Files
archy/.planning/phases/09-botfights-platform-upgrade/09-VALIDATION.md
T

68 lines
3.6 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
phase: 9
slug: botfights-platform-upgrade
# status lifecycle: draft (seeded by plan-phase) → validated (set by validate-phase §6)
status: draft
nyquist_compliant: false
wave_0_complete: false
created: 2026-07-30
---
# Phase 9 — Validation Strategy
> Per-phase validation contract for feedback sampling during execution.
---
## Test Infrastructure
| Property | Value |
|----------|-------|
| **Framework** | Vitest (server + frontend projects) + Playwright e2e — in the `botfight` repo, NOT archy |
| **Config file** | `botfight/vitest.workspace.ts`, `botfight/frontend/vitest.config.ts`, `botfight/e2e/playwright.config.ts` |
| **Quick run command** | `cd /home/archipelago/Projects/botfight && pnpm test -- --run` |
| **Full suite command** | `cd /home/archipelago/Projects/botfight && pnpm test -- --run && pnpm test:e2e` |
| **Estimated runtime** | ~60s unit, ~35 min with e2e |
---
## Sampling Rate
- **After every task commit:** `pnpm test -- --run` (botfight repo, unit only)
- **After every plan wave:** full suite + `cargo test` for archy manifest change where relevant
- **Before `/gsd-verify-work`:** Full suite green + manual real-path checks below
- **Max feedback latency:** ~120 seconds
---
## Per-Task Verification Map
| Task ID | Plan | Wave | Requirement | Threat Ref | Secure Behavior | Test Type | Automated Command | File Exists | Status |
|---------|------|------|-------------|------------|-----------------|-----------|-------------------|-------------|--------|
| TBD by planner | — | — | BOT-01 | NIP-98 forgery/replay | signature+window+path verified server-side | unit | `pnpm vitest run server/src/middleware/nip98.test.ts` | ✅ | ⬜ pending |
| TBD by planner | — | — | BOT-01 | session theft | JWT issue/verify/blacklist | unit | `pnpm vitest run server/src/middleware/jwt.test.ts` | ✅ | ⬜ pending |
| TBD by planner | — | — | BOT-01 | legacy bypass | no bare-pubkey login path remains | unit | `pnpm vitest run server/src/routes/auth.test.ts server/src/routes/auth-edge.test.ts server/src/routes/auth-audit.test.ts` | ✅ | ⬜ pending |
| TBD by planner | — | — | BOT-02 | N/A | prompt-documented flow works exactly as written | e2e | `pnpm test:e2e -- e2e/signup-bot.spec.ts` (extended) | ✅ extend | ⬜ pending |
| TBD by planner | — | — | BOT-03 | SSRF/leak via proxy | REST + SSE forwarding correct, no header leak | integration | `pnpm vitest run server/src/middleware/arena-proxy.test.ts` | ❌ W0 | ⬜ pending |
| TBD by planner | — | — | BOT-04 | crash-loop | manifest declares JWT_SECRET via generated_secrets | unit (archy) | `cd core && cargo test -p container manifest` | partial | ⬜ pending |
*Status: ⬜ pending · ✅ green · ❌ red · ⚠️ flaky*
---
## Wave 0 Requirements
- [ ] `server/src/routes/auth-me.test.ts` — new `GET /api/auth/me` route coverage (BOT-01)
- [ ] `server/src/middleware/arena-proxy.test.ts` — REST + SSE forwarding correctness (BOT-03)
- [ ] Manual demo-checklist doc (execution-phase artifact) — real NIP-07 extension login, Amber NIP-55 login, real cross-node fight visibility
- [ ] No framework install needed — Vitest/Playwright already configured
---
## Manual-Only Verifications
- Real NIP-07 signer login in a real browser (nos2x/Alby) on archi-dev-box — no `window.nostr` mock exists in Playwright.
- Amber (NIP-55) login from Android against the archi-dev-box instance.
- Cross-node fighter visibility: bot registered via VPS2 public arena appears on archi-dev-box instance and can fight.
- Cloud openclaw bot registers + fights using ONLY the unified prompt against the public arena (demo rehearsal, 2026-07-31).