Five passes are twenty-five seconds, shorter than a controller restart, a store reconnecting or a file half written; the operator asked for both (hq ADR 0230).
157 lines
4.0 KiB
Go
157 lines
4.0 KiB
Go
package main
|
|
|
|
// The shared harness, as postgres tests it (harness.go is the same file in both modules).
|
|
|
|
import (
|
|
"encoding/json"
|
|
"os"
|
|
"path/filepath"
|
|
"strings"
|
|
"testing"
|
|
"time"
|
|
)
|
|
|
|
type world struct {
|
|
t *testing.T
|
|
dir string
|
|
receives string
|
|
now time.Time
|
|
h *Harness
|
|
a *recorder
|
|
said []string
|
|
}
|
|
|
|
func newWorld(t *testing.T) *world {
|
|
w := &world{t: t, dir: t.TempDir(), now: time.Date(2026, 10, 5, 12, 0, 0, 0, time.UTC), a: &recorder{held: true}}
|
|
w.receives = filepath.Join(w.dir, "mesh.json")
|
|
w.h = &Harness{Resource: "oidc-client", Receives: w.receives, Adapter: w.a,
|
|
Now: func() time.Time { return w.now },
|
|
Log: func(f string, a ...any) { w.said = append(w.said, f) }}
|
|
return w
|
|
}
|
|
|
|
func (w *world) give(given ...map[string]any) {
|
|
for _, g := range given {
|
|
secret := filepath.Join(w.dir, g["as"].(string)+".secret")
|
|
if err := os.WriteFile(secret, []byte("pw-"+g["as"].(string)+"\n"), 0o600); err != nil {
|
|
w.t.Fatal(err)
|
|
}
|
|
g["secret"] = secret
|
|
}
|
|
if given == nil {
|
|
given = []map[string]any{}
|
|
}
|
|
raw, _ := json.Marshal(map[string]any{"requirement": "oidc-client", "given": given})
|
|
if err := os.WriteFile(w.receives, raw, 0o600); err != nil {
|
|
w.t.Fatal(err)
|
|
}
|
|
}
|
|
|
|
func TestAConsumerIsCreatedOnceUnderTheMeshsLoginAndPassword(t *testing.T) {
|
|
w := newWorld(t)
|
|
w.give(map[string]any{"as": "mesh_ace_letta", "node": "ace", "values": map[string]any{"name": "letta"}})
|
|
w.h.Reconcile(ctx)
|
|
w.h.Reconcile(ctx)
|
|
if len(w.a.created) != 1 {
|
|
t.Fatalf("created %d times", len(w.a.created))
|
|
}
|
|
p := w.a.created[0]
|
|
if p.As != "mesh_ace_letta" || p.Password != "pw-mesh_ace_letta" || p.Consumer != "ace" {
|
|
t.Fatalf("%+v", p)
|
|
}
|
|
}
|
|
|
|
func TestAConsumerNoLongerAskedForIsRetiredOnceStable(t *testing.T) {
|
|
w := newWorld(t)
|
|
w.give(map[string]any{"as": "a"}, map[string]any{"as": "b"})
|
|
w.h.Reconcile(ctx)
|
|
w.give(map[string]any{"as": "a"})
|
|
w.settle() // five passes and ten minutes
|
|
if strings.Join(w.a.removed, ",") != "b" {
|
|
t.Fatal(w.a.removed)
|
|
}
|
|
// Only a file that says nobody asks retires the last one.
|
|
w.give()
|
|
w.settle()
|
|
if strings.Join(w.a.removed, ",") != "b,a" {
|
|
t.Fatal(w.a.removed)
|
|
}
|
|
}
|
|
|
|
func TestNothingReadIsNotNobodyAsking(t *testing.T) {
|
|
for name, content := range map[string]string{
|
|
"unreadable": "",
|
|
"not JSON": "{",
|
|
"no given": `{"requirement": "oidc-client"}`,
|
|
"another": `{"requirement": "mssql-database", "given": []}`,
|
|
} {
|
|
t.Run(name, func(t *testing.T) {
|
|
w := newWorld(t)
|
|
w.give(map[string]any{"as": "a"})
|
|
w.h.Reconcile(ctx)
|
|
if content == "" {
|
|
os.Remove(w.receives)
|
|
} else {
|
|
os.WriteFile(w.receives, []byte(content), 0o600)
|
|
}
|
|
w.h.Reconcile(ctx)
|
|
if len(w.a.removed) != 0 {
|
|
t.Fatalf("retired %v on a file it could not use", w.a.removed)
|
|
}
|
|
})
|
|
}
|
|
}
|
|
|
|
func TestALostConsumerIsAppliedAgainAndBraked(t *testing.T) {
|
|
w := newWorld(t)
|
|
w.give(map[string]any{"as": "a"})
|
|
w.h.Reconcile(ctx)
|
|
w.a.held = false
|
|
w.now = w.now.Add(2 * time.Minute)
|
|
w.h.Reconcile(ctx)
|
|
if len(w.a.created) != 2 {
|
|
t.Fatalf("created %d times", len(w.a.created))
|
|
}
|
|
// Still not held a minute later: applied again, then braked for two minutes.
|
|
w.now = w.now.Add(61 * time.Second)
|
|
w.h.Reconcile(ctx)
|
|
w.now = w.now.Add(61 * time.Second)
|
|
w.h.Reconcile(ctx)
|
|
if len(w.a.created) != 3 {
|
|
t.Fatalf("not braked: created %d times", len(w.a.created))
|
|
}
|
|
}
|
|
|
|
func TestAFailingCreateIsRetriedAndSaidOnce(t *testing.T) {
|
|
w := newWorld(t)
|
|
w.a.failing = &pgErr{"realm refused, password pw-a"}
|
|
w.give(map[string]any{"as": "a"})
|
|
for i := 0; i < 5; i++ {
|
|
w.h.Reconcile(ctx)
|
|
}
|
|
n := 0
|
|
for _, s := range w.said {
|
|
if strings.Contains(s, "create failed") {
|
|
n++
|
|
}
|
|
}
|
|
if n != 1 {
|
|
t.Fatalf("said %d times", n)
|
|
}
|
|
w.a.failing = nil
|
|
w.h.Reconcile(ctx)
|
|
if len(w.a.created) != 1 {
|
|
t.Fatal("not retried")
|
|
}
|
|
}
|
|
|
|
type pgErr struct{ s string }
|
|
|
|
func (e *pgErr) Error() string { return e.s }
|
|
|
|
func TestScrubRemovesThePassword(t *testing.T) {
|
|
if got := scrub(&pgErr{"bad pw a/b c and a%2Fb+c"}, "a/b c"); strings.Contains(got, "a/b c") || strings.Contains(got, "a%2Fb+c") {
|
|
t.Fatal(got)
|
|
}
|
|
}
|