From 2fc730cfa21f4c6d5376db27c4b08ee447d96151 Mon Sep 17 00:00:00 2001 From: Dotta Date: Fri, 4 Sep 2026 15:13:46 -0500 Subject: [PATCH] fix(e2e): allowlist public screenshot metadata --- tests/runner-e2e/history-public-bundle.ts | 2 +- tests/runner-e2e/history.test.ts | 22 ++++++++++++++++------ 2 files changed, 17 insertions(+), 7 deletions(-) diff --git a/tests/runner-e2e/history-public-bundle.ts b/tests/runner-e2e/history-public-bundle.ts index a6484975b9..2adffb1af0 100644 --- a/tests/runner-e2e/history-public-bundle.ts +++ b/tests/runner-e2e/history-public-bundle.ts @@ -379,7 +379,7 @@ function safePassedScreenshot(input: unknown) { throw new Error("Passing result has unsafe screenshot metadata"); } return { - ...screenshot, + id: screenshot.id, label: `${screenshot.label} (redacted layout preview)`, file: `${PUBLIC_VISUAL_DIRECTORY}/${screenshot.file}`, privateFile: screenshot.file, diff --git a/tests/runner-e2e/history.test.ts b/tests/runner-e2e/history.test.ts index 6924eb5613..242e9e9540 100644 --- a/tests/runner-e2e/history.test.ts +++ b/tests/runner-e2e/history.test.ts @@ -312,8 +312,9 @@ describe("historical publication security", () => { id: "final-state", label: "Final state", file: "final-state.png", + unexpectedSecretMetadata: "sk-private-screenshot-metadata", }, - ], + ] as RunnerE2EResult["screenshots"], } satisfies RunnerE2EResult; const campaign = buildRunnerCampaign({ campaignId: "campaign-1", @@ -422,11 +423,20 @@ describe("historical publication security", () => { "utf8", ), ).resolves.toBe("{}\n"); - expect( - JSON.parse( - await readFile(path.join(output, "normalized-results.json"), "utf8"), - ).schema, - ).toBe("paperclip.runner-e2e.campaign/v2"); + const publicCampaign = JSON.parse( + await readFile(path.join(output, "normalized-results.json"), "utf8"), + ); + expect(publicCampaign.schema).toBe("paperclip.runner-e2e.campaign/v2"); + expect(publicCampaign.results[0].screenshots).toEqual([ + { + id: "final-state", + label: "Final state (redacted layout preview)", + file: "public-visuals/final-state.png", + }, + ]); + expect(JSON.stringify(publicCampaign)).not.toContain( + "sk-private-screenshot-metadata", + ); await expect( regenerateRunnerDashboard({ bundle: source,