diff --git a/test/sdk.test.ts b/test/sdk.test.ts index 82c5263..05294e0 100644 --- a/test/sdk.test.ts +++ b/test/sdk.test.ts @@ -4,19 +4,12 @@ import { mkdtemp, writeFile, readFile, readdir } from "node:fs/promises"; import { tmpdir } from "node:os"; import { join } from "node:path"; -import { seal, unseal, compareVersions } from "../dist/primitives/index.js"; -import { registerModuleTools, collectTools, resetTools, serveTools, listTools } from "../dist/tools/index.js"; -import { runProvisioner, type Grant } from "../dist/provisioner/index.js"; +import { compareVersions } from "../dist/primitives/index.js"; +import { registerModuleTools, collectTools, resetTools, serveTools, listTools, invokeTool } from "../dist/tools/index.js"; +import { runProvisioner } from "../dist/provisioner/index.js"; import { emit, on, type Event } from "../dist/events/index.js"; import { useBroker } from "../dist/messaging/index.js"; -test("seal round-trips and rejects the wrong key", () => { - const sealed = seal("hunter2", "node-key"); - assert.equal(unseal(sealed, "node-key"), "hunter2"); - assert.notEqual(sealed, "hunter2"); - assert.throws(() => unseal(sealed, "wrong-key")); -}); - test("semver orders releases", () => { assert.equal(compareVersions("1.2.3", "1.2.10"), -1); assert.equal(compareVersions("2.0.0", "1.9.9"), 1); @@ -38,39 +31,46 @@ test("module tools register and collect, a thrower is skipped not fatal", () => assert.equal(broken?.tools.length, 0); }); -test("provisioner creates a sealed credential for a grant, then removes on withdrawal", async () => { +test("provisioner creates each consumer with the mesh's login and password, removes on withdrawal", async () => { const dir = await mkdtemp(join(tmpdir(), "prov-")); - const created: string[] = []; + const created: { as: string; password: string; values: unknown }[] = []; const removed: string[] = []; - const grant: Grant = { resource: "analytics", consumer: "webapp", node: "anchor", values: { name: "webapp" } }; - await writeFile(join(dir, "webapp.grant.json"), JSON.stringify(grant)); + // What the mesh delivers: the password it minted (as the host leaves it after unsealing) and a + // contributions file naming the consumer's login and where that password is. + await writeFile(join(dir, "webapp.secret"), "minted-pw\n"); + const receives = join(dir, "analytics.json"); + const doc = (given: unknown[]): string => + JSON.stringify({ contributions: 1, requirement: "analytics", given }); + await writeFile( + receives, + doc([{ from: "webapp", node: "anchor", as: "webapp-anchor", secret: join(dir, "webapp.secret"), values: { name: "webapp" } }]), + ); const stop = runProvisioner( "analytics", { - async create(g) { - created.push(g.consumer); - return { fields: { siteId: "abc", snippet: "