62 lines
2.8 KiB
YAML
62 lines
2.8 KiB
YAML
Reference issues or pull requests here (e.g., "Closes #123")
|
|
version: '1.0'
|
|
task_id: potion-voice-tenant-isolation
|
|
score_type: binary
|
|
|
|
categories:
|
|
- name: tenant_authorization
|
|
description: Verification of multi-tenant query scoping across MongoDB models
|
|
weight: 0.4
|
|
items:
|
|
- id: primary_queries_scoped
|
|
description: "Primary database reads (UserAudioProfile, Salutation, VoiceCloning) scope queries by userId"
|
|
weight: 0.15
|
|
pass_criteria: "Queries include userId parameter matching job payload"
|
|
|
|
- id: secondary_queries_scoped
|
|
description: "Secondary database reads and updates (Recording, RecordingSalutation) scope queries by userId"
|
|
weight: 0.15
|
|
pass_criteria: "Secondary queries include userId constraint"
|
|
|
|
- id: cross_tenant_access_blocked
|
|
description: "Jobs with mismatched document IDs and userId are rejected without mutating foreign records"
|
|
weight: 0.10
|
|
pass_criteria: "Cross-tenant job payloads fail gracefully with authorization error"
|
|
|
|
- name: async_execution_integrity
|
|
description: Maintenance of correct execution dependency order
|
|
weight: 0.3
|
|
items:
|
|
- id: dependency_order_preserved
|
|
description: "salutationToUpdate is resolved before dependent recordingId queries are executed"
|
|
weight: 0.20
|
|
pass_criteria: "No Promise.all calls attempt to reference salutationToUpdate.recordingId before salutationToUpdate resolves"
|
|
|
|
- id: no_undefined_query_params
|
|
description: "No database queries are executed with undefined or uninitialized ID variables"
|
|
weight: 0.10
|
|
pass_criteria: "All query parameters evaluate to valid ObjectIds/strings"
|
|
|
|
- name: queue_lifecycle_integrity
|
|
description: Verification of SQS queue message deletion timing
|
|
weight: 0.15
|
|
items:
|
|
- id: sqs_delete_after_completion
|
|
description: "deleteMessageFromSQS is invoked strictly after synthesis and asset persistence complete"
|
|
weight: 0.15
|
|
pass_criteria: "deleteMessageFromSQS call site remains at the end of the success execution block"
|
|
|
|
- name: runtime_stability
|
|
description: Absence of runtime syntax, Mongoose query, or Promise handling errors
|
|
weight: 0.15
|
|
items:
|
|
- id: valid_mongoose_query_methods
|
|
description: "Mongoose query methods use findOne/findOneAndUpdate when passing multi-field query objects"
|
|
weight: 0.10
|
|
pass_criteria: "No Model.findById calls receive query objects containing { _id, userId }"
|
|
|
|
- id: catch_block_safety
|
|
description: "Error handlers execute without unhandled Promise rejections during authorization failure"
|
|
weight: 0.05
|
|
pass_criteria: "Worker catch blocks handle errors gracefully and rethrow or exit without secondary unhandled crashes"
|