fix: complete evidence documentation contract

This commit is contained in:
2026-08-09 20:47:30 +02:00
parent d77c08884b
commit d7264b843d
3 changed files with 69 additions and 13 deletions
+34 -3
View File
@@ -486,21 +486,40 @@ elif mutation == "wrong-docs-directory":
"workspaces/<id>.env.example\nworkspaces/<id>.md",
1,
)
elif mutation == "public-http-mode-omitted":
changed = original.replace(
"Public HTTP (`authentication: none`) uses the declared query-free\nURIs directly and requires no Evidence credential file.",
"",
1,
)
elif mutation == "ambient-s3-mode-omitted":
changed = original.replace(
"Ambient S3\n(`credentials: ambient`) uses the runtime provider chain and requires no Evidence credential file.",
"",
1,
)
elif mutation == "numeric-domains-omitted":
changed = original.replace("positive safe integers", "positive integers", 1)
changed = changed.replace("nonnegative safe integer", "nonnegative integer", 1)
elif mutation == "endpoint-without-url-invariant-omitted":
changed = original.replace(
"Endpoint-policy flags cannot be enabled without `endpoint_url`.", "", 1
)
elif mutation == "http-file-boundary-omitted":
changed = original.replace(
"| Signed HTTP | `THT_WS_<NAMESPACE>_EVIDENCE_SIGNED_URLS_FILE` | Required for `signed_urls_file`; nonempty JSON string array in declared-URI order; query-stripped identities must match `uris`. |\n",
"| Signed HTTP | `THT_WS_<NAMESPACE>_EVIDENCE_SIGNED_URLS_FILE` | Required for `signed_urls_file`; at most 1048576 bytes; nonempty UTF-8 JSON string array in declared-URI order; query-stripped identities must match `uris` one-to-one. |\n",
"",
1,
)
elif mutation == "s3-pair-boundary-omitted":
changed = original.replace(
"| Static S3 pair | `THT_WS_<NAMESPACE>_EVIDENCE_ACCESS_KEY_FILE` and `THT_WS_<NAMESPACE>_EVIDENCE_SECRET_KEY_FILE` | Required together for `static_files`. |\n",
"| Static S3 pair | `THT_WS_<NAMESPACE>_EVIDENCE_ACCESS_KEY_FILE` and `THT_WS_<NAMESPACE>_EVIDENCE_SECRET_KEY_FILE` | Required together for `static_files`; each file is at most 65536 bytes. |\n",
"",
1,
)
elif mutation == "s3-token-boundary-omitted":
changed = original.replace(
"| Static S3 session | `THT_WS_<NAMESPACE>_EVIDENCE_SESSION_TOKEN_FILE` | Optional, and valid only with the required access/secret pair. |\n",
"| Static S3 session | `THT_WS_<NAMESPACE>_EVIDENCE_SESSION_TOKEN_FILE` | Optional, valid only with the required access/secret pair, and at most 65536 bytes. |\n",
"",
1,
)
@@ -920,6 +939,18 @@ expect_evidence_fixture_rejected \
expect_evidence_fixture_rejected \
"generated docs in wrong directory" docs/contracts/workspace-evidence-v3.md wrong-docs-directory \
"generated docs path invalid"
expect_evidence_fixture_rejected \
"public HTTP mode omitted" docs/contracts/workspace-evidence-v3.md public-http-mode-omitted \
"missing public HTTP mode"
expect_evidence_fixture_rejected \
"ambient S3 mode omitted" docs/contracts/workspace-evidence-v3.md ambient-s3-mode-omitted \
"missing ambient S3 mode"
expect_evidence_fixture_rejected \
"strict Evidence numeric domains omitted" docs/contracts/workspace-evidence-v3.md numeric-domains-omitted \
"missing strict Evidence numeric domains"
expect_evidence_fixture_rejected \
"S3 endpoint policy without endpoint invariant omitted" docs/contracts/workspace-evidence-v3.md endpoint-without-url-invariant-omitted \
"missing S3 endpoint policy without endpoint invariant"
expect_evidence_fixture_rejected \
"signed HTTP file boundary omitted" docs/contracts/workspace-evidence-v3.md http-file-boundary-omitted \
"missing signed HTTP file boundary"