afba622fb6
gates / gates (push) Successful in 59s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
66 lines
1.7 KiB
Go
66 lines
1.7 KiB
Go
package main
|
|
|
|
import (
|
|
"encoding/hex"
|
|
"io"
|
|
"log"
|
|
"os"
|
|
"path/filepath"
|
|
"testing"
|
|
|
|
"gitea.dooplex.hu/admin/felhom-hub/internal/store"
|
|
)
|
|
|
|
// Under `go test` every store seals with this fixed key (store.New, testing.Testing()).
|
|
const testKey = "felhom-hub-test-only-seal-key-32"
|
|
|
|
func seededCopy(t *testing.T) string {
|
|
t.Helper()
|
|
p := filepath.Join(t.TempDir(), "hub.db")
|
|
s, err := store.New(p, log.New(io.Discard, "", 0))
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
for _, h := range []string{"h1", "h2"} {
|
|
if err := s.UpsertHost(&store.Host{HostID: h, CustomerID: "c", APIKey: "k-" + h}); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
}
|
|
if err := s.SaveHostRecoveryCredential("h1", "root@pam", "console-pw"); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
s.Close()
|
|
return p
|
|
}
|
|
|
|
func keyFile(t *testing.T, key string) string {
|
|
t.Helper()
|
|
p := filepath.Join(t.TempDir(), "k")
|
|
if err := os.WriteFile(p, []byte(hex.EncodeToString([]byte(key))+"\n"), 0o600); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
return p
|
|
}
|
|
|
|
// The consequence the runbook relies on: the SAME key opens every vaulted console password of the restored copy.
|
|
func TestCheck_SameKeyOpensEveryConsolePassword(t *testing.T) {
|
|
r, err := check(seededCopy(t), keyFile(t, testKey))
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if r.hosts != 2 || r.opened != 1 || r.failed != 0 || r.absent != 1 {
|
|
t.Fatalf("got %+v, want hosts=2 opened=1 failed=0 absent=1", r)
|
|
}
|
|
}
|
|
|
|
// A different key opens nothing — so "opened" is evidence that the key matches, not that the column is readable.
|
|
func TestCheck_WrongKeyOpensNothing(t *testing.T) {
|
|
r, err := check(seededCopy(t), keyFile(t, "a-completely-different-key-32byt"))
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if r.opened != 0 || r.failed != 1 {
|
|
t.Fatalf("got %+v, want opened=0 failed=1", r)
|
|
}
|
|
}
|