"""The published examples must satisfy the published schema. flex-auth shipped two defects in one day from fixtures that contradicted their own contracts, and secrets-engine built a validator against one of them. A contract whose examples contradict its prose will be implemented as its examples, so the examples are tested rather than trusted. """ import json from pathlib import Path import pytest jsonschema = pytest.importorskip("jsonschema") ROOT = Path(__file__).resolve().parent.parent SCHEMA = json.loads((ROOT / "schemas" / "approval_claim.schema.json").read_text()) EXAMPLES = sorted((ROOT / "examples").glob("claim.*.json")) def test_examples_exist(): assert EXAMPLES, "no claim examples found to validate" @pytest.mark.parametrize("path", EXAMPLES, ids=lambda p: p.name) def test_example_matches_schema(path): jsonschema.validate(json.loads(path.read_text()), SCHEMA) @pytest.mark.parametrize("path", EXAMPLES, ids=lambda p: p.name) def test_example_states_pdp_digest_explicitly(path): """Absence must be a stated null, never a missing key.""" assert "pdp_digest" in json.loads(path.read_text())["binding"] def test_examples_cover_both_pdp_binding_states(): """An implementer must see both shapes, not infer one from the other.""" states = { json.loads(p.read_text())["binding"]["pdp_digest"] is None for p in EXAMPLES } assert states == {True, False}