test: harden DWH auth review gates

This commit is contained in:
User
2026-08-21 05:29:57 +02:00
parent 7fe53164ba
commit 09290a0fe7
4 changed files with 75 additions and 13 deletions
@@ -129,10 +129,11 @@ Legacy accepts 1–128 opaque bytes without ASCII controls and hashes the entire
cd tools/dwh-auth
gofmt -w internal/credential internal/record
go test ./internal/credential ./internal/record -count=1
go list -deps ./... | grep -v '^github.com/aritmolab/thothii/tools/dwh-auth' | grep '\.'
test "$(go list -m all)" = 'github.com/aritmolab/thothii/tools/dwh-auth'
```
Expected: tests pass; dependency scan exits 1 with no third-party path.
Expected: tests pass; the exact module list contains only the main module, proving there are no
external module dependencies (the Go standard library is not listed as a module).
- [ ] **Step 7: Commit**
@@ -556,6 +557,7 @@ git commit -m "docs: explain per-installation DWH access"
bash scripts/test-dwh-auth-build-contract.sh
bash scripts/test-dwh-auth-nginx-contract.sh
bash scripts/test-dwh-auth-nginx-integration.sh
bash scripts/test-dwh-auth-secret-scan.sh
bash scripts/test-verify-dwh-auth-docs.sh
```
@@ -565,13 +567,36 @@ bash scripts/test-verify-dwh-auth-docs.sh
bash scripts/test-default-compose.sh
bash scripts/test-unified-compose.sh
bash scripts/test-no-deployment-coupling-scope.sh
bash scripts/test-no-deployment-coupling.sh
bash scripts/test-compose-secret-policy.sh
bash scripts/test-verify-workspace-install-docs.sh
(cd tools/tht && go test ./... -count=1)
```
Expected: all pass; Compose unchanged; `tht` has no DWH-key command; Mac/Windows need no new binary.
Required result: every command above passes; Compose remains unchanged; `tht` has no DWH-key
command; Mac/Windows need no new binary. `test-no-deployment-coupling-scope.sh` is the required
PASS regression gate for this candidate.
`test-no-deployment-coupling.sh` is a separately tracked **BASELINE_RED** debt: it was already
red at `4ef0a6a` because its global `\bpsd\b` prohibition scans approved PSD deployment/docs
content. Do not modify that global gate in this work. Record both sanitized category/path-only
outputs in `.artifacts/dwh-auth/source-verification.md`: `BASELINE_RED` for a detached `4ef0a6a`
worktree and `CANDIDATE_RED` for this candidate. The candidate is expected to add intentional DWH
manuals/bindings to that diagnostic output, so the two outputs are not expected to be identical.
The runtime non-regression proof is instead the required empty immutable-path diff plus the scope
regression PASS:
```bash
git diff --exit-code 4ef0a6a -- \
compose.yaml \
deploy/compose.local.yaml \
deploy/compose.server.yaml \
scripts/run-stack.sh \
tools/tht
```
Record only the scanner category and relative path (never matching text) for the global-gate
diagnostic. Its unrelated remediation remains future gate debt and is excluded from this Task 8
all-required-pass claim.
- [ ] **Step 3: Check scope and leaks**
@@ -579,10 +604,12 @@ Expected: all pass; Compose unchanged; `tht` has no DWH-key command; Mac/Windows
git diff --check
git status --short
git log --oneline --decorate -8
rg -n --hidden --glob '!.git/**' --glob '!docs/superpowers/**' 'legacy-shared\.[A-Za-z0-9_-]|thtdwh_v1\.[A-Za-z0-9_-]{16}\.[A-Za-z0-9_-]{43}' .
bash scripts/test-dwh-auth-secret-scan.sh
```
Expected: whitespace clean; only intended evidence untracked; secret scan exits 1; reviewed commits.
Expected: whitespace clean; only intended evidence untracked; the non-printing credential-literal
scan exits 0 only when there are zero full-format v1 matches; reviewed commits. Do not scan
`legacy-shared.`: legacy credentials are opaque and that string can be a legitimate file path.
- [ ] **Step 4: Terra review**