A provider keeps one grant file per holder, with the local name in its id and path
The lab's vault refused a declaration naming two files with one identity: the two secrets of one consumer. The holder's suffix is in the resource id and the path now.
This commit is contained in:
@@ -347,9 +347,11 @@ func (r Resolution) Declaration(with Rendering) ([]map[string]any, error) {
|
||||
continue
|
||||
}
|
||||
first = append(first, map[string]any{
|
||||
"id": GrantID(to, g.Consumer+"."+g.From),
|
||||
// One file per holder — the consumer's module with its local name after it
|
||||
// where it keeps several (ADR 0094); the lab found two files with one id.
|
||||
"id": GrantID(to, g.Consumer+"."+holderAs(g.From, g.Local)),
|
||||
"type": "file",
|
||||
"path": grantPath(m.Grants[to], g.Consumer, g.From),
|
||||
"path": grantPath(m.Grants[to], g.Consumer, holderAs(g.From, g.Local)),
|
||||
"sealed": g.Sealed,
|
||||
})
|
||||
}
|
||||
|
||||
@@ -134,3 +134,28 @@ func TestAProviderSeesEachLocalNameAsAHolderOfItsOwn(t *testing.T) {
|
||||
t.Fatalf("two holders share one file on the provider: %q", given[0].Secret)
|
||||
}
|
||||
}
|
||||
|
||||
// And on the provider's machine, two files with two ids — the lab's first run had the declaration
|
||||
// refused for two resources with one identity.
|
||||
func TestAProviderKeepsOneFilePerHolder(t *testing.T) {
|
||||
got, err := Resolve(vaultAndCA(), []string{"mesh-vault", "cache", "ca"}, workstation(), World{})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
out, err := got.Declaration(Rendering{Grants: []Grant{
|
||||
{Provision: "secret", Consumer: "workstation", From: "ca", Local: "root-key", Sealed: "x"},
|
||||
{Provision: "secret", Consumer: "workstation", From: "ca", Local: "root-pass", Sealed: "y"},
|
||||
}})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
ids := map[string]string{}
|
||||
for _, r := range out {
|
||||
if id, _ := r["id"].(string); strings.Contains(id, "grant-secret") {
|
||||
ids[id] = r["path"].(string)
|
||||
}
|
||||
}
|
||||
if len(ids) != 2 {
|
||||
t.Fatalf("two holders are two grant files: %v", ids)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user