A token can be issued for a machine's tunnel key, and it joins through the tunnel
token issue --overlay-key records the key the machine made, binds the token to it, gives the machine its address and makes it a peer of the hub, pushing the hub before the token is shown. The token carries the hub's tunnel and the bus at its address on the private network, and enrolment refuses any other key (novox/hq ADR 0169). Tokens without a key enrol as before until the bus is closed. Also a token verb.
This commit is contained in:
@@ -0,0 +1,37 @@
|
||||
package link_test
|
||||
|
||||
import (
|
||||
"context"
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"github.com/novox/mesh-controller/internal/link"
|
||||
)
|
||||
|
||||
// **A token issued for a tunnel key takes that key and no other** (novox/hq ADR 0169). The hub was
|
||||
// sent the key before the token was shown, so another key is a machine it does not know.
|
||||
func TestATokenIssuedForATunnelKeyTakesThatKeyAndNoOther(t *testing.T) {
|
||||
inv, ident := aMeshReadyToEnrol(t)
|
||||
ctx := context.Background()
|
||||
secret, public := aTokenFor(t, inv, "joiner")
|
||||
node, err := inv.NodeByName(ctx, "joiner")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
const issuedFor = "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA="
|
||||
if err := inv.BindTokenToKey(ctx, node.ID, issuedFor); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
e := link.Enrolment{Inventory: inv, Identity: ident}
|
||||
|
||||
_, err = e.Enrol(ctx, link.EnrolRequest{Node: "joiner", Secret: secret, PublicKey: public,
|
||||
OverlayKey: "BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB="})
|
||||
if err == nil || !strings.Contains(err.Error(), "issued for the tunnel key") {
|
||||
t.Fatalf("a token issued for one key took another: %v", err)
|
||||
}
|
||||
|
||||
if _, err := e.Enrol(ctx, link.EnrolRequest{Node: "joiner", Secret: secret, PublicKey: public,
|
||||
OverlayKey: issuedFor}); err != nil {
|
||||
t.Fatalf("the key the token was issued for was refused: %v", err)
|
||||
}
|
||||
}
|
||||
@@ -86,6 +86,18 @@ func (e Enrolment) Enrol(ctx context.Context, request EnrolRequest) (reply Enrol
|
||||
if err != nil {
|
||||
return EnrolReply{}, err
|
||||
}
|
||||
// **A token issued for a tunnel key takes that key and no other** (novox/hq ADR 0169). The hub
|
||||
// was told it before the token was shown; another key is a machine the hub does not know.
|
||||
// Checked before anything is recorded, so a refusal changes nothing.
|
||||
bound, err := e.Inventory.TokenKey(ctx, secret)
|
||||
if err != nil {
|
||||
return EnrolReply{}, err
|
||||
}
|
||||
if bound != "" && request.OverlayKey != bound {
|
||||
return EnrolReply{}, fmt.Errorf("%s's token was issued for the tunnel key %s and the machine "+
|
||||
"offered %q — the key it made with `nox-mesh-host key` is the one to issue for",
|
||||
node.Name, bound, request.OverlayKey)
|
||||
}
|
||||
|
||||
if _, err := e.Identity.RecordNodeKey(ctx, node.ID, public); err != nil {
|
||||
return EnrolReply{}, fmt.Errorf("%s's key could not be recorded: %w", node.Name, err)
|
||||
|
||||
Reference in New Issue
Block a user