From 8a85e2d02e274f19762815db8f884cb41f88254e Mon Sep 17 00:00:00 2001 From: jochen Date: Tue, 22 Sep 2026 01:41:16 +0200 Subject: [PATCH] The grant bed's tenancy assertions are scoped to the login's keyspace, as redis scopes the ACL --- test/integration/mesh-grant-end-to-end.test.ts | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/test/integration/mesh-grant-end-to-end.test.ts b/test/integration/mesh-grant-end-to-end.test.ts index f546c23..fef1361 100644 --- a/test/integration/mesh-grant-end-to-end.test.ts +++ b/test/integration/mesh-grant-end-to-end.test.ts @@ -228,13 +228,14 @@ test("the mesh grants a consumer redis's cache, and the credential it delivers a const runtimeEnv = await must(`docker inspect mesh-redis --format '{{json .Config.Env}}'`); assert.doesNotMatch(runtimeEnv, /MESH_SEAL_KEY/, `a seal key was set after all — ADR 0048 is not what ran:\n${runtimeEnv}`); - // A grant means exactly the consumer's own keys: under its name it reads and writes, outside it - // and on the server as a whole it is refused. Carried over from the large mesh bed's retired - // cache-grant test — without this a provisioner that granted everything would keep every bed green. + // A grant means exactly the consumer's own keys — `:*`, the keyspace redis's provisioner + // scopes the ACL user to: under it the consumer reads and writes, outside it and on the server as + // a whole it is refused. Carried over from the large mesh bed's retired cache-grant test — + // without this a provisioner that granted everything would keep every bed green. const asConsumer = (command: string) => on(`docker exec redis redis-cli --user ${quote(as)} --pass ${quote(password)} --no-auth-warning ${command} 2>&1`); - assert.match((await asConsumer("SET cacheuser:proof yes")).out, /OK/, "the consumer cannot write under its own name"); - assert.match((await asConsumer("GET cacheuser:proof")).out, /yes/, "the consumer cannot read back what it wrote"); + assert.match((await asConsumer(`SET ${as}:proof yes`)).out, /OK/, "the consumer cannot write under its own login"); + assert.match((await asConsumer(`GET ${as}:proof`)).out, /yes/, "the consumer cannot read back what it wrote"); assert.match((await asConsumer("SET other:proof no")).out, /NOPERM|no permissions/i, "the consumer wrote outside its own keys, so the grant means more than it says"); assert.match((await asConsumer("FLUSHALL")).out, /NOPERM|no permissions/i,