Review of 081: the bed asserts baserow chose its own cache and it challenges for its password; the check reads only what a module hands its software; stale comments
This commit is contained in:
@@ -21,9 +21,23 @@ import { catalogueIsPresent, catalogueDir } from "./integration/harness.ts";
|
||||
|
||||
const CACHE = "redis-cache";
|
||||
|
||||
/** What a module hands its software: every file it writes, and every container's environment and
|
||||
* arguments. A comment, a `why`, or a declared exception is not handed to anything. */
|
||||
function handedToSoftware(manifest: string): string[] {
|
||||
const m = JSON.parse(manifest) as { resources?: Record<string, unknown>[] };
|
||||
const out: string[] = [];
|
||||
for (const r of m.resources ?? []) {
|
||||
if (typeof r["content"] === "string") out.push(r["content"] as string);
|
||||
if (r["env"] && typeof r["env"] === "object") out.push(...Object.values(r["env"] as Record<string, string>).map(String));
|
||||
if (Array.isArray(r["args"])) out.push(...(r["args"] as unknown[]).map(String));
|
||||
}
|
||||
return out;
|
||||
}
|
||||
|
||||
/** Whether a manifest hands its software the login it is granted for the cache. */
|
||||
function presentsTheLogin(manifest: string): boolean {
|
||||
return manifest.includes(`\${bound:${CACHE}:as}`);
|
||||
const login = `\${bound:${CACHE}:as}`;
|
||||
return handedToSoftware(manifest).some((given) => given.includes(login));
|
||||
}
|
||||
|
||||
test("the check sees a module that hands its software the password and not the login", () => {
|
||||
@@ -33,6 +47,11 @@ test("the check sees a module that hands its software the password and not the l
|
||||
{ id: "env", type: "file", path: "/x", content: `USER=\${bound:${CACHE}:as}\nPASSWORD=\${secret:${CACHE}}\n` }] });
|
||||
assert.equal(presentsTheLogin(passwordOnly), false);
|
||||
assert.equal(presentsTheLogin(withLogin), true);
|
||||
// Named only where no software reads it — a declared reason — is not presenting it.
|
||||
const onlyInAReason = JSON.stringify({ module: "m", requires: [CACHE], resources: [
|
||||
{ id: "srv", type: "container", name: "s", image: "x", env: { PASSWORD: `\${secret:${CACHE}}` },
|
||||
"secrets-in-environment": `the login is \${bound:${CACHE}:as}` }] });
|
||||
assert.equal(presentsTheLogin(onlyInAReason), false);
|
||||
});
|
||||
|
||||
test("every catalogue module that takes the shared cache presents the login it was granted", (t) => {
|
||||
|
||||
Reference in New Issue
Block a user