"""Crystallized regression test — generated, do not edit by hand. Lineage ------- ancestor asset : va-grant-via-browser ancestor maturity: T1 descendant : va-grant-crystallized (T5 Deterministic) frozen from : 4 identical realizations surface version: lab-0.2.0-baseline generated : 2026-09-28 Why this file exists -------------------- An agent discovered this path 4 times running and it did not change. The search is now waste, so it has been frozen. **No model is involved in running this test.** The realization below is plain HTTP with no framework dependency. The assertions are imported from the originating use case rather than restated — a generated test that paraphrases its assertions creates a second, unverified statement of intent, and drift between the two would be silent. See F-0007 for what that costs. If this test starts failing, the correct first response is **not** to update the selectors. Re-run the agentic ancestor: if it recovers, the surface moved and this file should be regenerated; if it does not, the behaviour changed and that is a finding. """ from __future__ import annotations import unittest import urllib.error import urllib.parse import urllib.request from scenarios.alice_bob_carol import _bob_can_read, _bob_cannot_write, _carol_cannot_read TARGET = '/resources/R/grant' FIELDS = {'permission': 'READ', 'subject_id': 'bob'} class OriginViolation(ValueError): """An authenticated request attempted to leave its configured origin.""" def _origin(url): try: parsed = urllib.parse.urlsplit(url) if (parsed.scheme not in ('http', 'https') or not parsed.hostname or parsed.username is not None or parsed.password is not None): raise ValueError return (parsed.scheme, parsed.hostname, parsed.port if parsed.port is not None else (443 if parsed.scheme == 'https' else 80)) except ValueError: raise OriginViolation('invalid authenticated HTTP origin') from None class _OriginRedirectHandler(urllib.request.HTTPRedirectHandler): def __init__(self, origin): self.origin = origin def redirect_request(self, req, fp, code, msg, headers, newurl): if _origin(newurl) != self.origin: raise OriginViolation('authenticated redirect leaves configured origin') return super().redirect_request(req, fp, code, msg, headers, newurl) def authenticated_target(base_url, path): origin = _origin(base_url) target = urllib.parse.urljoin(base_url, path) if _origin(target) != origin: raise OriginViolation('authenticated request leaves configured origin') # The caller supplies the authorization header only after target validation. return target, urllib.request.build_opener(_OriginRedirectHandler(origin)) def evaluate_predicate(predicate, snapshot): """Shared deterministic judgment semantics, embeddable without the framework.""" if not snapshot: return "INCONCLUSIVE", "no observations were collected" try: satisfied = predicate(snapshot) except KeyError as missing: return "INCONCLUSIVE", f"required observation {missing} missing from snapshot" except Exception as exc: return "INCONCLUSIVE", f"predicate raised {type(exc).__name__}: {exc}" if type(satisfied) is not bool: return "INCONCLUSIVE", "predicate did not return a boolean" return ("PASS" if satisfied else "FAIL"), None def assert_predicates(predicates, snapshot): """Map oracle outcomes to pytest: FAIL dominates; INCONCLUSIVE is explicit skip.""" judgments = [(text, *evaluate_predicate(predicate, snapshot)) for predicate, text in predicates] failures = [text for text, verdict, _ in judgments if verdict == "FAIL"] if failures: raise AssertionError("; ".join(failures)) unknown = [f"{text}: {reason}" for text, verdict, reason in judgments if verdict == "INCONCLUSIVE"] if unknown or not judgments: raise unittest.SkipTest("INCONCLUSIVE: " + ("; ".join(unknown) or "no assertions")) def _post(base_url: str, token: str, path: str, fields: dict) -> int: target, opener = authenticated_target(base_url, path) request = urllib.request.Request( target, data=urllib.parse.urlencode(fields).encode(), method="POST", headers={ "Authorization": f"Bearer {token}", "Content-Type": "application/x-www-form-urlencoded", }, ) try: with opener.open(request, timeout=10) as response: return response.status except urllib.error.HTTPError as error: return error.code def realize(base_url: str, token: str) -> int: """Perform grant_access deterministically, exactly as the agent learned to.""" return _post(base_url, token, TARGET, FIELDS) def test_grant_access(crystallized_world): """grant_access still works, and the claims it protects still hold.""" base_url, token, observe = crystallized_world assert realize(base_url, token) < 400, "the frozen realization no longer works" snapshot = observe() assert_predicates([ (_bob_can_read, 'Bob can read R after the grant'), (_carol_cannot_read, 'Carol can never read R'), (_bob_cannot_write, 'A READ grant does not let Bob write R'), ], snapshot)