Skip to main content

AEROSIM-TS-38

Project task

Verify governed asset loading in the flight scene

The Web Application loads a validated optimized asset through the governed manifest and cannot import an unregistered runtime asset.

AEROSIM-TS-38Canonical ID TASK-0038
Verified flow state
Done
Owner
AeroSim Architecture and Delivery
Component
Web Application — governed runtime asset loader
Repository
corp-v1-aerosim/corp-v1-aerosim

Delivery scope

Resolve representative-aircraft only through the compiled validated manifest registry, fetch its runtime GLB, verify the expected runtime SHA-256 before parsing, render AircraftModel in the R3F scene, and release GLTF resources on unmount. Primary files: applications/web/src/flight/assets/governed-asset-loader.ts, applications/web/src/flight/assets/AircraftModel.tsx, applications/web/tests/flight/governed-asset-loader.test.tsx.

Implementation contract

Implementation artifacts

  • applications/web/src/flight/assets/governed-asset-loader.ts
  • applications/web/src/flight/assets/AircraftModel.tsx
  • applications/web/tests/flight/governed-asset-loader.test.tsx

Inputs

  • AssetId representative-aircraft and compiled AssetManifestV1 registry entry
  • Fetched GLB ArrayBuffer from manifest.runtimePath

Outputs

  • Loaded GovernedAsset {assetId,scene,animations,manifest} for AircraftModel
  • AssetLoadProblem with assetId and reason for a refused load

Failure boundaries

  • Refuse unknown assetId, path not present in the registry, hash mismatch, fetch failure, invalid GLB, or manifest marked invalid.
  • Do not add an unverified scene to R3F and dispose any partially created parser resources.

Excluded scope

  • Dynamic user uploads, remote URL loading, asset editing, and fallback to unregistered placeholder files are not allowed.

Verification steps

  • pnpm --filter @aerosim/web test -- flight/governed-asset-loader.test.tsx
  • Load representative-aircraft successfully, then exercise unknown ID, tampered bytes, 404, and malformed GLB; assert no scene node remains for failures.

Traceability

Requirements

Dependencies

UI/UX applicability

non_visual

This Task owns technical or behavioral acceptance and does not claim direct visual conformance to the approved UI/UX package.

Acceptance evidence

Verified delivery: application PR #54 merged the governed asset loader as 96d00db489b131560772b878306332e5130b0c75; current integration retains manifest-only resolution, runtime SHA-256 validation, failure refusal, and resource cleanup; the focused loader suite passes 28/28; exact-head integration validation and immutable image publication passed remotely at ade1706b80d1642a6763f2827cfb2e6b3fc8ddaf. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.

Current evidence boundary

No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.