SIGN IN SIGN UP

test(e2e): replace vulnerable multi TOC CSV assertion with guarded sheet contract

The old multi-toc-csv spec waited for POST /_/{room} with text/csv — the
direct parent-TOC write that 170eaa4 deleted because it minted unmarked
public children under private parents. That was contract drift, not a
defect: the test pinned the vulnerable transport.

Replace (not relax) the transport wait with POST /_/={room}/sheet
(application/json, 201 + authoritative {sheet}). Keep the user-visible
cold-seed / add / rename / delete / reload outcomes intact. Explicitly
assert that Add Sheet no longer emits the legacy parent CSV POST.

Strengthen on the seam this change is about: under a real private parent
(authWorkerBase + virtual authenticator), the created child denies
anonymous HTTP read (403) and reports isPrivate/canRead:false via
/_/{child}/access — proof the child carries meta:parent. An unmarked
child would stay public under authorize().

Local: build:assets + full packages/e2e chromium suite 51/51 green.
A
Audrey Tang committed
e35b3e5c19f9c8bbc150819d5b35ba38b4db6b75
Parent: 213f27b