commit 17fe887d4406f9a5bdf6da047f7790f9e74ec62c
parent 141843ff80d9d8ebab547b32ee795ef491744c1c
Author: triesap <tyson@radroots.org>
Date: Mon, 21 Sep 2026 13:52:24 +0000
core: validate typed matching input and scope
Diffstat:
2 files changed, 51 insertions(+), 0 deletions(-)
diff --git a/src/hyf_application/match_input.mojo b/src/hyf_application/match_input.mojo
@@ -0,0 +1,26 @@
+from std.collections import List
+
+
+def validate_match_scope(trusted_tenant: String, snapshot_tenant: String) raises:
+ if String(trusted_tenant).strip().byte_length() == 0:
+ raise Error("match requires a trusted tenant")
+ if snapshot_tenant != trusted_tenant:
+ raise Error("snapshot is outside the authorized tenant scope")
+
+
+def validate_supplied_lots(lot_keys: List[String]) raises -> List[String]:
+ var unique = List[String]()
+ for key in lot_keys:
+ if String(key).strip().byte_length() == 0:
+ raise Error("supplied lot key must not be empty")
+ for existing in unique:
+ if existing == key:
+ raise Error("duplicate supplied lot revision: " + key)
+ unique.append(String(key))
+ if len(unique) == 0:
+ raise Error("matching requires at least one supplied lot")
+ return unique^
+
+
+def caller_name_is_authentication() -> Bool:
+ return False
diff --git a/tests/test_application.mojo b/tests/test_application.mojo
@@ -329,3 +329,28 @@ def test_buyer_inference_failure_is_not_market_absence() raises:
var degraded = buyer_inference_degraded("provider_degraded")
assert_equal(degraded.status, "degraded")
assert_true(not buyer_failure_means_unavailable_supply())
+
+
+from hyf_application.match_input import (
+ caller_name_is_authentication,
+ validate_match_scope,
+ validate_supplied_lots,
+)
+
+
+def test_match_input_scope_and_lot_validation() raises:
+ validate_match_scope("tenant-1", "tenant-1")
+ with assert_raises():
+ validate_match_scope("tenant-1", "tenant-2")
+ with assert_raises():
+ validate_match_scope("", "tenant-1")
+ var keys = List[String]()
+ keys.append("lot-1@l1")
+ keys.append("lot-2@l1")
+ assert_equal(len(validate_supplied_lots(keys)), 2)
+ var dupes = List[String]()
+ dupes.append("lot-1@l1")
+ dupes.append("lot-1@l1")
+ with assert_raises():
+ _ = validate_supplied_lots(dupes)
+ assert_true(not caller_name_is_authentication())