Skip to content

fix: generate authorization cases using provider role IDs - #129

Merged
n-papaioannou merged 2 commits into
ifixai-ai:mainfrom
rudycelekli:fix/generated-cases-use-role-id
Oct 1, 2026
Merged

n-papaioannou merged 2 commits into
ifixai-ai:mainfrom
rudycelekli:fix/generated-cases-use-role-id

Conversation

@rudycelekli

Copy link
Copy Markdown
Contributor

Summary

generate_test_cases() looked up permissions only by Role.name, then emitted the display name as user_role. A provider can use a stable Role.role_id in its permission matrix while showing a different name to users. In that case an authorized tool is generated as a B08 deny case instead of a B01 allow case, and the case carries a role key the provider may not recognize. This misstates the audit fixture's access policy.

Prefer role_id when the permission matrix contains it; retain display-name fallback for fixtures keyed by name. Use the matched key in generated user_role while keeping the readable name in the scenario.

Reproduction and test plan

  • New regression with Role(name="Administrator", role_id="admin") and Permission(role="admin", tools=["delete_record"]) failed on main: it produced B08/deny. It now produces B01/allow with user_role="admin".
  • A second regression confirms display-name-keyed permissions still work. python -m pytest ifixai/tests/core/test_discovery_role_permissions.py -q — 2 passed.
  • uvx ruff check ifixai — passed.
  • uvx bandit -r ifixai -ll -q — passed.
  • uv run --python 3.11 ifixai validate and validation of every example fixture — passed (60 inspections).

No live provider or scorecard was run; the regression demonstrates the corrected generated case classification.

@n-papaioannou
n-papaioannou merged commit 0f6587a into ifixai-ai:main Oct 1, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants