hub-core/tests/fixtures/flex-auth
tegwick 3e386147fd
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / pytest-smoke (push) Failing after 3s
feat: add fail-closed Hub access profile foundation
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
2026-09-28 11:44:50 +02:00
..
check_request_allow_rotate.json feat: add fail-closed Hub access profile foundation 2026-09-28 11:44:50 +02:00
decision_rotate_signed.json feat: add fail-closed Hub access profile foundation 2026-09-28 11:44:50 +02:00
decision_rotate_signed_tampered.json feat: add fail-closed Hub access profile foundation 2026-09-28 11:44:50 +02:00
keys.json feat: add fail-closed Hub access profile foundation 2026-09-28 11:44:50 +02:00
README.md feat: add fail-closed Hub access profile foundation 2026-09-28 11:44:50 +02:00

These public conformance fixtures were copied from flex-auth examples/secrets-engine/replay/ and check_request_allow_rotate.json on 2026-09-28. They retain the owner's Go-generated signature and submitted digest. keys.json contains a well-known test-only public key, not production trust. The old decision is used only to test cryptographic interoperability, never as an active authorization decision. Hub policy lifetime/caller tests use fresh synthetic decisions with ephemeral test keys.