Rule templates

What each rule actually executes.

A rule is only as useful as its definition. Every template publishes the exact requests it sends and the exact conditions for PASS, FAIL and UNKNOWN. Nothing is inferred; nothing is hidden.

01Payments · Available

refund.amount-cap@1

Refunds never exceed the captured amount.

After a valid partial refund, a refund larger than the remaining captured amount is rejected with a client error and does not change the refunded total.

  • PASS

    The over-refund is rejected with a 4xx status and the refunded total does not change.

  • FAIL

    The over-refund is accepted, or it is rejected but the refunded total changes anyway.

  • UNKNOWN

    The payment cannot be created or read, the control refund is rejected or does not show in the total, or the over-refund gets neither a success nor a client error. Because the control refund must succeed, an application that rejects every refund cannot pass.

Amounts are integers in minor units. You configure the captured amount, the routes, the refund amount field and where to read the refunded total.

  1. 1 POST /payments · 100.00 201 · id Create a synthetic payment
  2. 2 GET refunded total 0.00 Read the refunded total
  3. 3 POST refund · 50.00 2xx Control refund of half: must be accepted
  4. 4 GET refunded total 50.00 The control refund shows
  5. 5 POST refund · 50.01 4xx Remaining amount plus one unit: must be rejected
  6. 6 GET refunded total 50.00 Must not have moved
Example values · your routes and amounts come from your rules file

02Access control · Available

http.auth-required@1

Each listed route refuses requests without credentials.

Every listed request is sent without credentials. Every response must be a denial.

  • PASS

    Every response is a denial: 401 or 403 by default, configurable with deniedStatuses.

  • FAIL

    Any request without credentials succeeds.

  • UNKNOWN

    Anything else, such as a server error or a redirect: it is neither a denial nor a success.

You list the requests by method and path. Denied statuses default to 401 and 403.

  1. 1 GET /admin/users · no credentials 401 / 403 Must be denied
  2. 2 PATCH /admin/roles/:id · no credentials 401 / 403 Must be denied
  3. 3 … every listed request 401 / 403 Each one, every time
Example values · your routes and amounts come from your rules file

Versions and withdrawal

A template is a contract. It is versioned like one.

  1. @1

    Templates are versioned, and your rules file pins the version, so what a check executes changes only when you change the pin.

  2. !

    A defect that can produce an incorrect PASS is treated as a security issue: affected teams are notified directly and a fixed release ships.

  3. ×

    The affected version is withdrawn. A check that names it reports UNKNOWN with template-withdrawn, never a silent pass.

  4. ✓

    A template is listed as available only after it is validated in a release. Two are available today.

Coming soon

Next in the catalog

Already defined in the engine. Not yet templates.

Each becomes a template when it is validated in a release, with the same published steps and conditions.

  • Isolation · planned

    A tenant cannot refund another tenant’s payment

  • Idempotency · planned

    Retrying the same refund cannot create a duplicate

  • Audit · planned

    Rejected refund attempts must be auditable

Point a template at your routes and read the verdict, in your browser.