package catalogue import "testing" // The mesh's user list reaches the module holding the bus, and nothing else. // // Three refusals and one delivery, because each of the refusals would be silent in a different way: // a module that asked and was given it could read every credential on the bus; a bus given an empty // file refuses every connection in the mesh and looks like a machine problem; and a bus that never // asked gets nothing rather than a file it does not read. func TestTheMeshsUserListGoesOnlyToTheModuleHoldingTheBus(t *testing.T) { theBus := func() Manifest { return Manifest{ Module: "nats", Version: "1", Claims: []Claim{{Name: "mesh-broker", Scope: ScopeMesh}}, BusUsers: "/var/lib/nats-module/conf/accounts.conf", Resources: []map[string]any{}, } } on := func(t *testing.T, m Manifest, with Rendering) ([]map[string]any, error) { t.Helper() return Resolution{Node: "anchor", Modules: []Manifest{m}}.Declaration(with) } t.Run("the holder is given it", func(t *testing.T) { resources, err := on(t, theBus(), Rendering{BusUsers: "accounts { MESH { users = [] } }"}) if err != nil { t.Fatal(err) } // Prefixed with the module it came from, like every resource: two modules may reasonably // both call something "config", and without the prefix the second would silently replace // the first. var found map[string]any for _, r := range resources { if r["id"] == "nats."+BusUsersID() { found = r } } if found == nil { t.Fatalf("the bus was given no user list: %+v", resources) } if found["path"] != "/var/lib/nats-module/conf/accounts.conf" { t.Errorf("written to %v rather than where the module asked", found["path"]) } if found["mode"] != "0600" { t.Errorf("mode %v: a list of every user in the mesh belongs to the one process that "+ "needs it", found["mode"]) } }) t.Run("a module that does not claim the seat is refused", func(t *testing.T) { m := theBus() m.Claims = nil if _, err := on(t, m, Rendering{BusUsers: "accounts {}"}); err == nil { t.Fatal("a module that claims nothing was handed every user's password hash") } }) t.Run("the holder with nothing composed is refused", func(t *testing.T) { if _, err := on(t, theBus(), Rendering{}); err == nil { t.Fatal("the bus was given an empty user list, so it would refuse every connection in " + "the mesh and look like a machine problem") } }) t.Run("a module that did not ask gets nothing", func(t *testing.T) { m := theBus() m.BusUsers = "" resources, err := on(t, m, Rendering{BusUsers: "accounts {}"}) if err != nil { t.Fatal(err) } for _, r := range resources { if r["id"] == "nats."+BusUsersID() { t.Fatal("a module that asked for no user list was given one") } } }) }