 10:06:39 -05:00
combine-inline-router.test.ts fix(vault): inline combine sourceFiles must match combined order 2026-05-18 12:20:48 -05:00
combine-inline.test.ts feat(vault): return combined content inline when destination is omitted 2026-05-18 08:10:12 -05:00
dataview-integration.test.ts fix(dataview): recover rows for implicit LIST GROUP BY; label whitespace group keys 2026-07-03 21:47:21 -05:00
dispatch-param-guards.test.ts fix(dispatch): address PR #212 review findings 2026-05-25 08:31:37 -05:00
file-lock-edit-serialization.test.ts fix(edit): serialize concurrent edits to the same file (closes #139) 2026-05-18 22:43:16 -05:00
fuzzy-match.test.ts fix(mcp): stop debug route shadowing the GET /mcp SSE stream + two-row Levenshtein 2026-05-18 21:05:22 -05:00
graph-ignore-exclusion.test.ts fix(graph): honor MCP ignore exclusions in graph traversal 2026-06-08 14:50:14 +02:00
graph-node-title.test.ts fix(graph): honor MCP ignore exclusions in graph traversal 2026-06-08 14:50:14 +02:00
graph-search-traversal.test.ts fix(graph): honor MCP ignore exclusions in graph traversal 2026-06-08 14:50:14 +02:00
graph-search.test.ts fix(graph): honor MCP ignore exclusions in graph traversal 2026-06-08 14:50:14 +02:00
graph-statistics-vault-wide.test.ts fix(graph): honor MCP ignore exclusions in graph traversal 2026-06-08 14:50:14 +02:00
list-files-recursive.test.ts fix(vault.list): Align paginated recursive sort with flat listFiles 2026-05-15 13:40:35 -05:00
mcp-server.test.ts fix: Mock fs module in tests to prevent certificate directory creation (v0.9.0a) 2025-08-12 10:52:39 -05:00
mcp-session-reinit.test.ts fix(mcp): client-driven session re-init via spec 404 (ADR-106, closes #190) 2026-05-18 22:37:23 -05:00
network-classifier.test.ts fix(network): address PR #211 self-review findings (ADR-107) 2026-05-24 17:06:16 -05:00
network-exposure-integration.test.ts feat(network): wire classifier into server, settings, UI (ADR-107) 2026-05-24 16:56:24 -05:00
patch-operations.test.ts feat: Implement structured patch targeting for headings, blocks, and frontmatter 2025-07-06 22:47:02 -05:00
read-only-mode.test.ts refactor: Remove concurrent mode toggle, simplify connection setup (ADR-100) 2026-03-14 23:13:35 -05:00
recursive-copy.test.ts fix: Eliminate all eslint any-type violations for Obsidian plugin review 2026-02-03 21:51:55 -06:00
search-tag-operator.test.ts feat: add tests for searches with the tag operator 2025-08-16 15:46:55 +01:00
setup.ts fix(lint): use window timers + window.console; drop forbidden eslint-disables (closes #226) 2026-06-09 11:13:48 -05:00
sse-socket-timeout.test.ts refactor(mcp): address review of #244 — document SSE backstop, test teardown 2026-06-24 02:00:33 -05:00
test-contract.test.ts fix: .mcpignore semantics, TLS 1.3 startup, rename extension (#250, #252, #253) 2026-07-13 17:46:50 -05:00
vault-read-fidelity.test.ts fix(formatter): emit verbatim content in default vault.read (PR #205 blocking review) 2026-05-19 00:38:29 -05:00
vault-rename-extension.test.ts fix: .mcpignore semantics, TLS 1.3 startup, rename extension (#250, #252, #253) 2026-07-13 17:46:50 -05:00