The grant bed's tenancy assertions are scoped to the login's keyspace, as redis scopes the ACL

This commit is contained in:
2026-09-22 01:41:16 +02:00
parent 146d7da9ef
commit 8a85e2d02e
@@ -228,13 +228,14 @@ test("the mesh grants a consumer redis's cache, and the credential it delivers a
const runtimeEnv = await must(`docker inspect mesh-redis --format '{{json .Config.Env}}'`); const runtimeEnv = await must(`docker inspect mesh-redis --format '{{json .Config.Env}}'`);
assert.doesNotMatch(runtimeEnv, /MESH_SEAL_KEY/, `a seal key was set after all — ADR 0048 is not what ran:\n${runtimeEnv}`); assert.doesNotMatch(runtimeEnv, /MESH_SEAL_KEY/, `a seal key was set after all — ADR 0048 is not what ran:\n${runtimeEnv}`);
// A grant means exactly the consumer's own keys: under its name it reads and writes, outside it // A grant means exactly the consumer's own keys — `<login>:*`, the keyspace redis's provisioner
// and on the server as a whole it is refused. Carried over from the large mesh bed's retired // scopes the ACL user to: under it the consumer reads and writes, outside it and on the server as
// cache-grant test — without this a provisioner that granted everything would keep every bed green. // a whole it is refused. Carried over from the large mesh bed's retired cache-grant test —
// without this a provisioner that granted everything would keep every bed green.
const asConsumer = (command: string) => const asConsumer = (command: string) =>
on(`docker exec redis redis-cli --user ${quote(as)} --pass ${quote(password)} --no-auth-warning ${command} 2>&1`); on(`docker exec redis redis-cli --user ${quote(as)} --pass ${quote(password)} --no-auth-warning ${command} 2>&1`);
assert.match((await asConsumer("SET cacheuser:proof yes")).out, /OK/, "the consumer cannot write under its own name"); assert.match((await asConsumer(`SET ${as}:proof yes`)).out, /OK/, "the consumer cannot write under its own login");
assert.match((await asConsumer("GET cacheuser:proof")).out, /yes/, "the consumer cannot read back what it wrote"); assert.match((await asConsumer(`GET ${as}:proof`)).out, /yes/, "the consumer cannot read back what it wrote");
assert.match((await asConsumer("SET other:proof no")).out, /NOPERM|no permissions/i, assert.match((await asConsumer("SET other:proof no")).out, /NOPERM|no permissions/i,
"the consumer wrote outside its own keys, so the grant means more than it says"); "the consumer wrote outside its own keys, so the grant means more than it says");
assert.match((await asConsumer("FLUSHALL")).out, /NOPERM|no permissions/i, assert.match((await asConsumer("FLUSHALL")).out, /NOPERM|no permissions/i,