Files
multica/server/internal/handler/quick_create_parent_test.go
Naiyuan Qing afc7ac4bd0 feat: space rollout — space-first navigation, per-user membership, move-to-space (MUL-4142)
Squashed history of PR #4892 (pr-4784-fix). Makes spaces the primary
navigation and working surface, on the "associations bind at creation
time only" model.

Model
- Issue <-> space is the only enforced ownership (per-space numbering).
  Parent/child and project<->space associations only seed defaults at
  creation; cross-space/child and project-association validations are
  removed.
- Moving an issue renumbers it and records the old identifier in
  issue_identifier_alias; API/CLI lookups and GitHub branch/PR
  auto-linking fall back to the alias, so old identifiers resolve forever.
- Membership drives only the sidebar and personal defaults — never
  access. Anyone can configure any space's member set wholesale
  (PUT /api/spaces/{id}/members); saving an empty set archives the
  space behind a confirm.
- Per-user space order (workspace_space_member.sort_order, fractional):
  drag-sorted sidebar, "my first space" is the personal issue-creation
  default; the workspace default space backs headless creation
  (agents/CLI/Slack) and system placement.

Surfaces
- Sidebar: joined-spaces section (drag reorder, row -> space page,
  per-group persisted collapse), Workspace group with a More menu,
  Settings demoted to a footer icon.
- /space/:key/{issues,projects,autopilots,settings} — space surfaces
  reuse shared page components; a routed /space/new create page
  (replacing the earlier create-space modal), reserved key "NEW" so it
  can never collide with a real space's /space/:key detail page.
- Issue detail moves to /issue/:id (identifier-first, Linear-style; old
  /issues/:id redirects); create dialogs lead with a required space pill.
- Agent runtime brief now carries Space context (id/key/name) through
  the daemon claim -> TaskContextForEnv -> prompt pipeline, with a
  "## Space Context" section and --space on issue create/update in both
  brief renderers, matching Project's existing treatment.
- zh-Hans: Space translated to 空间 across locales and conventions.zh.mdx.

Fixes along the way
- Cache membership judgment gains the space dimension + space_changed
  WS flag.
- Silent skip on default-space lookup during invite acceptance is now a
  hard failure (no space-less members).
- Backfilled space_id into ~28 raw-SQL Go test fixtures across
  internal/handler and cmd/server that predated migration 132's NOT
  NULL cutover.
- Fixed a resolve-loop bug in the IssueDetail identifier wrapper (mount/
  unmount cycle on resolution failure) and gave it its own loading
  skeleton instead of a blank screen while resolving.
- reserved-slugs generator's stale hardcoded doc-comment example synced
  back to /create-space.

Verification
- go build ./..., go vet ./..., go test ./... all clean.
- pnpm typecheck (core/views/web/desktop) clean.
- packages/views: 162 files / 1656 tests passing.
- pnpm generate:reserved-slugs produces no diff.

Follow-ups tracked in docs/follow-ups/space-rollout.md.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-08 20:57:38 +08:00

235 lines
9.5 KiB
Go

package handler
import (
"context"
"encoding/json"
"net/http"
"net/http/httptest"
"testing"
"github.com/multica-ai/multica/server/internal/service"
"github.com/multica-ai/multica/server/pkg/agent"
)
// TestQuickCreateIssueParentTrustBoundary locks the server-side trust boundary
// for the optional parent_issue_id field on POST /api/issues/quick-create.
//
// The frontend seeds parent_issue_id from the "Add sub issue" entry point and
// otherwise leaves it empty. The handler is the trust boundary: a forged
// request must not be able to smuggle a foreign parent UUID through to the
// quick-create task context, and the same-workspace happy path must thread
// the resolved UUID into QuickCreateContext.ParentIssueID so the daemon claim
// step can resolve the identifier and emit `--parent <uuid>` in the prompt.
//
// Three branches are covered:
//
// 1. Same-workspace parent → 202 Accepted, task enqueued with
// QuickCreateContext.ParentIssueID populated.
// 2. Foreign-workspace parent → 400 Bad Request, no task enqueued.
// 3. Bogus UUID parent → 400 Bad Request, no task enqueued.
func TestQuickCreateIssueParentTrustBoundary(t *testing.T) {
if testHandler == nil {
t.Skip("database not available")
}
ctx := context.Background()
// Resolve the seeded runtime + agent for this workspace, then bump the
// runtime metadata to a CLI version that clears MinQuickCreateCLIVersion.
// The seed runtime uses metadata '{}'::jsonb which would otherwise trip
// the daemon-version gate before we ever reach the parent_issue_id check.
var runtimeID, agentID string
if err := testPool.QueryRow(ctx,
`SELECT id FROM agent_runtime WHERE workspace_id = $1 LIMIT 1`,
testWorkspaceID,
).Scan(&runtimeID); err != nil {
t.Fatalf("fetch runtime: %v", err)
}
if err := testPool.QueryRow(ctx,
`SELECT id FROM agent WHERE workspace_id = $1 LIMIT 1`,
testWorkspaceID,
).Scan(&agentID); err != nil {
t.Fatalf("fetch agent: %v", err)
}
if _, err := testPool.Exec(ctx,
`UPDATE agent_runtime SET metadata = jsonb_build_object('cli_version', $1::text) WHERE id = $2`,
agent.MinQuickCreateCLIVersion, runtimeID,
); err != nil {
t.Fatalf("bump runtime cli_version: %v", err)
}
t.Cleanup(func() {
testPool.Exec(context.Background(),
`UPDATE agent_runtime SET metadata = '{}'::jsonb WHERE id = $1`, runtimeID)
})
// Same-workspace parent — must be accepted and threaded through.
var localParentID string
if err := testPool.QueryRow(ctx, `
INSERT INTO issue (workspace_id, title, creator_id, creator_type, number, space_id)
VALUES ($1, 'quick-create parent (local)', $2, 'member',
(SELECT COALESCE(MAX(number), 0) + 1 FROM issue WHERE workspace_id = $1),
(SELECT id FROM workspace_space WHERE workspace_id = $1 LIMIT 1))
RETURNING id
`, testWorkspaceID, testUserID).Scan(&localParentID); err != nil {
t.Fatalf("create local parent issue: %v", err)
}
t.Cleanup(func() {
testPool.Exec(context.Background(), `DELETE FROM issue WHERE id = $1`, localParentID)
})
// Foreign-workspace parent — must be rejected.
var foreignWorkspaceID, foreignUserID, foreignParentID string
if err := testPool.QueryRow(ctx, `
INSERT INTO "user" (name, email) VALUES ($1, $2) RETURNING id
`, "QuickCreate Foreign", "quickcreate-foreign@multica.ai").Scan(&foreignUserID); err != nil {
t.Fatalf("create foreign user: %v", err)
}
t.Cleanup(func() {
testPool.Exec(context.Background(), `DELETE FROM "user" WHERE id = $1`, foreignUserID)
})
if err := testPool.QueryRow(ctx, `
INSERT INTO workspace (name, slug, description, issue_prefix)
VALUES ($1, $2, $3, $4) RETURNING id
`, "QuickCreate Foreign WS", "quickcreate-foreign-ws", "", "QCF").Scan(&foreignWorkspaceID); err != nil {
t.Fatalf("create foreign workspace: %v", err)
}
t.Cleanup(func() {
testPool.Exec(context.Background(), `DELETE FROM workspace WHERE id = $1`, foreignWorkspaceID)
})
// The foreign parent issue below resolves space_id from this workspace's
// default Space; a freshly-created workspace has none, so seed it here.
if _, err := testPool.Exec(ctx, `
INSERT INTO workspace_space (workspace_id, name, key, issue_counter, created_by)
VALUES ($1, 'Default', 'QCF', 0, $2)
`, foreignWorkspaceID, foreignUserID); err != nil {
t.Fatalf("create foreign workspace_space: %v", err)
}
if err := testPool.QueryRow(ctx, `
INSERT INTO issue (workspace_id, title, creator_id, creator_type, number, space_id)
VALUES ($1, 'quick-create parent (foreign)', $2, 'member',
(SELECT COALESCE(MAX(number), 0) + 1 FROM issue WHERE workspace_id = $1),
(SELECT id FROM workspace_space WHERE workspace_id = $1 LIMIT 1))
RETURNING id
`, foreignWorkspaceID, foreignUserID).Scan(&foreignParentID); err != nil {
t.Fatalf("create foreign parent issue: %v", err)
}
// The foreign workspace cleanup above cascades, but the issue row also
// needs a direct cleanup in case workspace deletion ordering changes.
t.Cleanup(func() {
testPool.Exec(context.Background(), `DELETE FROM issue WHERE id = $1`, foreignParentID)
})
// Helper for the "must not enqueue" assertions. Each rejection subtest
// snapshots the count immediately before the request and re-checks after
// so sibling subtests (and their t.Cleanup deletions) can't false-positive
// or false-negative this assertion.
countQuickCreateTasks := func(t *testing.T) int {
t.Helper()
var count int
if err := testPool.QueryRow(context.Background(),
`SELECT COUNT(*) FROM agent_task_queue WHERE agent_id = $1 AND context->>'type' = 'quick_create'`,
agentID,
).Scan(&count); err != nil {
t.Fatalf("count quick-create tasks: %v", err)
}
return count
}
t.Run("same workspace parent enqueues with context", func(t *testing.T) {
attachmentID := "019ec09d-6222-722b-bdfa-427b105d80be"
w := httptest.NewRecorder()
req := newRequest("POST", "/api/issues/quick-create", map[string]any{
"agent_id": agentID,
"prompt": "Create a follow-up issue for the local parent",
"parent_issue_id": localParentID,
"attachment_ids": []string{attachmentID},
})
testHandler.QuickCreateIssue(w, req)
if w.Code != http.StatusAccepted {
t.Fatalf("expected 202, got %d: %s", w.Code, w.Body.String())
}
var resp QuickCreateIssueResponse
if err := json.NewDecoder(w.Body).Decode(&resp); err != nil {
t.Fatalf("decode response: %v", err)
}
t.Cleanup(func() {
testPool.Exec(context.Background(), `DELETE FROM agent_task_queue WHERE id = $1`, resp.TaskID)
})
// QuickCreateContext.ParentIssueID must contain the resolved UUID —
// the daemon claim step reads this field to attach the parent
// identifier and to inject `--parent <uuid>` into the prompt.
var contextJSON []byte
if err := testPool.QueryRow(context.Background(),
`SELECT context FROM agent_task_queue WHERE id = $1`, resp.TaskID,
).Scan(&contextJSON); err != nil {
t.Fatalf("load task context: %v", err)
}
var qc service.QuickCreateContext
if err := json.Unmarshal(contextJSON, &qc); err != nil {
t.Fatalf("unmarshal context: %v", err)
}
if qc.Type != service.QuickCreateContextType {
t.Fatalf("expected type=%q, got %q", service.QuickCreateContextType, qc.Type)
}
if qc.ParentIssueID != localParentID {
t.Fatalf("expected parent_issue_id=%q in context, got %q", localParentID, qc.ParentIssueID)
}
if len(qc.AttachmentIDs) != 1 || qc.AttachmentIDs[0] != attachmentID {
t.Fatalf("expected attachment_ids=[%q] in context, got %#v", attachmentID, qc.AttachmentIDs)
}
})
t.Run("foreign workspace parent is rejected", func(t *testing.T) {
before := countQuickCreateTasks(t)
w := httptest.NewRecorder()
req := newRequest("POST", "/api/issues/quick-create", map[string]any{
"agent_id": agentID,
"prompt": "Try to smuggle a foreign parent",
"parent_issue_id": foreignParentID,
})
testHandler.QuickCreateIssue(w, req)
if w.Code != http.StatusBadRequest {
t.Fatalf("expected 400 for foreign parent, got %d: %s", w.Code, w.Body.String())
}
if got := countQuickCreateTasks(t); got != before {
// Any increase means the foreign-parent request enqueued a
// task despite the 400 — the trust boundary leaked.
t.Fatalf("foreign parent must not enqueue a task: expected %d quick-create tasks, got %d", before, got)
}
})
t.Run("bogus uuid parent is rejected", func(t *testing.T) {
before := countQuickCreateTasks(t)
w := httptest.NewRecorder()
req := newRequest("POST", "/api/issues/quick-create", map[string]any{
"agent_id": agentID,
"prompt": "Try a malformed parent UUID",
"parent_issue_id": "not-a-uuid",
})
testHandler.QuickCreateIssue(w, req)
if w.Code != http.StatusBadRequest {
t.Fatalf("expected 400 for bogus parent, got %d: %s", w.Code, w.Body.String())
}
if got := countQuickCreateTasks(t); got != before {
t.Fatalf("bogus parent must not enqueue a task: expected %d quick-create tasks, got %d", before, got)
}
})
t.Run("bogus uuid attachment id is rejected", func(t *testing.T) {
before := countQuickCreateTasks(t)
w := httptest.NewRecorder()
req := newRequest("POST", "/api/issues/quick-create", map[string]any{
"agent_id": agentID,
"prompt": "Try a malformed attachment UUID",
"attachment_ids": []string{"not-a-uuid"},
})
testHandler.QuickCreateIssue(w, req)
if w.Code != http.StatusBadRequest {
t.Fatalf("expected 400 for bogus attachment id, got %d: %s", w.Code, w.Body.String())
}
if got := countQuickCreateTasks(t); got != before {
t.Fatalf("bogus attachment id must not enqueue a task: expected %d quick-create tasks, got %d", before, got)
}
})
}