package console import ( "errors" "strings" "testing" ) // A refusal is said only for the bus's own refusals; a tool's answer that mentions authorization is the // tool's answer, not the account's. func TestARefusalIsSaidOnlyForTheBussOwn(t *testing.T) { for msg, refusal := range map[string]bool{ `nats: Permissions Violation for Publish to "mesh.mod.x.tool.y"`: true, "nats: Authorization Violation": true, `claude-code's servers.all.x carries a field "Authorization", which names a credential`: false, } { got := strings.HasPrefix(whyItFailed("x.y", errors.New(msg)), "this account may not call") if got != refusal { t.Errorf("%q read as a refusal: %v, want %v", msg, got, refusal) } } } // **A timeout says it is not a failure** (novox/hq issue 265): a push that outlasted the wait had // pushed, and the caller read "did not answer in time". And from the controller, where its answer is. func TestATimeoutIsNotAFailure(t *testing.T) { got := whyItFailed("seat:mesh-controller.push", errors.New("timeout")) for _, want := range []string{"not a failure", "may already have done", "mesh-controller.calls"} { if !strings.Contains(got, want) { t.Errorf("a controller timeout does not say %q: %s", want, got) } } if other := whyItFailed("novox/postgres.postgres_list_databases", errors.New("timeout")); !strings.Contains(other, "not a failure") || strings.Contains(other, "calls") { t.Errorf("a module's timeout: %s", other) } }