The module is one Go binary the runtime launches: the renderer (its instruction file held byte for byte to the TypeScript one it replaces), the credentials and identity files, the licence flow of ADR 0206 and the MCP servers in state. Keeps the TypeScript module's key files, so a node moving to it keeps its key. The npm package, its tests and its build go. Both binaries were run together under the real runtime on a test bus with postgres and a stub vendor: a login was adopted by one exchange, the node bound and handed an access token, its file left with no refresh token, and no token in either state.
44 lines
1.1 KiB
Go
44 lines
1.1 KiB
Go
package main
|
|
|
|
import (
|
|
"encoding/json"
|
|
"os"
|
|
"testing"
|
|
)
|
|
|
|
// A box the agent module's TypeScript sealed opens here: the two implementations are one format.
|
|
func TestABoxSealedInTypeScriptOpensInGo(t *testing.T) {
|
|
raw, err := os.ReadFile("testdata/sealed-by-typescript.json")
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
var f struct {
|
|
PrivateKey string `json:"privateKey"`
|
|
Box SealedBox `json:"box"`
|
|
Plaintext string `json:"plaintext"`
|
|
}
|
|
if err := json.Unmarshal(raw, &f); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
got, err := Open(f.Box, f.PrivateKey)
|
|
if err != nil || got != f.Plaintext {
|
|
t.Fatalf("opened %q, %v", got, err)
|
|
}
|
|
}
|
|
|
|
// What Go seals opens with its own key and no other.
|
|
func TestABoxOpensOnlyForItsRecipient(t *testing.T) {
|
|
a, _ := GenerateKeyPair()
|
|
b, _ := GenerateKeyPair()
|
|
box, err := Seal("a token", a.PublicKey)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if got, err := Open(box, a.PrivateKey); err != nil || got != "a token" {
|
|
t.Fatalf("opened %q, %v", got, err)
|
|
}
|
|
if _, err := Open(box, b.PrivateKey); err == nil {
|
|
t.Fatal("a box opened for another key")
|
|
}
|
|
}
|