Make snapshot attribute validation enforce a real rule
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 40s
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 40s
Closes gap G06. checkNoUnknownAttributes was named for a rule it did not implement: it rejected blank keys, which is not an allow-list, so a snapshot carrying malformed or shadowing attribute names passed a check whose name said otherwise. A rule that passes for the wrong reason is worse than an absent one, because the report is read as evidence. raw_attributes_well_formed requires each key to be a valid LDAP attribute descriptor, forbids shadowing an attribute the canonical model owns (uid, cn, mail) in any casing, and rejects keys differing only by case, which LDAP treats as one attribute. spec/ldap-schema.yaml carries the same wording. Two corrections to the gap's description rather than implementations of it. An allow-list is not derivable: ldapAttributes is defined as what the canonical model does not cover, so the schema cannot enumerate what may appear there. And the reference constraint already existed -- checkValidGroupMemberships only checks emptiness, but the semantic rule checkReferencedUsersExist resolves every member against the user set. Neutering the rule fails four of the five new tests. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NV9oijZukGyGbRQGGKnK4P Assistant: claude-code Assistant-Model: opus Assistant-Process: 713576@bnt-lap001 Assistant-Session: 384c511d-9bce-4cb8-a676-2aef6c0c8df6
This commit is contained in:
parent
f366df814a
commit
21acb5cdd6
6 changed files with 298 additions and 26 deletions
6
SCOPE.md
6
SCOPE.md
|
|
@ -56,7 +56,11 @@ Keycloak interchangeability are not established.
|
|||
attribute. The output is a reviewed artifact, not a proven migration; that
|
||||
proof needs a live provider swap and is not established.
|
||||
- Snapshot validation is a limited Go rule set, not full machine-readable schema
|
||||
enforcement. The canonical YAML model and discovery metadata now match the
|
||||
enforcement. Raw LDAP attribute keys are checked for descriptor validity,
|
||||
canonical-mapping shadowing and case-only duplicates (KEY-WP-0021); attribute
|
||||
values are not validated against a directory schema, and no allow-list of
|
||||
permitted attribute names exists, since that field carries what the canonical
|
||||
model does not name. The canonical YAML model and discovery metadata now match the
|
||||
runtime client-registration surface and are held there by a conformance check
|
||||
(KEY-WP-0017); the Go model is the runtime authority and the YAML the reviewed
|
||||
contract. That is narrower than schema enforcement in general.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue