feat(okf): path/reserved-name validation gate — traversal + index.md/log.md shadow (T4, TDD, +10)
This commit is contained in:
parent
f8bc5db547
commit
ec121f3259
2 changed files with 104 additions and 0 deletions
|
|
@ -20,7 +20,9 @@ import pytest
|
|||
from llm_ingestion_guard.okf import (
|
||||
parse_frontmatter,
|
||||
scan_concept,
|
||||
validate_concept_path,
|
||||
OKFFrontmatterError,
|
||||
OKFPathError,
|
||||
)
|
||||
from llm_ingestion_guard.report import Report
|
||||
|
||||
|
|
@ -145,3 +147,56 @@ def test_scan_concept_clean_concept_is_clean():
|
|||
"tags:\n - pii\n---\nA clean paragraph describing the users table.\n"
|
||||
)
|
||||
assert scan_concept(doc).found is False
|
||||
|
||||
|
||||
# --- T4: path / reserved-name validation -------------------------------------
|
||||
# OKF spec (verified 2026-07-06): concept-ID = file path minus `.md`;
|
||||
# `index.md` and `log.md` are reserved and MUST NOT name concept documents.
|
||||
|
||||
def test_validate_concept_path_returns_concept_id():
|
||||
assert validate_concept_path("tables/users.md") == "tables/users"
|
||||
|
||||
|
||||
def test_validate_concept_path_accepts_deeply_nested():
|
||||
assert validate_concept_path("a/b/c/d.md") == "a/b/c/d"
|
||||
|
||||
|
||||
def test_validate_concept_path_rejects_leading_traversal():
|
||||
with pytest.raises(OKFPathError):
|
||||
validate_concept_path("../etc/passwd.md")
|
||||
|
||||
|
||||
def test_validate_concept_path_rejects_embedded_traversal():
|
||||
with pytest.raises(OKFPathError):
|
||||
validate_concept_path("tables/../../secret.md")
|
||||
|
||||
|
||||
def test_validate_concept_path_rejects_absolute():
|
||||
with pytest.raises(OKFPathError):
|
||||
validate_concept_path("/etc/passwd.md")
|
||||
|
||||
|
||||
def test_validate_concept_path_rejects_reserved_index():
|
||||
with pytest.raises(OKFPathError):
|
||||
validate_concept_path("index.md")
|
||||
|
||||
|
||||
def test_validate_concept_path_rejects_reserved_log_at_any_level():
|
||||
with pytest.raises(OKFPathError):
|
||||
validate_concept_path("tables/log.md")
|
||||
|
||||
|
||||
def test_validate_concept_path_rejects_reserved_case_insensitively():
|
||||
# a case-insensitive filesystem lets Index.md shadow index.md
|
||||
with pytest.raises(OKFPathError):
|
||||
validate_concept_path("Index.MD")
|
||||
|
||||
|
||||
def test_validate_concept_path_rejects_backslash():
|
||||
with pytest.raises(OKFPathError):
|
||||
validate_concept_path("tables\\users.md")
|
||||
|
||||
|
||||
def test_validate_concept_path_rejects_non_md():
|
||||
with pytest.raises(OKFPathError):
|
||||
validate_concept_path("tables/users.txt")
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue