| Vendor | FINOS |
| Product | CCC-Complete (Behavioural) |
| Version | 0.1 |
CCC-Complete (Behavioural) 0.1
Test results for this specific product, vendor, and version combination
Download Raw Results
Download the original OCSF, Gemara, or HTML result files used to generate this page
Test Summary
Aggregate summary of all tests for this configuration result
| Resources In Configuration | 2 |
| Count of Tests | 104 |
| Passing Tests | 50 |
| Failing Tests | 54 |
| Catalogs Tested | CCC.CoreCCC.ObjStor |
Control Catalog Summary
Summary of test results grouped by control catalog and resource
Test Mapping Summary
Summary of test mappings showing how event codes map to test requirements
| Control Catalog | Test Requirement | Mapped Tests (Event Code | Total | Passing | Failing) |
|---|---|---|
| CCC.Core | Service accepts TLS 1.3 encrypted traffic220 Service rejects TLS 1.0 traffic220 Service rejects TLS 1.1 traffic220 Service rejects TLS 1.2 traffic220 Verify no known SSL/TLS vulnerabilities202 Verify SSL/TLS protocol support202 Verify TLS 1.3 only certificate validity202 | |
| CCC.Core | HTTP redirects to HTTPS220 Only secure protocols are exposed202 | |
| CCC.Core | Verify HTTPS uses IANA-assigned port 443220 | |
| CCC.Core | Verify mTLS requires client certificate authentication202 | |
| CCC.Core | Verify objects are encrypted at rest220 | |
| CCC.Core | MFA requirement for destructive operations cannot be tested automatically - NotTestable220 | |
| CCC.Core | Verify admin actions are logged with identity and timestamp202 | |
| CCC.Core | Verify data modifications are logged with identity and timestamp202 | |
| CCC.Core | Verify data read operations are logged with identity and timestamp202 | |
| CCC.Core | Service allows data modification by user with write access202 Service prevents data modification by user with no access220 | |
| CCC.Core | Service allows administrative action (creating a new bucket) by user with admin access202 Service prevents administrative action (creating a new bucket) by user with no access220 Service prevents administrative action (creating a new bucket) by user with read-only access220 | |
| CCC.Core | Service prevents data read by user with no access220 | |
| CCC.Core | Child resource region compliance - NotTestable220 | |
| CCC.Core | Enumeration event publishing cannot be tested automatically - NotTestable220 | |
| CCC.Core | Enumeration logging cannot be verified automatically - NotTestable220 | |
| CCC.Core | Bucket data is replicated to physically separate locations202 | |
| CCC.Core | Replication status can be retrieved for monitoring202 | |
| CCC.Core | Replication destination trust cannot be verified automatically - NotTestable220 | |
| CCC.ObjStor | Service allows reading bucket with read access202 Service prevents reading bucket with no access220 | |
| CCC.ObjStor | Service allows reading object with read access202 Service prevents reading object with no access220 | |
| CCC.ObjStor | Service allows creating bucket with write access202 Service prevents creating bucket with no access220 | |
| CCC.ObjStor | Service allows writing object with write access202 Service prevents writing object with read-only access220 | |
| CCC.ObjStor | Service enforces uniform bucket-level access by rejecting object-level permissions202 | |
| CCC.ObjStor | Service enforces uniform bucket-level access denial220 | |
| CCC.ObjStor | Service supports bucket soft delete and recovery202 | |
| CCC.ObjStor | Service prevents modification of locked retention policy202 | |
| CCC.ObjStor | Service applies default retention policy to newly uploaded object202 Service enforces retention policy on newly created objects220 Service validates retention period meets minimum requirements220 | |
| CCC.ObjStor | Service allows object read access during retention period202 Service prevents object deletion by admin user during retention period220 Service prevents object deletion by write user during retention period202 Service prevents object modification during retention period202 | |
| CCC.ObjStor | Service enables versioning and objects receive unique version identifiers202 | |
| CCC.ObjStor | Modified objects receive new version identifiers202 | |
| CCC.ObjStor | Modified objects receive new version identifiers202 | |
| CCC.ObjStor | Deleted object data can be reloaded from previous version220 Deleted object version remains in version list202 |
Resource Summary
Summary of all resources mentioned in OCSF results
| Resource Name | Resource Type | Control Catalogs | Total Tests | Passing | Failing |
|---|---|---|---|---|---|
/subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | CCC.CoreCCC.ObjStor | 82 | 38 | 44 |
finoscccintegrationmain.blob.core.windows.net | object-storage | CCC.Core | 22 | 12 | 10 |
Test Results
OCSF test results filtered for entries with CCC compliance mappings
| Status | Finding | Resource Name | Resource Type | Message | Test Requirements |
|---|---|---|---|---|---|
| PASS | Service accepts TLS 1.3 encrypted traffic ✓ a cloud api for "{config}" in "api"
✓ an openssl s_client request using "tls1_3" to "{port-number}" on "{host-name}" protocol "{protocol}"
✓ I refer to "{result}" as "connection"
✓ "{connection}" state is open
✓ "{connection.State}" is "open"
✓ I close connection "{connection}"
✓ "{connection}" state is closed | finoscccintegrationmain.blob.core.windows.net | object-storage | ||
| PASS | Service rejects TLS 1.2 traffic ✓ a cloud api for "{config}" in "api"
✓ an openssl s_client request using "tls1_2" to "{port-number}" on "{host-name}" protocol "{protocol}"
✓ I refer to "{result}" as "connection"
✓ we wait for a period of "40" ms
✓ "{connection.State}" is "closed" | finoscccintegrationmain.blob.core.windows.net | object-storage | ||
| PASS | Service rejects TLS 1.1 traffic ✓ a cloud api for "{config}" in "api"
✓ an openssl s_client request using "tls1_1" to "{port-number}" on "{host-name}" protocol "{protocol}"
✓ I refer to "{result}" as "connection"
✓ we wait for a period of "40" ms
✓ "{connection.State}" is "closed" | finoscccintegrationmain.blob.core.windows.net | object-storage | ||
| PASS | Service rejects TLS 1.0 traffic ✓ a cloud api for "{config}" in "api"
✓ an openssl s_client request using "tls1" to "{port-number}" on "{host-name}" protocol "{protocol}"
✓ I refer to "{result}" as "connection"
✓ we wait for a period of "40" ms
✓ "{connection.State}" is "closed" | finoscccintegrationmain.blob.core.windows.net | object-storage | ||
| FAIL | Verify SSL/TLS protocol support ✓ a cloud api for "{config}" in "api"
✗ "report" contains details of SSL Support type "protocols" for "{host-name}" on port "{port-number}" - Error: failed to read testssl.sh output: open /tmp/testssl_protocols_finoscccintegrationmain.blob.core.windows.net_443.json: no such file or directory
⊘ "{report}" is an array of objects which doesn't contain any of (skipped)
⊘ "{report}" is an array of objects with at least the following contents (skipped) | finoscccintegrationmain.blob.core.windows.net | object-storage | ||
| FAIL | Verify no known SSL/TLS vulnerabilities ✓ a cloud api for "{config}" in "api"
✗ "report" contains details of SSL Support type "vulnerable" for "{host-name}" on port "{port-number}" - Error: failed to read testssl.sh output: open /tmp/testssl_vulnerable_finoscccintegrationmain.blob.core.windows.net_443.json: no such file or directory
⊘ "{report}" is an array of objects with at least the following contents (skipped) | finoscccintegrationmain.blob.core.windows.net | object-storage | ||
| FAIL | Verify TLS 1.3 only certificate validity ✓ a cloud api for "{config}" in "api"
✗ "report" contains details of SSL Support type "server-defaults" for "{host-name}" on port "{port-number}" - Error: failed to read testssl.sh output: open /tmp/testssl_server-defaults_finoscccintegrationmain.blob.core.windows.net_443.json: no such file or directory
⊘ "{report}" is an array of objects with at least the following contents (skipped) | finoscccintegrationmain.blob.core.windows.net | object-storage | ||
| PASS | HTTP redirects to HTTPS ✓ a client connects to "{host-name}" with protocol "http" on port "80"
✓ I refer to "{result}" as "connection"
✓ "{connection}" is not an error
✓ I transmit "GET / HTTP/1.1\r\nHost: {host-name}\r\n\r\n" to "{connection}"
✓ I attach "{connection}" to the test output as "HTTP response"
✓ "{connection.Output}" contains "301"
✓ I call "{connection}" with "Close"
✓ "{connection.State}" is "closed" | finoscccintegrationmain.blob.core.windows.net | object-storage | ||
| FAIL | Only secure protocols are exposed ✗ "report" contains details of SSL Support type "protocols" for "{host-name}" on port "{port-number}" - Error: failed to read testssl.sh output: open /tmp/testssl_protocols_finoscccintegrationmain.blob.core.windows.net_443.json: no such file or directory
⊘ "{report}" is an array of objects with at least the following contents (skipped) | finoscccintegrationmain.blob.core.windows.net | object-storage | ||
| PASS | Verify HTTPS uses IANA-assigned port 443 ✓ "{port-number}" is "443" | finoscccintegrationmain.blob.core.windows.net | object-storage | ||
| FAIL | Verify mTLS requires client certificate authentication ✗ "report" contains details of SSL Support type "server-defaults" for "{host-name}" on port "{port-number}" - Error: failed to read testssl.sh output: open /tmp/testssl_server-defaults_finoscccintegrationmain.blob.core.windows.net_443.json: no such file or directory
⊘ "{report}" is an array of objects with at least the following contents (skipped) | finoscccintegrationmain.blob.core.windows.net | object-storage | ||
| PASS | Verify objects are encrypted at rest ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ "{result}" is not an error
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "test-encryption-check={timestamp}.txt", and "encryption test data"
✓ "{result}" is not an error
✓ I refer to "{result}" as "uploadResult"
✓ "{uploadResult.Encryption}" is not null
✓ "{uploadResult.EncryptionAlgorithm}" is "AES256"
✓ I attach "{uploadResult}" to the test output as "Upload Result with Encryption Details" | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Service prevents data modification by user with no access ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-no-access"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "CreateObject" using arguments "{resource-name}", "test-cn05-unauthorized-modify={timestamp}.txt", and "unauthorized data"
✓ "{result}" is an error
✓ I attach "{result}" to the test output as "no-access-create-error.txt" | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Service allows data modification by user with write access ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-write"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "CreateObject" using arguments "{resource-name}", "test-cn05-authorized-modify={timestamp}.txt", and "authorized data"
✗ "{result}" is not an error - Error: expected {result} to not be an error, but got: failed to upload blob test-cn05-authorized-modify=1784277841329.txt: PUT https://finoscccintegrationmain.blob.core.windows.net/finos-ccc-integration-container-main/test-cn05-authorized-modify=1784277841329.txt
--------------------------------------------------------------------------------
RESPONSE 403: 403 This request is not authorized to perform this operation using this permission.
ERROR CODE: AuthorizationPermissionMismatch
--------------------------------------------------------------------------------
<?xml version="1.0" encoding="utf-8"?><Error><Code>AuthorizationPermissionMismatch</Code><Message>This request is not authorized to perform this operation using this permission.
RequestId:3a51344a-301e-0020-29c8-15d63c000000
Time:2026-07-17T08:44:01.7357820Z</Message></Error>
--------------------------------------------------------------------------------
⊘ I attach "{result}" to the test output as "write-create-object-result.json" (skipped) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Service prevents administrative action (creating a new bucket) by user with no access ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-no-access"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "CreateBucket" using argument "test-cn05-unauthorized-admin-container"
✓ "{result}" is an error
✓ I attach "{result}" to the test output as "no-admin-create-bucket-error.txt" | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Service prevents administrative action (creating a new bucket) by user with read-only access ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-read"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "CreateBucket" using argument "test-cn05-read-only-create-container"
✓ "{result}" is an error
✓ I attach "{result}" to the test output as "read-only-create-bucket-error.txt" | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Service allows administrative action (creating a new bucket) by user with admin access ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-admin"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "CreateBucket" using argument "test-cn05-authorized-admin-container"
✗ "{result}" is not an error - Error: expected {result} to not be an error, but got: failed to create container: failed to create container test-cn05-authorized-admin-container: PUT https://finoscccintegrationmain.blob.core.windows.net/test-cn05-authorized-admin-container
--------------------------------------------------------------------------------
RESPONSE 403: 403 This request is not authorized to perform this operation.
ERROR CODE: AuthorizationFailure
--------------------------------------------------------------------------------
<?xml version="1.0" encoding="utf-8"?><Error><Code>AuthorizationFailure</Code><Message>This request is not authorized to perform this operation.
RequestId:3a513662-301e-0020-70c8-15d63c000000
Time:2026-07-17T08:44:02.5274179Z</Message></Error>
--------------------------------------------------------------------------------
⊘ I attach "{result}" to the test output as "admin-create-bucket-result.json" (skipped)
⊘ I call "{storage}" with "DeleteBucket" using argument "test-cn05-authorized-admin-container" (skipped) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Child resource region compliance - NotTestable ✓ a cloud api for "{config}" in "api"
✓ no-op required | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Bucket data is replicated to physically separate locations ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "GetReplicationStatus" using argument "{resource-name}"
✓ I refer to "{result}" as "replicationStatus"
✓ I refer to "{replicationStatus.Locations}" as "locations"
✓ I attach "{replicationStatus}" to the test output as "Replication Status"
✗ "{locations}" is an array of objects with length "2" - Error: expected length 2, got 1
⊘ "{permitted-regions}" is an array of objects with at least the following contents (skipped)
⊘ "{permitted-regions}" is an array of objects with at least the following contents (skipped) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Replication status can be retrieved for monitoring ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "GetReplicationStatus" using argument "{resource-name}"
✓ I refer to "{result}" as "replicationStatus"
✓ I attach "{replicationStatus}" to the test output as "Replication Status"
✓ I refer to "{replicationStatus.Locations}" as "locations"
✗ "{locations}" is an array of objects with at least the following contents - Error: expected row not found: map[value:{replication-locations[0]}] | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Service prevents reading bucket with no access ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-no-access"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "ListObjects" using argument "{resource-name}"
✓ "{result}" is an error
✓ I attach "{result}" to the test output as "no-access-list-error.txt" | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Service allows reading bucket with read access ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-read"
✓ "{result}" is not an error
✓ I attach "{result}" to the test output as "read-storage-service.json"
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "ListObjects" using argument "{resource-name}"
✗ "{result}" is not an error - Error: expected {result} to not be an error, but got: failed to list blobs: GET https://finoscccintegrationmain.blob.core.windows.net/finos-ccc-integration-container-main
--------------------------------------------------------------------------------
RESPONSE 403: 403 This request is not authorized to perform this operation using this permission.
ERROR CODE: AuthorizationPermissionMismatch
--------------------------------------------------------------------------------
<?xml version="1.0" encoding="utf-8"?><Error><Code>AuthorizationPermissionMismatch</Code><Message>This request is not authorized to perform this operation using this permission.
RequestId:3a5137a2-301e-0020-7dc8-15d63c000000
Time:2026-07-17T08:44:03.0115745Z</Message></Error>
--------------------------------------------------------------------------------
⊘ I attach "{result}" to the test output as "read-list-objects-result.json" (skipped) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Service prevents reading object with no access ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "test-object={timestamp}.txt", and "test content"
✓ "{result}" is not an error
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-no-access"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "ReadObject" using arguments "{resource-name}" and "test-object={timestamp}.txt"
✓ "{result}" is an error
✓ I attach "{result}" to the test output as "no-access-read-object-error.txt" | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Service allows reading object with read access ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "test-object={timestamp}.txt", and "test content"
✓ "{result}" is not an error
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-read"
✓ "{result}" is not an error
✓ I attach "{result}" to the test output as "read-storage-service.json"
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "ReadObject" using arguments "{resource-name}" and "test-object={timestamp}.txt"
✗ "{result}" is not an error - Error: expected {result} to not be an error, but got: failed to download blob test-object=1784277843536.txt: GET https://finoscccintegrationmain.blob.core.windows.net/finos-ccc-integration-container-main/test-object=1784277843536.txt
--------------------------------------------------------------------------------
RESPONSE 403: 403 This request is not authorized to perform this operation using this permission.
ERROR CODE: AuthorizationPermissionMismatch
--------------------------------------------------------------------------------
<?xml version="1.0" encoding="utf-8"?><Error><Code>AuthorizationPermissionMismatch</Code><Message>This request is not authorized to perform this operation using this permission.
RequestId:3a513a4f-301e-0020-4bc8-15d63c000000
Time:2026-07-17T08:44:04.0200699Z</Message></Error>
--------------------------------------------------------------------------------
⊘ I attach "{result}" to the test output as "read-read-object-result.json" (skipped) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Service prevents creating bucket with no access ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-no-access"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "CreateBucket" using argument "test-bucket-no-access"
✓ "{result}" is an error
✓ I attach "{result}" to the test output as "no-access-create-bucket-error.txt" | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Service allows creating bucket with write access ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-write"
✓ "{result}" is not an error
✓ I attach "{result}" to the test output as "write-storage-service.json"
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "CreateBucket" using argument "test-bucket-write"
✗ "{result}" is not an error - Error: expected {result} to not be an error, but got: failed to create container: failed to create container test-bucket-write: PUT https://finoscccintegrationmain.blob.core.windows.net/test-bucket-write
--------------------------------------------------------------------------------
RESPONSE 403: 403 This request is not authorized to perform this operation.
ERROR CODE: AuthorizationFailure
--------------------------------------------------------------------------------
<?xml version="1.0" encoding="utf-8"?><Error><Code>AuthorizationFailure</Code><Message>This request is not authorized to perform this operation.
RequestId:3a513a90-301e-0020-7ec8-15d63c000000
Time:2026-07-17T08:44:04.1051111Z</Message></Error>
--------------------------------------------------------------------------------
⊘ I attach "{result}" to the test output as "write-create-bucket-result.json" (skipped)
⊘ I call "{storage}" with "DeleteBucket" using argument "{result.ID}" (skipped) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Service prevents writing object with read-only access ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ "{result}" is not an error
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-read"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "CreateObject" using arguments "{resource-name}", "test-write-object={timestamp}.txt", and "test content"
✓ "{result}" is an error
✓ I attach "{result}" to the test output as "read-create-object-error.txt" | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Service allows writing object with write access ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ "{result}" is not an error
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-write"
✓ "{result}" is not an error
✓ I attach "{result}" to the test output as "write-storage-service.json"
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "CreateObject" using arguments "{resource-name}", "test-write-object={timestamp}.txt", and "test content"
✗ "{result}" is not an error - Error: expected {result} to not be an error, but got: failed to upload blob test-write-object=1784277844172.txt: PUT https://finoscccintegrationmain.blob.core.windows.net/finos-ccc-integration-container-main/test-write-object=1784277844172.txt
--------------------------------------------------------------------------------
RESPONSE 403: 403 This request is not authorized to perform this operation using this permission.
ERROR CODE: AuthorizationPermissionMismatch
--------------------------------------------------------------------------------
<?xml version="1.0" encoding="utf-8"?><Error><Code>AuthorizationPermissionMismatch</Code><Message>This request is not authorized to perform this operation using this permission.
RequestId:3a513ae6-301e-0020-43c8-15d63c000000
Time:2026-07-17T08:44:04.1916758Z</Message></Error>
--------------------------------------------------------------------------------
⊘ I attach "{result}" to the test output as "write-create-object-result.json" (skipped) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Service enforces uniform bucket-level access by rejecting object-level permissions ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "test-object={timestamp}.txt", and "test data"
✓ "{result}" is not an error
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-read"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "ReadObject" using arguments "{resource-name}" and "test-object={timestamp}.txt"
✗ "{result}" is not an error - Error: expected {result} to not be an error, but got: failed to download blob test-object=1784277844214.txt: GET https://finoscccintegrationmain.blob.core.windows.net/finos-ccc-integration-container-main/test-object=1784277844214.txt
--------------------------------------------------------------------------------
RESPONSE 403: 403 This request is not authorized to perform this operation using this permission.
ERROR CODE: AuthorizationPermissionMismatch
--------------------------------------------------------------------------------
<?xml version="1.0" encoding="utf-8"?><Error><Code>AuthorizationPermissionMismatch</Code><Message>This request is not authorized to perform this operation using this permission.
RequestId:3a513c95-301e-0020-3fc8-15d63c000000
Time:2026-07-17T08:44:04.7062053Z</Message></Error>
--------------------------------------------------------------------------------
⊘ I call "{storage}" with "SetObjectPermission" using arguments "{resource-name}", "test-object={timestamp}.txt", and "none" (skipped)
⊘ "{result}" is an error (skipped)
⊘ I attach "{result}" to the test output as "set-object-permission-error.txt" (skipped)
⊘ I call "{userStorage}" with "ReadObject" using arguments "{resource-name}" and "test-object={timestamp}.txt" (skipped)
⊘ "{result}" is not an error (skipped) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Service enforces uniform bucket-level access denial ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "test-object={timestamp}.txt", and "test data"
✓ "{result}" is not an error
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-no-access"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "ReadObject" using arguments "{resource-name}" and "test-object={timestamp}.txt"
✓ "{result}" is an error
✓ I call "{storage}" with "SetObjectPermission" using arguments "{resource-name}", "test-object={timestamp}.txt", and "read"
✓ "{result}" is an error
✓ I attach "{result}" to the test output as "set-object-permission-error.txt"
✓ I call "{userStorage}" with "ReadObject" using arguments "{resource-name}" and "test-object={timestamp}.txt"
✓ "{result}" is an error | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Service supports bucket soft delete and recovery ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "CreateBucket" using argument "ccc-test-soft-delete"
✓ "{result}" is not an error
✓ I refer to "{result}" as "testBucket"
✓ I attach "{result}" to the test output as "created-bucket.json"
✓ I call "{storage}" with "DeleteBucket" using argument "ccc-test-soft-delete"
✓ "{result}" is not an error
✓ I call "{storage}" with "ListDeletedBuckets"
✓ "{result}" is not an error
✓ I attach "{result}" to the test output as "deleted-buckets.json"
✗ "{result}" is an array of objects with length "1" - Error: expected length 1, got 0
⊘ I call "{storage}" with "RestoreBucket" using argument "ccc-test-soft-delete" (skipped)
⊘ "{result}" is not an error (skipped)
⊘ I call "{storage}" with "ListBuckets" (skipped)
⊘ "{result}" is not an error (skipped)
⊘ I attach "{result}" to the test output as "restored-buckets.json" (skipped)
⊘ I call "{storage}" with "DeleteBucket" using argument "ccc-test-soft-delete" (skipped)
⊘ "{result}" is not an error (skipped) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Service prevents modification of locked retention policy ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "GetBucketRetentionDurationDays" using argument "{resource-name}"
✓ "{result}" is not an error
✓ I refer to "{result}" as "originalRetention"
✓ I attach "{result}" to the test output as "original-retention-days.txt"
✓ "{result}" should be greater than "0"
✓ I call "{storage}" with "SetBucketRetentionDurationDays" using arguments "{resource-name}" and "1"
✗ "{result}" is an error - Error: expected {result} to be an error, got <nil>
⊘ I attach "{result}" to the test output as "set-retention-error.txt" (skipped)
⊘ I call "{storage}" with "GetBucketRetentionDurationDays" using argument "{resource-name}" (skipped)
⊘ "{result}" is not an error (skipped)
⊘ "{result}" should be greater than "0" (skipped) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Service applies default retention policy to newly uploaded object ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-write"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "CreateObject" using arguments "{resource-name}", "test-retention-object={timestamp}.txt", and "protected data"
✓ I attach "{result}" to the test output as "uploaded-object.json"
✓ I call "{userStorage}" with "GetObjectRetentionDurationDays" using arguments "{resource-name}" and "test-retention-object={timestamp}.txt"
✗ "{result}" should be greater than "1" - Error: cannot parse {result} as number: strconv.ParseFloat: parsing "failed to get blob properties: HEAD https://finoscccintegrationmain.blob.core.windows.net/finos-ccc-integration-container-main/test-retention-object=1784277847983.txt\n--------------------------------------------------------------------------------\nRESPONSE 403: 403 This request is not authorized to perform this operation using this permission.\nERROR CODE: AuthorizationPermissionMismatch\n--------------------------------------------------------------------------------\nResponse contained no body\n--------------------------------------------------------------------------------\n": invalid syntax | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Service enforces retention policy on newly created objects ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "immediate-delete-test={timestamp}.txt", and "test content"
✓ "{result}" is not an error
✓ I call "{storage}" with "DeleteObject" using arguments "{resource-name}" and "immediate-delete-test={timestamp}.txt"
✓ "{result}" is an error
✓ I attach "{result}" to the test output as "immediate-delete-error.txt" | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Service validates retention period meets minimum requirements ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "retention-period-test={timestamp}.txt", and "compliance data"
✓ I call "{storage}" with "GetObjectRetentionDurationDays" using arguments "{resource-name}" and "retention-period-test={timestamp}.txt"
✓ "{result}" should be greater than "1"
✓ I attach "{result}" to the test output as "retention-period-days.json" | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Service prevents object deletion by write user during retention period ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-write"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "CreateObject" using arguments "{resource-name}", "protected-object={timestamp}.txt", and "immutable data"
✗ "{result}" is not an error - Error: expected {result} to not be an error, but got: failed to upload blob protected-object=1784277850338.txt: PUT https://finoscccintegrationmain.blob.core.windows.net/finos-ccc-integration-container-main/protected-object=1784277850338.txt
--------------------------------------------------------------------------------
RESPONSE 403: 403 This request is not authorized to perform this operation using this permission.
ERROR CODE: AuthorizationPermissionMismatch
--------------------------------------------------------------------------------
<?xml version="1.0" encoding="utf-8"?><Error><Code>AuthorizationPermissionMismatch</Code><Message>This request is not authorized to perform this operation using this permission.
RequestId:3a514c11-301e-0020-06c8-15d63c000000
Time:2026-07-17T08:44:10.3573521Z</Message></Error>
--------------------------------------------------------------------------------
⊘ I attach "{result}" to the test output as "protected-object.json" (skipped)
⊘ I call "{userStorage}" with "DeleteObject" using arguments "{resource-name}" and "protected-object={timestamp}.txt" (skipped)
⊘ "{result}" is an error (skipped)
⊘ I attach "{result}" to the test output as "delete-protected-error.txt" (skipped)
? "{result}" should contain one of "retention, locked, immutable, protected" (undefined) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Service prevents object deletion by admin user during retention period ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "admin-protected-object={timestamp}.txt", and "compliance data"
✓ "{result}" is not an error
✓ I call "{storage}" with "DeleteObject" using arguments "{resource-name}" and "admin-protected-object={timestamp}.txt"
✓ "{result}" is an error
✓ I attach "{result}" to the test output as "admin-delete-protected-error.txt" | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Service prevents object modification during retention period ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-write"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "CreateObject" using arguments "{resource-name}", "modify-test-object={timestamp}.txt", and "original content"
✗ "{result}" is not an error - Error: expected {result} to not be an error, but got: failed to upload blob modify-test-object=1784277851311.txt: PUT https://finoscccintegrationmain.blob.core.windows.net/finos-ccc-integration-container-main/modify-test-object=1784277851311.txt
--------------------------------------------------------------------------------
RESPONSE 403: 403 This request is not authorized to perform this operation using this permission.
ERROR CODE: AuthorizationPermissionMismatch
--------------------------------------------------------------------------------
<?xml version="1.0" encoding="utf-8"?><Error><Code>AuthorizationPermissionMismatch</Code><Message>This request is not authorized to perform this operation using this permission.
RequestId:3a514e1f-301e-0020-49c8-15d63c000000
Time:2026-07-17T08:44:11.3292583Z</Message></Error>
--------------------------------------------------------------------------------
⊘ I attach "{result}" to the test output as "original-object.json" (skipped)
⊘ I call "{userStorage}" with "CreateObject" using arguments "{resource-name}", "modify-test-object={timestamp}.txt", and "modified content" (skipped)
⊘ "{result}" is an error (skipped)
⊘ I attach "{result}" to the test output as "modify-protected-error.txt" (skipped)
? "{result}" should contain one of "retention, locked, immutable, protected, exists" (undefined) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Service allows object read access during retention period ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "readable-protected-object={timestamp}.txt", and "readable data"
✓ "{result}" is not an error
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-read"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "ReadObject" using arguments "{resource-name}" and "readable-protected-object={timestamp}.txt"
✗ "{result}" is not an error - Error: expected {result} to not be an error, but got: failed to download blob readable-protected-object=1784277851352.txt: GET https://finoscccintegrationmain.blob.core.windows.net/finos-ccc-integration-container-main/readable-protected-object=1784277851352.txt
--------------------------------------------------------------------------------
RESPONSE 403: 403 This request is not authorized to perform this operation using this permission.
ERROR CODE: AuthorizationPermissionMismatch
--------------------------------------------------------------------------------
<?xml version="1.0" encoding="utf-8"?><Error><Code>AuthorizationPermissionMismatch</Code><Message>This request is not authorized to perform this operation using this permission.
RequestId:3a514f5e-301e-0020-63c8-15d63c000000
Time:2026-07-17T08:44:11.8223877Z</Message></Error>
--------------------------------------------------------------------------------
⊘ I refer to "{result}" as "readResult" (skipped)
⊘ I attach "{result}" to the test output as "read-protected-object.json" (skipped)
⊘ "{readResult.Name}" is "readable-protected-object={timestamp}.txt" (skipped) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Service enables versioning and objects receive unique version identifiers ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "IsBucketVersioningEnabled" using argument "{resource-name}"
✓ "{result}" is true
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "versioned-object.txt", and "test content"
✓ I refer to "{result}" as "createdObject"
? "{createdObject.VersionID}" is not empty (undefined)
⊘ I attach "{result}" to the test output as "versioned-object.json" (skipped) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Modified objects receive new version identifiers ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "version-test-object={timestamp}.txt", and "original content"
✓ I refer to "{result.VersionID}" as "version1"
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "version-test-object={timestamp}.txt", and "modified content"
✓ I refer to "{result.VersionID}" as "version2"
? "{version1}" is not equal to "{version2}" (undefined) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Modified objects receive new version identifiers ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "version-test-object={timestamp}.txt", and "original content"
✓ I refer to "{result.VersionID}" as "version1"
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "version-test-object={timestamp}.txt", and "modified content"
✓ I refer to "{result.VersionID}" as "version2"
✓ I call "{storage}" with "ReadObjectAtVersion" using arguments "{resource-name}", "version-test-object={timestamp}.txt", and "{version1}"
✓ I attach "{result}" to the test output as "original-content.json"
✓ "{result.Data}" contains "original content"
✓ I call "{storage}" with "ReadObjectAtVersion" using arguments "{resource-name}", "version-test-object={timestamp}.txt", and "{version2}"
✗ "{result.Data}" contains "modified content" - Error: expected {result.Data} to contain 'modified content', but got '[original content]'
⊘ I attach "{result}" to the test output as "modified-content.json" (skipped) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Deleted object data can be reloaded from previous version ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "recover-deleted-object={timestamp}.txt", and "data to retain"
✓ I refer to "{result.VersionID}" as "retainedVersionId"
✓ I call "{storage}" with "DeleteObject" using arguments "{resource-name}" and "recover-deleted-object={timestamp}.txt"
✓ I call "{storage}" with "ReadObjectAtVersion" using arguments "{resource-name}", "recover-deleted-object={timestamp}.txt", and "{retainedVersionId}"
✓ "{result.Data}" contains "data to retain"
✓ I attach "{result}" to the test output as "recovered-deleted-version.json" | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Deleted object version remains in version list ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "list-deleted-versions-object={timestamp}.txt", and "versioned data"
✓ I refer to "{result.VersionID}" as "listedVersionId"
✓ I call "{storage}" with "DeleteObject" using arguments "{resource-name}" and "list-deleted-versions-object={timestamp}.txt"
✓ I call "{storage}" with "ListObjectVersions" using arguments "{resource-name}" and "list-deleted-versions-object={timestamp}.txt"
✗ "{result}" is an array of objects with at least the following contents - Error: expected row not found: map[ObjectID:list-deleted-versions-object={timestamp}.txt VersionID:{listedVersionId}]
⊘ I attach "{result}" to the test output as "versions-after-delete.json" (skipped) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | MFA requirement for destructive operations cannot be tested automatically - NotTestable ✓ a cloud api for "{config}" in "api"
✓ no-op required | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Verify admin actions are logged with identity and timestamp ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "{service-type}"
✓ I refer to "{result}" as "theService"
✓ I call "{api}" with "GetServiceAPI" using argument "logging"
✓ I refer to "{result}" as "loggingService"
✓ I call "{theService}" with "UpdateResourcePolicy"
✓ "{result}" is not an error
✓ I attach "{result}" to the test output as "Policy Update Result"
✓ we wait for a period of "10000" ms
✓ I call "{loggingService}" with "QueryLogs" using arguments "{resource-name}", "admin", and "{20}"
✓ "{result}" is not an error
✓ I refer to "{result}" as "adminLogs"
✓ I attach "{adminLogs}" to the test output as "Admin Activity Logs"
✗ "{adminLogs}" is an array of objects with at least the following contents - Error: expected row not found: map[result:Succeeded] | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Verify data modifications are logged with identity and timestamp ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "{service-type}"
✓ I refer to "{result}" as "theService"
✓ I call "{api}" with "GetServiceAPI" using argument "logging"
✓ I refer to "{result}" as "loggingService"
✓ I call "{theService}" with "TriggerDataWrite" using argument "{resource-name}"
✓ I attach "{result}" to the test output as "Data Write Trigger Result"
✓ we wait for a period of "10000" ms
✓ I call "{loggingService}" with "QueryLogs" using arguments "{resource-name}", "data-write", and "{20}"
✓ I refer to "{result}" as "dataLogs"
✓ I attach "{dataLogs}" to the test output as "Data Write Logs"
✗ "{dataLogs}" is an array of objects with at least the following contents - Error: expected row not found: map[result:Succeeded] | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Verify data read operations are logged with identity and timestamp ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "{service-type}"
✓ I refer to "{result}" as "theService"
✓ I call "{api}" with "GetServiceAPI" using argument "logging"
✓ I refer to "{result}" as "loggingService"
✓ I call "{theService}" with "TriggerDataRead" using argument "{resource-name}"
✓ I attach "{result}" to the test output as "Data Read Trigger Result"
✓ we wait for a period of "10000" ms
✓ I call "{loggingService}" with "QueryLogs" using arguments "{resource-name}", "data-read", and "{20}"
✓ "{result}" is not an error
✓ I refer to "{result}" as "readLogs"
✓ I attach "{readLogs}" to the test output as "Data Read Logs"
✗ "{readLogs}" is an array of objects with at least the following contents - Error: expected row not found: map[result:Succeeded] | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Service prevents data read by user with no access ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "{service-type}" and "test-user-no-access"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userReadableService"
✓ I call "{userReadableService}" with "TriggerDataRead" using argument "{resource-name}"
✓ "{result}" is an error
✓ I attach "{result}" to the test output as "no-access-trigger-data-read-error.txt" | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Enumeration event publishing cannot be tested automatically - NotTestable ✓ a cloud api for "{config}" in "api"
✓ no-op required | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Enumeration logging cannot be verified automatically - NotTestable ✓ a cloud api for "{config}" in "api"
✓ no-op required | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Replication destination trust cannot be verified automatically - NotTestable ✓ a cloud api for "{config}" in "api"
✓ no-op required | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Service accepts TLS 1.3 encrypted traffic ✓ a cloud api for "{config}" in "api"
✓ an openssl s_client request using "tls1_3" to "{port-number}" on "{host-name}" protocol "{protocol}"
✓ I refer to "{result}" as "connection"
✓ "{connection}" state is open
✓ "{connection.State}" is "open"
✓ I close connection "{connection}"
✓ "{connection}" state is closed | finoscccintegrationmain.blob.core.windows.net | object-storage | ||
| PASS | Service rejects TLS 1.2 traffic ✓ a cloud api for "{config}" in "api"
✓ an openssl s_client request using "tls1_2" to "{port-number}" on "{host-name}" protocol "{protocol}"
✓ I refer to "{result}" as "connection"
✓ we wait for a period of "40" ms
✓ "{connection.State}" is "closed" | finoscccintegrationmain.blob.core.windows.net | object-storage | ||
| PASS | Service rejects TLS 1.1 traffic ✓ a cloud api for "{config}" in "api"
✓ an openssl s_client request using "tls1_1" to "{port-number}" on "{host-name}" protocol "{protocol}"
✓ I refer to "{result}" as "connection"
✓ we wait for a period of "40" ms
✓ "{connection.State}" is "closed" | finoscccintegrationmain.blob.core.windows.net | object-storage | ||
| PASS | Service rejects TLS 1.0 traffic ✓ a cloud api for "{config}" in "api"
✓ an openssl s_client request using "tls1" to "{port-number}" on "{host-name}" protocol "{protocol}"
✓ I refer to "{result}" as "connection"
✓ we wait for a period of "40" ms
✓ "{connection.State}" is "closed" | finoscccintegrationmain.blob.core.windows.net | object-storage | ||
| FAIL | Verify SSL/TLS protocol support ✓ a cloud api for "{config}" in "api"
✗ "report" contains details of SSL Support type "protocols" for "{host-name}" on port "{port-number}" - Error: failed to read testssl.sh output: open /tmp/testssl_protocols_finoscccintegrationmain.blob.core.windows.net_443.json: no such file or directory
⊘ "{report}" is an array of objects which doesn't contain any of (skipped)
⊘ "{report}" is an array of objects with at least the following contents (skipped) | finoscccintegrationmain.blob.core.windows.net | object-storage | ||
| FAIL | Verify no known SSL/TLS vulnerabilities ✓ a cloud api for "{config}" in "api"
✗ "report" contains details of SSL Support type "vulnerable" for "{host-name}" on port "{port-number}" - Error: failed to read testssl.sh output: open /tmp/testssl_vulnerable_finoscccintegrationmain.blob.core.windows.net_443.json: no such file or directory
⊘ "{report}" is an array of objects with at least the following contents (skipped) | finoscccintegrationmain.blob.core.windows.net | object-storage | ||
| FAIL | Verify TLS 1.3 only certificate validity ✓ a cloud api for "{config}" in "api"
✗ "report" contains details of SSL Support type "server-defaults" for "{host-name}" on port "{port-number}" - Error: failed to read testssl.sh output: open /tmp/testssl_server-defaults_finoscccintegrationmain.blob.core.windows.net_443.json: no such file or directory
⊘ "{report}" is an array of objects with at least the following contents (skipped) | finoscccintegrationmain.blob.core.windows.net | object-storage | ||
| PASS | HTTP redirects to HTTPS ✓ a client connects to "{host-name}" with protocol "http" on port "80"
✓ I refer to "{result}" as "connection"
✓ "{connection}" is not an error
✓ I transmit "GET / HTTP/1.1\r\nHost: {host-name}\r\n\r\n" to "{connection}"
✓ I attach "{connection}" to the test output as "HTTP response"
✓ "{connection.Output}" contains "301"
✓ I call "{connection}" with "Close"
✓ "{connection.State}" is "closed" | finoscccintegrationmain.blob.core.windows.net | object-storage | ||
| FAIL | Only secure protocols are exposed ✗ "report" contains details of SSL Support type "protocols" for "{host-name}" on port "{port-number}" - Error: failed to read testssl.sh output: open /tmp/testssl_protocols_finoscccintegrationmain.blob.core.windows.net_443.json: no such file or directory
⊘ "{report}" is an array of objects with at least the following contents (skipped) | finoscccintegrationmain.blob.core.windows.net | object-storage | ||
| PASS | Verify HTTPS uses IANA-assigned port 443 ✓ "{port-number}" is "443" | finoscccintegrationmain.blob.core.windows.net | object-storage | ||
| FAIL | Verify mTLS requires client certificate authentication ✗ "report" contains details of SSL Support type "server-defaults" for "{host-name}" on port "{port-number}" - Error: failed to read testssl.sh output: open /tmp/testssl_server-defaults_finoscccintegrationmain.blob.core.windows.net_443.json: no such file or directory
⊘ "{report}" is an array of objects with at least the following contents (skipped) | finoscccintegrationmain.blob.core.windows.net | object-storage | ||
| PASS | Verify objects are encrypted at rest ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ "{result}" is not an error
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "test-encryption-check={timestamp}.txt", and "encryption test data"
✓ "{result}" is not an error
✓ I refer to "{result}" as "uploadResult"
✓ "{uploadResult.Encryption}" is not null
✓ "{uploadResult.EncryptionAlgorithm}" is "AES256"
✓ I attach "{uploadResult}" to the test output as "Upload Result with Encryption Details" | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Service prevents data modification by user with no access ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-no-access"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "CreateObject" using arguments "{resource-name}", "test-cn05-unauthorized-modify={timestamp}.txt", and "unauthorized data"
✓ "{result}" is an error
✓ I attach "{result}" to the test output as "no-access-create-error.txt" | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Service allows data modification by user with write access ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-write"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "CreateObject" using arguments "{resource-name}", "test-cn05-authorized-modify={timestamp}.txt", and "authorized data"
✗ "{result}" is not an error - Error: expected {result} to not be an error, but got: failed to upload blob test-cn05-authorized-modify=1784277841329.txt: PUT https://finoscccintegrationmain.blob.core.windows.net/finos-ccc-integration-container-main/test-cn05-authorized-modify=1784277841329.txt
--------------------------------------------------------------------------------
RESPONSE 403: 403 This request is not authorized to perform this operation using this permission.
ERROR CODE: AuthorizationPermissionMismatch
--------------------------------------------------------------------------------
<?xml version="1.0" encoding="utf-8"?><Error><Code>AuthorizationPermissionMismatch</Code><Message>This request is not authorized to perform this operation using this permission.
RequestId:3a51344a-301e-0020-29c8-15d63c000000
Time:2026-07-17T08:44:01.7357820Z</Message></Error>
--------------------------------------------------------------------------------
⊘ I attach "{result}" to the test output as "write-create-object-result.json" (skipped) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Service prevents administrative action (creating a new bucket) by user with no access ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-no-access"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "CreateBucket" using argument "test-cn05-unauthorized-admin-container"
✓ "{result}" is an error
✓ I attach "{result}" to the test output as "no-admin-create-bucket-error.txt" | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Service prevents administrative action (creating a new bucket) by user with read-only access ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-read"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "CreateBucket" using argument "test-cn05-read-only-create-container"
✓ "{result}" is an error
✓ I attach "{result}" to the test output as "read-only-create-bucket-error.txt" | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Service allows administrative action (creating a new bucket) by user with admin access ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-admin"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "CreateBucket" using argument "test-cn05-authorized-admin-container"
✗ "{result}" is not an error - Error: expected {result} to not be an error, but got: failed to create container: failed to create container test-cn05-authorized-admin-container: PUT https://finoscccintegrationmain.blob.core.windows.net/test-cn05-authorized-admin-container
--------------------------------------------------------------------------------
RESPONSE 403: 403 This request is not authorized to perform this operation.
ERROR CODE: AuthorizationFailure
--------------------------------------------------------------------------------
<?xml version="1.0" encoding="utf-8"?><Error><Code>AuthorizationFailure</Code><Message>This request is not authorized to perform this operation.
RequestId:3a513662-301e-0020-70c8-15d63c000000
Time:2026-07-17T08:44:02.5274179Z</Message></Error>
--------------------------------------------------------------------------------
⊘ I attach "{result}" to the test output as "admin-create-bucket-result.json" (skipped)
⊘ I call "{storage}" with "DeleteBucket" using argument "test-cn05-authorized-admin-container" (skipped) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Child resource region compliance - NotTestable ✓ a cloud api for "{config}" in "api"
✓ no-op required | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Bucket data is replicated to physically separate locations ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "GetReplicationStatus" using argument "{resource-name}"
✓ I refer to "{result}" as "replicationStatus"
✓ I refer to "{replicationStatus.Locations}" as "locations"
✓ I attach "{replicationStatus}" to the test output as "Replication Status"
✗ "{locations}" is an array of objects with length "2" - Error: expected length 2, got 1
⊘ "{permitted-regions}" is an array of objects with at least the following contents (skipped)
⊘ "{permitted-regions}" is an array of objects with at least the following contents (skipped) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Replication status can be retrieved for monitoring ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "GetReplicationStatus" using argument "{resource-name}"
✓ I refer to "{result}" as "replicationStatus"
✓ I attach "{replicationStatus}" to the test output as "Replication Status"
✓ I refer to "{replicationStatus.Locations}" as "locations"
✗ "{locations}" is an array of objects with at least the following contents - Error: expected row not found: map[value:{replication-locations[0]}] | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Service prevents reading bucket with no access ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-no-access"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "ListObjects" using argument "{resource-name}"
✓ "{result}" is an error
✓ I attach "{result}" to the test output as "no-access-list-error.txt" | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Service allows reading bucket with read access ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-read"
✓ "{result}" is not an error
✓ I attach "{result}" to the test output as "read-storage-service.json"
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "ListObjects" using argument "{resource-name}"
✗ "{result}" is not an error - Error: expected {result} to not be an error, but got: failed to list blobs: GET https://finoscccintegrationmain.blob.core.windows.net/finos-ccc-integration-container-main
--------------------------------------------------------------------------------
RESPONSE 403: 403 This request is not authorized to perform this operation using this permission.
ERROR CODE: AuthorizationPermissionMismatch
--------------------------------------------------------------------------------
<?xml version="1.0" encoding="utf-8"?><Error><Code>AuthorizationPermissionMismatch</Code><Message>This request is not authorized to perform this operation using this permission.
RequestId:3a5137a2-301e-0020-7dc8-15d63c000000
Time:2026-07-17T08:44:03.0115745Z</Message></Error>
--------------------------------------------------------------------------------
⊘ I attach "{result}" to the test output as "read-list-objects-result.json" (skipped) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Service prevents reading object with no access ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "test-object={timestamp}.txt", and "test content"
✓ "{result}" is not an error
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-no-access"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "ReadObject" using arguments "{resource-name}" and "test-object={timestamp}.txt"
✓ "{result}" is an error
✓ I attach "{result}" to the test output as "no-access-read-object-error.txt" | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Service allows reading object with read access ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "test-object={timestamp}.txt", and "test content"
✓ "{result}" is not an error
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-read"
✓ "{result}" is not an error
✓ I attach "{result}" to the test output as "read-storage-service.json"
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "ReadObject" using arguments "{resource-name}" and "test-object={timestamp}.txt"
✗ "{result}" is not an error - Error: expected {result} to not be an error, but got: failed to download blob test-object=1784277843536.txt: GET https://finoscccintegrationmain.blob.core.windows.net/finos-ccc-integration-container-main/test-object=1784277843536.txt
--------------------------------------------------------------------------------
RESPONSE 403: 403 This request is not authorized to perform this operation using this permission.
ERROR CODE: AuthorizationPermissionMismatch
--------------------------------------------------------------------------------
<?xml version="1.0" encoding="utf-8"?><Error><Code>AuthorizationPermissionMismatch</Code><Message>This request is not authorized to perform this operation using this permission.
RequestId:3a513a4f-301e-0020-4bc8-15d63c000000
Time:2026-07-17T08:44:04.0200699Z</Message></Error>
--------------------------------------------------------------------------------
⊘ I attach "{result}" to the test output as "read-read-object-result.json" (skipped) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Service prevents creating bucket with no access ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-no-access"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "CreateBucket" using argument "test-bucket-no-access"
✓ "{result}" is an error
✓ I attach "{result}" to the test output as "no-access-create-bucket-error.txt" | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Service allows creating bucket with write access ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-write"
✓ "{result}" is not an error
✓ I attach "{result}" to the test output as "write-storage-service.json"
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "CreateBucket" using argument "test-bucket-write"
✗ "{result}" is not an error - Error: expected {result} to not be an error, but got: failed to create container: failed to create container test-bucket-write: PUT https://finoscccintegrationmain.blob.core.windows.net/test-bucket-write
--------------------------------------------------------------------------------
RESPONSE 403: 403 This request is not authorized to perform this operation.
ERROR CODE: AuthorizationFailure
--------------------------------------------------------------------------------
<?xml version="1.0" encoding="utf-8"?><Error><Code>AuthorizationFailure</Code><Message>This request is not authorized to perform this operation.
RequestId:3a513a90-301e-0020-7ec8-15d63c000000
Time:2026-07-17T08:44:04.1051111Z</Message></Error>
--------------------------------------------------------------------------------
⊘ I attach "{result}" to the test output as "write-create-bucket-result.json" (skipped)
⊘ I call "{storage}" with "DeleteBucket" using argument "{result.ID}" (skipped) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Service prevents writing object with read-only access ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ "{result}" is not an error
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-read"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "CreateObject" using arguments "{resource-name}", "test-write-object={timestamp}.txt", and "test content"
✓ "{result}" is an error
✓ I attach "{result}" to the test output as "read-create-object-error.txt" | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Service allows writing object with write access ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ "{result}" is not an error
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-write"
✓ "{result}" is not an error
✓ I attach "{result}" to the test output as "write-storage-service.json"
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "CreateObject" using arguments "{resource-name}", "test-write-object={timestamp}.txt", and "test content"
✗ "{result}" is not an error - Error: expected {result} to not be an error, but got: failed to upload blob test-write-object=1784277844172.txt: PUT https://finoscccintegrationmain.blob.core.windows.net/finos-ccc-integration-container-main/test-write-object=1784277844172.txt
--------------------------------------------------------------------------------
RESPONSE 403: 403 This request is not authorized to perform this operation using this permission.
ERROR CODE: AuthorizationPermissionMismatch
--------------------------------------------------------------------------------
<?xml version="1.0" encoding="utf-8"?><Error><Code>AuthorizationPermissionMismatch</Code><Message>This request is not authorized to perform this operation using this permission.
RequestId:3a513ae6-301e-0020-43c8-15d63c000000
Time:2026-07-17T08:44:04.1916758Z</Message></Error>
--------------------------------------------------------------------------------
⊘ I attach "{result}" to the test output as "write-create-object-result.json" (skipped) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Service enforces uniform bucket-level access by rejecting object-level permissions ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "test-object={timestamp}.txt", and "test data"
✓ "{result}" is not an error
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-read"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "ReadObject" using arguments "{resource-name}" and "test-object={timestamp}.txt"
✗ "{result}" is not an error - Error: expected {result} to not be an error, but got: failed to download blob test-object=1784277844214.txt: GET https://finoscccintegrationmain.blob.core.windows.net/finos-ccc-integration-container-main/test-object=1784277844214.txt
--------------------------------------------------------------------------------
RESPONSE 403: 403 This request is not authorized to perform this operation using this permission.
ERROR CODE: AuthorizationPermissionMismatch
--------------------------------------------------------------------------------
<?xml version="1.0" encoding="utf-8"?><Error><Code>AuthorizationPermissionMismatch</Code><Message>This request is not authorized to perform this operation using this permission.
RequestId:3a513c95-301e-0020-3fc8-15d63c000000
Time:2026-07-17T08:44:04.7062053Z</Message></Error>
--------------------------------------------------------------------------------
⊘ I call "{storage}" with "SetObjectPermission" using arguments "{resource-name}", "test-object={timestamp}.txt", and "none" (skipped)
⊘ "{result}" is an error (skipped)
⊘ I attach "{result}" to the test output as "set-object-permission-error.txt" (skipped)
⊘ I call "{userStorage}" with "ReadObject" using arguments "{resource-name}" and "test-object={timestamp}.txt" (skipped)
⊘ "{result}" is not an error (skipped) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Service enforces uniform bucket-level access denial ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "test-object={timestamp}.txt", and "test data"
✓ "{result}" is not an error
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-no-access"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "ReadObject" using arguments "{resource-name}" and "test-object={timestamp}.txt"
✓ "{result}" is an error
✓ I call "{storage}" with "SetObjectPermission" using arguments "{resource-name}", "test-object={timestamp}.txt", and "read"
✓ "{result}" is an error
✓ I attach "{result}" to the test output as "set-object-permission-error.txt"
✓ I call "{userStorage}" with "ReadObject" using arguments "{resource-name}" and "test-object={timestamp}.txt"
✓ "{result}" is an error | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Service supports bucket soft delete and recovery ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "CreateBucket" using argument "ccc-test-soft-delete"
✓ "{result}" is not an error
✓ I refer to "{result}" as "testBucket"
✓ I attach "{result}" to the test output as "created-bucket.json"
✓ I call "{storage}" with "DeleteBucket" using argument "ccc-test-soft-delete"
✓ "{result}" is not an error
✓ I call "{storage}" with "ListDeletedBuckets"
✓ "{result}" is not an error
✓ I attach "{result}" to the test output as "deleted-buckets.json"
✗ "{result}" is an array of objects with length "1" - Error: expected length 1, got 0
⊘ I call "{storage}" with "RestoreBucket" using argument "ccc-test-soft-delete" (skipped)
⊘ "{result}" is not an error (skipped)
⊘ I call "{storage}" with "ListBuckets" (skipped)
⊘ "{result}" is not an error (skipped)
⊘ I attach "{result}" to the test output as "restored-buckets.json" (skipped)
⊘ I call "{storage}" with "DeleteBucket" using argument "ccc-test-soft-delete" (skipped)
⊘ "{result}" is not an error (skipped) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Service prevents modification of locked retention policy ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "GetBucketRetentionDurationDays" using argument "{resource-name}"
✓ "{result}" is not an error
✓ I refer to "{result}" as "originalRetention"
✓ I attach "{result}" to the test output as "original-retention-days.txt"
✓ "{result}" should be greater than "0"
✓ I call "{storage}" with "SetBucketRetentionDurationDays" using arguments "{resource-name}" and "1"
✗ "{result}" is an error - Error: expected {result} to be an error, got <nil>
⊘ I attach "{result}" to the test output as "set-retention-error.txt" (skipped)
⊘ I call "{storage}" with "GetBucketRetentionDurationDays" using argument "{resource-name}" (skipped)
⊘ "{result}" is not an error (skipped)
⊘ "{result}" should be greater than "0" (skipped) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Service applies default retention policy to newly uploaded object ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-write"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "CreateObject" using arguments "{resource-name}", "test-retention-object={timestamp}.txt", and "protected data"
✓ I attach "{result}" to the test output as "uploaded-object.json"
✓ I call "{userStorage}" with "GetObjectRetentionDurationDays" using arguments "{resource-name}" and "test-retention-object={timestamp}.txt"
✗ "{result}" should be greater than "1" - Error: cannot parse {result} as number: strconv.ParseFloat: parsing "failed to get blob properties: HEAD https://finoscccintegrationmain.blob.core.windows.net/finos-ccc-integration-container-main/test-retention-object=1784277847983.txt\n--------------------------------------------------------------------------------\nRESPONSE 403: 403 This request is not authorized to perform this operation using this permission.\nERROR CODE: AuthorizationPermissionMismatch\n--------------------------------------------------------------------------------\nResponse contained no body\n--------------------------------------------------------------------------------\n": invalid syntax | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Service enforces retention policy on newly created objects ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "immediate-delete-test={timestamp}.txt", and "test content"
✓ "{result}" is not an error
✓ I call "{storage}" with "DeleteObject" using arguments "{resource-name}" and "immediate-delete-test={timestamp}.txt"
✓ "{result}" is an error
✓ I attach "{result}" to the test output as "immediate-delete-error.txt" | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Service validates retention period meets minimum requirements ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "retention-period-test={timestamp}.txt", and "compliance data"
✓ I call "{storage}" with "GetObjectRetentionDurationDays" using arguments "{resource-name}" and "retention-period-test={timestamp}.txt"
✓ "{result}" should be greater than "1"
✓ I attach "{result}" to the test output as "retention-period-days.json" | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Service prevents object deletion by write user during retention period ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-write"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "CreateObject" using arguments "{resource-name}", "protected-object={timestamp}.txt", and "immutable data"
✗ "{result}" is not an error - Error: expected {result} to not be an error, but got: failed to upload blob protected-object=1784277850338.txt: PUT https://finoscccintegrationmain.blob.core.windows.net/finos-ccc-integration-container-main/protected-object=1784277850338.txt
--------------------------------------------------------------------------------
RESPONSE 403: 403 This request is not authorized to perform this operation using this permission.
ERROR CODE: AuthorizationPermissionMismatch
--------------------------------------------------------------------------------
<?xml version="1.0" encoding="utf-8"?><Error><Code>AuthorizationPermissionMismatch</Code><Message>This request is not authorized to perform this operation using this permission.
RequestId:3a514c11-301e-0020-06c8-15d63c000000
Time:2026-07-17T08:44:10.3573521Z</Message></Error>
--------------------------------------------------------------------------------
⊘ I attach "{result}" to the test output as "protected-object.json" (skipped)
⊘ I call "{userStorage}" with "DeleteObject" using arguments "{resource-name}" and "protected-object={timestamp}.txt" (skipped)
⊘ "{result}" is an error (skipped)
⊘ I attach "{result}" to the test output as "delete-protected-error.txt" (skipped)
? "{result}" should contain one of "retention, locked, immutable, protected" (undefined) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Service prevents object deletion by admin user during retention period ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "admin-protected-object={timestamp}.txt", and "compliance data"
✓ "{result}" is not an error
✓ I call "{storage}" with "DeleteObject" using arguments "{resource-name}" and "admin-protected-object={timestamp}.txt"
✓ "{result}" is an error
✓ I attach "{result}" to the test output as "admin-delete-protected-error.txt" | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Service prevents object modification during retention period ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-write"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "CreateObject" using arguments "{resource-name}", "modify-test-object={timestamp}.txt", and "original content"
✗ "{result}" is not an error - Error: expected {result} to not be an error, but got: failed to upload blob modify-test-object=1784277851311.txt: PUT https://finoscccintegrationmain.blob.core.windows.net/finos-ccc-integration-container-main/modify-test-object=1784277851311.txt
--------------------------------------------------------------------------------
RESPONSE 403: 403 This request is not authorized to perform this operation using this permission.
ERROR CODE: AuthorizationPermissionMismatch
--------------------------------------------------------------------------------
<?xml version="1.0" encoding="utf-8"?><Error><Code>AuthorizationPermissionMismatch</Code><Message>This request is not authorized to perform this operation using this permission.
RequestId:3a514e1f-301e-0020-49c8-15d63c000000
Time:2026-07-17T08:44:11.3292583Z</Message></Error>
--------------------------------------------------------------------------------
⊘ I attach "{result}" to the test output as "original-object.json" (skipped)
⊘ I call "{userStorage}" with "CreateObject" using arguments "{resource-name}", "modify-test-object={timestamp}.txt", and "modified content" (skipped)
⊘ "{result}" is an error (skipped)
⊘ I attach "{result}" to the test output as "modify-protected-error.txt" (skipped)
? "{result}" should contain one of "retention, locked, immutable, protected, exists" (undefined) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Service allows object read access during retention period ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "readable-protected-object={timestamp}.txt", and "readable data"
✓ "{result}" is not an error
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "object-storage" and "test-user-read"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userStorage"
✓ I call "{userStorage}" with "ReadObject" using arguments "{resource-name}" and "readable-protected-object={timestamp}.txt"
✗ "{result}" is not an error - Error: expected {result} to not be an error, but got: failed to download blob readable-protected-object=1784277851352.txt: GET https://finoscccintegrationmain.blob.core.windows.net/finos-ccc-integration-container-main/readable-protected-object=1784277851352.txt
--------------------------------------------------------------------------------
RESPONSE 403: 403 This request is not authorized to perform this operation using this permission.
ERROR CODE: AuthorizationPermissionMismatch
--------------------------------------------------------------------------------
<?xml version="1.0" encoding="utf-8"?><Error><Code>AuthorizationPermissionMismatch</Code><Message>This request is not authorized to perform this operation using this permission.
RequestId:3a514f5e-301e-0020-63c8-15d63c000000
Time:2026-07-17T08:44:11.8223877Z</Message></Error>
--------------------------------------------------------------------------------
⊘ I refer to "{result}" as "readResult" (skipped)
⊘ I attach "{result}" to the test output as "read-protected-object.json" (skipped)
⊘ "{readResult.Name}" is "readable-protected-object={timestamp}.txt" (skipped) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Service enables versioning and objects receive unique version identifiers ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "IsBucketVersioningEnabled" using argument "{resource-name}"
✓ "{result}" is true
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "versioned-object.txt", and "test content"
✓ I refer to "{result}" as "createdObject"
? "{createdObject.VersionID}" is not empty (undefined)
⊘ I attach "{result}" to the test output as "versioned-object.json" (skipped) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Modified objects receive new version identifiers ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "version-test-object={timestamp}.txt", and "original content"
✓ I refer to "{result.VersionID}" as "version1"
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "version-test-object={timestamp}.txt", and "modified content"
✓ I refer to "{result.VersionID}" as "version2"
? "{version1}" is not equal to "{version2}" (undefined) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Modified objects receive new version identifiers ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "version-test-object={timestamp}.txt", and "original content"
✓ I refer to "{result.VersionID}" as "version1"
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "version-test-object={timestamp}.txt", and "modified content"
✓ I refer to "{result.VersionID}" as "version2"
✓ I call "{storage}" with "ReadObjectAtVersion" using arguments "{resource-name}", "version-test-object={timestamp}.txt", and "{version1}"
✓ I attach "{result}" to the test output as "original-content.json"
✓ "{result.Data}" contains "original content"
✓ I call "{storage}" with "ReadObjectAtVersion" using arguments "{resource-name}", "version-test-object={timestamp}.txt", and "{version2}"
✗ "{result.Data}" contains "modified content" - Error: expected {result.Data} to contain 'modified content', but got '[original content]'
⊘ I attach "{result}" to the test output as "modified-content.json" (skipped) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Deleted object data can be reloaded from previous version ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "recover-deleted-object={timestamp}.txt", and "data to retain"
✓ I refer to "{result.VersionID}" as "retainedVersionId"
✓ I call "{storage}" with "DeleteObject" using arguments "{resource-name}" and "recover-deleted-object={timestamp}.txt"
✓ I call "{storage}" with "ReadObjectAtVersion" using arguments "{resource-name}", "recover-deleted-object={timestamp}.txt", and "{retainedVersionId}"
✓ "{result.Data}" contains "data to retain"
✓ I attach "{result}" to the test output as "recovered-deleted-version.json" | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Deleted object version remains in version list ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "object-storage"
✓ I refer to "{result}" as "storage"
✓ I call "{storage}" with "CreateObject" using arguments "{resource-name}", "list-deleted-versions-object={timestamp}.txt", and "versioned data"
✓ I refer to "{result.VersionID}" as "listedVersionId"
✓ I call "{storage}" with "DeleteObject" using arguments "{resource-name}" and "list-deleted-versions-object={timestamp}.txt"
✓ I call "{storage}" with "ListObjectVersions" using arguments "{resource-name}" and "list-deleted-versions-object={timestamp}.txt"
✗ "{result}" is an array of objects with at least the following contents - Error: expected row not found: map[ObjectID:list-deleted-versions-object={timestamp}.txt VersionID:{listedVersionId}]
⊘ I attach "{result}" to the test output as "versions-after-delete.json" (skipped) | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | MFA requirement for destructive operations cannot be tested automatically - NotTestable ✓ a cloud api for "{config}" in "api"
✓ no-op required | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Verify admin actions are logged with identity and timestamp ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "{service-type}"
✓ I refer to "{result}" as "theService"
✓ I call "{api}" with "GetServiceAPI" using argument "logging"
✓ I refer to "{result}" as "loggingService"
✓ I call "{theService}" with "UpdateResourcePolicy"
✓ "{result}" is not an error
✓ I attach "{result}" to the test output as "Policy Update Result"
✓ we wait for a period of "10000" ms
✓ I call "{loggingService}" with "QueryLogs" using arguments "{resource-name}", "admin", and "{20}"
✓ "{result}" is not an error
✓ I refer to "{result}" as "adminLogs"
✓ I attach "{adminLogs}" to the test output as "Admin Activity Logs"
✗ "{adminLogs}" is an array of objects with at least the following contents - Error: expected row not found: map[result:Succeeded] | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Verify data modifications are logged with identity and timestamp ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "{service-type}"
✓ I refer to "{result}" as "theService"
✓ I call "{api}" with "GetServiceAPI" using argument "logging"
✓ I refer to "{result}" as "loggingService"
✓ I call "{theService}" with "TriggerDataWrite" using argument "{resource-name}"
✓ I attach "{result}" to the test output as "Data Write Trigger Result"
✓ we wait for a period of "10000" ms
✓ I call "{loggingService}" with "QueryLogs" using arguments "{resource-name}", "data-write", and "{20}"
✓ I refer to "{result}" as "dataLogs"
✓ I attach "{dataLogs}" to the test output as "Data Write Logs"
✗ "{dataLogs}" is an array of objects with at least the following contents - Error: expected row not found: map[result:Succeeded] | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| FAIL | Verify data read operations are logged with identity and timestamp ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPI" using argument "{service-type}"
✓ I refer to "{result}" as "theService"
✓ I call "{api}" with "GetServiceAPI" using argument "logging"
✓ I refer to "{result}" as "loggingService"
✓ I call "{theService}" with "TriggerDataRead" using argument "{resource-name}"
✓ I attach "{result}" to the test output as "Data Read Trigger Result"
✓ we wait for a period of "10000" ms
✓ I call "{loggingService}" with "QueryLogs" using arguments "{resource-name}", "data-read", and "{20}"
✓ "{result}" is not an error
✓ I refer to "{result}" as "readLogs"
✓ I attach "{readLogs}" to the test output as "Data Read Logs"
✗ "{readLogs}" is an array of objects with at least the following contents - Error: expected row not found: map[result:Succeeded] | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Service prevents data read by user with no access ✓ a cloud api for "{config}" in "api"
✓ I call "{api}" with "GetServiceAPIWithIdentity" using arguments "{service-type}" and "test-user-no-access"
✓ "{result}" is not an error
✓ I refer to "{result}" as "userReadableService"
✓ I call "{userReadableService}" with "TriggerDataRead" using argument "{resource-name}"
✓ "{result}" is an error
✓ I attach "{result}" to the test output as "no-access-trigger-data-read-error.txt" | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Enumeration event publishing cannot be tested automatically - NotTestable ✓ a cloud api for "{config}" in "api"
✓ no-op required | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Enumeration logging cannot be verified automatically - NotTestable ✓ a cloud api for "{config}" in "api"
✓ no-op required | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage | ||
| PASS | Replication destination trust cannot be verified automatically - NotTestable ✓ a cloud api for "{config}" in "api"
✓ no-op required | /subscriptions/c1cedd8e-bf91-4d7d-a4cc-45700402a2a1/resourceGroups/finos-ccc-integration-rg/providers/Microsoft.Storage/storageAccounts/finoscccintegrationmain | object-storage |