AEROSIM-TS-38
Verify governed asset loading in the flight scene
The Web Application loads a validated optimized asset through the governed manifest and cannot import an unregistered runtime asset.
- Verified flow state
- Done
- Owner
- AeroSim Architecture and Delivery
- Feature
- AEROSIM-FT-48
- Component
- Web Application — governed runtime asset loader
- Repository
- corp-v1-aerosim/corp-v1-aerosim
Delivery scope
Resolve representative-aircraft only through the compiled validated manifest registry, fetch its runtime GLB, verify the expected runtime SHA-256 before parsing, render AircraftModel in the R3F scene, and release GLTF resources on unmount. Primary files: applications/web/src/flight/assets/governed-asset-loader.ts, applications/web/src/flight/assets/AircraftModel.tsx, applications/web/tests/flight/governed-asset-loader.test.tsx.
Implementation contract
Implementation artifacts
- applications/web/src/flight/assets/governed-asset-loader.ts
- applications/web/src/flight/assets/AircraftModel.tsx
- applications/web/tests/flight/governed-asset-loader.test.tsx
Inputs
- AssetId representative-aircraft and compiled AssetManifestV1 registry entry
- Fetched GLB ArrayBuffer from manifest.runtimePath
Outputs
- Loaded GovernedAsset {assetId,scene,animations,manifest} for AircraftModel
- AssetLoadProblem with assetId and reason for a refused load
Failure boundaries
- Refuse unknown assetId, path not present in the registry, hash mismatch, fetch failure, invalid GLB, or manifest marked invalid.
- Do not add an unverified scene to R3F and dispose any partially created parser resources.
Excluded scope
- Dynamic user uploads, remote URL loading, asset editing, and fallback to unregistered placeholder files are not allowed.
Verification steps
- pnpm --filter @aerosim/web test -- flight/governed-asset-loader.test.tsx
- Load representative-aircraft successfully, then exercise unknown ID, tampered bytes, 404, and malformed GLB; assert no scene node remains for failures.
Traceability
Dependencies
- AEROSIM-TS-37Canonical ID: TASK-0037
UI/UX applicability
non_visual
This Task owns technical or behavioral acceptance and does not claim direct visual conformance to the approved UI/UX package.
Acceptance evidence
Verified delivery: application PR #54 merged the governed asset loader as 96d00db489b131560772b878306332e5130b0c75; current integration retains manifest-only resolution, runtime SHA-256 validation, failure refusal, and resource cleanup; the focused loader suite passes 28/28; exact-head integration validation and immutable image publication passed remotely at ade1706b80d1642a6763f2827cfb2e6b3fc8ddaf. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.
Current evidence boundary
No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.