Mediate.Conformance.AdapterCase.Laws.Audit (mediate_conformance v0.1.0)

Copy Markdown View Source

The bodies of the audit laws, au2, au3, and au12. They assert what a decision event, a change event, and an access event carry. They assert what the seam records or refuses of a read and a write. Each is a function of the test context, as Mediate.Conformance.AdapterCase.Laws describes.

Summary

Functions

au3-03: a get of the granted object under its decision is one access event. It carries the object type, the row's id, the decision's id, the subject, the operation id, and the moment.

au12-03: a statement written by hand deletes the grant's row and publishes nothing.

au12-02: every bulk write to the grant's schema raises, publishes nothing, and leaves the count as it was.

au3-02: the event of a grant written carries every fact column from nothing to its value. The event of the same grant revoked carries each from that value to nothing. Both carry the stamps the law names.

au2-01: four calls are four decision events. They are an allowed authorize and check for the user, and a denied check and authorize for the privileged subject of the same account. Each event carries every field the law names.

au2-02: the event of a denial carries the reason the error names.

au12-01: the seam publishes the change event of a grant written while the repo is in the write's transaction.

au12-06: get, all, exists?, aggregate, stream, and reload of the granted object's schema under its decision each publish one access event. The event has the activity and the ids the read answers with. The same reads under the world's exemption publish none.

au3-01: no value the world's rule reads appears in the decision events of an allowed authorize, a denied check, and a scope. The scope's event carries the rule where the object goes. The rule is the policy's own text and not a value read from a row, so the comparison leaves it out.

au3-04: a decision taken under a given operation id, a grant written under that decision, and a read under it are three events. Each carries the operation id and the decision's id.

au12-04: a second grant of the same pair is a write the database refuses, with no row and no event.

au2-03: a scope, and a review of one subject, are three decision events whose verdict is :scoped.

au12-05: a read and a write of each protected schema with no mediation raise :unmediated.

Functions

access_event(context)

@spec access_event(Mediate.Conformance.AdapterCase.Laws.context()) :: true

au3-03: a get of the granted object under its decision is one access event. It carries the object type, the row's id, the decision's id, the subject, the operation id, and the moment.

around_seam(context)

@spec around_seam(Mediate.Conformance.AdapterCase.Laws.context()) :: true

au12-03: a statement written by hand deletes the grant's row and publishes nothing.

bulk_refused(context)

@spec bulk_refused(Mediate.Conformance.AdapterCase.Laws.context()) :: true

au12-02: every bulk write to the grant's schema raises, publishes nothing, and leaves the count as it was.

change_event(context)

@spec change_event(Mediate.Conformance.AdapterCase.Laws.context()) :: true

au3-02: the event of a grant written carries every fact column from nothing to its value. The event of the same grant revoked carries each from that value to nothing. Both carry the stamps the law names.

decision_events(context)

@spec decision_events(Mediate.Conformance.AdapterCase.Laws.context()) :: true

au2-01: four calls are four decision events. They are an allowed authorize and check for the user, and a denied check and authorize for the privileged subject of the same account. Each event carries every field the law names.

denial_reason(context)

@spec denial_reason(Mediate.Conformance.AdapterCase.Laws.context()) :: true

au2-02: the event of a denial carries the reason the error names.

inside_transaction(context)

@spec inside_transaction(Mediate.Conformance.AdapterCase.Laws.context()) :: :ok

au12-01: the seam publishes the change event of a grant written while the repo is in the write's transaction.

mediated_reads(context)

@spec mediated_reads(Mediate.Conformance.AdapterCase.Laws.context()) :: true

au12-06: get, all, exists?, aggregate, stream, and reload of the granted object's schema under its decision each publish one access event. The event has the activity and the ids the read answers with. The same reads under the world's exemption publish none.

no_attribute_value(context)

@spec no_attribute_value(Mediate.Conformance.AdapterCase.Laws.context()) :: :ok

au3-01: no value the world's rule reads appears in the decision events of an allowed authorize, a denied check, and a scope. The scope's event carries the rule where the object goes. The rule is the policy's own text and not a value read from a row, so the comparison leaves it out.

one_operation(context)

@spec one_operation(Mediate.Conformance.AdapterCase.Laws.context()) :: true

au3-04: a decision taken under a given operation id, a grant written under that decision, and a read under it are three events. Each carries the operation id and the decision's id.

refused_write(context)

@spec refused_write(Mediate.Conformance.AdapterCase.Laws.context()) :: true

au12-04: a second grant of the same pair is a write the database refuses, with no row and no event.

scoped_verdicts(context)

@spec scoped_verdicts(Mediate.Conformance.AdapterCase.Laws.context()) :: true

au2-03: a scope, and a review of one subject, are three decision events whose verdict is :scoped.

unmediated_refused(map)

@spec unmediated_refused(Mediate.Conformance.AdapterCase.Laws.context()) :: :ok

au12-05: a read and a write of each protected schema with no mediation raise :unmediated.