Skip to content

test(role-matrix-lab): cover x-masking, x-encryption and task credential - #27

Merged
yilmaztayfun merged 2 commits into
masterfrom
feature/field-masking-lab
Oct 1, 2026
Merged

yilmaztayfun merged 2 commits into
masterfrom
feature/field-masking-lab

Conversation

@yilmaztayfun

Copy link
Copy Markdown
Contributor

Summary

  • role-matrix-lab master schema 1.0.3 adds x-masking (mask/replace, auditor exemption), x-encryption hash (top-level and nested) and encrypt (vault.email with an auditor exemption, vault.pin without one), plus nested, array and numeric x-roles fixtures.
  • New test classes: SchemaFieldMaskingTests, SchemaFieldExposureNestedTests, SchemaFieldEncryptionTests, covering every guarded read surface.
  • mirror-self reads with the transition caller's credential. The new mirror-self-auditor reads with an auditor credential set in its own mapping headers. The script sees the encrypt token and opens its own field with DecryptAsync (workflow 1.0.8).

Changes

  • core/Schemas/role-matrix-lab/role-matrix-master.json, core/Workflows/role-matrix-lab/*, core/Tasks/role-matrix-lab/role-matrix-self-read-task.json
  • tests/Core.IntegrationTests/Tests/RoleMatrixLab/* and its README
  • TEST-SCENARIOS.md row

Test Plan

Integration test evidence

  • Scenario: Tests/RoleMatrixLab (--filter FullyQualifiedName~RoleMatrixLab)
  • Runtime: vnext c4cf7c32 at http://localhost:4201
  • Result: 92/115. The 23 reds are the known set (queryRoles at the gateway 16, CS8197 5, $InstanceStarter 2); every field-protection test is green.
  • TEST-SCENARIOS.md row updated: yes

Notes

🤖 Generated with Claude Code

yilmaztayfun and others added 2 commits October 1, 2026 15:24
Master schema and workflow 1.0.3. New RoleMatrixLab classes:
SchemaFieldMaskingTests, SchemaFieldExposureNestedTests and
SchemaFieldEncryptionTests, plus a self-read trigger task (mirror-self)
proving system reads see stored values.

- roles on x-masking / x-encryption are allow-only.
- hash is stored as HASHED:SHA256:<hex>, differs across instances.
- encrypt is stored as an ENCRYPTED:AES256:i1: token; the allow-listed
  role reads plaintext on the data function and sync responses.
- instance GET and list serve data as stored.

Scenario README and TEST-SCENARIOS row updated (2026-09-30 run: field
tests 55/55 against the locally built runtime).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ncrypt tokens

- mirror-self reads with the transition caller's credential; a new
  mirror-self-auditor reads with an auditor credential in its own
  mapping headers (workflow 1.0.8).
- The script view shows encrypt fields as tokens; DecryptAsync opens
  the instance's own field and returns null for a token passed as a
  path.
- README and TEST-SCENARIOS record the runs against the raw instance
  data model.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@yilmaztayfun
yilmaztayfun requested review from a team October 1, 2026 12:33
@coldtea-pr-lens

Copy link
Copy Markdown

◈ PR Lens

Note

The title starts with test(role-matrix-lab):, so PR Lens left this pull request undrawn. Comment @pr-lens draw to draw it

github.comment.notice: false in .github/pr-lens.yml turns this note off

@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: b0c495a4-0589-459b-a229-faa77a9e9357

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@yilmaztayfun yilmaztayfun self-assigned this Oct 1, 2026
@yilmaztayfun
yilmaztayfun merged commit 4e6eca0 into master Oct 1, 2026
2 of 3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant