from dataclasses import replace import pytest from secrets_engine.config import repo_root from secrets_engine.errors import PolicyGuardError from secrets_engine.publication_policy import PublicationPolicy, resolve def _policy(): return PublicationPolicy.load(repo_root() / "policies") def test_netkingdom_is_build_and_dormant(): p = _policy() assert p.netkingdom_maturity == "maturity-build" assert p.production_grade is False def test_dormant_clamps_to_repo_and_default_token_env(): p = _policy() r = resolve(p, org="coulomb", repo="whynot-design", npm_scope="@whynot", package_maturity="maturity-build") assert r.effective_scope == "repo" assert r.token_env == "NPM_AUTH_TOKEN" assert r.clamped is True # build->gitea would be broader; clamped down assert r.active is False def test_active_graduated_scoping_when_production_grade(): p = replace(_policy(), netkingdom_maturity="maturity-prod") build = resolve(p, org="coulomb", repo="whynot-design", npm_scope="@whynot", package_maturity="maturity-build") test = resolve(p, org="coulomb", repo="whynot-design", npm_scope="@whynot", package_maturity="maturity-test") prod = resolve(p, org="coulomb", repo="whynot-design", npm_scope="@whynot", package_maturity="maturity-prod") assert (build.effective_scope, build.token_env) == ("gitea", "NPM_AUTH_GITEA_TOKEN") assert (test.effective_scope, test.token_env) == ("org", "NPM_AUTH_COULOMB_TOKEN") assert (prod.effective_scope, prod.token_env) == ("repo", "NPM_AUTH_TOKEN") assert build.active is True and build.clamped is False def test_token_env_override_wins(): p = _policy() r = resolve(p, org="coulomb", repo="whynot-design", npm_scope="@whynot", package_maturity="maturity-build", token_env_override="NPM_AUTH_WHYNOTDESIGN") assert r.token_env == "NPM_AUTH_WHYNOTDESIGN" def test_invalid_maturity_rejected(): p = _policy() with pytest.raises(PolicyGuardError): resolve(p, org="coulomb", repo="x", npm_scope="@y", package_maturity="maturity-ga")