Skip to content

chore: keep tests, examples and benches out of the published crates - #1

Merged
RobertoIskandarani merged 1 commit into
mainfrom
chore/exclude-tests-from-crates
Oct 1, 2026
Merged

RobertoIskandarani merged 1 commit into
mainfrom
chore/exclude-tests-from-crates

Conversation

@RobertoIskandarani

Copy link
Copy Markdown
Contributor

Packaging metadata only — no source, no API, no test behaviour changes. Three Cargo.toml files gain exclude = ["tests/", "examples/", "benches/"].

Why now

core/tests/fixtures/ holds four PEM files — two RSA private keys, one EC private key, one public key — that the unit tests, the conformance suites and core/examples/dpop_roundtrip.rs load through include_str!. They are test material: nothing in the SDK verifies against them, and they are named test-*.

But cargo package --list showed all four shipping inside the authplane-sdk tarball, and a crates.io version is immutable — it can be yanked, never deleted. Whatever 0.1.0 carries, it carries permanently, into every cargo vendor, SBOM and downstream secret scan. Before the first publish is the only cheap moment to decide this.

Why examples/ goes with tests/

dpop_roundtrip.rs reads tests/fixtures/test-private.pem and hardcodes the matching RSA modulus as a literal, so it is bound to that exact key pair. Excluding the fixture while shipping the example would leave the example unbuildable from the tarball. Both stay in the repository, which is where anyone reading an example is already looking.

The alternative — rewriting the ~10 include_str! sites to generate keys in-test, which is what the other SDKs in the family do — is a change to the scaffolding that proves DPoP and JWS behaviour. That belongs in its own PR, not on the path to the first release.

Verification

  • cargo package -p authplane-sdk builds and verifies clean; tar tzf on the result finds no .pem.
  • cargo fmt --check clean, full cargo test green from a checkout — the suites are unaffected, they read the fixtures from the working tree as before.
  • authplane-mcp and authplane-fastmcp cannot be packaged yet: they resolve authplane-sdk from the crates.io index, which does not have it. That is pre-existing and expected — it is the publish order RELEASE_SETUP.md §4 prescribes, and publish-crates.yml already waits for the index between crates.

`core/tests/fixtures/` holds RSA and EC private keys that the unit tests and
the DPoP example load through `include_str!`. They are test material — nothing
in the SDK verifies against them — but `cargo package --list` showed all four
shipping inside the `authplane-sdk` tarball, and a crates.io version is
immutable: whatever 0.1.0 carries, it carries for good. Key-shaped files in a
published tarball are permanent noise for every downstream secret scanner and
SBOM, so the cheapest moment to keep them out is before the first publish.

`examples/` is excluded alongside `tests/` rather than kept: the DPoP example
reads `tests/fixtures/test-private.pem`, so shipping it without the fixture
would leave it unbuildable from the tarball. Both stay in the repository, which
is where anyone reading them is already looking.

Packaging only — no source, no API and no test behaviour changes. The suites
still run from a checkout, and `cargo package -p authplane-sdk` verifies clean
with no `.pem` in the result. `authplane-mcp` and `authplane-fastmcp` cannot be
packaged until `authplane-sdk` is on the index, which is the publish order
RELEASE_SETUP.md already prescribes.
@RobertoIskandarani
RobertoIskandarani merged commit e2fc9f9 into main Oct 1, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants