e2-inbox-fixture¶
This local read-only echo example demonstrates a trusted native connector. It does not implement or certify an external provider.
- Edit
connector.json, then copy the reviewed declaration intosrc/e2_inbox_fixture/connector.json. - Validate data with
weave connector validate connector.json(no package code runs). - Build with
weave connector package . --directory distin an author-controlled environment containingbuild. - Install the wheel and the matching Weave/PyFly artifacts into an isolated environment.
- Run
pytest tests/test_conformance.py, thenweave connector test 'e2-inbox-fixture:e2-inbox-fixture:e2_inbox_fixture:package'. - Configure that exact identity in the operator's
WEAVE_CONNECTOR_PACKAGESJSON array to enable it.
connector test executes installed trusted declaration, lifecycle, and fixture code, records
installed-fixture-contract, and does not call a real provider. Add explicit
fixture tests for protected headers, credential redaction, cancellation, response
bounds and unknown outcomes when replacing echo with an external operation.
Never change an uncertain external outcome into a safe automatic retry.
Read the fixture's boundaries¶
How to read this diagram: This directory supplies the installed test package in the top-left card. Publishing contracts follows it in the top row; environment authority and activation appear in the lower row. Creating a connection and binding an admitted release remain separate test-harness or deployment operations.
The package contains two native services with different responsibilities:
| Component | What it exercises | Boundary |
|---|---|---|
Echo in the installed module |
Bounded read-only Action input/output and native composition | It returns local JSON and performs no provider send |
FixtureVerifier in that module |
Test-only HMAC verification, configured account matching, normalized events, and a transactional admission hook | Its protocol and failure switches exist for the controlled provider-inbox tests |
| provider_verifier.py | A fail-closed design skeleton for future provider authoring | It is excluded from installed service discovery and raises NotImplementedError |
The root connector.json pins FixtureVerifier and declares
message and secret as dispatchable kinds. Lifecycle kinds exercise ignored
admission; the secret-marked kind exercises classification rejection. None of
these names advertise a commercial provider. The registered test verifier and
the unregistered design skeleton are distinct implementations.
Run the commands above from this directory in the isolated test environment. The package build output must be absent or empty. The echo conformance command checks installed trusted code; it does not by itself exercise a running inbox, its database transaction, or a real provider. The integration harness supplies its disposable database, fixture effects table, authority, and source setup. Do not copy the challenge token, signature protocol, or failure switches into a production provider adapter.
For a production package, start with connector authoring and the provider-source contract. Implement and verify the provider's actual raw-byte authentication, installation policy, stable event identity, schemas, and admission behavior before enabling it.