/** * Regression lock for Sentry hq-cli 7711917661. * * A one-shot company push driven straight from hq-cli (`hq skill create` -> * defaultSyncFile -> share()) never ran the sync-runner's transport selection, * so `createPushRunContext` still vended STS write credentials for the `cmp_` * vault. When a member's ACL grant set overflowed the STS session-policy budget, * hq-pro refused the vend with HTTP 422 `POLICY_WRITE_SCOPE_TRUNCATED`, which * share() turned into a thrown `VaultCredentialScopeError` — aborting the push * with the file stamped locally but never uploaded. * * The fix routes the one-shot push through `ensureCompanyVaultTransport`, which * selects the presigned-URL transport for company vaults and tells * `resolveEntityContext` to SKIP the `cmp_` STS vend entirely. These tests drive * share() exactly as defaultSyncFile does and assert the company vend route is * never touched — so the recorded 422 can never be reached. * * The byte transport (`../s3.js`) is fully mocked: the assertion under test is * the credential-vend DECISION, not the upload itself. */ export {}; //# sourceMappingURL=share-presign-transport.test.d.ts.map