Review: the cache grant's tenancy assertions move into the grant bed; retirement notes say what the beds prove; the builder binary is pushed on a warm return; the large bed needs the catalogue
This commit is contained in:
@@ -227,4 +227,16 @@ test("the mesh grants a consumer redis's cache, and the credential it delivers a
|
||||
// writing the contributions rather than the bed.
|
||||
const runtimeEnv = await must(`docker inspect mesh-redis --format '{{json .Config.Env}}'`);
|
||||
assert.doesNotMatch(runtimeEnv, /MESH_SEAL_KEY/, `a seal key was set after all — ADR 0048 is not what ran:\n${runtimeEnv}`);
|
||||
|
||||
// A grant means exactly the consumer's own keys: under its name it reads and writes, outside it
|
||||
// and on the server as a whole it is refused. Carried over from the large mesh bed's retired
|
||||
// cache-grant test — without this a provisioner that granted everything would keep every bed green.
|
||||
const asConsumer = (command: string) =>
|
||||
on(`docker exec redis redis-cli --user ${quote(as)} --pass ${quote(password)} --no-auth-warning ${command} 2>&1`);
|
||||
assert.match((await asConsumer("SET cacheuser:proof yes")).out, /OK/, "the consumer cannot write under its own name");
|
||||
assert.match((await asConsumer("GET cacheuser:proof")).out, /yes/, "the consumer cannot read back what it wrote");
|
||||
assert.match((await asConsumer("SET other:proof no")).out, /NOPERM|no permissions/i,
|
||||
"the consumer wrote outside its own keys, so the grant means more than it says");
|
||||
assert.match((await asConsumer("FLUSHALL")).out, /NOPERM|no permissions/i,
|
||||
"the consumer flushed the whole server, so the grant means more than it says");
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user