hub v0.129.0: operator raises ONE clean-up window's cap (R-833); restore-beside script + runbooks (R-834)
gates / gates (push) Successful in 30s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-04 08:56:56 +02:00
parent 3885640f66
commit 55f7621c90
20 changed files with 647 additions and 28 deletions
+22
View File
@@ -138,3 +138,25 @@ func TestOffsiteKeyEndpoints_AuthAndNoPasswordInAnyResponse(t *testing.T) {
t.Fatalf("service not reached: pub=%q fp=%q", f.gotPub, f.gotFP)
}
}
// R-833: a box cannot raise its own window cap. No box-authenticated route sets a grant, and a
// window-open body that names a cap is not a grant. Asserted on the consequence: the store holds no
// grant after every box call.
func TestOffsiteWindow_BoxCannotGrantItself(t *testing.T) {
h, st, _ := newTestHandler(t)
st.SaveCustomerConfig(&store.CustomerConfig{CustomerID: "c1", APIKey: "ckey", RetrievalPassword: "pp"})
h.SetOffsiteKeyService(&fakeKeySvc{})
for _, c := range []struct{ path, body string }{
{"/api/v1/offsite/window-open/c1", `{"count_before":40,"max_remove":400}`},
{"/api/v1/offsite/window-grant/c1", `{"max_remove":400}`},
{"/api/v1/offsite/window-large-grant/c1", `{"max_remove":400}`},
{"/offsite/window-grant/c1", `max_remove=400`},
} {
req := httptest.NewRequest(http.MethodPost, c.path, strings.NewReader(c.body))
req.Header.Set("Authorization", "Bearer ckey")
h.ServeHTTP(httptest.NewRecorder(), req)
}
if ok, n := st.TakeOffsiteWindowGrant("c1"); ok || n != 0 {
t.Fatalf("a box call left a grant (ok=%v max=%d)", ok, n)
}
}