key-cape/src/cmd/keycape/clients_test.go

72 lines
2.1 KiB
Go
Raw Normal View History

package main
import (
"keycape/internal/config"
"testing"
"time"
)
func TestServiceRegistrationAudienceAndScopeIsolation(t *testing.T) {
cfg, err := config.Load("../../../config/service-clients.example.yaml")
if err != nil {
t.Fatal(err)
}
for _, c := range cfg.Clients {
t.Setenv(c.SecretRef[4:], "test-only-secret")
}
registry, err := buildClientRegistry(cfg.Clients)
if err != nil {
t.Fatal(err)
}
for _, id := range []string{"secrets-engine-approval", "approval-engine-operator"} {
c := registry[id]
if c == nil || c.Audience != "approval-engine" || c.TokenLifetime != 15*time.Minute {
t.Fatalf("invalid registration for %s", id)
}
for _, scope := range c.AllowedScopes {
if id == "approval-engine-operator" && scope == "approval:consume" {
t.Fatal("operator may not consume")
}
if id == "secrets-engine-approval" && scope != "approval:read" && scope != "approval:consume" {
t.Fatal("excess PEP scope")
}
}
}
if registry["secrets-engine-openbao"].Audience != "" {
t.Fatal("OpenBao audience default changed")
}
}
// The Glas approval chain requires exact tenant spelling across the approval
// store, these JWT claims and the lifecycle CheckRequest (decision
// 5ed3fb35-eca9-413a-82b9-95171ba85bf6). Aliases to "platform" or
// "tenant:coulomb" are rejected, and unrelated clients keep their own tenant.
func TestServiceRegistrationTenantsAreExactPerDecision(t *testing.T) {
cfg, err := config.Load("../../../config/service-clients.example.yaml")
if err != nil {
t.Fatal(err)
}
want := map[string]string{
"secrets-engine-approval": "tenant:platform",
"approval-engine-operator": "tenant:platform",
"codex-railiance-platform": "tenant:coulomb",
"secrets-engine-openbao": "tenant:coulomb",
}
seen := map[string]bool{}
for _, c := range cfg.Clients {
expected, ok := want[c.ClientID]
if !ok {
t.Fatalf("unreviewed client %s has tenant %q", c.ClientID, c.Tenant)
}
if c.Tenant != expected {
t.Fatalf("%s: tenant %q, want exactly %q", c.ClientID, c.Tenant, expected)
}
seen[c.ClientID] = true
}
for id := range want {
if !seen[id] {
t.Fatalf("missing reviewed registration %s", id)
}
}
}