Checked at 8113abd.
Two things in examples/minimal/README.md:
- Line 14 tells readers to run
--trusted-root-issuer <trusted-root-issuer-hex>, but the real key is already pinned in ca2a-config.yaml (eda38c44...eb162). With that key, ca2a verify-chain --chain chain.json --trusted-root-issuer <key> returns {"verified": true, "hops": 3, "leaf_scope": ["cap:read"], ...}.
- Line 7 calls the config "software-only, advisory". The file sets
enforcement_mode: enforcing, and ca2a validate-config prints ok: provider=software-only enforcement=enforcing.
There is also no test for examples/minimal, while the other examples each have one.
Done when
- the README uses the real key and says "enforcing"
- a new
tests/unit/test_example_minimal.py runs both commands through ca2a_runtime.cli.main and asserts verified: true and the config ok line
Files: examples/minimal/README.md, one new test file.
Checked at 8113abd.
Two things in
examples/minimal/README.md:--trusted-root-issuer <trusted-root-issuer-hex>, but the real key is already pinned inca2a-config.yaml(eda38c44...eb162). With that key,ca2a verify-chain --chain chain.json --trusted-root-issuer <key>returns{"verified": true, "hops": 3, "leaf_scope": ["cap:read"], ...}.enforcement_mode: enforcing, andca2a validate-configprintsok: provider=software-only enforcement=enforcing.There is also no test for
examples/minimal, while the other examples each have one.Done when
tests/unit/test_example_minimal.pyruns both commands throughca2a_runtime.cli.mainand assertsverified: trueand the configoklineFiles:
examples/minimal/README.md, one new test file.