"""Local routing-policy fixture. No DNS, certificate or provider API calls."""
import json
from pathlib import Path

def allow(state, assigned, requester, generation, proof_generation, proof_tenant):
    return (state == 'active' and assigned == requester == proof_tenant
            and generation == proof_generation)

cases = [
    ('original-active', 'active', 'a', 'a', 1, 1, 'a', True),
    ('disabled-route', 'disabled', 'a', 'a', 1, 1, 'a', False),
    ('removed-binding', 'removed', 'a', 'a', 1, 1, 'a', False),
    ('new-owner-awaiting-proof', 'pending', 'b', 'b', 2, 1, 'a', False),
    ('old-proof-new-owner', 'active', 'b', 'b', 2, 1, 'a', False),
    ('fresh-proof-wrong-tenant', 'active', 'b', 'b', 2, 2, 'a', False),
    ('fresh-proof-matching-owner', 'active', 'b', 'b', 2, 2, 'b', True),
    ('foreign-requester', 'active', 'b', 'a', 2, 2, 'b', False),
]
rows=[]
for name,*args,expected in cases:
    observed=allow(*args)
    assert observed is expected, name
    rows.append(dict(case=name,allow=observed,expected=expected))
result=dict(scope='Illustrative application predicate only; identity supplied by trusted context',
            cases=rows,allowed=sum(r['allow'] for r in rows),denied=sum(not r['allow'] for r in rows),
            not_tested=['DNS propagation','provider hostname deletion','certificate cleanup','real authorization'],assertions='passed')
Path(__file__).with_name('results.json').write_text(json.dumps(result,indent=2)+'\n')
print(json.dumps(result,indent=2))
