mirror of
https://github.com/multica-ai/multica.git
synced 2026-08-05 17:40:11 +02:00
Two review nits from #6119. The CLI's setHeaders call is the only place Phase 1 is switched on, and nothing observed it: the server tests prove a request carrying `X-Client-Capabilities: stable_attachment_urls` gets stable paths, but a typo in the CLI token — or dropping the header — would have left every test green while the CLI silently went back to ~800-char signed URLs. Assert the header verbatim across GET, GET-with-headers, POST, and the no-token client. Verified the assertion is load-bearing by mutating the constant to `stable_attachment_url`: the test fails. TestAttachmentToResponse_SignedModeRotatesButStableDoesNot only checked the "stable does not" half, so its name overstated coverage. Add the rotation half. It drives the signer with two explicit expiries rather than calling attachmentToResponse twice: that function mints its expiry from time.Now() at second granularity, so consecutive calls usually land in the same second and asserting on them directly would be a flaky test of a real property. Also pins that only the query rotates, and that a fixed expiry re-signs deterministically — without which the rotation assertion would prove nothing about the clock. MUL-5372 Co-authored-by: multica-agent <github@multica.ai>