events: an e2e test — an emitted event reaches the audit trail over the mesh's broker #2
@@ -813,10 +813,13 @@ test("rotating a credential moves both ends, and the old one stops working", {
|
|||||||
// A real login from the consumer's machine, over the private network — not over loopback, where
|
// A real login from the consumer's machine, over the private network — not over loopback, where
|
||||||
// pg_hba trusts anything and every password looks correct. That was done here once and the test
|
// pg_hba trusts anything and every password looks correct. That was done here once and the test
|
||||||
// passed for an afternoon while verifying nothing: a deliberately wrong password returned a row.
|
// passed for an afternoon while verifying nothing: a deliberately wrong password returned a row.
|
||||||
|
// As the role the provisioner made, into the database it made. The provisioner names a role
|
||||||
|
// after the machine and a database after what the module asked for — which is the contract, and
|
||||||
|
// getting it wrong here made the test fail against a provisioner that had done its job.
|
||||||
const login = async (password: string) =>
|
const login = async (password: string) =>
|
||||||
await on("laptop", `docker run --rm -e PGPASSWORD=${quote(password)} ` +
|
await on("laptop", `docker run --rm -e PGPASSWORD=${quote(password)} ` +
|
||||||
`${pinned("postgres")} psql -h anchor.internal -p 5433 -U realapp ` +
|
`${pinned("postgres")} psql -h anchor.internal -p 5433 -U mesh_laptop ` +
|
||||||
`-d postgres -qAt -c "select 1"`, 120_000);
|
`-d realapp -qAt -c "select 1"`, 120_000);
|
||||||
|
|
||||||
const diagnostics = async () =>
|
const diagnostics = async () =>
|
||||||
`provisioner:\n${(await on("anchor", `docker logs real-provisioner 2>&1 | tail -20`)).out}\n` +
|
`provisioner:\n${(await on("anchor", `docker logs real-provisioner 2>&1 | tail -20`)).out}\n` +
|
||||||
@@ -957,15 +960,19 @@ test("model access is answered by a record, and the key the mesh took is one it
|
|||||||
`> /tmp/assistant.json`);
|
`> /tmp/assistant.json`);
|
||||||
await must("anchor", `docker cp /tmp/assistant.json mesh-control:/assistant.json`);
|
await must("anchor", `docker cp /tmp/assistant.json mesh-control:/assistant.json`);
|
||||||
await mesh("module add /assistant.json");
|
await mesh("module add /assistant.json");
|
||||||
await mesh("assign laptop assistant");
|
|
||||||
|
|
||||||
|
// The licences first. With none recorded at all the honest answer is that nothing provides
|
||||||
|
// model-access — correct, and a different refusal from the one being tested.
|
||||||
await mesh(`licence add anthropic personal --serves '{"model":"a-model"}'`);
|
await mesh(`licence add anthropic personal --serves '{"model":"a-model"}'`);
|
||||||
await mesh(`licence add anthropic the-organisation --serves '{"model":"a-model"}'`);
|
await mesh(`licence add anthropic the-organisation --serves '{"model":"a-model"}'`);
|
||||||
|
|
||||||
// Refused until somebody says which, and the refusal names both candidates and the command.
|
// Refused at the earliest point somebody could meet it: assigning records the assignment and
|
||||||
// ADR 0024 warns this will be felt — which is correct, and correct is not the same as usable.
|
// then says the machine's set cannot be applied. The refusal names both candidates and the
|
||||||
const refused = await on("anchor", `docker exec mesh-control /mesh-control plan laptop`);
|
// command. ADR 0024 warns this will be felt — which is correct, and correct is not the same as
|
||||||
assert.ok(!refused.ok, `a consumer was given model access without anybody saying which:\n${refused.out}`);
|
// usable.
|
||||||
|
const refused = await on("anchor", `docker exec mesh-control /mesh-control assign laptop assistant`);
|
||||||
|
assert.ok(!refused.ok,
|
||||||
|
`a consumer was given model access without anybody saying which:\n${refused.out}`);
|
||||||
for (const want of ["personal", "the-organisation", "licence use"]) {
|
for (const want of ["personal", "the-organisation", "licence use"]) {
|
||||||
assert.match(refused.out, new RegExp(want),
|
assert.match(refused.out, new RegExp(want),
|
||||||
`the refusal does not name ${want}:\n${refused.out}`);
|
`the refusal does not name ${want}:\n${refused.out}`);
|
||||||
|
|||||||
Reference in New Issue
Block a user