Fix full-size authenticated HTTP binary requests - #653
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
|
ty-everett
left a comment
There was a problem hiding this comment.
Qualified maintainer review accepted exact head 6eb34251bf5b31c1d990ea181b8433e0a8361080: 40 terminal successful or governed-skip checks, exact-head zero new Sonar findings/unreviewed hotspots and zero CodeQL alerts; no open review threads. Complete diff reviewed: finite binary-byte Peer capacity matches existing HTTP request and configured response framing, with safe-integer clamping and small-response request compatibility. Custom Peer defaults, public declarations, signatures, nonce/certificate/handshake bounds, redirect policy, wire encodings and persistence remain unchanged. Synthetic real authenticated CHIRP consumer tests exercise non-text bytes and complete 4 MiB chunks with exact bytes, caller identity, object hashes and root commit. Oversized HTTP frames still reject before dispatch. Only SDK published bytes change, requiring 2.8.9; the CHIRP test is excluded from its artifact. Existing dependency graph, security findings/thresholds/overrides and test classifications are unchanged. Node22/24, coverage, governed mutation, conformance, exact-tarball consumers/browser and documentation checks accepted. Protected publication and full live acceptance remain separate prerequisites.



AuthFetch rejects a valid 4 MiB CHIRP chunk before HTTP dispatch because the generic authentication envelope charges each binary byte as four JSON characters. This patch gives its Peer a finite binary-byte payload budget matching the HTTP request and configured response capacity. The real authenticated CHIRP upload test now covers both non-text bytes and a complete chunk, including exact bytes, object hashes, caller identity and root commit.
Program and scope
@bsv/sdk2.8.9. CHIRP's test changes are excluded from its published artifact, so its version remains 0.1.3.6eb34251bf5b31c1d990ea181b8433e0a8361080.Verification
Hosted final-head runs: CI, CodeQL, Conformance.
Commands include
pnpm health:check,pnpm lint,pnpm format:check,pnpm build,pnpm typecheck,pnpm audit:security, SDKtest:coverage,pack:check,test:browser, CHIRP authenticated tests and package/browser checks,pnpm test:mutation --target sdk-auth-http, documentation examples, test governance, conformance, and protected-artifact staging/verification/publication dry run.Security, release and completion
Protected SDK publication must complete before the separate UHRP service binary-parser fix pins this release and exercises its full chunk boundary in frozen service installs. Existing open PR #569 changes payment preparation elsewhere in AuthFetch and does not change this Peer construction; its branch and ownership are preserved.