test(role-matrix-lab): cover x-masking, x-encryption and task credential - #27
Merged
Merged
Conversation
Master schema and workflow 1.0.3. New RoleMatrixLab classes: SchemaFieldMaskingTests, SchemaFieldExposureNestedTests and SchemaFieldEncryptionTests, plus a self-read trigger task (mirror-self) proving system reads see stored values. - roles on x-masking / x-encryption are allow-only. - hash is stored as HASHED:SHA256:<hex>, differs across instances. - encrypt is stored as an ENCRYPTED:AES256:i1: token; the allow-listed role reads plaintext on the data function and sync responses. - instance GET and list serve data as stored. Scenario README and TEST-SCENARIOS row updated (2026-09-30 run: field tests 55/55 against the locally built runtime). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ncrypt tokens - mirror-self reads with the transition caller's credential; a new mirror-self-auditor reads with an auditor credential in its own mapping headers (workflow 1.0.8). - The script view shows encrypt fields as tokens; DecryptAsync opens the instance's own field and returns null for a token passed as a path. - README and TEST-SCENARIOS record the runs against the raw instance data model. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
◈ PR LensNote The title starts with
|
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
1.0.3adds x-masking (mask/replace, auditor exemption), x-encryptionhash(top-level and nested) andencrypt(vault.emailwith an auditor exemption,vault.pinwithout one), plus nested, array and numeric x-roles fixtures.mirror-selfreads with the transition caller's credential. The newmirror-self-auditorreads with an auditor credential set in its own mapping headers. The script sees the encrypt token and opens its own field withDecryptAsync(workflow1.0.8).Changes
core/Schemas/role-matrix-lab/role-matrix-master.json,core/Workflows/role-matrix-lab/*,core/Tasks/role-matrix-lab/role-matrix-self-read-task.jsontests/Core.IntegrationTests/Tests/RoleMatrixLab/*and its READMETEST-SCENARIOS.mdrowTest Plan
Integration test evidence
Tests/RoleMatrixLab(--filter FullyQualifiedName~RoleMatrixLab)c4cf7c32athttp://localhost:4201$InstanceStarter2); every field-protection test is green.TEST-SCENARIOS.mdrow updated: yesNotes
🤖 Generated with Claude Code