A person's account (step 4.4, the account half)
Design 25 §7. A person is not a module and holds no seat: nothing is addressed to them, nothing is delivered to them, and they have no durable consumer. What they have is permission to ask, as a list of tools or `*` for an administrator. Four properties the tests hold it to, each of which is a way of being wrong that would not announce itself: a person reaches nothing but tools, so one cannot claim a module said something; no ack subject, because authority over a consumer that does not exist is authority nobody would audit; no allow_responses, because a person who can answer a request is impersonating a module on a bus where anyone may serve a tool; and two people do not share an inbox.
This commit is contained in:
@@ -164,3 +164,80 @@ func TestAUserWithoutAPasswordIsRefused(t *testing.T) {
|
||||
t.Fatal("composed a user with no password hash")
|
||||
}
|
||||
}
|
||||
|
||||
// A person reaches the mesh's tools from a workstation (design 25 §7). Their authority is a list
|
||||
// of tools and nothing else.
|
||||
func TestAPersonMayAskOnlyTheToolsTheyWereGiven(t *testing.T) {
|
||||
perms, err := PermissionsFor(Principal{Kind: KindPerson, Module: "jo",
|
||||
Invokes: []string{"shop.price", "telegram.status"}, PasswordHash: "x"})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
has(t, perms.Publish, "mesh.mod.shop.tool.price")
|
||||
has(t, perms.Publish, "mesh.mod.telegram.tool.status")
|
||||
hasNot(t, perms.Publish, "mesh.mod.shop.tool.refund")
|
||||
hasNot(t, perms.Publish, "mesh.mod.*.tool.>")
|
||||
}
|
||||
|
||||
// An administrator gets every tool, which is a different grant and looks like one.
|
||||
func TestAnAdministratorMayAskAnyTool(t *testing.T) {
|
||||
perms, _ := PermissionsFor(Principal{Kind: KindPerson, Module: "jo",
|
||||
Invokes: []string{"*"}, PasswordHash: "x"})
|
||||
has(t, perms.Publish, "mesh.mod.*.tool.>")
|
||||
}
|
||||
|
||||
// **Nothing but tools.** A person who could publish an event would be able to claim a module
|
||||
// said something; one who could publish control traffic would be a second controller.
|
||||
func TestAPersonReachesNothingButTools(t *testing.T) {
|
||||
perms, _ := PermissionsFor(Principal{Kind: KindPerson, Module: "jo",
|
||||
Invokes: []string{"*"}, PasswordHash: "x"})
|
||||
for _, p := range perms.Publish {
|
||||
if !strings.Contains(p, ".tool.") {
|
||||
t.Errorf("a person may publish %q, which is not a tool call", p)
|
||||
}
|
||||
}
|
||||
for _, s := range perms.Subscribe {
|
||||
if !strings.HasPrefix(s, "_INBOX.person.") {
|
||||
t.Errorf("a person may subscribe %q; only their own inbox should be reachable", s)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// A person has no durable consumer, because nothing is delivered to a person — so no ack
|
||||
// subject, and an ack permission would be authority over something that does not exist.
|
||||
func TestAPersonHasNoAckSubject(t *testing.T) {
|
||||
perms, _ := PermissionsFor(Principal{Kind: KindPerson, Module: "jo",
|
||||
Invokes: []string{"*"}, PasswordHash: "x"})
|
||||
for _, p := range perms.Publish {
|
||||
if strings.HasPrefix(p, "$JS.ACK") {
|
||||
t.Errorf("a person was granted %q, and has no consumer to acknowledge", p)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// A person asks and is answered; they never answer. allow_responses would let a person reply to
|
||||
// a request — which, on a bus where anyone may serve a tool, is somebody impersonating a module.
|
||||
func TestAPersonMayNotAnswer(t *testing.T) {
|
||||
perms, _ := PermissionsFor(Principal{Kind: KindPerson, Module: "jo",
|
||||
Invokes: []string{"*"}, PasswordHash: "x"})
|
||||
if perms.AllowResponses {
|
||||
t.Fatal("a person may answer a request, which is impersonating a module")
|
||||
}
|
||||
}
|
||||
|
||||
// Two people do not share an inbox, or one would read the other's answers.
|
||||
func TestTwoPeopleDoNotShareAnInbox(t *testing.T) {
|
||||
a, _ := PermissionsFor(Principal{Kind: KindPerson, Module: "jo", Invokes: []string{"*"}, PasswordHash: "x"})
|
||||
b, _ := PermissionsFor(Principal{Kind: KindPerson, Module: "sam", Invokes: []string{"*"}, PasswordHash: "x"})
|
||||
if a.Subscribe[0] == b.Subscribe[0] {
|
||||
t.Fatalf("both read %s", a.Subscribe[0])
|
||||
}
|
||||
}
|
||||
|
||||
// A malformed grant is refused rather than widened into something that happens to parse.
|
||||
func TestAToolGrantThatNamesNoToolIsRefused(t *testing.T) {
|
||||
if _, err := PermissionsFor(Principal{Kind: KindPerson, Module: "jo",
|
||||
Invokes: []string{"shop"}, PasswordHash: "x"}); err == nil {
|
||||
t.Fatal("a grant naming a module but no tool was accepted")
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user