docs: what a domain's tests owe - #244
Merged
Merged
Conversation
The corpus said where validation is declared and nothing about proving it runs. A tag can be dropped from the specification and the generator will quietly stop emitting it, validation.Struct will quietly stop checking it, and nothing fails until somebody sends bad input to production. States the four obligations: validation proved to fire rather than proved to exist, the RBAC trio per endpoint, a path through the tests for every status the specification declares, and the collection shape asserted for one host and for many. The part worth having written down is that a validation test asserts the body names the rule that rejected the request, not only the status code. A test checking for 400 alone passes when the handler rejects for an unrelated reason, which is the failure it exists to catch. Measured counts included so the next reading can tell drift from a figure somebody guessed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FuKUsHFG1EqZXamffh9M2c
|
Thank you for contributing to this project! 😊🕹️ |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
One section in
domains.md, one routing row in the skill.This is the piece of "go implement X and have it wired soup to nuts, fully tested" that was never written down.
The gap
The corpus said where validation is declared and nothing about proving it runs. A tag can be dropped from the specification, the generator quietly stops emitting it,
validation.Struct()quietly stops checking it, and nothing fails until somebody sends bad input to production.The four obligations
Validation is proved to fire, not proved to exist. The test asserts 400 and that the body names the rule that rejected it:
A test checking only the status code passes just as happily when the handler rejects for an unrelated reason. That is the failure it exists to catch.
The RBAC trio per endpoint. No token is 401, a token without the permission is 403, a token with it succeeds. The third case catches a permission spelled one way in the spec and another in the table.
Every declared status has a path. A documented 404 nobody produces is either undocumented behaviour or a lie in the specification.
Broadcast asserted both directions. One host and forty, because the single-host case is what gets special-cased.
What the audit found
75 validation suites and 80 RBAC suites across the domains, 21 of 22 with an integration test. The obligation was already being met almost everywhere, by habit rather than by rule, which is exactly how three domains drifted without anyone noticing.
Filing the specific gaps separately rather than widening this.
just testpasses. All skill links and anchors resolve.🤖 Generated with Claude Code
https://claude.ai/code/session_01FuKUsHFG1EqZXamffh9M2c