Files
attesto-go/effective_assurance_test.go
CodexandClaude Opus 5 974095c5f9 feat(sdk): derive assurance in TypeScript and Go, not only Python
Python derived the assurance ladder and the other two clients did not, so a
TypeScript verifier -- which is what the product UI is -- had no way to
present it without inventing one. The rule that L3 is derived and never
signed only holds if every client applies it, so this is the property rather
than tidiness.

All three now report four facts kept apart: what the vault signed, whether a
quorum was met, whether an anchor confirmed, and what a verifier may
therefore report. A single badge would hide which of them was observed, and
that matters most exactly when one is missing.

Each carries the two asymmetries in its own tests. A witness outage withholds
L3 without reducing what the vault signed, because event-time assurance is a
fact about the past that no later outage changes. And an anchor never
promotes anything -- the report says so out loud, so a reader does not infer
it did.

The nine-case table is enumerated in each language, which is the only way two
implementations of a rule this narrow can be shown to agree. Python and
TypeScript were checked against each other directly.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-22 20:45:18 +02:00

91 lines
2.7 KiB
Go

package attesto
import "testing"
// Python derived assurance, TypeScript and Go did not. The rule that L3 is
// derived and never signed only holds if every client applies it, so parity
// here is the property rather than tidiness.
func boolPtr(value bool) *bool { return &value }
func TestL3IsDerivedAndNeverSigned(t *testing.T) {
report, err := EffectiveAssurance("L2", boolPtr(true), nil)
if err != nil {
t.Fatal(err)
}
if report.Effective != DerivedAssuranceLevel || !report.Derived {
t.Fatalf("expected derived L3, got %+v", report)
}
if report.VaultAssurance != "L2" {
t.Fatalf("the signed level must survive derivation, got %q", report.VaultAssurance)
}
if _, err := EffectiveAssurance("L3", nil, nil); err == nil {
t.Fatal("L3 was accepted as a signed vault assurance")
}
}
func TestAWithheldQuorumDoesNotReduceWhatTheVaultSigned(t *testing.T) {
for _, quorum := range []*bool{boolPtr(false), nil} {
report, err := EffectiveAssurance("L2", quorum, nil)
if err != nil {
t.Fatal(err)
}
if report.Effective != "L2" || report.Derived {
t.Fatalf("expected L2 withheld, got %+v", report)
}
}
}
func TestAnAnchorNeverPromotesAssurance(t *testing.T) {
report, err := EffectiveAssurance("L1", nil, boolPtr(true))
if err != nil {
t.Fatal(err)
}
if report.Effective != "L1" {
t.Fatalf("an anchor promoted the level to %q", report.Effective)
}
found := false
for _, reason := range report.Reasons {
if reason == "anchor confirmed; anchoring does not promote assurance" {
found = true
}
}
if !found {
t.Fatal("the report did not say that anchoring does not promote")
}
}
func TestTheTableAgreesWithTheOtherClients(t *testing.T) {
// Enumerated, because two implementations of a rule this narrow can only be
// shown to agree by listing every case.
cases := map[string]struct {
level string
quorum *bool
want string
}{
"L0/none": {"L0", nil, "L0"}, "L0/met": {"L0", boolPtr(true), "L0"},
"L0/unmet": {"L0", boolPtr(false), "L0"},
"L1/none": {"L1", nil, "L1"}, "L1/met": {"L1", boolPtr(true), "L1"},
"L1/unmet": {"L1", boolPtr(false), "L1"},
"L2/none": {"L2", nil, "L2"}, "L2/met": {"L2", boolPtr(true), "L3"},
"L2/unmet": {"L2", boolPtr(false), "L2"},
}
for name, item := range cases {
report, err := EffectiveAssurance(item.level, item.quorum, nil)
if err != nil {
t.Fatalf("%s: %v", name, err)
}
if report.Effective != item.want {
t.Fatalf("%s: got %q want %q", name, report.Effective, item.want)
}
}
}
func TestAnUnknownLevelIsRefused(t *testing.T) {
for _, level := range []string{"L9", "", "l2"} {
if _, err := EffectiveAssurance(level, nil, nil); err == nil {
t.Fatalf("%q was accepted as a vault assurance", level)
}
}
}