Context
HeaderProof records a full-response SHA-256 while retaining only a bounded body sample. That distinction is part of the evidence integrity contract and deserves a focused regression test.
Scope
Add unit tests around consume_body(), decode_body(), and snapshot_summary() in src/headerproof/transport.py. Use in-memory streams/snapshots only; no network target is needed.
Acceptance criteria
- A body larger than the sample limit records the full byte length and SHA-256 of the complete response.
- The stored sample is capped at the configured limit and body_truncated is true only when appropriate.
- Empty and exactly-at-limit bodies are covered.
- Unknown response charsets fall back safely to UTF-8 replacement decoding.
- snapshot_summary() preserves the full-response hash scope and does not include body_sample unless requested.
- Existing tests remain green.
Comment before starting so ownership can be confirmed.
Context
HeaderProof records a full-response SHA-256 while retaining only a bounded body sample. That distinction is part of the evidence integrity contract and deserves a focused regression test.
Scope
Add unit tests around consume_body(), decode_body(), and snapshot_summary() in src/headerproof/transport.py. Use in-memory streams/snapshots only; no network target is needed.
Acceptance criteria
Comment before starting so ownership can be confirmed.