Skip to main content

Tests: internal/api

internal/api · 155 tests

Each test is named for the property it holds, and runs against a real deployment: there is no mock of the database and no arm that skips when it is absent. The sentence is the test's name read back; the name is what go test -run takes.

admission_internal_test.go

admission_test.go

api_test.go

  • The whole journey runs over HTTPTestTheWholeJourneyRunsOverHTTP. ── The claim ───────────────────────────────────────────────────────────────────────────────── Observe a turn, watch it form, recall a fact with the words behind it, erase the person, and read a residual of zero — all of it over HTTP.
  • Every operation refuses an unauthenticated callerTestEveryOperationRefusesAnUnauthenticatedCaller. Every operation is behind a credential.
  • Every refusal a client can provoke names a published codeTestEveryRefusalAClientCanProvokeNamesAPublishedCode. Every refusal a client can provoke names a code the contract publishes.
  • An unknown credential is refused the same way as noneTestAnUnknownCredentialIsRefusedTheSameWayAsNone. A token that is not ours, and one that is shaped like ours but unknown, are the same answer as no token at all.
  • A request cannot name a projectTestARequestCannotNameAProject. A caller cannot name a project at all, so a request that tries is refused as malformed.
  • Two credentials for two projects see different memoryTestTwoCredentialsForTwoProjectsSeeDifferentMemory. Two credentials for two projects see different memory, which is the boundary stated as a property rather than as a refusal.
  • An erasure without a subject is refused over the wireTestAnErasureWithoutASubjectIsRefusedOverTheWire. An erasure without a subject would be a scope-wide delete wearing a governance label.
  • A document is erased by its source observations over the wireTestADocumentIsErasedByItsSourceObservationsOverTheWire. ── Erasing a document by its own sources, over the wire ────────────────────────────────────── A document observed project-wide is erased by the observation ids its manifest holds, with the same receipt as a subject erasure; naming both a person and sources, or something that is not an id, is refused before anything is read.
  • Health is open and says nothingTestHealthIsOpenAndSaysNothing. Health is the one unauthenticated route, and it says nothing.
  • A malformed request is refused without touching the databaseTestAMalformedRequestIsRefusedWithoutTouchingTheDatabase. ── What the surface refuses to parse ───────────────────────────────────────────────────────── Every one of these is a way a client can be wrong, and each must produce an answer the client can act on rather than a five hundred or a partial write.
  • A turn the domain refuses is refused with its reasonTestATurnTheDomainRefusesIsRefusedWithItsReason. A turn the domain will not accept is refused with the domain's own reason, not a generic error.
  • A recall without a question is refusedTestARecallWithoutAQuestionIsRefused. A question is required, because a recall with none would anchor on nothing and return an empty bundle that looks like an answer.
  • A recall with no scopes uses the credentials ownTestARecallWithNoScopesUsesTheCredentialsOwn. An omitted scope list means everything the credential holds, which is the useful default and the one that cannot leak: the set it falls back to is the credential's own.
  • An oversized body is refusedTestAnOversizedBodyIsRefused. A body larger than the cap is refused rather than read.
  • Freshness for a scope with no turns says soTestFreshnessForAScopeWithNoTurnsSaysSo. Freshness for a scope that exists in the grant but has never been written to is an error the caller can act on rather than a zero that looks like an empty memory.
  • A revoked credential stops working at onceTestARevokedCredentialStopsWorkingAtOnce. A revoked credential stops working immediately, which is what makes revocation an answer to a leak rather than a note in a ticket.
  • A credential for a suspended project is refusedTestACredentialForASuspendedProjectIsRefused. A credential for a suspended project stops working, and says only that it does not work.
  • A credential naming a project that is gone is refusedTestACredentialNamingAProjectThatIsGoneIsRefused. A credential naming a project that does not exist at all is refused the same way.
  • Every operation leaves an attributed ledger rowTestEveryOperationLeavesAnAttributedLedgerRow. Every operation leaves a row naming the principal that performed it.
  • The ledger holds nothing a person could ask to have removedTestTheLedgerHoldsNothingAPersonCouldAskToHaveRemoved. The ledger holds nothing that could ever be the subject of an erasure request.
  • A refused credential is recordedTestARefusedCredentialIsRecorded. A refused credential is recorded, because a repeated refusal is what an attack looks like from inside the ledger.
  • An export names a person or its turns and refuses anything elseTestAnExportNamesAPersonOrItsTurnsAndRefusesAnythingElse. An export produces what an erasure would delete, and the two walks agree.
  • An export produces what an erasure would deleteTestAnExportProducesWhatAnErasureWouldDelete
  • An export without a subject is refusedTestAnExportWithoutASubjectIsRefused. An export names the person it is for, or it is a copy of the project wearing a governance label.
  • An export for somebody with nothing held is empty rather than absentTestAnExportForSomebodyWithNothingHeldIsEmptyRatherThanAbsent. An export for somebody with nothing held is empty sections rather than absent ones.
  • An export is recorded in the ledgerTestAnExportIsRecordedInTheLedger. An export is recorded in the ledger like every other operation.
  • A request succeeds even if the ledger cannotTestARequestSucceedsEvenIfTheLedgerCannot. A ledger failure does not fail the request that produced it.
  • A refused authentication records no secretTestARefusedAuthenticationRecordsNoSecret. A refused authentication with a short or absent token is still recorded, and records nothing that could be a secret.
  • A question can be asked of a moment in the pastTestAQuestionCanBeAskedOfAMomentInThePast. ── A question can be asked of a moment ─────────────────────────────────────────────────────── The wire carries both instants and the interval each fact held, because a fact returned by a read of last March that does not say it stopped holding is indistinguishable from one that holds now.
  • A question can reach one relation further and says how it got thereTestAQuestionCanReachOneRelationFurtherAndSaysHowItGotThere. ── A chain over the wire ───────────────────────────────────────────────────────────────────── A fact about something the question never named is only worth returning if the route to it can be read, so the chain is on the wire beside the fact rather than implied by a score.

artifacts_internal_test.go

artifacts_test.go

artifactsearch_test.go

assertions_test.go

auth_audit_internal_test.go

auth_audit_test.go

authorization_internal_test.go

authorization_test.go

citation_test.go

composedrecall_test.go

  • Composed recall answers from themes and passages and never invents factsTestComposedRecallAnswersFromThemesAndPassagesAndNeverInventsFacts. A question that anchors nothing is answered from the report hierarchy and from passages, over the same authenticated route, with every surface labelled for what it is: a report carries its sources, a passage carries its role, and neither is ever presented as a fact.
  • Semantic surfaces refuse what is not configured and filter roles in memoryTestSemanticSurfacesRefuseWhatIsNotConfiguredAndFilterRolesInMemory. The adapter composes what is configured and refuses, by name, what is not; a passage query over several roles filters in memory because the retriever takes one role.

connectionslots_test.go

  • A write that cannot get a connection is answered retryably rather than as an internal errorTestAWriteThatCannotGetAConnectionIsAnsweredRetryablyRatherThanAsAnInternalError. ── A write that cannot get a connection ────────────────────────────────────────────────────── A write that cannot get a connection used to be an internal error, which tells a caller nothing they can act on.

contexts_test.go

contract_test.go

contractdoc_test.go

contractfreeze_test.go

  • The frozen v 1 contract is still servedTestTheFrozenV1ContractIsStillServed. Every operation, field and refusal code in the frozen snapshot is still served, with the same method, path, status and type.
  • The freeze refuses removals renames and retypingsTestTheFreezeRefusesRemovalsRenamesAndRetypings. The freeze refuses what it must: a doctored snapshot with an operation this surface does not serve, a moved route, a retyped and a missing field, and a code nobody declares, is named violation by violation, while an addition on the served side is not one.
  • The freeze reads inside an object rather than comparing its renderingTestTheFreezeReadsInsideAnObjectRatherThanComparingItsRendering. ── The freeze descends into an object instead of comparing its rendering ───────────────────── wireType expands a nested object inline, so every change inside one shows up as a change to the enclosing field's rendered kind.
  • A freeze written today is one the current surface keepsTestAFreezeWrittenTodayIsOneTheCurrentSurfaceKeeps. FreezeJSON is what make freeze-contract commits, and its only caller is a script the build excludes (//go:build ignore), which is why nothing reached it.

correctioncapacity_test.go

corrections_test.go

entities_test.go

entitycandidates_test.go

entitynames_test.go

feedback_test.go

freshness_test.go

groups_test.go

health_test.go

history_test.go

idempotency_test.go

ingestionbudget_test.go

manage_test.go

  • The management door opens for an operator credential and nothing elseTestTheManagementDoorOpensForAnOperatorCredentialAndNothingElse. The management door opens for an operator credential and nothing else, and the memory door does not open for an operator credential: two kinds, each refused at the other's door with the answer a stranger gets, and a revoked operator is a stranger.
  • An operator runs the project and credential lifecycle over the APITestAnOperatorRunsTheProjectAndCredentialLifecycleOverTheAPI. An operator creates a project, mints a credential for it that works on the memory routes, suspends the project so the credential stops working, resumes it, lists and revokes the credential; a project that does not exist mints nothing and a name that is not an identifier is refused before anything is touched.
  • An operator reads what the instance refused erased and formed and every read is on the ledgerTestAnOperatorReadsWhatTheInstanceRefusedErasedAndFormedAndEveryReadIsOnTheLedger. An operator reads what the instance refused, erased and formed without a database connection and without reading a word of anybody's: counts, receipts, watermarks and parked turns; unparks one; seals and verifies the ledger.
  • The management surface answers internal when the database cannotTestTheManagementSurfaceAnswersInternalWhenTheDatabaseCannot. A database that cannot answer is an internal error from every management operation, never an empty answer that reads as "nothing to report": the tables are moved away one at a time under the running server, and each operation that reads them says so.

mcp_test.go

  • MCP lists exactly the six tools and none deletesTestMCPListsExactlyTheSixToolsAndNoneDeletes. The tool list is exactly the six, in the order declared, and none of them deletes: a host reads the list as a menu, and erasure, export and feedback promotion are deliberately absent from it.
  • MCP observe freshness recall and citation are the same operationsTestMCPObserveFreshnessRecallAndCitationAreTheSameOperations. A turn observed through a tool is the same observation a REST caller makes: freshness sees it, recall answers from it, and a citation resolves to it, each through the same credential and the same ledger.
  • MCP refuses without a credential before any tool runsTestMCPRefusesWithoutACredentialBeforeAnyToolRuns. Without a credential the door is closed before the protocol is spoken, and a credential the deployment does not know is refused the same way: one answer, no distinction for a stranger.

messages_test.go

notifications_test.go

operations_test.go

passages_live_test.go

passages_test.go

plugin_test.go

  • The plugin names this route and only tools that existTestThePluginNamesThisRouteAndOnlyToolsThatExist. The plugin's declarations agree with the server: the MCP server it configures is this route, with the credential as a bearer, and every command names only tools that exist.
  • The plugin hooks run against a live deploymentTestThePluginHooksRunAgainstALiveDeployment. The hooks run against a live deployment with the plugin's settings in the environment: the session-start hook says how far behind memory is and never blocks; the capture hook records the user's message only when capture is on, under a key that makes a second firing a replay.

portal_test.go

  • The portal shows nothing before an operator signs in and every panel is a table on the ledgerTestThePortalShowsNothingBeforeAnOperatorSignsInAndEveryPanelIsATableOnTheLedger. The portal serves nothing to a browser that has not signed in, opens for an operator credential and no other, shows every panel from the tables that exist with the numbers those tables hold, leaves every panel on the ledger, and signs a revoked operator out at the registry.
  • The portal says when a table cannot answer and refuses what it cannot readTestThePortalSaysWhenATableCannotAnswerAndRefusesWhatItCannotRead. A page whose table cannot answer is an error page, never an empty panel that reads as "nothing to report"; a sign-in whose form cannot be read is refused; a session the process no longer holds is sent to sign in.
  • The portal loads nothing from outside its own originTestThePortalLoadsNothingFromOutsideItsOwnOrigin. ── The console loads nothing it does not carry ─────────────────────────────────────────────── Every page the portal renders references nothing outside its own origin: no script, no remote stylesheet or font, no image.
  • The overview counts the ledger for the window and project askedTestTheOverviewCountsTheLedgerForTheWindowAndProjectAsked. ── What the instance has been doing ────────────────────────────────────────────────────────── The overview counts the ledger for the window and the project the operator asks for, and only those: a window is one the page offers and a project is one the instance holds, anything else is the default.

portalactions_test.go

portalactivity_internal_test.go

  • A trend says how a number moved and colours only refusalsTestATrendSaysHowANumberMovedAndColoursOnlyRefusals. A trend is a percentage against the window before, "new" when there was nothing before, and is coloured good or bad only where the direction means something: refusals.
  • A window is one the page offersTestAWindowIsOneThePageOffers. A window is one the page offers or the default; a query cannot name one of its own.
  • The activity is shaped for the page from the ledgers countsTestTheActivityIsShapedForThePageFromTheLedgersCounts. The chart draws in the window's own scale and names a bucket at the precision its width needs; the ranking within one project is its busiest operations, at most six, scaled to the busiest.
  • The switcher marks the project shownTestTheSwitcherMarksTheProjectShown. The switcher lists every project and all of them, marks the one shown, and says which it is.

portalshare_internal_test.go

  • A meter is clamped and never divides by nothingTestAMeterIsClampedAndNeverDividesByNothing. A meter never leaves its box and never divides by nothing: an empty ceiling is an empty bar, a count past its ceiling is a full one, and between them the share is truncated rather than rounded, so a bar never reads full before it is.

rebuildvisibility_test.go

recall_controls_test.go

recalllimits_test.go

records_internal_test.go

records_test.go

reportcandidates_test.go

request_test.go

retractionlimits_test.go

retractions_test.go

sensitivity_test.go

speaker_test.go

subjects_internal_test.go

subjects_test.go