@@ -80,4 +80,67 @@ void testEp003S1() throws Exception {
8080 }
8181 }
8282
83+
84+ @ Test
85+ void testEp001S2TrustedPrivateRequiresExplicitPolicy () {
86+ assertThrows (IllegalArgumentException .class , () ->
87+ EndpointPolicy .strictPublic ().require ("http://10.20.30.40:8642" ));
88+
89+ EndpointPolicy policy = EndpointPolicy .trustedPrivate ("10.20.30.40" , 8642 );
90+ assertDoesNotThrow (() -> policy .require ("http://10.20.30.40:8642" ));
91+ assertThrows (IllegalArgumentException .class , () ->
92+ policy .require ("http://10.20.30.41:8642" ));
93+ assertThrows (IllegalArgumentException .class , () ->
94+ policy .require ("http://10.20.30.40:8643" ));
95+ }
96+
97+ @ Test
98+ void testPublicPolicyRequiresHttps () {
99+ EndpointPolicy policy = EndpointPolicy .strictPublic ();
100+ assertThrows (IllegalArgumentException .class , () ->
101+ policy .require ("http://1.1.1.1/v1" ));
102+ assertDoesNotThrow (() -> policy .require ("https://1.1.1.1/v1" ));
103+ }
104+
105+ @ Test
106+ void testEp002S1RejectsMixedResolutionCandidates () throws Exception {
107+ EndpointPolicy policy = EndpointPolicy .strictPublic (host -> new java .net .InetAddress [] {
108+ java .net .InetAddress .getByAddress (new byte [] {1 , 1 , 1 , 1 }),
109+ java .net .InetAddress .getByAddress (new byte [] {127 , 0 , 0 , 1 })
110+ });
111+
112+ assertThrows (IllegalArgumentException .class , () ->
113+ policy .require ("https://mixed.example/v1" ));
114+ }
115+
116+ @ Test
117+ void testEp003RejectsUserInfo () {
118+ assertThrows (IllegalArgumentException .class , () ->
119+ EndpointPolicy .strictPublic ().require ("https://user:secret@1.1.1.1/v1" ));
120+ }
121+
122+ @ Test
123+ void testEp003S2EncodesReservedRunIdentifierAsOnePathSegment () throws Exception {
124+ try (MockWebServer server = new MockWebServer ()) {
125+ server .enqueue (new MockResponse ()
126+ .setResponseCode (200 )
127+ .setHeader ("Content-Type" , "application/json" )
128+ .setBody ("{}" ));
129+ server .start ();
130+
131+ HermesHttpClientConfig config = new HermesHttpClientConfig ()
132+ .setEndpointPolicy (EndpointPolicy .trustedLocal ("127.0.0.1" , server .getPort ()))
133+ .setBaseUrl ("http://127.0.0.1:" + server .getPort ());
134+
135+ try (HermesHttpClient client = new HermesHttpClient (config )) {
136+ assertNotNull (client .getRun ("run/alpha?x=1" ));
137+ }
138+
139+ okhttp3 .mockwebserver .RecordedRequest request = server .takeRequest (1 , TimeUnit .SECONDS );
140+ assertNotNull (request );
141+ org .junit .jupiter .api .Assertions .assertEquals (
142+ "/v1/runs/run%2Falpha%3Fx%3D1" , request .getPath ());
143+ }
144+ }
145+
83146}
0 commit comments