The bodies of the audit laws, au2, au3, and au12. They assert what
a decision event, a change event, and an access event carry. They assert
what the seam records or refuses of a read and a write. Each is a
function of the test context, as Mediate.Conformance.AdapterCase.Laws
describes.
Summary
Functions
au3-03: a get of the granted object under its decision is one access
event. It carries the object type, the row's id, the decision's id, the
subject, the operation id, and the moment.
au12-03: a statement written by hand deletes the grant's row and publishes nothing.
au12-02: every bulk write to the grant's schema raises, publishes nothing, and leaves the count as it was.
au3-02: the event of a grant written carries every fact column from
nothing to its value. The event of the same grant revoked carries each
from that value to nothing. Both carry the stamps the law names.
au2-01: four calls are four decision events. They are an allowed
authorize and check for the user, and a denied check and authorize for
the privileged subject of the same account. Each event carries every
field the law names.
au2-02: the event of a denial carries the reason the error names.
au12-01: the seam publishes the change event of a grant written while the repo is in the write's transaction.
au12-06: get, all, exists?, aggregate, stream, and reload of
the granted object's schema under its decision each publish one access
event. The event has the activity and the ids the read answers with.
The same reads under the world's exemption publish none.
au3-01: no value the world's rule reads appears in the decision events
of an allowed authorize, a denied check, and a scope. The scope's event
carries the rule where the object goes. The rule is the policy's own
text and not a value read from a row, so the comparison leaves it out.
au3-04: a decision taken under a given operation id, a grant written
under that decision, and a read under it are three events. Each carries
the operation id and the decision's id.
au12-04: a second grant of the same pair is a write the database refuses, with no row and no event.
au2-03: a scope, and a review of one subject, are three decision events whose verdict is :scoped.
au12-05: a read and a write of each protected schema with no mediation raise :unmediated.
Functions
@spec access_event(Mediate.Conformance.AdapterCase.Laws.context()) :: true
au3-03: a get of the granted object under its decision is one access
event. It carries the object type, the row's id, the decision's id, the
subject, the operation id, and the moment.
@spec around_seam(Mediate.Conformance.AdapterCase.Laws.context()) :: true
au12-03: a statement written by hand deletes the grant's row and publishes nothing.
@spec bulk_refused(Mediate.Conformance.AdapterCase.Laws.context()) :: true
au12-02: every bulk write to the grant's schema raises, publishes nothing, and leaves the count as it was.
@spec change_event(Mediate.Conformance.AdapterCase.Laws.context()) :: true
au3-02: the event of a grant written carries every fact column from
nothing to its value. The event of the same grant revoked carries each
from that value to nothing. Both carry the stamps the law names.
@spec decision_events(Mediate.Conformance.AdapterCase.Laws.context()) :: true
au2-01: four calls are four decision events. They are an allowed
authorize and check for the user, and a denied check and authorize for
the privileged subject of the same account. Each event carries every
field the law names.
@spec denial_reason(Mediate.Conformance.AdapterCase.Laws.context()) :: true
au2-02: the event of a denial carries the reason the error names.
@spec inside_transaction(Mediate.Conformance.AdapterCase.Laws.context()) :: :ok
au12-01: the seam publishes the change event of a grant written while the repo is in the write's transaction.
@spec mediated_reads(Mediate.Conformance.AdapterCase.Laws.context()) :: true
au12-06: get, all, exists?, aggregate, stream, and reload of
the granted object's schema under its decision each publish one access
event. The event has the activity and the ids the read answers with.
The same reads under the world's exemption publish none.
@spec no_attribute_value(Mediate.Conformance.AdapterCase.Laws.context()) :: :ok
au3-01: no value the world's rule reads appears in the decision events
of an allowed authorize, a denied check, and a scope. The scope's event
carries the rule where the object goes. The rule is the policy's own
text and not a value read from a row, so the comparison leaves it out.
@spec one_operation(Mediate.Conformance.AdapterCase.Laws.context()) :: true
au3-04: a decision taken under a given operation id, a grant written
under that decision, and a read under it are three events. Each carries
the operation id and the decision's id.
@spec refused_write(Mediate.Conformance.AdapterCase.Laws.context()) :: true
au12-04: a second grant of the same pair is a write the database refuses, with no row and no event.
@spec scoped_verdicts(Mediate.Conformance.AdapterCase.Laws.context()) :: true
au2-03: a scope, and a review of one subject, are three decision events whose verdict is :scoped.
@spec unmediated_refused(Mediate.Conformance.AdapterCase.Laws.context()) :: :ok
au12-05: a read and a write of each protected schema with no mediation raise :unmediated.