"""allowlist_tool_calls must reject both a disallowed tool name and an allowed tool called with
arguments that don't match its schema -- a name-only check lets a malformed call through."""
from sec_prompt_injection import allowlist_tool_calls


def test_allowlist_tool_calls_blocks_disallowed_and_passes_allowed(tool_policy):
    calls = [
        {"name": "search", "arguments": {"query": "capital of France"}},
        {"name": "exec_shell", "arguments": {"cmd": "rm -rf /"}},
    ]
    allowed = allowlist_tool_calls(calls, tool_policy)
    assert allowed == [calls[0]], (
        f"exec_shell is not a key of the policy and must be blocked; search's call matches its "
        f"schema and must pass through unchanged -- got {allowed}"
    )


def test_allowlist_tool_calls_rejects_calls_that_fail_the_argument_schema(tool_policy):
    calls = [
        {"name": "search", "arguments": {"query": 123}},
        {"name": "get_weather", "arguments": {"city": "Paris"}},
        {"name": "search", "arguments": {}},
    ]
    allowed = allowlist_tool_calls(calls, tool_policy)
    assert allowed == [calls[1]], (
        f"search's first call has a non-string 'query' (123) and its third call is missing the "
        f"required 'query' argument -- both must be blocked even though 'search' is an allowed "
        f"tool name; only get_weather's valid call should pass -- got {allowed}"
    )
