A claim may name the verbs it serves for its seat (hq ADR 0160)
The store's databases is not postgres's postgres_list_databases, and a holder may serve both. A claim's serves names the seat's verbs the module implements for the role; absent, the module's own tools must list every verb the seat promises, which is how a module named like its seat says they are one and the same. Registration refuses a claim naming a verb the seat never promised, and the credential's claims carry the claim's own verbs to the runtime.
This commit is contained in:
@@ -70,6 +70,22 @@ func TestAHolderMustServeWhatItsSeatPromises(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// The claim may say what it serves for the role instead, when the module's own tools are not the
|
||||
// seat's verbs (ADR 0160).
|
||||
func TestAClaimMayNameWhatItServesForTheSeat(t *testing.T) {
|
||||
m := telegram()
|
||||
m.Tools = []string{"telegram_send"}
|
||||
m.Claims = append([]Claim(nil), m.Claims...)
|
||||
for i := range m.Claims {
|
||||
if m.Claims[i].Name == "telegram-sender" {
|
||||
m.Claims[i].Serves = []string{"status"}
|
||||
}
|
||||
}
|
||||
if got := problemsFor(t, Shelf{"telegram": m}); strings.Contains(got, "does not serve") {
|
||||
t.Fatalf("a claim naming the seat's verb was refused: %s", got)
|
||||
}
|
||||
}
|
||||
|
||||
// A seat with no protocol is a marker: which module is this node's showcase, or its packet filter.
|
||||
// Most node-scoped seats are markers, so refusing one would refuse the majority of the set.
|
||||
func TestASeatWithoutAProtocolIsAMarkerNotAMistake(t *testing.T) {
|
||||
|
||||
Reference in New Issue
Block a user