"authorization" alone matched a tool's own answer mentioning the word — the runtime refusing a state value with an Authorization header read as "this account may not call".
23 lines
793 B
Go
23 lines
793 B
Go
package console
|
|
|
|
import (
|
|
"errors"
|
|
"strings"
|
|
"testing"
|
|
)
|
|
|
|
// A refusal is said only for the bus's own refusals; a tool's answer that mentions authorization is the
|
|
// tool's answer, not the account's.
|
|
func TestARefusalIsSaidOnlyForTheBussOwn(t *testing.T) {
|
|
for msg, refusal := range map[string]bool{
|
|
`nats: Permissions Violation for Publish to "mesh.mod.x.tool.y"`: true,
|
|
"nats: Authorization Violation": true,
|
|
`claude-code's servers.all.x carries a field "Authorization", which names a credential`: false,
|
|
} {
|
|
got := strings.HasPrefix(whyItFailed("x.y", errors.New(msg)), "this account may not call")
|
|
if got != refusal {
|
|
t.Errorf("%q read as a refusal: %v, want %v", msg, got, refusal)
|
|
}
|
|
}
|
|
}
|