The console says an account was refused only when the bus refused it
"authorization" alone matched a tool's own answer mentioning the word — the runtime refusing a state value with an Authorization header read as "this account may not call".
This commit is contained in:
@@ -0,0 +1,22 @@
|
||||
package console
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
// A refusal is said only for the bus's own refusals; a tool's answer that mentions authorization is the
|
||||
// tool's answer, not the account's.
|
||||
func TestARefusalIsSaidOnlyForTheBussOwn(t *testing.T) {
|
||||
for msg, refusal := range map[string]bool{
|
||||
`nats: Permissions Violation for Publish to "mesh.mod.x.tool.y"`: true,
|
||||
"nats: Authorization Violation": true,
|
||||
`claude-code's servers.all.x carries a field "Authorization", which names a credential`: false,
|
||||
} {
|
||||
got := strings.HasPrefix(whyItFailed("x.y", errors.New(msg)), "this account may not call")
|
||||
if got != refusal {
|
||||
t.Errorf("%q read as a refusal: %v, want %v", msg, got, refusal)
|
||||
}
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user