Files

3.3 KiB

phase, slug, status, nyquist_compliant, wave_0_complete, created, audited
phase slug status nyquist_compliant wave_0_complete created audited
7.4 07.4-security-token-fingerprinting-token-binding-inserted complete true true 2026-06-06 2026-06-06

Phase 7.4 — Validation Strategy

Per-phase validation contract for feedback sampling during execution.


Test Infrastructure

Property Value
Framework pytest + pytest-asyncio
Config file backend/pytest.ini
Quick run command pytest tests/test_auth_fgp.py -v
Full suite command pytest -v
Estimated runtime ~30 seconds

Sampling Rate

  • After every task commit: Run pytest tests/test_auth_fgp.py tests/test_auth_deps.py -x
  • After every plan wave: Run pytest -v
  • Before /gsd:verify-work: Full suite must be green
  • Max feedback latency: 30 seconds

Per-Task Verification Map

Task ID Plan Wave Requirement Threat Ref Secure Behavior Test Type Automated Command File Exists Status
FGP-01 01 0 D-04/D-05 T-7.4-01 xfail stubs created for all 4 test cases unit pytest tests/test_auth_fgp.py -v green
FGP-02 01 1 D-04 T-7.4-01 _compute_fgp helper returns 16-char hex HMAC unit pytest tests/test_auth_fgp.py::test_fgp_match_returns_200 -x green
FGP-03 01 1 D-05 create_access_token embeds fgp claim unit pytest tests/test_auth_fgp.py::test_fgp_match_returns_200 -x green
FGP-04 01 1 D-06 T-7.4-01 Correct fgp → 200 integration pytest tests/test_auth_fgp.py::test_fgp_match_returns_200 -x green
FGP-05 01 1 D-03/D-06 T-7.4-01 Wrong fgp → 401 "Token fingerprint mismatch" integration pytest tests/test_auth_fgp.py::test_fgp_mismatch_returns_401 -x green
FGP-06 01 1 D-06 Token without fgp claim → 200 (migration grace) integration pytest tests/test_auth_fgp.py::test_no_fgp_claim_allowed -x green
FGP-07 01 1 D-02 Missing headers → empty-string binding works integration pytest tests/test_auth_fgp.py::test_missing_headers_empty_string_binding -x green

Status: pending · green · red · ⚠️ flaky


Wave 0 Requirements

  • tests/test_auth_fgp.py — created (Wave 0 stubs) then promoted to 4 real assertions (Wave 1)

Existing infrastructure covers all other requirements (conftest autouse fixtures, pytest-asyncio, FakeRedis).


Manual-Only Verifications

Behavior Requirement Why Manual Test Instructions
Full suite regression check All prior phases Confirm 0 regressions from signature changes Run pytest -v and verify count ≥ prior passing total

Validation Audit 2026-06-06

Metric Count
Gaps found 0
Resolved 7
Escalated 0

All 7 tasks confirmed COVERED. Ran pytest tests/test_auth_fgp.py tests/test_auth_deps.py -v — 14 passed, 0 failed. Full suite (404 passed, 4 skipped, 7 xfailed, 0 failed) confirmed in Plan 02 summary. No test generation needed — Wave 1 promoted all stubs to real assertions during execution.