Skip to main content

Negative tests

Negative test ต้องใช้กรณีที่กำหนดไว้ใน private grant manifest และต้องพิสูจน์ว่าไม่มี job หรือ business row เกิดขึ้น อย่าทดลองสุ่ม UUID หรือข้อมูลขององค์กรอื่น

กรณีผลที่ยอมรับ
ungranted destination403 AUTHORIZATION_DENIED หรือ anti-enumeration 404 RESOURCE_NOT_FOUND
subset: supported-but-ungranted capability403 AUTHORIZATION_DENIED
complete catalog: supported-but-ungrantedNOT_APPLICABLE พร้อม exact-set proof; ห้ามยิง request
complete catalog: unsupported input422 ACTIVITY_CAPABILITY_UNAVAILABLE
malformed/invalid valuedocumented 400/validation error แต่ไม่นับแทน authorization proof
expired tokenresource 401 จากนั้น refresh หนึ่งครั้ง
controlled rate limit429 พร้อม bounded wait/retry

ถ้า negative probe ถูก 202 Accepted ให้ถือว่า FAIL แม้ job ภายหลังล้มเหลว เพราะ authorization/validation boundary ไม่ได้หยุด request ในจุดที่คาดไว้ เก็บเฉพาะ status, stable error code และ correlation ID ที่ redact แล้ว