approval-engine/tests/test_examples.py
tegwick d5d1e41035 Publish the valid-but-unbound claim; the missing shape was confounded
The example set satisfied §11's both-shapes clause only by accident. Both
values of pdp_digest and pdp_path appeared, but they appeared in perfect
correlation with validity: claim.valid carried a digest with pdp_path true,
claim.revoked carried null with pdp_path false, and nothing else existed.

Two independent dimensions presented as one. A reader could reasonably conclude
that pdp_digest is null because the claim is revoked, or that pdp_path tracks
validity. Both are false, and the example set is what would have taught them --
the failure the both-shapes clause exists to catch, which this repo proposed and
then shipped a case of.

The missing shape is the consequential one: a claim that is entirely valid --
valid_now true, reason_code ok, not consumed -- and carries no PDP binding. It
is usable for a consumer comparing the native binding.digest and unusable on the
GH-DEC-2026-003 path, where a PEP MUST refuse it. valid_now true is not
permission to proceed on that lane. A consumer writing that refusal previously
had no published shape to test against and would have had to invent a fixture,
which is the drift §12 names.

examples/claim.valid.no-pdp.json publishes it. The tests now assert the
decorrelation rather than mere presence: one requires a valid claim with no PDP
binding to exist, the other requires valid claims to cover both pdp_path
declarations. Verified both fail when the new example is removed, so they hold
the property rather than restating today's file list. 121 tests pass.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PM5HnEAhokxdfcPqBNpT7D

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 715850@bnt-lap001
Assistant-Session: eb557e93-7cb1-45d0-9e57-7d15b3edc60e
2026-09-07 13:48:00 +02:00

98 lines
3.6 KiB
Python

"""The published examples must satisfy the published schema.
flex-auth shipped two defects in one day from fixtures that contradicted their
own contracts, and secrets-engine built a validator against one of them. A
contract whose examples contradict its prose will be implemented as its
examples, so the examples are tested rather than trusted.
"""
import json
from pathlib import Path
import pytest
jsonschema = pytest.importorskip("jsonschema")
ROOT = Path(__file__).resolve().parent.parent
SCHEMA = json.loads((ROOT / "schemas" / "approval_claim.schema.json").read_text())
EXAMPLES = sorted((ROOT / "examples").glob("claim.*.json"))
def test_examples_exist():
assert EXAMPLES, "no claim examples found to validate"
@pytest.mark.parametrize("path", EXAMPLES, ids=lambda p: p.name)
def test_example_matches_schema(path):
jsonschema.validate(json.loads(path.read_text()), SCHEMA)
@pytest.mark.parametrize("path", EXAMPLES, ids=lambda p: p.name)
def test_example_states_pdp_digest_explicitly(path):
"""Absence must be a stated null, never a missing key."""
assert "pdp_digest" in json.loads(path.read_text())["binding"]
def test_examples_cover_both_pdp_binding_states():
"""An implementer must see both shapes, not infer one from the other."""
states = {
json.loads(p.read_text())["binding"]["pdp_digest"] is None for p in EXAMPLES
}
assert states == {True, False}
def test_examples_cover_both_pdp_path_declarations():
states = {json.loads(p.read_text())["binding"]["pdp_path"] for p in EXAMPLES}
assert states == {True, False}
def test_pdp_binding_is_not_confounded_with_validity():
"""Both shapes present is not enough if they only ever co-vary.
With only `claim.valid` (pdp_digest set, pdp_path true) and `claim.revoked`
(null, false), the two dimensions are perfectly correlated and an
implementer can reasonably infer that pdp_digest is null *because* the claim
is revoked, or that pdp_path tracks validity. Both inferences are wrong and
the example set is what teaches them.
The shape that must exist is a claim that is entirely valid -- `valid_now`
true, `reason_code` ok, not consumed -- and still carries no PDP binding.
That is the claim a privileged-lane PEP MUST refuse under
`GH-DEC-2026-008`, and it is the one a consumer would otherwise have to
invent a fixture for.
"""
claims = [json.loads(p.read_text()) for p in EXAMPLES]
valid_without_pdp = [
c
for c in claims
if c["valid_now"]
and c["reason_code"] == "ok"
and not c["consumed"]
and c["binding"]["pdp_digest"] is None
and c["binding"]["pdp_path"] is False
]
assert valid_without_pdp, (
"no example of a valid claim with no PDP binding; a consumer writing the "
"privileged-lane refusal has no published shape to test against"
)
def test_valid_claims_cover_both_pdp_path_declarations():
"""The decorrelation stated as coverage rather than as one instance."""
paths = {
c["binding"]["pdp_path"]
for c in (json.loads(p.read_text()) for p in EXAMPLES)
if c["valid_now"]
}
assert paths == {True, False}, (
f"valid examples declare only pdp_path={paths}; both are reachable states "
"for a valid approval"
)
@pytest.mark.parametrize("path", EXAMPLES, ids=lambda p: p.name)
def test_pdp_path_examples_always_carry_a_digest(path):
"""GH-DEC-2026-008: pdp_path true guarantees pdp_digest non-null."""
binding = json.loads(path.read_text())["binding"]
if binding["pdp_path"]:
assert binding["pdp_digest"] is not None