Review: module issue's pre-check factored and tested; a pair delivery for a requirement the module keeps no secret for is refused; builder issue's usage says the module comes first

This commit is contained in:
2026-09-21 23:58:36 +02:00
parent 66332705cd
commit 0d1f2a4152
5 changed files with 61 additions and 10 deletions
+26
View File
@@ -0,0 +1,26 @@
package main
import (
"strings"
"testing"
"github.com/novox/mesh-controller/internal/catalogue"
)
// `module issue` makes a broker account and delivers it as the module's own secret named broker.
// A module that declares none is refused before the account exists, so the bus never carries an
// account nothing reads (novox/hq 04-ISSUES/078).
func TestAModuleWithNoBrokerSecretCannotBeIssued(t *testing.T) {
err := mayIssue(catalogue.Manifest{Module: "step-ca", OwnSecrets: map[string]string{"password": "/run/password"}})
if err == nil {
t.Fatal("a module with no broker own secret was issued an account")
}
for _, want := range []string{"step-ca", "broker", "own-secrets"} {
if !strings.Contains(err.Error(), want) {
t.Errorf("the refusal does not say %q: %v", want, err)
}
}
if err := mayIssue(catalogue.Manifest{Module: "redis", OwnSecrets: map[string]string{"broker": "/run/broker"}}); err != nil {
t.Errorf("a module declaring its broker secret was refused: %v", err)
}
}