test(authz): cover GHDR controller transport endpoints
This commit is contained in:
parent
6857684626
commit
12517bf2ba
1 changed files with 58 additions and 0 deletions
|
|
@ -731,6 +731,64 @@ test("GHDR double signing is email-authorized and bound to one canonical layout
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
|
test("GHDR controller transport endpoints expose jobs and public authority without private keys", async () => {
|
||||||
|
const calls = [];
|
||||||
|
await withServer(async ({ base }) => {
|
||||||
|
const publicResponse = await fetch(`${base}/api/ghdr/authorizer-public-key`);
|
||||||
|
assert.equal(publicResponse.status, 200);
|
||||||
|
const publicPayload = await publicResponse.json();
|
||||||
|
assert.equal(publicPayload.binding.algorithm, "Ed25519");
|
||||||
|
assert.equal(publicPayload.binding.public_key_sha256, "ab".repeat(32));
|
||||||
|
assert.doesNotMatch(JSON.stringify(publicPayload), /PRIVATE KEY/);
|
||||||
|
|
||||||
|
const pollBody = { request: { schema: "poll" }, request_signature_hex: "11" };
|
||||||
|
const poll = await fetch(`${base}/api/ghdr/controllers/poll`, {
|
||||||
|
method: "POST",
|
||||||
|
headers: { "content-type": "application/json" },
|
||||||
|
body: JSON.stringify(pollBody),
|
||||||
|
});
|
||||||
|
assert.equal(poll.status, 200);
|
||||||
|
assert.equal((await poll.json()).job.job_id, "job-1");
|
||||||
|
|
||||||
|
const resultBody = {
|
||||||
|
request: { schema: "result" },
|
||||||
|
request_signature_hex: "22",
|
||||||
|
signature: { signature_hex: "33" },
|
||||||
|
};
|
||||||
|
const result = await fetch(`${base}/api/ghdr/controllers/result`, {
|
||||||
|
method: "POST",
|
||||||
|
headers: { "content-type": "application/json" },
|
||||||
|
body: JSON.stringify(resultBody),
|
||||||
|
});
|
||||||
|
assert.equal(result.status, 403);
|
||||||
|
assert.equal((await result.json()).error, "controller_result_refused");
|
||||||
|
assert.deepEqual(calls, [
|
||||||
|
["poll", pollBody],
|
||||||
|
["submit", resultBody],
|
||||||
|
]);
|
||||||
|
}, {
|
||||||
|
getGhdrAuthorizer: () => ({
|
||||||
|
publicBinding: () => ({
|
||||||
|
schema: "guanghu.ghdr-authorizer-public-binding/v1",
|
||||||
|
authorizer_id: "JD-FD-PRIMARY-LAKE-LAMP",
|
||||||
|
algorithm: "Ed25519",
|
||||||
|
public_key_pem: "-----BEGIN PUBLIC KEY-----\nTEST\n-----END PUBLIC KEY-----\n",
|
||||||
|
public_key_sha256: "ab".repeat(32),
|
||||||
|
}),
|
||||||
|
}),
|
||||||
|
getGhdrControllerBroker: () => ({
|
||||||
|
poll: body => {
|
||||||
|
calls.push(["poll", body]);
|
||||||
|
return { ok: true, job: { job_id: "job-1" } };
|
||||||
|
},
|
||||||
|
submit: body => {
|
||||||
|
calls.push(["submit", body]);
|
||||||
|
return { ok: false, error: "controller_result_refused" };
|
||||||
|
},
|
||||||
|
}),
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
test("deployment is dispatched only by an explicit approved second signal", async () => {
|
test("deployment is dispatched only by an explicit approved second signal", async () => {
|
||||||
const dir = fs.mkdtempSync(path.join(os.tmpdir(), "lake-lamp-deploy-dispatch-"));
|
const dir = fs.mkdtempSync(path.join(os.tmpdir(), "lake-lamp-deploy-dispatch-"));
|
||||||
const mapsDir = path.join(dir, "maps"); fs.mkdirSync(mapsDir);
|
const mapsDir = path.join(dir, "maps"); fs.mkdirSync(mapsDir);
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue