diff --git a/harness/tests/test_registry_evidence_config.py b/harness/tests/test_registry_evidence_config.py index 89019985..3f7db24a 100644 --- a/harness/tests/test_registry_evidence_config.py +++ b/harness/tests/test_registry_evidence_config.py @@ -128,6 +128,18 @@ def test_signed_http_file_requires_explicit_provenance_urls(tmp_path): assert_no_canaries(caught.value) +def test_signed_http_file_rejects_explicit_null_provenance(tmp_path): + secret_file = tmp_path / "signed-urls.json" + secret_file.write_text(json.dumps(["https://evidence.example.test/guide.md"])) + path = write_config(tmp_path, { + "type": "http", "provenance_urls": None, "signed_urls_file": str(secret_file), + }) + + with pytest.raises(ConfigError) as caught: + load_config(path) + assert "provenance" in str(caught.value).lower() + + def test_public_http_rejects_inline_query_bearing_transport_urls(tmp_path): path = write_config(tmp_path, { "type": "http", diff --git a/harness/tht/config.py b/harness/tht/config.py index 102e6b99..040bdf1f 100644 --- a/harness/tht/config.py +++ b/harness/tht/config.py @@ -60,7 +60,12 @@ def _resolve_http_signed_url_files(value: Any) -> Any: return resolved if "urls" in resolved: raise ConfigError("HTTP signed URL file cannot be combined with urls") - if "provenance_urls" not in resolved: + provenance_urls = resolved.get("provenance_urls") + if ( + not isinstance(provenance_urls, list) + or not provenance_urls + or any(not isinstance(item, str) or not item for item in provenance_urls) + ): raise ConfigError("HTTP signed URL file requires provenance_urls") path_value = resolved.pop("signed_urls_file") if not isinstance(path_value, str):