token issue --overlay-key records the key the machine made, binds the token to it, gives the machine its address and makes it a peer of the hub, pushing the hub before the token is shown. The token carries the hub's tunnel and the bus at its holder's address on the private network, and enrolment refuses any other key (novox/hq ADR 0169). The bus is no longer public, so a machine outside the mesh can join only this way; a token without a key is still what the machine running the bus joins its own mesh with. Also a token verb, which says it replaces running the command by hand and adding a peer to the hub with wg.
38 lines
1.3 KiB
Go
38 lines
1.3 KiB
Go
package link_test
|
|
|
|
import (
|
|
"context"
|
|
"strings"
|
|
"testing"
|
|
|
|
"github.com/novox/mesh-controller/internal/link"
|
|
)
|
|
|
|
// **A token issued for a tunnel key takes that key and no other** (novox/hq ADR 0169). The hub was
|
|
// sent the key before the token was shown, so another key is a machine it does not know.
|
|
func TestATokenIssuedForATunnelKeyTakesThatKeyAndNoOther(t *testing.T) {
|
|
inv, ident := aMeshReadyToEnrol(t)
|
|
ctx := context.Background()
|
|
secret, public := aTokenFor(t, inv, "joiner")
|
|
node, err := inv.NodeByName(ctx, "joiner")
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
const issuedFor = "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA="
|
|
if err := inv.BindTokenToKey(ctx, node.ID, issuedFor); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
e := link.Enrolment{Inventory: inv, Identity: ident}
|
|
|
|
_, err = e.Enrol(ctx, link.EnrolRequest{Node: "joiner", Secret: secret, PublicKey: public,
|
|
OverlayKey: "BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB="})
|
|
if err == nil || !strings.Contains(err.Error(), "issued for the tunnel key") {
|
|
t.Fatalf("a token issued for one key took another: %v", err)
|
|
}
|
|
|
|
if _, err := e.Enrol(ctx, link.EnrolRequest{Node: "joiner", Secret: secret, PublicKey: public,
|
|
OverlayKey: issuedFor}); err != nil {
|
|
t.Fatalf("the key the token was issued for was refused: %v", err)
|
|
}
|
|
}
|