polyc-query-credential 2026.10.2

Credential verification and query scope derivation, shared by the control plane's forensics authorization funnel and the standalone Query plane, with no DataFusion, Arrow, or engine dependency.
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
//! 10C-1's seal proof, the same [`trybuild`] pattern `polyc-query`'s own
//! QRY-6 fixture (`crates/query/tests/compile_fail.rs`) uses: compile
//! `tests/compile-fail/sealed_construction.rs` as a genuinely EXTERNAL crate
//! — the same vantage point `polyc-query` or `polyc-control-plane` has, with
//! no `test-util` feature enabled — and assert every direct-construction
//! attempt in it fails to compile. See that fixture's own doc comment for
//! which constructions it proves, and `principal`'s own module doc's
//! "Pinning the seal" section for the invariant this protects.
//!
//! Regenerate the pinned `.stderr` after a deliberate wording change with
//! `TRYBUILD=overwrite cargo test -p polyc-query-credential --test
//! compile_fail`, then review the diff.

#[test]
fn scoping_and_principal_cannot_be_constructed_outside_this_crate() {
    let t = trybuild::TestCases::new();
    t.compile_fail("tests/compile-fail/sealed_construction.rs");
}