From 7be84668b320417284232a972d65077d2d4427de Mon Sep 17 00:00:00 2001 From: Vincent Herbst Date: Mon, 28 Sep 2026 19:38:06 +0200 Subject: [PATCH] test(relay): look for origin fragments long enough to mean something localURLCarriesNoOriginText checked that the relay URL does not contain "jf", but the reference in that URL is random base64 of about 190 characters, which contains any given two-letter pair on roughly one run in twenty. It failed the 7.22.0 release run on main that way ("...BjyjfBTh..."), with the code unchanged since its green PR run. The fragments are now the ones that would actually give the origin away (jf.example, master.m3u8, api_key); 40 runs in a row are green. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01Mf4MXgM9bqugHoe5TW4BYf --- Tests/AetherEngineTests/HLSOriginRelayTests.swift | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/Tests/AetherEngineTests/HLSOriginRelayTests.swift b/Tests/AetherEngineTests/HLSOriginRelayTests.swift index 8c6ea1b8..91f0f76e 100644 --- a/Tests/AetherEngineTests/HLSOriginRelayTests.swift +++ b/Tests/AetherEngineTests/HLSOriginRelayTests.swift @@ -36,7 +36,9 @@ struct HLSOriginRelayAddressingTests { string: "https://jf.example.com/Videos/abc/master.m3u8?MediaSourceId=x&api_key=\(secret)")! let local = try #require(relay.localURL(for: origin, port: 51234, token: token)) let text = local.absoluteString - for fragment in [secret, "jf", "example", "Videos", "master", "api", "MediaSourceId"] { + // Fragments long enough to mean something: the reference is random base64, and a two-letter + // fragment ("jf") turns up in it by chance on about one run in twenty (CI, 2026-09-28). + for fragment in [secret, "jf.example", "example", "Videos", "master.m3u8", "api_key", "MediaSourceId"] { #expect(!text.contains(fragment), "\(fragment) is readable in \(text)") } #expect(!text.contains("%"), "the reference should need no escaping: \(text)")