# M2 TDD Evidence ## RED — behavioral contracts absent Commit command: ```bash .venv/bin/python -m pytest tests/unit/test_redaction.py \ tests/contract/test_api_conventions.py tests/integration/test_auth.py \ tests/security/test_auth.py tests/security/test_leakage_scan.py -q ``` Observed before implementation on 2026-07-27: - Exit: `1` - Result: `4 failed, 13 errors` - Intended causes: `backup_tool.api`, `backup_tool.security`, and `tools/leakage_scan.py` did not exist. Tests described setup, authentication, CSRF, token, secret, audit, pagination, ETag, idempotency, readiness, and leakage behavior through public interfaces. ## GREEN — secure control plane ```bash make check .venv/bin/python -m pytest tests/unit/test_redaction.py \ tests/contract/test_api_conventions.py tests/integration/test_auth.py \ tests/security/test_auth.py tests/security/test_leakage_scan.py -q ``` Observed on 2026-07-27: - Focused M2 behavior suite: `17 passed`. - Complete local check: `39` unit/contract, `12` integration, and `3` security tests passed; Ruff, mypy, forbidden-v1 scan, TypeScript typecheck, and frontend build passed. - Security tests prove Argon2id hashes, encrypted secret persistence, CSRF, scoped/revoked/expired tokens, request-digest idempotency, problem details, request IDs, ETags, cursor pagination, setup race handling, readiness states, and output canary scanning.