test(secrets-cli): structural no-plaintext assert (base64 '+' JSON-escaping flake) + override doc note
This commit is contained in:
@@ -99,7 +99,10 @@ public sealed class BundleService
|
|||||||
/// verbatim replicate would be silently rejected by the LWW gate, so that single case is written
|
/// verbatim replicate would be silently rejected by the LWW gate, so that single case is written
|
||||||
/// through <see cref="ISecretStore.UpsertAsync"/> instead — a local-write that restamps the row as
|
/// through <see cref="ISecretStore.UpsertAsync"/> instead — a local-write that restamps the row as
|
||||||
/// current, which is exactly what makes the operator's forced choice durable rather than flipped
|
/// current, which is exactly what makes the operator's forced choice durable rather than flipped
|
||||||
/// back on the next reconciliation.
|
/// back on the next reconciliation. Note the narrowed remnant of this: a
|
||||||
|
/// <paramref name="conflictOverride"/> that forces an <em>older, tombstoned</em> bundle row over a
|
||||||
|
/// newer live local row resurrects it, because that forced <see cref="ISecretStore.UpsertAsync"/>
|
||||||
|
/// path clears the tombstone.
|
||||||
/// </para>
|
/// </para>
|
||||||
/// </remarks>
|
/// </remarks>
|
||||||
/// <param name="session">The full session to import into.</param>
|
/// <param name="session">The full session to import into.</param>
|
||||||
|
|||||||
+6
-2
@@ -239,11 +239,15 @@ public sealed class BundleServiceTests : IDisposable
|
|||||||
string raw = await File.ReadAllTextAsync(BundlePath, CancellationToken.None);
|
string raw = await File.ReadAllTextAsync(BundlePath, CancellationToken.None);
|
||||||
Assert.DoesNotContain(sentinel, raw, StringComparison.Ordinal);
|
Assert.DoesNotContain(sentinel, raw, StringComparison.Ordinal);
|
||||||
|
|
||||||
// The base64 ciphertext of the sealed row is present in the file.
|
// The base64 ciphertext of the sealed row is present in the file. Assert structurally through
|
||||||
|
// the codec rather than by raw-text match: System.Text.Json escapes '+' as +, so a raw
|
||||||
|
// Contains on the base64 string is flaky whenever the ciphertext base64 contains a '+'.
|
||||||
StoredSecret? row = await source.Store.GetAsync(new SecretName("svc/secret"), CancellationToken.None);
|
StoredSecret? row = await source.Store.GetAsync(new SecretName("svc/secret"), CancellationToken.None);
|
||||||
Assert.NotNull(row);
|
Assert.NotNull(row);
|
||||||
Assert.Contains(Convert.ToBase64String(row!.Ciphertext), raw, StringComparison.Ordinal);
|
|
||||||
Assert.Contains("\"Ciphertext\"", raw, StringComparison.Ordinal);
|
Assert.Contains("\"Ciphertext\"", raw, StringComparison.Ordinal);
|
||||||
|
SecretBundle parsed = SecretBundleCodec.Deserialize(raw);
|
||||||
|
BundleEntry parsedEntry = Assert.Single(parsed.Entries);
|
||||||
|
Assert.Equal(Convert.ToBase64String(row!.Ciphertext), parsedEntry.Ciphertext);
|
||||||
}
|
}
|
||||||
|
|
||||||
[Fact]
|
[Fact]
|
||||||
|
|||||||
Reference in New Issue
Block a user