Review of 083: a message the store cannot take is held and retried on a ticker, not slept on, so enrolments are answered meanwhile; a newer one per subject supersedes; the password is replaced after the spend; the same presenter may finish after a lost answer; upgrades retry only on the store

This commit is contained in:
2026-09-22 14:23:03 +02:00
parent 1a41b88ed3
commit a3b7e830c8
7 changed files with 280 additions and 184 deletions
+12 -4
View File
@@ -413,10 +413,18 @@ func TestATokenIsClaimedByOnePresenterAndSpentOnlyByIt(t *testing.T) {
if err := inv.Spend(ctx, issued.Secret, "key-a"); err != nil {
t.Fatalf("the presenter holding the claim could not spend it: %v", err)
}
for _, by := range []string{"key-a", "key-b"} {
if _, err := inv.Claim(ctx, issued.Secret, by); !errors.Is(err, ErrTokenRefused) {
t.Fatalf("a spent token was claimed again by %s: %v", by, err)
}
// Spent: nobody else may claim it, ever.
if _, err := inv.Claim(ctx, issued.Secret, "key-b"); !errors.Is(err, ErrTokenRefused) {
t.Fatalf("a spent token was claimed by another presenter: %v", err)
}
// But the presenter that spent it may, and spend it again: its spend reached the store and the
// answer did not reach the node, which asked again — refusing it would lock out a machine the
// mesh holds as enrolled.
if _, err := inv.Claim(ctx, issued.Secret, "key-a"); err != nil {
t.Fatalf("the presenter whose answer was lost after its spend was refused: %v", err)
}
if err := inv.Spend(ctx, issued.Secret, "key-a"); err != nil {
t.Fatalf("spending again by the same presenter failed: %v", err)
}
}