events: an e2e test — an emitted event reaches the audit trail over the mesh's broker #2
@@ -270,7 +270,10 @@ test("a credential reaches both ends and the mesh holds neither", { skip, timeou
|
|||||||
await new Promise((r) => setTimeout(r, 8000));
|
await new Promise((r) => setTimeout(r, 8000));
|
||||||
|
|
||||||
const onConsumer = (await must("laptop", `cat /etc/meshboard/database.password`)).trim();
|
const onConsumer = (await must("laptop", `cat /etc/meshboard/database.password`)).trim();
|
||||||
const onProvider = (await must("anchor", `cat /var/lib/mesh-host/grants/laptop.secret`)).trim();
|
// Named after the machine *and* the module, because a consumer is both (novox/hq
|
||||||
|
// 04-ISSUES/022) — a node routinely runs several modules wanting one database.
|
||||||
|
const onProvider = (await must("anchor",
|
||||||
|
`cat /var/lib/mesh-host/grants/laptop.meshboard.secret`)).trim();
|
||||||
assert.ok(onConsumer.length >= 40, `the consumer's credential is ${onConsumer.length} characters`);
|
assert.ok(onConsumer.length >= 40, `the consumer's credential is ${onConsumer.length} characters`);
|
||||||
assert.equal(onConsumer, onProvider,
|
assert.equal(onConsumer, onProvider,
|
||||||
"the two ends hold different passwords, so nothing could ever authenticate");
|
"the two ends hold different passwords, so nothing could ever authenticate");
|
||||||
@@ -890,7 +893,9 @@ test("rotating a credential moves both ends, and the old one stops working", {
|
|||||||
|
|
||||||
const login = async (password: string) =>
|
const login = async (password: string) =>
|
||||||
await on("laptop", `docker run --rm -e PGPASSWORD=${quote(password)} ` +
|
await on("laptop", `docker run --rm -e PGPASSWORD=${quote(password)} ` +
|
||||||
`${pinned("postgres")} psql -h ${where} -p 5433 -U mesh_laptop ` +
|
// The role the provisioner made: mesh_<node>_<module>, because a consumer is a module on
|
||||||
|
// a machine (novox/hq 04-ISSUES/022).
|
||||||
|
`${pinned("postgres")} psql -h ${where} -p 5433 -U mesh_laptop_realapp ` +
|
||||||
`-d realapp -qAt -c "select 1"`, 120_000);
|
`-d realapp -qAt -c "select 1"`, 120_000);
|
||||||
|
|
||||||
const diagnostics = async () =>
|
const diagnostics = async () =>
|
||||||
|
|||||||
@@ -253,6 +253,6 @@ test("a manifest naming a credential that was never written is refused", { skip,
|
|||||||
);
|
);
|
||||||
const { out, ok } = await provision();
|
const { out, ok } = await provision();
|
||||||
assert.equal(ok, false, "it carried on past a missing credential");
|
assert.equal(ok, false, "it carried on past a missing credential");
|
||||||
assert.match(out, /should be at .*ghost\.secret/);
|
assert.match(out, /should be at .*ghost\.meshboard\.secret/);
|
||||||
assert.equal(await sql(`select count(*) from pg_roles where rolname = 'mesh_ghost_meshboard'`), "0");
|
assert.equal(await sql(`select count(*) from pg_roles where rolname = 'mesh_ghost_meshboard'`), "0");
|
||||||
});
|
});
|
||||||
|
|||||||
Reference in New Issue
Block a user