use super::*;
#[test]
fn seal_format_serde_round_trips() {
for fmt in [
SealFormat::Jades,
SealFormat::Pades,
SealFormat::Cades,
SealFormat::Xades,
] {
let json = serde_json::to_string(&fmt).unwrap();
let back: SealFormat = serde_json::from_str(&json).unwrap();
assert_eq!(fmt, back);
}
}
#[test]
fn a_signature_check_is_not_a_qualified_pass() {
let signature_only = SealVerification {
indication: SealIndication::TotalPassed,
checks: SealChecks::SignatureOnly,
placeholder: false,
};
assert!(
!signature_only.is_qualified_pass(),
"a signature check says nothing about the certificate behind it"
);
let qualified = SealVerification {
checks: SealChecks::QualifiedValidation,
..signature_only.clone()
};
assert!(qualified.is_qualified_pass());
let placeholder = SealVerification {
placeholder: true,
..qualified.clone()
};
assert!(!placeholder.is_qualified_pass());
}
#[test]
fn a_complete_ades_validation_is_not_yet_a_qualified_pass() {
let ades = SealVerification::passed(SealChecks::AdesValidation);
assert!(
ades.is_ades_pass(),
"path, revocation and timestamp did check out"
);
assert!(
!ades.is_qualified_pass(),
"but nothing here consulted a Trusted List or looked for the Annex III(j) \
creation-device indication"
);
let qualified = SealVerification::passed(SealChecks::QualifiedValidation);
assert!(qualified.is_qualified_pass());
assert!(
qualified.is_ades_pass(),
"the qualified check is strictly more than the AdES one, so it satisfies both"
);
}
#[test]
fn a_signature_check_is_not_an_ades_pass() {
assert!(!SealVerification::passed(SealChecks::SignatureOnly).is_ades_pass());
assert!(!SealVerification::placeholder("nothing to validate").is_ades_pass());
}
#[test]
fn indeterminate_is_not_a_pass() {
let unresolved = SealVerification {
indication: SealIndication::Indeterminate("revocation data unreachable".into()),
checks: SealChecks::QualifiedValidation,
placeholder: false,
};
assert!(!unresolved.is_qualified_pass());
assert_ne!(unresolved.indication, SealIndication::TotalPassed);
}
#[test]
fn seal_mode_serde_round_trips() {
for mode in [SealMode::ProviderSeal, SealMode::OperatorSeal] {
let json = serde_json::to_string(&mode).unwrap();
let back: SealMode = serde_json::from_str(&json).unwrap();
assert_eq!(mode, back);
}
}
#[test]
fn seal_envelope_serde_round_trips() {
for envelope in SealEnvelope::ALL {
let json = serde_json::to_string(envelope).unwrap();
let back: SealEnvelope = serde_json::from_str(&json).unwrap();
assert_eq!(*envelope, back);
}
}
#[test]
fn every_format_and_packaging_is_reachable() {
for format in SealFormat::ALL {
assert!(
!format.envelopes().is_empty(),
"{format:?} defines no packaging, so no request for it is well-formed"
);
}
for envelope in SealEnvelope::ALL {
assert!(
SealFormat::ALL.iter().any(|f| f.admits(*envelope)),
"{envelope:?} belongs to no format, so nothing can ask for it"
);
}
}
#[test]
fn packagings_are_scoped_to_the_formats_that_define_them() {
assert!(SealFormat::Xades.admits(SealEnvelope::Enveloping));
assert!(!SealFormat::Jades.admits(SealEnvelope::Enveloping));
assert!(!SealFormat::Cades.admits(SealEnvelope::Enveloping));
assert!(SealFormat::Pades.admits(SealEnvelope::Certification));
assert!(!SealFormat::Pades.admits(SealEnvelope::Detached));
assert!(!SealFormat::Jades.admits(SealEnvelope::Certification));
assert!(SealFormat::Jades.admits(SealEnvelope::Parallel));
assert!(SealFormat::Cades.admits(SealEnvelope::Parallel));
assert!(!SealFormat::Xades.admits(SealEnvelope::Parallel));
}
#[test]
fn a_defaulted_pades_request_cannot_be_satisfied() {
let everything = SealCapabilities {
supported_formats: SealFormat::ALL.to_vec(),
supported_modes: SealMode::ALL.to_vec(),
supported_levels: SealConformanceLevel::ALL.to_vec(),
supported_envelopes: SealEnvelope::ALL.to_vec(),
};
let wire = r#"{
"payloadHash": "abababababababababababababababababababababababababababababababab",
"mode": "provider_seal",
"keyRef": { "qtspId": "q", "credentialId": "c" },
"sigFormat": "PADES"
}"#;
let defaulted: SealRequest = serde_json::from_str(wire).expect("defaults fill the rest");
assert_eq!(
defaulted.envelope,
SealEnvelope::Detached,
"the default is format-blind, which is the premise of this test"
);
assert!(
!everything.can_produce(&defaulted),
"PAdES does not define Detached, so nothing can produce this request"
);
let named = SealRequest {
envelope: SealEnvelope::Certification,
..defaulted
};
assert!(everything.can_produce(&named));
}
#[test]
fn can_produce_refuses_a_pair_no_format_defines() {
let capabilities = SealCapabilities {
supported_formats: vec![SealFormat::Jades, SealFormat::Xades],
supported_modes: vec![SealMode::ProviderSeal],
supported_levels: vec![SealConformanceLevel::BaselineLt],
supported_envelopes: vec![SealEnvelope::Enveloping, SealEnvelope::Detached],
};
let request = |sig_format: SealFormat, envelope: SealEnvelope| SealRequest {
payload_hash: "ab".repeat(32),
mode: SealMode::ProviderSeal,
key_ref: SealCredentialRef {
qtsp_id: "q".into(),
credential_id: "c".into(),
},
sig_format,
conformance_level: SealConformanceLevel::BaselineLt,
envelope,
};
assert!(!capabilities.can_produce(&request(SealFormat::Jades, SealEnvelope::Enveloping)));
assert!(capabilities.can_produce(&request(SealFormat::Xades, SealEnvelope::Enveloping)));
assert!(capabilities.can_produce(&request(SealFormat::Jades, SealEnvelope::Detached)));
}
#[test]
fn an_envelope_without_a_level_still_deserialises() {
let legacy = serde_json::json!({
"format": "CADES",
"sealValue": "MIIB",
"sealedAt": "2026-08-14T00:00:00Z",
"placeholder": false,
});
let env: SealedEnvelope = serde_json::from_value(legacy).expect("legacy envelope reads");
assert_eq!(
env.conformance_level, None,
"an absent level must read as `not recorded`, never as a default"
);
}
#[test]
fn the_conformance_level_round_trips_including_absent() {
let envelope = |level| SealedEnvelope {
format: SealFormat::Cades,
seal_value: "MIIB".to_owned(),
signing_cert_ref: None,
conformance_level: level,
sealed_at: chrono::Utc::now(),
placeholder: false,
};
for level in SealConformanceLevel::ALL {
let json = serde_json::to_value(envelope(Some(*level))).unwrap();
assert_eq!(json["conformanceLevel"], serde_json::json!(level));
let back: SealedEnvelope = serde_json::from_value(json).unwrap();
assert_eq!(back.conformance_level, Some(*level));
}
let json = serde_json::to_value(envelope(None)).unwrap();
assert!(
json.get("conformanceLevel").is_none(),
"an unrecorded level must be absent from the JSON, not null: {json}"
);
}