fix(rpc): deep-freeze procedures in defineService, not just the map
This commit is contained in:
@@ -48,6 +48,20 @@ describe("defineService", () => {
|
||||
).toThrow(/procedure name/i);
|
||||
});
|
||||
|
||||
test("a hand-built procedure is frozen too, not just builder output", () => {
|
||||
// AnyProcedures accepts any ProcedureDef shape; the guarantee must not
|
||||
// depend on the caller having used procedure.build().
|
||||
const contract = defineService({
|
||||
name: "demo",
|
||||
procedures: { ping: { permission: "demo:read" } },
|
||||
});
|
||||
expect(Object.isFrozen(contract.procedures.ping)).toBe(true);
|
||||
expect(() => {
|
||||
(contract.procedures.ping as { permission?: string }).permission = "hacked";
|
||||
}).toThrow();
|
||||
expect(contract.procedures.ping.permission).toBe("demo:read");
|
||||
});
|
||||
|
||||
test("the builder is immutable — reusing a base does not cross-contaminate", () => {
|
||||
const base = procedure.permission("a:read");
|
||||
const one = base.idempotent().build();
|
||||
|
||||
Reference in New Issue
Block a user