/** * A refused announcement is said and never fatal (novox/hq 04-ISSUES/217): against a bus whose * permissions refuse one discovery subject, the runtime's raw subscription is refused, logged, and * the process keeps serving — its tools still answer. * * docker run -d --rm --name t -p 14233:4222 -v $PWD/test/fixtures/refusing-nats.conf:/c.conf nats:2.10-alpine -c /c.conf * MESH_TEST_REFUSING_NATS=nats://127.0.0.1:14233 node --test --experimental-strip-types test/refused.test.ts */ import assert from "node:assert/strict"; import { test } from "node:test"; import { connectNats } from "../dist/broker-nats.js"; import { callTool } from "../dist/client.js"; const url = process.env.MESH_TEST_REFUSING_NATS; test("a refused discovery subscription is logged and the runtime serves on", async (t) => { if (!url) return t.skip("MESH_TEST_REFUSING_NATS unset"); const bus = await connectNats({ url, user: "runtime", password: "runtime", module: "alpha", node: "anchor" }); const said: string[] = []; const log = console.log; console.log = (...a: unknown[]) => said.push(a.join(" ")); const crashed: unknown[] = []; const onRejection = (e: unknown) => crashed.push(e); process.on("unhandledRejection", onRejection); try { (bus as unknown as { raw: (s: string, f: () => Uint8Array | undefined) => () => void }).raw("$SRV.PING.>", () => undefined); const stop = await bus.handle("alpha.ping", async () => ({ pong: true })); for (let i = 0; i < 50 && !said.some((s) => s.includes("the bus refused $SRV.PING.>")); i++) await new Promise((r) => setTimeout(r, 50)); console.log = log; assert.ok(said.some((s) => /the bus refused \$SRV\.PING\.>.*serves on/.test(s)), said.join("\n")); assert.equal(crashed.length, 0, `the refusal escaped: ${String(crashed[0])}`); stop(); } finally { console.log = log; process.off("unhandledRejection", onRejection); await bus.close(); } }); // novox/hq issue 218: a tool subject the grants leave out — a seat claimed here and held elsewhere — // is refused, said, and the module's other tools still answer. test("a refused tool subscription is logged and the module's other tools answer", async (t) => { if (!url) return t.skip("MESH_TEST_REFUSING_NATS unset"); const bus = await connectNats({ url, user: "runtime", password: "runtime", module: "alpha", node: "anchor" }); const asker = await connectNats({ url, user: "runtime", password: "runtime", module: "console", node: "workstation" }); const said: string[] = []; const log = console.log; console.log = (...a: unknown[]) => said.push(a.join(" ")); const crashed: unknown[] = []; const onRejection = (e: unknown) => crashed.push(e); process.on("unhandledRejection", onRejection); try { const refused = await bus.handleSubject!("mesh.seat.held-elsewhere.tool.databases", async () => ({ seat: true })); const stop = await bus.handle("alpha.ping", async () => ({ pong: true })); for (let i = 0; i < 50 && !said.some((s) => s.includes("the bus refused mesh.seat.held-elsewhere")); i++) await new Promise((r) => setTimeout(r, 50)); console.log = log; assert.ok(said.some((s) => /the bus refused mesh\.seat\.held-elsewhere\.tool\.databases.*serves on/.test(s)), said.join("\n")); assert.equal(crashed.length, 0, `the refusal escaped: ${String(crashed[0])}`); assert.deepEqual((await callTool(asker, "alpha.ping@anchor", {})).result, { pong: true }); stop(); refused(); } finally { console.log = log; process.off("unhandledRejection", onRejection); await asker.close(); await bus.close(); } });