test-driver/crystallized/test_grant_access.py

143 lines
5.2 KiB
Python
Raw Normal View History

"""Crystallized regression test — generated, do not edit by hand.
Lineage
-------
ancestor asset : va-grant-via-browser
ancestor maturity: T1
descendant : va-grant-crystallized (T5 Deterministic)
frozen from : 4 identical realizations
surface version: lab-0.2.0-baseline
generated : 2026-09-28
Why this file exists
--------------------
An agent discovered this path 4 times running and it did not change. The
search is now waste, so it has been frozen. **No model is involved in running
this test.**
The realization below is plain HTTP with no framework dependency. The assertions
are imported from the originating use case rather than restated — a generated
test that paraphrases its assertions creates a second, unverified statement of
intent, and drift between the two would be silent. See F-0007 for what that
costs.
If this test starts failing, the correct first response is **not** to update the
selectors. Re-run the agentic ancestor: if it recovers, the surface moved and
this file should be regenerated; if it does not, the behaviour changed and that
is a finding.
"""
from __future__ import annotations
import unittest
import urllib.error
import urllib.parse
import urllib.request
from scenarios.alice_bob_carol import _bob_can_read, _bob_cannot_write, _carol_cannot_read
TARGET = '/resources/R/grant'
FIELDS = {'permission': 'READ', 'subject_id': 'bob'}
class OriginViolation(ValueError):
"""An authenticated request attempted to leave its configured origin."""
def _origin(url):
try:
parsed = urllib.parse.urlsplit(url)
if (parsed.scheme not in ('http', 'https') or not parsed.hostname
or parsed.username is not None or parsed.password is not None):
raise ValueError
return (parsed.scheme, parsed.hostname,
parsed.port if parsed.port is not None else (443 if parsed.scheme == 'https' else 80))
except ValueError:
raise OriginViolation('invalid authenticated HTTP origin') from None
class _OriginRedirectHandler(urllib.request.HTTPRedirectHandler):
def __init__(self, origin):
self.origin = origin
def redirect_request(self, req, fp, code, msg, headers, newurl):
if _origin(newurl) != self.origin:
raise OriginViolation('authenticated redirect leaves configured origin')
return super().redirect_request(req, fp, code, msg, headers, newurl)
def authenticated_target(base_url, path):
origin = _origin(base_url)
target = urllib.parse.urljoin(base_url, path)
if _origin(target) != origin:
raise OriginViolation('authenticated request leaves configured origin')
# The caller supplies the authorization header only after target validation.
return target, urllib.request.build_opener(_OriginRedirectHandler(origin))
def evaluate_predicate(predicate, snapshot):
"""Shared deterministic judgment semantics, embeddable without the framework."""
if not snapshot:
return "INCONCLUSIVE", "no observations were collected"
try:
satisfied = predicate(snapshot)
except KeyError as missing:
return "INCONCLUSIVE", f"required observation {missing} missing from snapshot"
except Exception as exc:
return "INCONCLUSIVE", f"predicate raised {type(exc).__name__}: {exc}"
if type(satisfied) is not bool:
return "INCONCLUSIVE", "predicate did not return a boolean"
return ("PASS" if satisfied else "FAIL"), None
def assert_predicates(predicates, snapshot):
"""Map oracle outcomes to pytest: FAIL dominates; INCONCLUSIVE is explicit skip."""
judgments = [(text, *evaluate_predicate(predicate, snapshot))
for predicate, text in predicates]
failures = [text for text, verdict, _ in judgments if verdict == "FAIL"]
if failures:
raise AssertionError("; ".join(failures))
unknown = [f"{text}: {reason}" for text, verdict, reason in judgments
if verdict == "INCONCLUSIVE"]
if unknown or not judgments:
raise unittest.SkipTest("INCONCLUSIVE: " + ("; ".join(unknown) or "no assertions"))
def _post(base_url: str, token: str, path: str, fields: dict) -> int:
target, opener = authenticated_target(base_url, path)
request = urllib.request.Request(
target,
data=urllib.parse.urlencode(fields).encode(),
method="POST",
headers={
"Authorization": f"Bearer {token}",
"Content-Type": "application/x-www-form-urlencoded",
},
)
try:
with opener.open(request, timeout=10) as response:
return response.status
except urllib.error.HTTPError as error:
return error.code
def realize(base_url: str, token: str) -> int:
"""Perform grant_access deterministically, exactly as the agent learned to."""
return _post(base_url, token, TARGET, FIELDS)
def test_grant_access(crystallized_world):
"""grant_access still works, and the claims it protects still hold."""
base_url, token, observe = crystallized_world
assert realize(base_url, token) < 400, "the frozen realization no longer works"
snapshot = observe()
assert_predicates([
(_bob_can_read, 'Bob can read R after the grant'),
(_carol_cannot_read, 'Carol can never read R'),
(_bob_cannot_write, 'A READ grant does not let Bob write R'),
], snapshot)