package link_test import ( "context" "strings" "testing" "github.com/novox/mesh-controller/internal/link" ) // **A token issued for a tunnel key takes that key and no other** (novox/hq ADR 0169). The hub was // sent the key before the token was shown, so another key is a machine it does not know. func TestATokenIssuedForATunnelKeyTakesThatKeyAndNoOther(t *testing.T) { inv, ident := aMeshReadyToEnrol(t) ctx := context.Background() secret, public := aTokenFor(t, inv, "joiner") node, err := inv.NodeByName(ctx, "joiner") if err != nil { t.Fatal(err) } const issuedFor = "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=" if err := inv.BindTokenToKey(ctx, node.ID, issuedFor); err != nil { t.Fatal(err) } e := link.Enrolment{Inventory: inv, Identity: ident} _, err = e.Enrol(ctx, link.EnrolRequest{Node: "joiner", Secret: secret, PublicKey: public, OverlayKey: "BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB="}) if err == nil || !strings.Contains(err.Error(), "issued for the tunnel key") { t.Fatalf("a token issued for one key took another: %v", err) } if _, err := e.Enrol(ctx, link.EnrolRequest{Node: "joiner", Secret: secret, PublicKey: public, OverlayKey: issuedFor}); err != nil { t.Fatalf("the key the token was issued for was refused: %v", err) } }