A cancel writes the ask's id into the seat's cancelled set before deleting the ask, and a write is a publish to the bucket's subject, which the controller was not granted: against a server holding exactly the controller's composed list, every cancel timed out.
32 lines
1.0 KiB
Go
32 lines
1.0 KiB
Go
package broker
|
|
|
|
import (
|
|
"slices"
|
|
"testing"
|
|
)
|
|
|
|
// **The controller may write every bucket it writes** (novox/hq to-be 45 §1, issue 269). Writing a
|
|
// key is a publish to the bucket's own subject, which the management interface's grant does not
|
|
// cover: the cancelled sets' writes timed out for want of this, and the controller's own buckets
|
|
// would have.
|
|
func TestTheControllerMayWriteEveryBucketItWrites(t *testing.T) {
|
|
p, err := PermissionsFor(Principal{Kind: KindController, PasswordHash: "x"})
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
want := []string{"$KV." + CallsBucket + ".>", "$KV." + HandActsBucket + ".>"}
|
|
for _, seat := range seatsTheControllerAsks {
|
|
if hasCancelledSet(seat) {
|
|
want = append(want, "$KV."+CancelledSetName(seat)+".>")
|
|
}
|
|
}
|
|
for _, subject := range want {
|
|
if !slices.Contains(p.Publish, subject) {
|
|
t.Errorf("the controller may not publish %s, so it cannot write that bucket", subject)
|
|
}
|
|
}
|
|
if slices.Contains(p.Publish, "$KV.>") {
|
|
t.Error("the controller may write any bucket, a module's state included")
|
|
}
|
|
}
|