Conformance vectors¶
Generated from the source of truth
This page mirrors spec/conformance/README.md.
The vectors themselves live in
spec/conformance/vectors.json.
Conformance vectors¶
Language-neutral test vectors that pin down the Altium-specific behavior in SPEC.md. Every SDK (TS, .NET, Java, …) should run these against a mock IdP and assert the same outgoing requests and outcomes, so all implementations stay consistent.
Source of truth: ../../src/index.test.ts (unit behavior) and the live
Commercial/Gov/Dev captures (Tests A/B/C + dev confidential) recorded during
validation.
File¶
vectors.json— the vectors, grouped by category.
Categories & matchers¶
Values in expect blocks may be literals or one of these matchers (strings):
"<any>"— key/param must be present, any value."contains:<substr>"— string value must contain<substr>."basic(clientId:clientSecret)"— anAuthorizationheader ofBasic base64(clientId ":" clientSecret)."none"— (forauthorization) the header must be absent."epochWithin:<offset>:<tol>"— (for a numeric result field likeexpires_at) the value must be within<tol>seconds ofnow + <offset>.
authorizeUrl¶
Input: config + options (a fixed codeVerifier/state make it deterministic).
expect: origin, pathname, query (exact key→value), queryAbsent (keys that must not appear).
tokenRequest¶
Input: operation (exchangeCode | signIntoWorkspace | refreshToken), config, input.
expectRequest: endpoint, method, authorization, bodyParams (key→value/matcher), bodyParamsAbsent.
Then either mockResponse + expectResult, or mockResponse + expectErrorContains.
actionWait¶
Input: pollResponses (an ordered list the mock returns to successive POST /await calls).
expect: outcome (code | errorContains) — verifies 408=reconnect, 410=terminal, 200 parse rules.
liveClaims¶
Golden decoded access-token claims from real runs — integration references (assert after decoding a token obtained from the live server for that scenario).
Coverage checklist¶
- [x] Authorize URL — Commercial + Gov host,
securenever on/authorize, PKCES256 - [x] Authorize URL —
selectWorkspacestrict/optional/none (SPEC §3.1) - [x] Code exchange — public (client_id) vs confidential (Basic)
- [x] Workspace exchange — non-Gov (no
secure) vs Gov (secure=1, Commercial→Gov bridge) - [x] Refresh — no
scopesent; Commercial vs Gov (secure) - [x] Cross-partition exchange →
access_denied - [x] ActionWait — 200/408/410, non-JSON, missing
code - [x] Live claims —
iss/secure/workspaceIdfor global, non-Gov, Gov tokens - [x] Revocation — request shape + refresh →
invalid_grant(spec §9; skipped in the TS runner, norevoke()in the lib) - [x] userinfo response shape (
../schemas/userinfo.schema.json; reference) - [x]
expires_atcomputation (30s skew) - [x] State-mismatch (CSRF) rejection after ActionWait
200
Next¶
- Wire
../../src/index.test.tsto loadvectors.json(proves the vectors match the reference). - Stand up a shared mock IdP (WireMock/Prism, or recorded interactions) so non-TS SDKs run the same vectors.