Point the OpenRouter cycle at memo version 3.
Fresh receipts use the new approval IDs. A matching live policy and AppRole skips apply without claiming that approval. A difference fails closed. Assistant: grok Assistant-Session: 01a0e2a1-8058-7553-9999-b7d106c17047
This commit is contained in:
parent
1cd546e77c
commit
53825190ca
5 changed files with 47 additions and 17 deletions
|
|
@ -28,11 +28,22 @@ class TestProbe(unittest.TestCase):
|
|||
def test_server_failure_is_not_revocation_proof(self):
|
||||
with self.assertRaisesRegex(ValueError,'revocation_probe_not_definitive'):self.check(500)
|
||||
def test_reconciled_prior_phase(self):
|
||||
prior={'phase':'verify_attempt_started','failure_code':'revoked_token_still_usable','actions':[{'action':'apply','approval_id':m.IDS['apply'],'exit_code':0,'limits':{'token_ttl':900,'token_max_ttl':1800,'secret_id_ttl':900,'secret_id_num_uses':1,'token_num_uses':8}}]}
|
||||
prior={'phase':'verify_attempt_started','failure_code':'revoked_token_still_usable','actions':[{'action':'apply','approval_id':m.PRIOR_IDS['apply'],'exit_code':0,'limits':{'token_ttl':900,'token_max_ttl':1800,'secret_id_ttl':900,'secret_id_num_uses':1,'token_num_uses':8}}]}
|
||||
with patch.object(Path,'read_text',return_value=json.dumps(prior)):
|
||||
self.assertEqual(m.resume_receipt(),prior)
|
||||
prior['actions'][0]['approval_id']='other'
|
||||
with patch.object(Path,'read_text',return_value=json.dumps(prior)):
|
||||
with self.assertRaisesRegex(ValueError,'prior_apply_not_verified'):m.resume_receipt()
|
||||
def test_fresh_apply_branch(self):
|
||||
hcl='path "auth/token/lookup-self" {\n capabilities = ["read"]\n}\n'
|
||||
role=dict(m.LIMITS,token_policies=[m.ROLE])
|
||||
self.assertEqual(m.fresh_apply_plan(hcl,None,None),(tuple(m.IDS),None))
|
||||
actions,row=m.fresh_apply_plan(hcl,hcl+'\n',role)
|
||||
self.assertEqual(actions,('verify','exec'))
|
||||
self.assertNotIn('apply',actions)
|
||||
self.assertEqual(row,{'action':'apply','already_satisfied':True,'limits':dict(m.LIMITS)})
|
||||
self.assertNotIn('approval_id',row)
|
||||
for existing,live in ((hcl,None),(None,role),('other\n',role),(hcl,dict(role,token_ttl=1)),(hcl,dict(role,token_policies=[m.ROLE,'default'])),(hcl,dict(role,token_policies=m.ROLE))):
|
||||
with self.assertRaisesRegex(ValueError,'existing_native_objects_require_reconciliation'):m.fresh_apply_plan(hcl,existing,live)
|
||||
|
||||
if __name__=='__main__':unittest.main()
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue