""" Making sure the browser runs the build we deployed. A fix can be written, tested, deployed, and served, and still not be what runs. `Cache-Control: no-cache` requires a browser to revalidate — but it only binds one that asks, and a browser that cached the SPA *before* that header existed applies heuristic freshness instead: a fraction of the file's age, which for a file dated weeks ago is days. It does not ask, so it never learns. That happened here. A phone ran a player without the read-ahead bound and filled the browser's buffer ceiling at 106 MB — the exact symptom the bound was written to remove — for an hour after the bounded player went live. Two sessions were spent looking at the node. So the URL now carries a fingerprint of what is being served, and the whole module graph lives under it: `/a//app.js` importing `./i18n.js` resolves to `/a//i18n.js`. A URL that changes with the content cannot serve yesterday's build, and cannot serve half of each. """ import re import pytest from fastapi.testclient import TestClient from meshbay_hub.api.webapp import ASSET_V, STATIC_DIR, _asset_version from meshbay_hub.app import create_app @pytest.fixture(scope="module") def client(): return TestClient(create_app()) def _shell_refs(html: str) -> list[str]: """What the shell loads: script sources and files. Not the canonical link nor the