package link_test import ( "crypto/ed25519" "crypto/rand" "errors" "testing" "time" "github.com/novox/mesh-controller/internal/inventory" "github.com/novox/mesh-controller/internal/link" ) // A token another enrolment holds for the moment is "not now", not a refusal: the node asks again // with the same request, and nothing is spent (novox/hq issue 083). func TestAnEnrolmentMetByAHeldTokenIsAskedToTryAgain(t *testing.T) { inv := inventory.ForTest(t) ctx := t.Context() if _, err := inv.AddNode(ctx, "laptop"); err != nil { t.Fatal(err) } issued, err := inv.IssueToken(ctx, "laptop", time.Hour) if err != nil { t.Fatal(err) } if _, err := inv.Claim(ctx, issued.Secret, "another enrolment's key"); err != nil { t.Fatal(err) } public, _, err := ed25519.GenerateKey(rand.Reader) if err != nil { t.Fatal(err) } _, err = link.Enrolment{Inventory: inv}.Enrol(ctx, link.EnrolRequest{ Node: "laptop", Secret: issued.Secret, PublicKey: public}) if !errors.Is(err, link.ErrTryAgain) { t.Fatalf("an enrolment met by a held token was not asked to try again: %v", err) } // And a token that cannot be used at all is still refused outright. _, err = link.Enrolment{Inventory: inv}.Enrol(ctx, link.EnrolRequest{ Node: "laptop", Secret: "not-a-token", PublicKey: public}) if err == nil || errors.Is(err, link.ErrTryAgain) { t.Fatalf("a token that cannot be used was not refused outright: %v", err) } }