package main import ( "os" "path/filepath" "strings" "testing" ) // A file has a trailing newline and a password does not. // // The failure this prevents is the worst kind to diagnose: the credential is delivered, the // machine applies it, everything reports success, and authentication fails one byte from correct // somewhere else entirely. func TestATrailingNewlineIsNotPartOfTheSecret(t *testing.T) { dir := t.TempDir() path := filepath.Join(dir, "password") if err := os.WriteFile(path, []byte("the-database-password\n"), 0o600); err != nil { t.Fatal(err) } got, err := valueFor("anchor", "umami", "database", path) if err != nil { t.Fatal(err) } if asSupplied(got) != "the-database-password" { t.Fatalf("read %q", got) } } // A password may contain spaces, and they are the operator's. // // Trimming both ends is the obvious thing and it is wrong: a value chosen with a leading space is // a value the mesh would silently deliver as a different one. func TestOnlyLineEndingsAreRemoved(t *testing.T) { dir := t.TempDir() path := filepath.Join(dir, "password") if err := os.WriteFile(path, []byte(" spaces matter \n"), 0o600); err != nil { t.Fatal(err) } got, err := valueFor("anchor", "umami", "database", path) if err != nil { t.Fatal(err) } if asSupplied(got) != " spaces matter " { t.Fatalf("the value was altered beyond its line ending: %q", got) } } // A file that is not there is said plainly, rather than becoming an empty secret. func TestAMissingFileIsRefused(t *testing.T) { if _, err := valueFor("anchor", "umami", "database", filepath.Join(t.TempDir(), "absent")); err == nil { t.Fatal("a missing file produced a value") } } // The command refuses what it cannot act on, rather than acting on part of it. func TestTheArgumentsAreRequired(t *testing.T) { for _, args := range [][]string{ {}, {"accept"}, {"accept", "anchor"}, {"accept", "anchor", "umami"}, {"give", "anchor", "umami", "database"}, } { if err := secretCommand(t.Context(), args); err == nil { t.Errorf("%v was accepted", args) } } } // The invocation that actually gets used, which the first version of these tests never tried. // // Every case here was a rejection, so the command was broken in the one way that matters — it // refused what it is for — and the tests were green. The lab found it at the first call. func TestTheArgumentsAndTheFlagAreBothSeen(t *testing.T) { rest, flags := split([]string{"anchor", "umami", "database", "--from", "-"}) assert(t, len(rest) == 3, "the three positionals were not kept: %v", rest) assert(t, len(flags) == 2, "the flag was not separated: %v", flags) // And with no flag at all, which is the interactive form. rest, flags = split([]string{"anchor", "umami", "database"}) assert(t, len(rest) == 3 && len(flags) == 0, "%v / %v", rest, flags) // A flag before the positionals still works, because somebody will write it that way. rest, flags = split([]string{"--from", "/tmp/x"}) assert(t, len(rest) == 0 && len(flags) == 2, "%v / %v", rest, flags) } // And the wiring, not just the helper. // // Testing `split` alone left the command able to ignore it entirely — removing the call changed // no test. This reaches secretCommand: with a `--from` naming a file that is not there, the // complaint must be about the file. A complaint about usage would mean the flag was never seen. func TestTheCommandItselfSeesTheFlag(t *testing.T) { err := secretCommand(t.Context(), []string{"accept", "anchor", "umami", "database", "--from", "/nonexistent/nowhere"}) if err == nil { t.Fatal("a missing file was accepted") } if strings.Contains(err.Error(), "secret accept ") { t.Fatalf("the command did not see its flag and complained about usage instead: %v", err) } } func assert(t *testing.T, ok bool, format string, args ...any) { t.Helper() if !ok { t.Fatalf(format, args...) } }