@@ -14,12 +14,14 @@ function setup(hasToken = false) {
1414 this . flags = { checkout : id !== null } ;
1515 } ,
1616 } ;
17- vi . stubGlobal ( "window" , { __B44_EXPERIMENTS__ : runtime } ) ;
17+ const page = { __B44_EXPERIMENTS__ : runtime , __B44_EXPERIMENTS_BOOTSTRAP__ : { config : { app_id : "app" } } } ;
18+ vi . stubGlobal ( "window" , page ) ;
1819 vi . stubGlobal ( "document" , { } ) ;
1920 const requests : { resolve : ( user : User ) => void ; reject : ( error : Error ) => void } [ ] = [ ] ;
2021 const me = vi . fn ( ( ) => new Promise < User > ( ( resolve , reject ) => requests . push ( { resolve, reject } ) ) ) ;
2122 const trackExposure = vi . fn ( ) ;
2223 const bridge = createExperimentsModule ( {
24+ appId : "app" ,
2325 getAuth : ( ) => ( { hasToken : ( ) => hasToken , me } ) as InternalAuthModule ,
2426 trackExposure,
2527 } ) ;
@@ -28,7 +30,7 @@ function setup(hasToken = false) {
2830 if ( state . status === "authenticated" ) requests [ index ] ?. resolve ( { id : state . userId } as User ) ;
2931 else requests [ index ] ?. reject ( new Error ( "lookup failed" ) ) ;
3032 } ;
31- return { ...bridge , runtime, requests, settle, me, trackExposure } ;
33+ return { ...bridge , runtime, page , requests, settle, me, trackExposure } ;
3234}
3335
3436afterEach ( ( ) => vi . unstubAllGlobals ( ) ) ;
@@ -139,11 +141,26 @@ describe("browser experiments", () => {
139141 b . module . getSnapshot ( ) ;
140142 b . runtime . userId = "old-user" ;
141143 b . runtime . flags . checkout = true ;
142- vi . stubGlobal ( "window" , { __B44_EXPERIMENTS__ : b . runtime } ) ;
144+ vi . stubGlobal ( "window" , b . page ) ;
143145 expect ( b . module . isEnabled ( "checkout" ) ) . toBe ( false ) ;
144146 expect ( b . runtime . userId ) . toBeNull ( ) ;
145147 } ) ;
146148
149+ test ( "auth updates cannot adopt a replacement runtime owned by another app" , ( ) => {
150+ const b = setup ( ) ;
151+ expect ( b . module . isEnabled ( "checkout" ) ) . toBe ( false ) ;
152+ b . trackExposure . mockClear ( ) ;
153+ b . page . __B44_EXPERIMENTS_BOOTSTRAP__ . config . app_id = "other-app" ;
154+ const setUser = vi . spyOn ( b . runtime , "setUser" ) ;
155+
156+ b . onAuthStateChange ( { status : "authenticated" , userId : "user-b" } ) ;
157+ expect ( b . module . getSnapshot ( ) ) . toEqual ( { flags : { } , isLoading : false } ) ;
158+ b . onAuthStateChange ( { status : "anonymous" } ) ;
159+ expect ( b . module . isEnabled ( "checkout" , true ) ) . toBe ( true ) ;
160+ expect ( setUser ) . not . toHaveBeenCalled ( ) ;
161+ expect ( b . trackExposure ) . not . toHaveBeenCalled ( ) ;
162+ } ) ;
163+
147164 test ( "cleanup and throwing subscribers cannot restore or interrupt identity" , async ( ) => {
148165 const b = setup ( true ) ;
149166 const listener = vi . fn ( ( ) => { throw new Error ( "render error" ) ; } ) ;
0 commit comments