diff --git a/internal/link/enrol_proof_test.go b/internal/link/enrol_proof_test.go new file mode 100644 index 0000000..727197f --- /dev/null +++ b/internal/link/enrol_proof_test.go @@ -0,0 +1,13 @@ +package link + +import "testing" + +// The bytes a node signs when it enrols, built here to check its signature. The host builds the +// same bytes in another repository; this known answer is repeated in its test, so the two cannot +// drift apart without one of them failing (novox/hq issue 083). +func TestWhatAnEnrollingNodeSignsIsFixed(t *testing.T) { + got := string(EnrolProof("s", []byte{1, 2, 3}, "o", "e", "v")) + if want := "novox-mesh-enrol\x00s\x00AQID\x00o\x00e\x00v"; got != want { + t.Fatalf("the enrolment proof's message changed: %q, want %q", got, want) + } +}