The end-to-end test reads the grant where the mesh now writes it
Two assertions in the full-mesh test encoded the old naming: the grant file read back from the provider, and the PostgreSQL role the real application logs in as. Both are named after the consumer now, and a consumer is a module on a machine. These are the two that matter most in this file — it is the only place where a real application authenticates against a real database with a password the mesh delivered and cannot read, so they are what would have caught the naming going wrong end to end.
This commit is contained in:
@@ -253,6 +253,6 @@ test("a manifest naming a credential that was never written is refused", { skip,
|
||||
);
|
||||
const { out, ok } = await provision();
|
||||
assert.equal(ok, false, "it carried on past a missing credential");
|
||||
assert.match(out, /should be at .*ghost\.secret/);
|
||||
assert.match(out, /should be at .*ghost\.meshboard\.secret/);
|
||||
assert.equal(await sql(`select count(*) from pg_roles where rolname = 'mesh_ghost_meshboard'`), "0");
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user