fix: require signed evidence provenance

This commit is contained in:
2026-08-09 19:17:54 +02:00
parent df8dc1e219
commit e50aad7e41
2 changed files with 18 additions and 1 deletions
@@ -128,6 +128,18 @@ def test_signed_http_file_requires_explicit_provenance_urls(tmp_path):
assert_no_canaries(caught.value)
def test_signed_http_file_rejects_explicit_null_provenance(tmp_path):
secret_file = tmp_path / "signed-urls.json"
secret_file.write_text(json.dumps(["https://evidence.example.test/guide.md"]))
path = write_config(tmp_path, {
"type": "http", "provenance_urls": None, "signed_urls_file": str(secret_file),
})
with pytest.raises(ConfigError) as caught:
load_config(path)
assert "provenance" in str(caught.value).lower()
def test_public_http_rejects_inline_query_bearing_transport_urls(tmp_path):
path = write_config(tmp_path, {
"type": "http",