Mediate.Conformance.AdapterCase.Laws.Accounts (mediate_conformance v0.1.0)

Copy Markdown View Source

The bodies of the account laws, ac2-01 to ac2-04 and ac6-01. They assert:

  • what the seam records when a caller writes an account
  • how a grant's expiry and an account's fact reach the next decision
  • what a review answers
  • that a privileged subject holds nothing a user's grant gives

Each is a function of the test context, as Mediate.Conformance.AdapterCase.Laws describes.

Summary

Functions

ac2-01: the write of the granted world creates its account with one change event. The clear of the tables deletes it with one. The disqualification of the subject updates it with one. Each event names the actor the mediation gave, the account as its target, and the fact before and after.

ac2-03: the account fact changes with one change event, and the next check denies.

ac2-02: a grant that expires one second after the configured clock is in force. One that expired one second before is not. The stub holds the clock at a moment the database's own clock passed long ago. So an adapter that reads the database's clock denies both and fails the law.

ac6-01: the port allows the user the granted world grants to and denies the privileged subject of the account.

ac2-04: the last subject of the population reviews every subject it knows. The review answers each subject a rule that admits exactly the objects check allows that subject. It publishes one decision per subject and one for the reviewer, all under the operation id of the call.

Functions

account_changes(context)

@spec account_changes(Mediate.Conformance.AdapterCase.Laws.context()) :: true

ac2-01: the write of the granted world creates its account with one change event. The clear of the tables deletes it with one. The disqualification of the subject updates it with one. Each event names the actor the mediation gave, the account as its target, and the fact before and after.

disqualified(context)

@spec disqualified(Mediate.Conformance.AdapterCase.Laws.context()) :: false

ac2-03: the account fact changes with one change event, and the next check denies.

expiry(context)

ac2-02: a grant that expires one second after the configured clock is in force. One that expired one second before is not. The stub holds the clock at a moment the database's own clock passed long ago. So an adapter that reads the database's clock denies both and fails the law.

privileged_denied(context)

@spec privileged_denied(Mediate.Conformance.AdapterCase.Laws.context()) :: true

ac6-01: the port allows the user the granted world grants to and denies the privileged subject of the account.

review(context, world, operation)

ac2-04: the last subject of the population reviews every subject it knows. The review answers each subject a rule that admits exactly the objects check allows that subject. It publishes one decision per subject and one for the reviewer, all under the operation id of the call.