use serde_json::json;
use crate::Disclosure;
use super::policy::{DocumentScope, ProductGroupAccessPolicy};
#[test]
fn a_cyclic_ref_terminates() {
let policy = policy_from(&json!({
"properties": {
"component": { "$ref": "#/definitions/component" }
},
"definitions": {
"component": {
"properties": {
"partNumber": { "x-disclosure": "restricted" },
"subComponents": {
"items": { "$ref": "#/definitions/component" }
}
}
}
}
}));
assert_eq!(
policy.disclosure_for_path(
&["component", "partNumber"],
DocumentScope::ProductGroupData
),
Disclosure::Restricted,
"the cycle is cut, and the class before the cycle is still recorded"
);
}
#[test]
fn a_two_step_ref_cycle_terminates() {
let policy = policy_from(&json!({
"properties": { "a": { "$ref": "#/definitions/a" } },
"definitions": {
"a": {
"properties": {
"aField": { "x-disclosure": "restricted" },
"toB": { "$ref": "#/definitions/b" }
}
},
"b": {
"properties": {
"bField": { "x-disclosure": "individual" },
"toA": { "$ref": "#/definitions/a" }
}
}
}
}));
assert_eq!(
policy.disclosure_for_path(&["a", "aField"], DocumentScope::ProductGroupData),
Disclosure::Restricted
);
assert_eq!(
policy.disclosure_for_path(&["a", "toB", "bField"], DocumentScope::ProductGroupData),
Disclosure::Individual
);
}
#[test]
fn an_unresolvable_ref_is_not_fatal() {
let policy = policy_from(&json!({
"properties": {
"external": { "$ref": "https://example.invalid/other.json#/definitions/thing" },
"dangling": { "$ref": "#/definitions/absent" }
},
"definitions": {
"present": { "properties": { "known": { "x-disclosure": "restricted" } } }
}
}));
assert_eq!(
policy.disclosure_for_path(&["known"], DocumentScope::ProductGroupData),
Disclosure::Restricted,
"the resolvable part of the schema is unaffected"
);
assert_eq!(
policy.disclosure_for_path(&["external", "anything"], DocumentScope::ProductGroupData),
Disclosure::Public,
"an unreadable shape declares nothing"
);
}
#[test]
fn additional_properties_values_keep_matchable_keys() {
let policy = policy_from(&json!({
"properties": {
"measurements": {
"additionalProperties": {
"properties": { "rawReading": { "x-disclosure": "individual" } }
}
}
}
}));
assert_eq!(
policy.disclosure_for_path(
&["measurements", "sensorA", "rawReading"],
DocumentScope::ProductGroupData
),
Disclosure::Individual,
"the dynamic key is not knowable from the schema, so the leaf must match \
at any depth or it matches nothing at all"
);
}
fn policy_from(schema: &serde_json::Value) -> ProductGroupAccessPolicy {
ProductGroupAccessPolicy::from_schema("test", "1.0.0", &schema.to_string())
.expect("schema has a root properties map")
}