+114
@@ -357,3 +357,117 @@ WS: normal browser websocket connects; a foreign browser Origin is rejected
|
||||
```
|
||||
|
||||
The OpenAI circuit breaker uses rolling windows and successful usage rows. Set very small limits in Admin Runtime to verify that a winning artifact stays `pending` with an `OpenAI cost circuit breaker active` diagnostic instead of making another provider call. Restore the desired limits afterward.
|
||||
|
||||
## V3.9 portable identity + owned artifact recovery
|
||||
|
||||
1. Start the CLI with a persistent identity path and note the printed Client-ID and file path:
|
||||
|
||||
```bash
|
||||
NEURALHUNT_IDENTITY=/tmp/nh-client/identity.json go run ./cmd/client -url http://127.0.0.1:8080
|
||||
```
|
||||
|
||||
2. Run `identity` and verify the same Client-ID/path is shown. Restart with the same file and verify the Client-ID is unchanged.
|
||||
3. Set a passphrase of at least 12 characters and create an encrypted browser-compatible backup:
|
||||
|
||||
```bash
|
||||
export NEURALHUNT_IDENTITY_PASSPHRASE='correct horse battery staple'
|
||||
go run ./cmd/client -identity /tmp/nh-client/identity.json -export /tmp/neuralhunt-browser-import.json
|
||||
```
|
||||
|
||||
4. In the browser choose **IDENTITÄT → IMPORT**, select that JSON, enter the same passphrase and confirm the switch. The browser Client-ID must exactly equal the CLI Client-ID. The import validates that public/private P-256 keys can sign/verify and that the optional export Client-ID matches.
|
||||
5. After a win is fully rendered, **MEINE NFTS** must list the artifact and **ORIGINAL** must download the unwatermarked artifact. A different identity requesting `/api/me/artifacts/<task-id>/download` must receive 404.
|
||||
6. In the CLI, `my-nfts` lists only the authenticated identity's ready winner artifacts and `nft original <task-id> <datei>` downloads the original. `nfts` / `nft get` remain public watermarked previews.
|
||||
7. Verify legacy encrypted exports without `format/clientId/iterations` metadata still import using 250,000 PBKDF2 iterations.
|
||||
|
||||
Focused identity tests can run without the optional network/database dependencies:
|
||||
|
||||
```bash
|
||||
go test ./cmd/client/identity.go ./cmd/client/identity_test.go
|
||||
node --check internal/webui/dist/app.js
|
||||
```
|
||||
|
||||
## V4.0 Beacon Hunt + Hosted Service smoke test
|
||||
|
||||
### Beacon Hunt
|
||||
|
||||
1. Start the game and enable `Guess Lottery Max Accepted > 0` plus `Beacon Hunt` in Admin Runtime.
|
||||
2. Open two browser/CLI identities and choose different paths (`PULSE`, `FLUX`, `ORBIT`).
|
||||
3. Confirm requests wait until the window closes and that `/api/public/beacon/<task-id>/latest` returns the recorded drand round, signature, derived randomness and boosted path.
|
||||
4. Disable Beacon Hunt again and confirm the legacy `crypto/rand` lottery still works.
|
||||
|
||||
### Hosted reward pairing
|
||||
|
||||
1. Build with `make images-compose`, then start with `docker compose --profile hosted up -d` and route 8090 publicly over HTTPS; keep 8081/8091/8092 private.
|
||||
2. Create/log in to a Customer Service account.
|
||||
3. Log into the normal Neural Hunt browser with the desired reward identity and click **HOSTED CODE** (or run `hosted-code` in the CLI).
|
||||
4. Paste the one-shot code into the Customer Service portal. Confirm the portal shows the proven Client-ID. Reusing the same code must fail.
|
||||
|
||||
### Protected manual credits
|
||||
|
||||
1. Set `CS_ALLOW_MANUAL_CREDITS=1` only in a test/private environment.
|
||||
2. Log into the Customer Service admin on private port 8091 and grant a small amount of credits.
|
||||
3. Verify the customer ledger contains a positive `manual_test_grant` entry.
|
||||
4. Set `CS_ALLOW_MANUAL_CREDITS=0` again and verify grants are rejected.
|
||||
|
||||
### Managed workers / prepaid stop
|
||||
|
||||
1. Create a worker and assign an active task and Beacon path.
|
||||
2. Start it. The worker should create/register its own P-256 identity and the game should install `worker -> reward owner` delegation.
|
||||
3. Let the worker win a test task (use a deliberately tiny range only in a private test environment). Confirm `winner_client_id` is the main reward owner while `winner_worker_client_id` is the worker identity.
|
||||
4. Reduce the prepaid balance to less than one billable minute and verify Customer Service stops the worker before another paid minute is allowed.
|
||||
5. Stop/start the worker and confirm its Docker identity volume preserves the same Client-ID.
|
||||
6. Download the worker identity, replace it with another valid raw identity, start again and confirm a new worker Client-ID registers while reward ownership remains delegated to the same main identity.
|
||||
|
||||
### PayPal Sandbox
|
||||
|
||||
1. Keep `PAYPAL_ENVIRONMENT=sandbox` and configure sandbox client ID/secret/webhook ID.
|
||||
2. Buy the smallest test package from the Customer Service portal.
|
||||
3. Confirm credits are added only after a server-confirmed `COMPLETED` capture whose amount and currency match the stored package.
|
||||
4. Repeat the return/capture callback or webhook and verify the `paypal:<order-id>` ledger reference prevents duplicate credits.
|
||||
5. Leave live mode disabled until the provider/legal review for the actual product is complete.
|
||||
|
||||
|
||||
## V4.1 split Docker images
|
||||
|
||||
1. Build the three roles locally:
|
||||
|
||||
```bash
|
||||
docker buildx bake --load
|
||||
```
|
||||
|
||||
2. Verify the image contents/entrypoints:
|
||||
|
||||
```bash
|
||||
docker image inspect neuralhunt-server:local --format '{{json .Config.Entrypoint}}'
|
||||
docker image inspect neuralhunt-customer-service:local --format '{{json .Config.Entrypoint}}'
|
||||
docker image inspect neuralhunt-worker:local --format '{{json .Config.Entrypoint}}'
|
||||
```
|
||||
|
||||
Expected entrypoints are `/app/neuralhunt`, `/app/neuralhunt-customer-service`
|
||||
and `/app/neuralhunt-client` respectively. The server image should not contain
|
||||
the client or Customer Service binaries.
|
||||
|
||||
3. For local Hosted Service testing, build/tag the worker image before starting
|
||||
the hosted profile:
|
||||
|
||||
```bash
|
||||
make images-compose
|
||||
docker compose --profile hosted up -d
|
||||
```
|
||||
|
||||
4. Set `CS_WORKER_IMAGE` to a deliberately missing public image with
|
||||
`CS_WORKER_AUTO_PULL=true`; starting a worker should cause Docker Engine to pull
|
||||
the configured image. Repeat with `CS_WORKER_AUTO_PULL=false`; the request must
|
||||
fail before prepaid credits are charged.
|
||||
|
||||
5. For a private registry, configure a read-only token with
|
||||
`CS_WORKER_REGISTRY_SERVER/USERNAME/PASSWORD`, remove the local worker image and
|
||||
confirm an on-demand pull succeeds. Verify the credentials do not appear in the
|
||||
managed worker container environment (`docker inspect`).
|
||||
|
||||
Focused stdlib-only tests for the Docker image orchestration can be run even
|
||||
without the application's external Go dependencies:
|
||||
|
||||
```bash
|
||||
go test ./internal/customer/docker.go ./internal/customer/docker_test.go
|
||||
```
|
||||
|
||||
Reference in New Issue
Block a user