70 lines
2.1 KiB
Go
70 lines
2.1 KiB
Go
package store
|
|
|
|
import (
|
|
"encoding/json"
|
|
"testing"
|
|
"time"
|
|
|
|
"git.ipao.vip/rogee/go-sip/contracts"
|
|
"git.ipao.vip/rogee/go-sip/internal/contract"
|
|
"git.ipao.vip/rogee/go-sip/internal/tenant"
|
|
)
|
|
|
|
func validAIReply(t *testing.T, now time.Time) []byte {
|
|
t.Helper()
|
|
raw, err := contracts.Files.ReadFile("upstream/" + contract.MQSourceCommit + "/examples/ai-config-result.json")
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
var message map[string]any
|
|
if err := json.Unmarshal(raw, &message); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
payload := message["payload"].(map[string]any)
|
|
authorization := payload["authorization"].(map[string]any)
|
|
delete(authorization, "allowed_egress_pool_ids")
|
|
authorization["config_sha256"] = payload["snapshot"].(map[string]any)["content_sha256"]
|
|
authorization["issued_at"] = now.Add(-time.Second).Format(time.RFC3339Nano)
|
|
authorization["expires_at"] = now.Add(time.Minute).Format(time.RFC3339Nano)
|
|
raw, err = json.Marshal(message)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
return raw
|
|
}
|
|
|
|
func TestCachedAIRequiresLiveBoundAuthorization(t *testing.T) {
|
|
s, err := Open(":memory:")
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
defer s.Close()
|
|
if err := s.BindDispatcherID(identityA); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
now := time.Date(2026, 9, 21, 0, 0, 1, 0, time.UTC)
|
|
s.now = func() time.Time { return now }
|
|
request, err := contracts.Files.ReadFile("upstream/" + contract.MQSourceCommit + "/examples/ai-config-request.json")
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if err := s.QueueAIConfigRequest(request); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
route, err := tenant.NewDispatcherRoute(identityA, "tenant-a")
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if err := s.StoreAIConfigResponse(validAIReply(t, now), route.InboundKey); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
snapshot, authorization, err := s.LoadAuthorizedAI("tenant-a", "tenant-a", "version-a")
|
|
if err != nil || len(authorization) == 0 || snapshot.AgentVersionID != "version-a" {
|
|
t.Fatalf("authorized cache: %v", err)
|
|
}
|
|
now = now.Add(time.Hour)
|
|
if _, _, err := s.LoadAuthorizedAI("tenant-a", "tenant-a", "version-a"); err == nil {
|
|
t.Fatal("expired cached authorization admitted work")
|
|
}
|
|
}
|