fix: reject unsafe evidence documentation claims
This commit is contained in:
@@ -525,6 +525,12 @@ elif mutation == "s3-token-boundary-omitted":
|
||||
)
|
||||
elif mutation == "credential-literal":
|
||||
changed = original + "\nTHT_WS_STATIC_S3_EVIDENCE_SECRET_KEY=AKIAEXAMPLECREDENTIAL\n"
|
||||
elif mutation == "credential-literal-public-prose":
|
||||
changed = original + "\nPublic credential example: AKIAABCDEFGHIJKLMNOP\n"
|
||||
elif mutation == "credential-literal-public-yaml":
|
||||
document = yaml.safe_load(original)
|
||||
document["public_credential_example"] = "AKIAABCDEFGHIJKLMNOP"
|
||||
changed = yaml.safe_dump(document, sort_keys=False)
|
||||
elif mutation == "signed-query-example":
|
||||
signed_query = "https://evidence.example.invalid/report" + "?X-Amz-Signature=unsafe"
|
||||
changed = original + f"\nTHT_EVIDENCE_URI={signed_query}\n"
|
||||
@@ -538,6 +544,23 @@ elif mutation == "p1-scope-inversion":
|
||||
"P1 materializes, extracts, and indexes Evidence before publication.",
|
||||
1,
|
||||
)
|
||||
elif mutation.startswith("p1-append-"):
|
||||
claims = {
|
||||
"p1-append-acquisition": "P1 owns Evidence acquisition.",
|
||||
"p1-append-materialization": "P1 owns Evidence materialization.",
|
||||
"p1-append-extraction": "P1 owns Evidence extraction.",
|
||||
"p1-append-preprocessing": "P1 owns Evidence preprocessing.",
|
||||
"p1-append-embeddings": "P1 owns Evidence embeddings.",
|
||||
"p1-append-qdrant-writes": "P1 owns Evidence Qdrant writes.",
|
||||
"p1-append-indexing": "P1 owns Evidence indexing.",
|
||||
"p1-append-active": "P1 owns Evidence `ACTIVE` publication.",
|
||||
"p1-append-retention": "P1 owns Evidence retention.",
|
||||
"p1-append-gc": "P1 owns Evidence GC.",
|
||||
}
|
||||
claim = claims.get(mutation)
|
||||
if claim is None:
|
||||
raise SystemExit(f"unknown P1 append mutation: {mutation}")
|
||||
changed = original + f"\n{claim}\n"
|
||||
elif mutation == "config-ordering":
|
||||
changed = original.replace(
|
||||
"tht config check -c <path>", "tht -c <path> config check", 1
|
||||
@@ -963,6 +986,12 @@ expect_evidence_fixture_rejected \
|
||||
expect_evidence_fixture_rejected \
|
||||
"credential literal in public bindings" docs/install/examples/workspace-bindings.env.example credential-literal \
|
||||
"credential literal forbidden"
|
||||
expect_evidence_fixture_rejected \
|
||||
"credential literal in public prose" docs/contracts/workspace-evidence-v3.md credential-literal-public-prose \
|
||||
"credential literal forbidden"
|
||||
expect_evidence_fixture_rejected \
|
||||
"credential literal in public YAML" deploy/workspaces/example.yaml credential-literal-public-yaml \
|
||||
"credential literal forbidden"
|
||||
expect_evidence_fixture_rejected \
|
||||
"signed query in public bindings" docs/install/examples/workspace-bindings.env.example signed-query-example \
|
||||
"query-bearing public URI forbidden"
|
||||
@@ -972,6 +1001,36 @@ expect_evidence_fixture_rejected \
|
||||
expect_evidence_fixture_rejected \
|
||||
"P1 Evidence scope inversion" docs/contracts/workspace-evidence-v3.md p1-scope-inversion \
|
||||
"P1 scope violation"
|
||||
expect_evidence_fixture_rejected \
|
||||
"appended P1 acquisition claim" docs/contracts/workspace-evidence-v3.md p1-append-acquisition \
|
||||
"P1 scope violation"
|
||||
expect_evidence_fixture_rejected \
|
||||
"appended P1 materialization claim" docs/contracts/workspace-evidence-v3.md p1-append-materialization \
|
||||
"P1 scope violation"
|
||||
expect_evidence_fixture_rejected \
|
||||
"appended P1 extraction claim" docs/contracts/workspace-evidence-v3.md p1-append-extraction \
|
||||
"P1 scope violation"
|
||||
expect_evidence_fixture_rejected \
|
||||
"appended P1 preprocessing claim" docs/contracts/workspace-evidence-v3.md p1-append-preprocessing \
|
||||
"P1 scope violation"
|
||||
expect_evidence_fixture_rejected \
|
||||
"appended P1 embeddings claim" docs/contracts/workspace-evidence-v3.md p1-append-embeddings \
|
||||
"P1 scope violation"
|
||||
expect_evidence_fixture_rejected \
|
||||
"appended P1 Qdrant writes claim" docs/contracts/workspace-evidence-v3.md p1-append-qdrant-writes \
|
||||
"P1 scope violation"
|
||||
expect_evidence_fixture_rejected \
|
||||
"appended P1 indexing claim" docs/contracts/workspace-evidence-v3.md p1-append-indexing \
|
||||
"P1 scope violation"
|
||||
expect_evidence_fixture_rejected \
|
||||
"appended P1 ACTIVE publication claim" docs/contracts/workspace-evidence-v3.md p1-append-active \
|
||||
"P1 scope violation"
|
||||
expect_evidence_fixture_rejected \
|
||||
"appended P1 retention claim" docs/contracts/workspace-evidence-v3.md p1-append-retention \
|
||||
"P1 scope violation"
|
||||
expect_evidence_fixture_rejected \
|
||||
"appended P1 garbage collection claim" docs/contracts/workspace-evidence-v3.md p1-append-gc \
|
||||
"P1 scope violation"
|
||||
expect_evidence_fixture_rejected \
|
||||
"config check option reordered" docs/contracts/workspace-evidence-v3.md config-ordering \
|
||||
"exact config-check ordering missing"
|
||||
|
||||
Reference in New Issue
Block a user