Repository navigation
test: cover implicitTransforms and idAttribute - #635
Conversation
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThis change adds tests for the ChangesConstructor option verification
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Other Merge Risk: ⚪ Minimal · up to This change adds regression coverage for custom ID lookup and implicit canonicalization. No merge-blocking risk is evident; it is ready for normal checks. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #635 +/- ##
==========================================
+ Coverage 83.89% 84.22% +0.32%
==========================================
Files 9 9
Lines 1217 1217
Branches 308 308
==========================================
+ Hits 1021 1025 +4
+ Misses 118 115 -3
+ Partials 78 77 -1 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
The implicitTransforms test counted calls to an identity transform and pinned the Id name signing adds, which node-saml#508 changes in 7.0. It now shows that an implicit transform decides whether a document verifies. Both tests find the signature with findSignatures(). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Replace the test-only transform that stripped an added attribute with the case the README documents: a signer applied exclusive c14n without declaring it, and the signed element was then placed in a parent that declares an unused namespace. Verification fails by default and passes with implicitTransforms set to exclusive c14n. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The helper defaulted to exclusive c14n, so the idAttribute test's transform was visible only in the helper. Both tests now name their transforms. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Fixes #573.
Tests the documented
idAttributeandimplicitTransformsconstructor options through the public signing and verification APIs. This is item 1 of #573, which #599 left open. Tests only; no runtime change. The existing 6.xidAttributebehavior is kept.idAttribute: withidAttribute: "AssertionID", signing references the element's existingAssertionIDand adds no ID of its own. A verifier given the same option resolves it and returns the element as signed.implicitTransforms: the case from the README's Caring for Implicit transform section. A reference declares only enveloped-signature, and the signed element is then placed in a parent that declares an unused namespace. Verification fails withoutimplicitTransformsand passes withimplicitTransforms: ["http://www.w3.org/2001/10/xml-exc-c14n#"], returning the element as signed.Neither test asserts the name of the ID attribute signing adds to an element without one, which #508 changes in 7.0. Disabling either option in
src/fails its test.🤖 Generated with Claude Code
Summary by CodeRabbit