The end-to-end test reads the grant where the mesh now writes it

Two assertions in the full-mesh test encoded the old naming: the grant
file read back from the provider, and the PostgreSQL role the real
application logs in as. Both are named after the consumer now, and a
consumer is a module on a machine.

These are the two that matter most in this file — it is the only place
where a real application authenticates against a real database with a
password the mesh delivered and cannot read, so they are what would have
caught the naming going wrong end to end.
This commit is contained in:
2026-09-01 02:48:24 +02:00
parent e7f4a49e40
commit cb0edcee8d
2 changed files with 8 additions and 3 deletions
+1 -1
View File
@@ -253,6 +253,6 @@ test("a manifest naming a credential that was never written is refused", { skip,
);
const { out, ok } = await provision();
assert.equal(ok, false, "it carried on past a missing credential");
assert.match(out, /should be at .*ghost\.secret/);
assert.match(out, /should be at .*ghost\.meshboard\.secret/);
assert.equal(await sql(`select count(*) from pg_roles where rolname = 'mesh_ghost_meshboard'`), "0");
});