Bind OpenBao builds to approved inputs and secure credential delivery

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e75a-fc5c-7913-9dba-9846210c766d
This commit is contained in:
tegwick 2026-09-28 11:55:39 +02:00
parent ee1dc2b651
commit 2b83324c01
8 changed files with 622 additions and 84 deletions

View file

@ -49,3 +49,24 @@ def test_missing_required_field_raises(tmp_path) -> None:
path = _write(tmp_path, "id: p\n# status omitted")
with pytest.raises(PlanError, match="missing field"):
ConstructionPlan.load(path)
@pytest.mark.parametrize("frontmatter", [
"id: p\nstatus: reviewed\nstatus: approved",
"id: p\nstatus: approved\nbuild_spec:\n token_num_uses: 8\n token_num_uses: 0",
"- not-a-mapping",
])
def test_ambiguous_or_malformed_approval_document_refused(tmp_path, frontmatter):
with pytest.raises(PlanError):
ConstructionPlan.load(_write(tmp_path, frontmatter))
@pytest.mark.parametrize("approver", ['" "', "true", "[bernd]"])
def test_non_string_or_blank_approval_marker_is_not_approval(tmp_path, approver):
path = _write(tmp_path, f'id: p\nstatus: approved\napproved_by: {approver}\napproved_at: "2026-09-28"')
assert not ConstructionPlan.load(path).is_approved()
def test_triple_dash_inside_specification_is_not_frontmatter_delimiter(tmp_path):
path = _write(tmp_path, 'id: p\nstatus: draft\nbuild_spec:\n policy_name: "lane---example"')
assert ConstructionPlan.load(path).build_spec["policy_name"] == "lane---example"